Account protection
Customer passwords are stored as salted PBKDF2 hashes, not readable passwords. Signed, HTTP-only session cookies help protect authenticated sessions. Administrative routes require separate authentication.
The practical safeguards used to protect accounts, reservation requests and administration.
Reviewed: 3 September 2026Customer passwords are stored as salted PBKDF2 hashes, not readable passwords. Signed, HTTP-only session cookies help protect authenticated sessions. Administrative routes require separate authentication.
Prices are calculated on the server from the published package record. Unique request keys prevent accidental duplicate submissions, and reservation references are generated by the server.
Public forms validate submitted data. Database access and email credentials remain server-side. Access is limited to functions needed to manage reservations and support requests.
Use a unique password, keep devices updated, sign out on shared devices and never send passwords through email or WhatsApp. Confirm that messages claiming to represent us use the contact details published on this website.
Report suspected misuse or a security concern to agadir.stories@gmail.com. Include the affected page and what you observed, but do not include passwords or sensitive documents.