Privacy Policy
Last updated: 3 September 2026
This policy explains what personal data we process, why, who we share it with and what you can require from us. It is written to be read — if any part is unclear, write to us and we will explain.
1. Who processes your data
The controller is Golden Sardines, Lda, company number 514133180, registered at Rua Ramalho Ortigão, 8200-604 Albufeira, Portugal, trading as Algarve Moments (RNAAT 1319/2016 · RNAVT 9292).
For anything to do with privacy, including exercising your rights, the contact is info@algarvemoments.pt. We reply in Portuguese or English.
We have not appointed a data protection officer: the law requires one only from those who process data on a large scale, systematically monitor people, or handle sensitive data in volume, and that is not our case. The company itself answers, at the address above.
2. What we collect, why, and on what basis
We collect only what we need in order to answer you and to arrange your experience. This site has four different paths, and the data changes with the path — each experience page always says which one it is on:
- When you contact us or ask for a quote — by form, email, phone or WhatsApp: your name, the contact detail you used and what you wrote to us, plus dates and party size if you mention them. We process these to reply and to prepare the proposal you asked for (pre-contractual steps, article 6(1)(b) GDPR). The transfer request also carries your express consent — see point 3.
- When you buy on this site: your name, email and phone number — the booking is held in your name — and your tax number, if you ask for an invoice with it. You may write each participant’s name, but you do not have to: leave it blank and it becomes "Visitor 1", "Visitor 2", and the booking still goes through. There is one exception: on the swim-with-dolphins experiences the park requires each participant’s date of birth, sex and country, from age 6 upwards — it is a safety rule of theirs, and without those details the booking cannot be made. We process all of this to perform the contract (article 6(1)(b) GDPR) and, as regards the invoice, to comply with Portuguese tax law (article 6(1)(c) GDPR). Payment is handled by Stripe: we know that you paid and how much, never your card number.
- When you book in a partner’s system: some pages open the operator’s own booking system, and the details you enter are collected by that platform, under its own privacy policy. What reaches us is the confirmation, with your name and contact, so we can follow the service through and help if something goes wrong (performance of the contract).
- When you visit the site: nothing that identifies you. We carry no advertising, we do not track you and we do not count visits — since 3 September 2026 there is no analytics tool here at all. The cookies on the site store preferences of yours and stay on that device. The detail of all this is in the Cookie Policy.
3. The forms on this site
The transfer request sends your details to a server of ours, which forwards them by email to our inbox. Before it is sent we ask for your express permission through a box that starts unticked — that is your consent (Article 6(1)(a) GDPR) and you may withdraw it at any time by writing to us.
We receive your name, your email, your phone number if you give it, the route you chose and whatever you write to us. We use them to reply and to arrange the transport, and they stay in our inbox — we do not build a marketing contact list and we do not send you marketing. The email itself is sent through Resend (see point 4).
We also keep, in an internal log, the shape of the request: the route, the date, how many people, which vehicle, and whether it came with a message. Without your name, your email, your phone number or what you wrote. It exists so we can see what people ask us for and where our offer falls short, not to talk to you — it is a legitimate interest of ours (article 6(1)(f) GDPR), and you may object to it.
The contact, group and agency forms still work differently: they send nothing to a server of ours, they open your email programme or WhatsApp with the message already written, so that you are the one who sends it. There, your data only reaches us when you press "send", and by the channel you chose.
We do not use reCAPTCHA or any other third-party system to tell people from robots. This site’s defences run on our own server and share nothing with you or about you. To stop bulk submissions, the server keeps the address a submission came from for ten minutes — in memory only, never written to a file or a database, and gone once those minutes pass.
4. Who we share with, and why
We sell data to nobody and pass it to nobody for third-party marketing. We share only what is necessary, and only with:
- The operator running the experience you booked — they need your name, contact and party size in order to receive you. Where it is the operator who issues the ticket, they also receive the participant details their system requires, through the direct connection between our site and theirs. Each operator is responsible for the data it processes; the operators we work with are identified on the experience pages.
