Privacy Policy
Last Updated: August 5, 2026
Introduction
Welcome to AirCheckIn. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our guest ID verification platform.
This policy is established in compliance with Moroccan Law n°09-08 on the protection of individuals with regard to the processing of personal data and its implementing decree, as enforced by the Commission Nationale de contrôle de la Protection des Données à caractère personnel (CNDP).
By using AirCheckIn, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.
1. Data Controller Identity
AirCheckIn is the data controller responsible for the personal data processed through this platform.
Email: privacy@aircheckin.co
The processing has been authorized by the CNDP under authorization number A-PO-311/2042, issued pursuant to decision n° 22-2024.
2. Information We Collect
2.1 Information You Provide
- Host Account Information: Name, email address, phone number, payment information, and property details
- Guest Verification Information: Guest names, email addresses, phone numbers, check-in/check-out dates, and booking references
- Identity Documents: ID cards, passports, and selfie photos submitted through the verification portal
2.2 Automatically Collected Information
- Device information (IP address, browser type, operating system)
- Usage data (pages visited, time spent, features used)
- Cookies and similar tracking technologies
- Bot protection data: When you create a host account, we display a Cloudflare Turnstile widget (visible mode) on the sign-up form. Turnstile processes technical signals such as your IP address, browser user-agent, TLS fingerprint, and site key to distinguish human users from bots. Cloudflare does not use Turnstile to identify you for advertising or profiling purposes.
2.3 Special Categories of Data
Identity documents (national ID cards, passports) and associated biometric-like data (selfie photos) constitute sensitive personal data under Law n°09-08. The processing of such data is authorized by the CNDP under authorization number A-PO-311/2042 (decision n° 22-2024) and is carried out exclusively for the purpose of fulfilling the guest registration obligations imposed by Moroccan Law n°80.14 on tourist accommodation.
3. Legal Basis for Processing
In accordance with Law n°09-08, we process your personal data on the following legal bases:
- Performance of a contract: To provide and maintain the AirCheckIn service you have subscribed to.
- Legal obligation: To enable Hosts to comply with Moroccan Law n°80.14 requiring the collection and recording of guest identity details.
- Legitimate interest: To detect and prevent fraud, ensure platform security, and improve our services.
- Consent: Where required by law (e.g., for certain cookies and marketing communications), we will request your prior, free, specific, and informed consent.
4. Purpose Limitation and Data Minimization
Personal data is collected for specified, explicit, and legitimate purposes and is not processed in any manner incompatible with those purposes. We collect only the data that is adequate, relevant, and not excessive in relation to the purposes for which it is processed:
- Host account data is used solely to operate, maintain, and bill the Service.
- Guest identity documents are used solely to fulfil the regulatory obligations of Law n°80.14 and to generate the Bulletin Individuel d'Hébergement.
- Automatically collected technical data is used solely for security, performance, and service improvement.
5. How We Use Your Information
We use the collected information to:
- Provide and maintain our guest verification services
- Process verification requests and store identity documents securely
- Send verification links and notifications to guests
- Manage host subscriptions and process payments
- Comply with Moroccan regulatory requirements for guest registration (Law n°80.14)
- Improve our services and develop new features
- Detect and prevent fraud, security threats, or illegal activities
- Communicate with you about your account and our services
6. Data Sharing and Disclosure
We may share your information with:
- Service Providers: Third-party companies that help us operate our platform (payment processing, email delivery, cloud storage, bot protection). Each sub-processor is bound by contractual data protection obligations that are at least as protective as those in this policy.
- Cloudflare Turnstile: We use Cloudflare Turnstile on our sign-up page to protect against automated abuse. Cloudflare processes the signals described above on our behalf to verify that sign-up requests come from humans. For details on how Cloudflare handles Turnstile data, see the Cloudflare Turnstile Privacy Addendum, which supplements Cloudflare's main Privacy Policy. If you have questions about Turnstile data processed to provide this service, you may contact us at privacy@aircheckin.co.
