Privacy Policy
How Crystal Reef Bookings collects, uses, and protects your personal information.
Last Updated: July 2026
1. Who We Are
Crystal Reef Bookings is a trading name of Raphael Pierre Payet, who operates in the Republic of Seychelles under Commission Agent (Tourism Related Activities) Licence No. 926592 . We act as a booking agent, arranging excursions, transportation, and related tourism services that are delivered by independent operators.
For the purposes of data protection law, Raphael Pierre Payet, trading as Crystal Reef Bookings, is the data controller responsible for the personal information described in this policy. Any request you make about your data, and any complaint, is made against the controller.
- Data controller: Raphael Pierre Payet, trading as Crystal Reef Bookings
- Email: [email protected]
- Phone / WhatsApp: +248 2578695
- Location: Anse Lazio, Praslin, Seychelles
We serve visitors from around the world, including the European Union and the United Kingdom. Where the General Data Protection Regulation (GDPR) applies to you, this policy explains the rights it gives you and how to exercise them.
2. Information We Collect
When you submit a booking request, we collect:
- Your full name
- Your email address
- Your phone number
- Your travel dates and pick-up time
- The number of people travelling
- Pick-up and drop-off locations, including the map coordinates you pin
- The service, option, or package you selected
- Any special requests you choose to write
When you use the contact form, your name, your email address, and your message are placed into a WhatsApp message that you then choose to send us. The form does not submit anything to this website — the message reaches us through WhatsApp, and WhatsApp processes it under its own privacy policy. We receive whatever you send and use it only to reply.
When you leave a review after your trip, we collect your ratings and your written review. Your review is published under your first name only — never your surname, email, phone number, or booking reference.
Automatically, when you submit a form, we process your IP address as part of a security check that protects the site from automated abuse and spam.
We do not collect payment card details through this website. No payments are taken online — all payments are completed onsite.
3. Why We Use Your Information, and Our Legal Basis
We only use your personal information for the purposes set out below. Under the GDPR, each purpose relies on a specific legal basis:
- To arrange and deliver your booking — confirming availability, coordinating with the operator, sending confirmations and updates, and providing customer support. Legal basis: performance of a contract with you.
- To contact you about your booking by email, telephone, or WhatsApp, until your booking is finalised. Legal basis: performance of a contract with you.
- To protect the website from spam and automated abuse, using your IP address. Legal basis: our legitimate interest in keeping the service secure and available.
- To invite you to review your experience after your trip has ended, and to publish your review if you submit one. Legal basis: our legitimate interest in improving and promoting our services.
- To understand which countries our customers book from — we record, as part of your booking, the country indicated by your phone number's international dialling code (for example, +49 for Germany), and use it to produce aggregated statistics on where our bookings come from. These statistics help us decide which markets to advertise in and which languages to prioritise. They are counts per country only and are never used to single you out or to send you anything. Legal basis: our legitimate interest in understanding and developing our business.
- To keep accounting and tax records of the bookings we have handled. Legal basis: compliance with a legal obligation.
- To send you offers and news, but only if you tick the optional marketing box on the booking form. Legal basis: your consent.
Marketing is entirely optional. The box is never ticked for you, booking with us does not depend on it, and you can withdraw your consent at any time by contacting us or using the unsubscribe link. Withdrawing it does not stop the messages we must send to arrange your booking.
Beyond the aggregated country statistics described above, we do not use your information for advertising, profiling, or automated decision-making, and we never sell it.
4. Cookies
This website uses strictly necessary cookies only . These are required for the site to function and cannot be switched off. They are used to:
- Protect forms against cross-site request forgery
- Keep your session active while you move between pages
- Display one-off status messages, such as a booking confirmation
We do not use analytics cookies, advertising cookies, or any third-party tracking cookies. Because we set no non-essential cookies, no cookie consent banner is required.
If we introduce analytics or any other non-essential cookie in the future, we will update this policy and ask for your consent before setting it.
5. Who We Share Your Information With
We do not sell your personal information, and we do not share it for anyone else's marketing.
We share your booking details with the independent operator who delivers your excursion, transfer, or rental, so that they can provide the service you booked.
We also rely on a small number of trusted service providers who process data on our behalf:
- Railway — website and database hosting
- Cloudflare — DNS, image and file storage, and the Turnstile security check that processes your IP address when you submit a form
- Resend — sending booking confirmation and notification emails
- MapTiler — powering the map on our booking form. When you search for an address or set a pin, your IP address and the text you type into the map search are sent to MapTiler.
- WhatsApp (Meta) — carrying the messages you send us through our contact form, and any booking correspondence we exchange with you on WhatsApp. Meta processes these under its own privacy policy, not ours.
We self-host our fonts, so no font provider receives your IP address. Some pages still load icons and styling from third-party content delivery networks — jsDelivr, unpkg, and cdnjs. When your browser requests those files, your IP address is visible to those providers.
We may also disclose information where we are required to do so by law, or to establish, exercise, or defend legal claims.
6. International Transfers
We operate from the Seychelles, and the providers listed above may store or process your information on servers located outside the Seychelles and outside the European Economic Area.
Where information is transferred out of the EEA or the United Kingdom, we rely on our providers' Standard Contractual Clauses or an equivalent safeguard recognised under the GDPR.
7. How Long We Keep Your Information
We keep your personal information only for as long as we need it:
- Booking and invoicing records — retained for seven years after the booking, to meet accounting and tax obligations.
- Messages you send us by WhatsApp or email — retained for up to twelve months after we reply. These are not stored in this website's database.
- Marketing consent — retained, together with the date you gave it, for as long as you remain opted in, and for two years afterwards so we can evidence that the consent was given and later withdrawn.
- Published reviews — retained for as long as the review remains published. You may ask us to remove it at any time.
- Review invitation links — expire automatically thirty days after they are sent.
8. Your Rights
Depending on where you live, and in all cases where the GDPR applies to you, you have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate or incomplete
- Erase your information, where we have no overriding legal reason to keep it
- Restrict or object to our use of your information, including any use based on our legitimate interests
- Receive your information in a portable format (data portability)
To exercise any of these rights, contact us at [email protected]. We will respond within one month. We may ask you to confirm your identity first.
Please note that where we are legally required to retain booking and accounting records, we may not be able to erase them until that period has passed.
If you believe we have handled your information improperly, you have the right to lodge a complaint with a supervisory authority — in the EU, the data protection authority in the country where you live or work. We would appreciate the chance to address your concern directly first.
9. How We Protect Your Information
This website is served over an encrypted HTTPS connection. Access to booking data is limited to authorised staff and to the operator assigned to your booking.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Children
This website is not directed at children, and we do not knowingly collect information from children. Bookings that include children are made by an adult, who provides the participant details.
11. Changes to This Policy
We may update this Privacy Policy from time to time — for example if we introduce new features, change service providers, or begin using analytics.
When we do, we will revise the Last Updated date at the top of this page. Where the change is significant, we will make it clear on the site. If a change requires your consent, we will ask for it before it takes effect.
12. Contact Us
If you have questions about this Privacy Policy, or about how we handle your personal information, please contact the data controller:
- Data controller: Raphael Pierre Payet, trading as Crystal Reef Bookings
- Email: [email protected]
- Phone / WhatsApp: +248 2578695
- Location: Anse Lazio, Praslin, Seychelles
See also our Terms & Conditions .