Privacy policy.
Arabian Wonders DMC, operated by Ramz al Masira International LLC, is an Omani company registered in the Sultanate of Oman. This policy explains what information we collect, why we collect it, what we do with it, and the rights you have over it. It applies to arabian-wonders.com.
We are governed by the laws of Oman, including its Personal Data Protection Law. We are not an EU company and this policy is not a GDPR notice. We have nonetheless chosen to hold ourselves to a standard equivalent to the EU General Data Protection Regulation for every client and every traveller, wherever they are based, because our partner agencies expect it and because we believe it is the right way to treat the people who trust us with a trip.
For questions, write to info@awdmc.com.
Our commitments
- We never sell, rent or trade your data. Not to advertisers, data brokers, or anyone else. This has never been part of our business and never will be.
- We collect only what a trip needs. Traveller data goes only to the hotels, guides and suppliers running that specific booking.
- We never market to travellers. Our clients are agencies; their travellers are not our leads.
- We delete when we are done. Traveller data is removed once the trip concludes, except where Omani accounting law requires booking records to be kept.
- Same standard for everyone. The rights in §7 apply to you regardless of your country of residence.
- We support your own compliance. Partner agencies in the EU/EEA, UK, Norway or elsewhere can request a data-processing agreement, including the EU Standard Contractual Clauses where their rules require them.
1. Information we collect
1.1 Personal information you give us.
When you contact us via email or the brief form, you share:
- Name and work email address.
- Agency or company name, the country it is based in, and the type of business.
- Phone or WhatsApp number (optional).
- The contents of your brief — trip type, hotel tier, budget band, dates, number of travellers, and how you found us (optional).
1.2 Non-personal information collected automatically.
When you visit the website, our hosting provider and analytics processor may collect technical information including:
- Browser type and version.
- Operating system.
- Truncated IP address (full IP is not stored — see §4.2).
- Referring website or search engine.
- Pages viewed and approximate time spent.
Analytics data is collected only after you give consent via the cookie banner. If you decline, analytics are not loaded.
2. Data about your clients (travellers)
When a partner agency sends us a booking, they share personal data about the travellers on that trip. Depending on what the hotels, permits or activities require, this can include:
- Full names.
- Passport data, where hotels or permits require it.
- Dates of birth.
- Contact numbers.
- Dietary and accessibility notes.
For this data, Arabian Wonders acts as a processor on the partner agency's documented instructions, not as controller. We share it only with the hotels, guides, transport and activity suppliers needed to run that specific booking. We never market to travellers, and we delete their data once the trip has concluded, except where Omani accounting law requires us to retain booking records (see §6). A data-processing agreement — including the EU Standard Contractual Clauses where your agency's own rules require them — is available on request from info@awdmc.com.
3. How we use your information
- To respond to your inquiry and prepare a quote.
- To deliver the trip you have booked, where applicable.
- To send occasional, non-marketing operational updates (e.g., trade-show invitations or new-itinerary notes) — only if you have opted in.
- To improve the website by understanding which pages are useful.
- To meet legal and tax obligations (e.g., audit trails for booked trips).
We do not sell, rent, trade, or share your personal data for third-party marketing.
4. Sub-processors
We rely on a small number of vetted service providers to operate this website and process inquiries.
4.1 Hosting — Firebase Hosting (Google LLC).
The website is hosted on Firebase Hosting, a service of Google LLC. Server logs (request URL, timestamp, truncated IP, user agent) are retained for security and abuse-prevention purposes. Google's data-processing terms apply. Data may be transferred to and stored in countries outside the EU/EEA, including the United States, under standard contractual clauses. See: firebase.google.com/support/privacy.
4.2 Analytics — Google Analytics 4.
We use Google Analytics 4 (GA4) to count visits and understand
which pages are useful. GA4 is loaded only after you consent via
the cookie banner. GA4 does not log or store IP addresses. Cookies
set by GA4 (_ga, _ga_*) expire after
13 months.
See: policies.google.com/privacy.
