Skip to content

Privacy Policy

What personal data we collect when you book with SeaExplore, who else touches it, how long we keep it and how to get it removed.

Last updated 20 August 2026.

1.Who is responsible for your data

BILI (OIB 57502897113), Trogir, Croatia, trading as SeaExplore, is the data controller for personal data collected through sea-explore.com.

For anything in this policy, or to exercise any of the rights described below, write to info@sea-explore.com or call +385 99 210 7755. We do not have a designated Data Protection Officer — the owner handles these requests directly.

2.What we collect, and why

We collect only what a booking actually needs. There is no account to create and no marketing profile built.

  • Booking: your name, email address, mobile number, chosen tour, date, departure, number of guests and pickup point. Legal basis — performance of the contract you enter with us.
  • Enquiries: name, email, mobile number and whatever you write in the message. Legal basis — steps taken at your request before entering a contract.
  • Payment record: the amount, the deposit paid and the payment provider's order reference. Legal basis — contract, plus our legal obligation to keep accounting records.
  • Website analytics: pages viewed, device and approximate location, and completed bookings. Legal basis — our legitimate interest in understanding how the site is used. See section 5, which explains how to opt out.

We never ask for and never receive your full card number. Card details are entered on the payment provider's own systems, not ours.

3.Who else processes it

We use a small number of service providers. Each processes data only on our instructions and under a data processing agreement.

  • Viva.com — card payments and payment security. Receives your name, email and payment details directly.
  • Supabase — the database holding your booking record.
  • Resend — sends your confirmation email and notifies us of new bookings.
  • Vercel — hosts the website and serves the pages you request.
  • Google Analytics 4 — aggregate usage statistics and completed-booking events.
  • Microsoft Clarity — usage analytics, including session recordings and heatmaps (see section 5).

We do not sell your data, and we do not share it with anyone for their own marketing.

Some of these providers are based outside the European Economic Area, primarily in the United States. Where that is the case, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.

4.How long we keep it

  • Booking and payment records: kept for as long as Croatian accounting and tax law requires us to retain them, which is currently eleven years from the end of the business year.
  • Enquiries that do not lead to a booking: deleted within 12 months.
  • Analytics data: retained according to each provider's default period — currently 14 months for Google Analytics and 30 days for Clarity recordings.

When a retention period ends, the data is deleted or irreversibly anonymised.

5.Cookies, analytics and session recording

This site uses two analytics tools, and we want to be plain about what one of them does.

  • Google Analytics 4 sets cookies and reports aggregate statistics: which pages are visited, roughly where visitors come from, and which bookings complete.
  • Microsoft Clarity records how visitors interact with pages — mouse movement, scrolling, clicks and taps — and can replay those sessions. Clarity automatically masks text you type into form fields, so what you enter into a booking form is not captured in the recording.

Neither tool runs on our administrator pages, so recordings never capture other guests' booking details.

At present these tools load when the page loads. You can prevent them entirely by using your browser's tracking protection, an ad or script blocker, or Google's official opt-out add-on for Analytics. If you would prefer we delete analytics data associated with your visit, write to us and we will pass the request on.

Aside from analytics, the site sets one short-lived cookie remembering the language you booked in, so the confirmation page appears in the right language. It expires after two hours and contains nothing else.

6.Your rights

Under the General Data Protection Regulation you can ask us to:

  • give you a copy of the personal data we hold about you,
  • correct anything inaccurate,
  • delete your data, where we are not legally required to keep it,
  • restrict or object to processing based on our legitimate interests,
  • provide your data in a portable, machine-readable format.

Write to info@sea-explore.com and we will respond within one month. There is no charge, and you do not need to give a reason.

If you think we have handled your data badly, you can complain to the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, Zagreb, or to the supervisory authority in your own country of residence.

7.Security

The site is served over HTTPS, our administrator area is password-protected, and access to the booking database is limited to the owner and the systems that need it. Payment card data never reaches our servers.

No system is perfectly secure. If a breach ever affected your data and posed a real risk to you, we would tell you and the supervisory authority as the GDPR requires.

8.Children

Our tours welcome children, but the site is not directed at them and we do not knowingly collect data from anyone under 16. Bookings are made by the accompanying adult, who provides the contact details.

9.Changes to this policy

If we add a service provider or change what we collect, we will update this page and the date at the top. Material changes affecting how we use data you have already given us will be communicated to you directly.

BILI · OIB 57502897113 · Trogir, Croatia
info@sea-explore.com · +385 99 210 7755