- Legal Authorities: When required by law or to comply with legal processes, including Moroccan tourism and public security authorities.
- Business Transfers: In connection with any merger, sale, or acquisition of all or part of our company, subject to the prior information of data subjects.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
7. Data Security
We implement appropriate administrative, technical, and organizational security measures to protect your information against loss, alteration, unauthorized disclosure, or access, as required by Article 23 of Law n°09-08, including:
- Encryption of data in transit and at rest
- Secure cloud storage with access controls
- Regular security audits and vulnerability assessments
- Limited employee access to personal data on a need-to-know basis
- Row Level Security (RLS) policies in our database
While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
In the event of a personal data breach likely to adversely affect the rights or privacy of data subjects, we will take all necessary steps in accordance with applicable law.
8. Data Retention
In accordance with Article 20 of Law n°09-08, personal data is kept in a form that allows identification of data subjects for no longer than is necessary for the purposes for which it is collected. Specifically:
- Host account data is retained for the duration of the contractual relationship and for the period required by applicable accounting and commercial law thereafter.
- Guest identity documents and Bulletins Individuels d'Hébergement are retained for the minimum period prescribed by Moroccan Law n°80.14 and related regulations.
- After the applicable retention period, data is securely deleted or anonymized unless retention is required to resolve disputes, enforce agreements, or comply with legal obligations.
9. Your Rights Under Law n°09-08
In accordance with Articles 7, 8, 9, and 10 of Moroccan Law n°09-08, you have the following rights regarding your personal data:
- Right of Access (Art. 7): You may obtain confirmation of whether personal data concerning you is being processed and, if so, receive a copy of that data and information about the processing.
- Right to Rectification (Art. 8): You may request the correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 8): You may request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
- Right to Object (Art. 10): You may object, on legitimate grounds, to the processing of your personal data. You may also object, without justification, to the processing of your data for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
To exercise any of these rights, please submit a written request to privacy@aircheckin.co with the subject line "Data Rights Request", together with proof of your identity. We will respond within a reasonable period.
9.1 Right to Lodge a Complaint with the CNDP
If you believe that the processing of your personal data infringes Law n°09-08, you have the right to lodge a complaint with the CNDP:
Commission Nationale de contrôle de la Protection des Données à caractère personnel (CNDP) Website: www.cndp.ma Address: Angle Avenue Annakhil et Rue Mozambique, Hay Riad, Rabat, Morocco
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience. Cookies are small data files stored on your device that help us:
- Remember your preferences and settings
- Maintain your session and keep you logged in
- Analyze site usage and improve our services
- Provide personalized content and features
- Run bot protection through Cloudflare Turnstile on the sign-up page
Cookies that are not strictly necessary for the operation of the Service are set only with your prior consent. You may withdraw your consent at any time by adjusting your browser settings or using our cookie preference center.
Cloudflare Turnstile: The signals and cookies used by Turnstile are strictly necessary to detect and block bots and to keep the sign-up process secure. We reference Cloudflare's Turnstile Privacy Addendum for additional information about the data Turnstile collects and how Cloudflare uses it, including when Turnstile is shown in visible mode on our site.
11. Children's Privacy
AirCheckIn is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
12. International Data Transfers
Certain personal data may be transferred to, and processed on, servers located outside Morocco, including for cloud hosting and operational services. In accordance with Article 43 of Law n°09-08, such transfers are carried out only:
- To countries recognized by the CNDP as providing an adequate level of protection; or
- Subject to prior CNDP authorization and the implementation of appropriate safeguards (such as standard contractual clauses or binding corporate rules) that guarantee an equivalent level of protection to that afforded by Moroccan law.
By using AirCheckIn, you acknowledge that your data may be transferred outside Morocco under these conditions.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by posting the updated policy on our website and updating the "Last Updated" date.
Your continued use of AirCheckIn after changes are posted constitutes your acceptance of the updated policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: privacy@aircheckin.co Support: support@aircheckin.co
For privacy-related inquiries, please use the subject line: "Privacy Request"