Privacy & cookies
Last updated: October 6, 2026
This policy explains what personal data Tamraght Forum handles and why. It follows Moroccan Law 09-08 on the protection of personal data and, where it applies, the EU General Data Protection Regulation (GDPR).
Who is responsible
Noeris SARLAU (Noeris Studio) — contact@noeris.studio. CNDP reference: Declaration with the CNDP in progress
What we collect
- Account: username, email address, password (stored only as a one-way hash), display name, account type.
- Profile and pages: what you choose to add — bio, area, photos, and for artists, businesses and organisations the details on their page (description, category, address, phone, opening hours, links).
- Verification: the information you give when applying (portfolio link, business details, notes).
- Activity: topics, replies, images, events and RSVPs, poll votes, meetups, offers, reports you send, notifications.
- Security: failed login attempts are counted against a hashed IP address for 15 minutes; our host keeps standard server logs (IP address, browser) for security.
We do not use advertising, analytics or tracking cookies, and we never sell personal data.
Why
- To run your account and the features you use (performance of our terms).
- To moderate, prevent abuse and keep the site secure (legitimate interest).
- To verify artist, business and organisation accounts (at your request).
- To meet legal obligations when they apply.
What is public
Your display name, picture, profile and posts are public. Contact details you add to an artist, business or organisation page are public. Your email address is never shown publicly. Poll votes are anonymous to other members.
Who receives data
Our host, Hostinger, stores the site and its database. Weather, marine and exchange-rate data are fetched by our server, so your device does not contact those services. When you follow a link to another site (Surfline, maps, a business’s website), that site’s own policy applies. We share data with authorities only when legally required.
How long
- Account and profile data: until you delete your account.
- Posts and replies: kept after account deletion but no longer linked to you (“Former member”).
- Verification information: as long as the account exists.
- Login-attempt counters: 15 minutes. Server logs and backups: for the limited period set by our host.
Your rights
You can access, correct, download and delete your data. Most of this is self-service: edit your profile in your dashboard, and use “Your data” to download a copy or delete your account. For anything else, contact us. You can also object to certain uses, and complain to the CNDP (cndp.ma) or, in the EU, to your data protection authority.
Security
The site uses HTTPS, hashed passwords, protection against forged requests and repeated login attempts, and restricted administrator access. No online service can be completely secure; if a breach affected your data, we would inform you and the authorities as required by law.
Children
The forum is for people aged 16 and over.
Cookies
We only use cookies needed for the site to work, so no consent banner is required:
wordpress_logged_in_*,wordpress_sec_*,wordpress_test_cookie: keep you logged in (session, or 14 days with “remember me”).tmf_lang: remembers your language (1 year).tmf_mode: remembers day or night mode if you switch it (1 year).
Changes
We will update this page if our practices change; the date above shows the current version.