- Pluralo and FareHarbor — the platforms where some bookings are made. When you book through one of them, the details you enter are also processed by that platform, under its own privacy policy.
- Stripe — processing of payments made on this site. We neither receive nor store your card number.
- Supabase — the database where purchases and requests are kept: your name, contact details, your tax number if you gave one, and the detail of what you bought. It is what lets us reissue a document, answer a question months later and account for a sale. The servers are in the European Union.
- ZoneSoft — the certified invoicing software we use to issue invoices. It receives what tax law requires the invoice to carry: your name and your tax number, when you ask for an invoice with it.
- Resend — the service that delivers our email. It handles your transfer request message and our purchase confirmations, so that they reach our inbox and the documents reach you.
- Our web host (Vercel), which keeps the site online and records technical requests, including IP addresses, for security and diagnosis. That is all Vercel handles for us: their analytics tool was switched off on 3 September 2026.
- Public authorities, where the law requires it — for example the Portuguese tax authority, as regards invoicing, or the maritime authorities, as regards participant lists for activities at sea.
5. Where the data sits, and transfers outside the European Union
Purchases and requests recorded on this site are held in a database hosted in the European Union.
Some of the providers in point 4 are US companies, or process data outside the European Economic Area. Where that happens, the transfer relies on the mechanisms set out in the GDPR: the European Commission’s adequacy decision for the EU-US Data Privacy Framework, where the provider is certified under it, and standard contractual clauses approved by the European Commission in the remaining cases.
6. How long we keep it
- Messages and quote requests that did not lead to a booking: up to 1 year, so we can pick the conversation back up if you contact us again.
- Purchases and bookings: for the duration of the contractual relationship and, after it, for as long as they may be needed to exercise or defend legal claims.
- Invoicing documents: 10 years, as Portuguese tax law requires. That is the period that overrides a request for erasure — an invoice cannot disappear simply because the purchase was long ago.
- The log of the shape of requests, described in point 3: it stays with us, because it identifies nobody.
- Technical hosting logs: short periods, set by the provider, for security and diagnosis only.
7. Your rights
You may ask us for access to your data, for it to be corrected or erased, for processing to be restricted, for portability, and you may object to processing we carry out on the basis of our legitimate interest. Where processing relies on your consent, you may withdraw it at any time, without affecting what was done beforehand.
Just write to info@algarvemoments.pt. We reply within one month. We may need to confirm your identity before acting on a request — that is a protection for you, not an obstacle.
If you believe we have not handled the matter as we should, you have the right to lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD), the Portuguese supervisory authority: Av. D. Carlos I, 134 — 1.º, 1200-651 Lisbon, www.cnpd.pt.
8. Security
The site is served entirely over an encrypted connection (HTTPS). The purchases database can only be reached from our server, with a key that never reaches your browser, and access to customer information is limited to those who need it in order to work.
Even so, no system is infallible: should a data breach ever occur that could put you at high risk, you will be informed, as the law requires.
9. Children
Many of our experiences welcome families, which is why it is worth being exact. On park admission tickets we collect no children’s data at all: the booking is held in the name of the adult who makes it, and writing each participant’s name is optional. The one exception is the swim-with-dolphins experiences, where the park requires each participant’s date of birth, sex and country from age 6 upwards — details you give us, as the responsible adult, which serve only for the park to register the participant and apply its own age and safety rules. They are used for nothing else, and we do not verify them: what you tell us is what goes to the park, and it is the park that may ask for ID at the entrance if it has doubts about an age.
We do not direct marketing at minors and do not collect data from them directly.
10. Changes to this policy
When this policy changes, the date at the top changes with it. Material changes — such as our starting to store data we do not store today — are made before the change goes live, not after.
Contact for privacy matters: info@algarvemoments.pt · See also Cookies · Terms & Conditions.