4.3 Inquiry form — Firebase (Google LLC), no third-party relay.
The brief you send via the form on our contact and market pages is
written directly to our own database (Cloud Firestore, part of the
Firebase/Google Cloud infrastructure already covered by §4.1 — no
separate sub-processor). It is protected in transit and at rest,
restricted by access rules so it cannot be read back over the web,
and guarded against automated submissions by Firebase App Check
(Google reCAPTCHA Enterprise, which scores the browser session —
it does not receive the contents of your brief). A notification is
then sent to our mailbox
(info@awdmc.com) and a short
confirmation to the email address you provided. No third party
relay handles or stores your submission at any point. Alongside
the fields you fill in, the form also records the page and
referring site you arrived from, the first page you landed on in
your browsing session, any utm_ campaign parameters
in the URL, your browser's language setting, and whether you had
given analytics consent — so we can tell which pages and
campaigns bring in enquiries. Data is
stored in our Firestore database (EU multi-region: Belgium and the
Netherlands) for as long
as the inquiry or resulting booking is active (see §6).
See: firebase.google.com/support/privacy
and Google reCAPTCHA Enterprise data use.
4.4 Consent management — Klaro.
The cookie consent banner is provided by Klaro
(KIProtect GmbH, Germany), an open-source tool. Klaro stores
your preferences in a first-party cookie (aw-consent)
on your device only — no data is sent to third parties.
See: klaro.kiprotect.com.
5. Cookies
We use the following cookie categories:
- Strictly necessary. The Klaro consent cookie (
aw-consent). Cannot be disabled. - Analytics (optional). Google Analytics 4 cookies. Loaded only after consent.
You can change or withdraw your consent at any time via the "Manage cookies" link in the footer. Disabling cookies does not affect site functionality.
6. Data retention
- Inquiries that do not lead to a booking: retained for up to 24 months, then deleted.
- Booking records: retained for the period required by Omani tax and accounting law (currently 10 years).
- Analytics data: retained for 14 months.
- Server logs: retained for 30 days.
7. Your rights
Wherever you are based, we extend the following rights to you. They mirror those granted under GDPR, and we honour them for every client and traveller, not only those in the EU/EEA:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion ("right to be forgotten"), subject to our legal retention obligations.
- Restrict or object to processing.
- Receive your data in a portable format.
- Raise a complaint with the data protection authority in your country. We will cooperate fully with any such inquiry.
To exercise any of these rights, write to info@awdmc.com. We will respond within 30 days.
8. International transfers
Arabian Wonders is based in Muscat, Oman, and our team works with your data there. Your inquiry itself is stored in our Firestore database in the EU (multi-region: Belgium and the Netherlands). Our sole sub-processor, Google LLC (Firebase/Google Cloud, covering hosting, analytics and the inquiry form — see §4), operates globally and is bound by its own data-processing terms and the European Commission's Standard Contractual Clauses.
If your agency is in the EU/EEA, UK or Norway, sending traveller data to us is an international transfer under your own rules. We make that straightforward: we will sign the EU Standard Contractual Clauses (controller-to-processor module) with your agency on request, and we apply the safeguards described in this policy to all data regardless of where it originated.
9. Security
The website is served exclusively over HTTPS. Hosting and CDN security is provided by Firebase Hosting / Google Cloud infrastructure. Inquiries submitted via the contact form are encrypted in transit (HTTPS) and delivered to our mailbox. We acknowledge that no internet transmission method is 100% secure.
10. Children
The website is intended for travel professionals aged 18 and older. We do not knowingly collect personal data from children.
11. Third-party links
This site links to external services (Google, Klaro, partner operators). We are not responsible for the privacy practices of those external services.
12. Changes to this policy
We may update this policy as our practices or applicable law changes. Material updates will be reflected in the effective date at the top of this page.
13. Contact
Ramz al Masira International LLC (trading as Arabian Wonders DMC)
Kharais Street, G7 Building, Al Hail, Seeb, Muscat, Oman.
Email: info@awdmc.com.