Privacy and Booking Information
This page describes the behavior visible in this site’s current form, tracking, browser storage, and forwarding code. It does not invent legal-entity details, downstream providers, or commercial terms that the current site cannot prove.
An inquiry, not a booking
Submitting the form sends a request for information and availability. It does not reserve a place, create a booking, confirm availability, or take payment.
Information submitted
The form submits full name, email, phone, country, experience level, module duration, preferred start date, package choice, room preference, optional notes, and coupon or referral code. The payload also includes camp name, request type, submission and idempotency IDs, a private-room flag, and a discipline field that is currently sent empty.
Measurement and attribution
The inquiry carries package, duration, preferred date, lead value and currency, event ID, source site, sport, language, UTM fields, gclid, fbclid, gbraid, wbraid, Meta browser identifiers when present, landing and referrer details, conversion page, and guide attribution. After success, normalized first name, email, and phone are placed in the data layer for the configured analytics and advertising measurement.
Browser storage and lifetimes
Campaign and guide attribution is kept in localStorage for up to 90 days. The WhatsApp attribution token and inquiry retry fingerprint and event ID use sessionStorage; the token is capped at 90 days, may expire earlier, and normally ends with the browser session, while the retry record is removed after success. The retry record contains no raw contact fields. Consent preference keys read from localStorage have no code-level expiry in this repository. Meta cookie lifetimes are not defined by this site code.
Where the inquiry goes
The browser posts to the same-origin /api/booking route. A Cloudflare Pages function validates and forwards the JSON request to a public AWS API Gateway endpoint in eu-central-1. This repository does not prove a complete list of downstream service providers or processing locations; ask for the current list before submitting if you need it.
Retention and data requests
An organization-wide retention schedule is not published in the current site code. Email [email protected] to request access, correction, deletion, current retention details, or the current downstream-provider list. Do not put passport numbers, payment-card data, medical details, or other sensitive information in the notes field; ask for an appropriate secure channel.
Written commercial terms before payment or travel
Treat displayed dates and prices as planning information, not live inventory or a confirmed offer. Before paying, obtain a written offer covering current availability, dates, room and package scope, total price and currency, payment method, deposit and balance due dates, cancellation, refunds, credits, and exceptions. Do not make non-refundable travel arrangements until you receive written booking confirmation.