Legal
Privacy Policy
1. Who we are
Rooiberg Wander (“we”, “us”, “our”) is the Responsible Party as defined in the Protection of Personal Information Act, 4 of 2013 (POPIA). Rooiberg Wander is operated by a South African business entity currently being formalised; this policy will be updated with the registered company name and number once registration is complete.
Contact us at hanlie@rooibergwander.co.za for any privacy-related query.
2. What personal information we collect
We collect only what is necessary to take and fulfil your booking.
At booking:
- Full name, email address and mobile phone number of the lead guest
- Group size and catering preference (self-catered or fully catered, which affects pricing)
- Preferred trail start date
After booking (pre-trip form):
- Full names of all guests in your group
- Mobile number for guides on trail
- Vehicle make, model and registration (for secure parking at Temminck's Lodge)
- Estimated arrival time on Day 1
- Any relevant medical conditions, injuries, allergies or fitness limitations
- Special requests
Payments:
We do not collect or store your card details. Payments are processed securely by Paystack (Paystack Commerce Limited, a Stripe company). Paystack handles all card data under their own PCI DSS compliance programme. We receive only a transaction reference and confirmation of payment.
Enquiries:
If you submit an enquiry through our website, we collect your name, email address and the content of your message.
3. Why we collect it (purpose and lawful basis)
We collect and use your personal information to:
- Process, confirm and administer your trail booking
- Communicate with you about your booking: confirmation, pre-trip reminders, payment links, and payment receipts
- Prepare for your trail experience: guest manifest, medical considerations, vehicle parking, and guide briefings
- Comply with our legal and regulatory obligations as a reserve access provider
- Respond to enquiries
The primary lawful basis for processing is performance of a contract, as we need this information to fulfil your booking. Where applicable, we also rely on our legitimate interests (e.g. fraud prevention, record-keeping) and legal obligation.
4. How long we keep it
We retain booking and pre-trip information for five years from your trail date, in line with our financial record-keeping obligations under South African law. Enquiries that do not result in a booking are retained for 12 months.
After these periods, personal information is securely deleted or anonymised.
5. Who we share it with
We share your information only with trusted service providers (operators/processors) necessary to fulfil your booking. We do not sell your personal information or share it with any third party for marketing purposes.
| Service provider | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database: booking and pre-trip records | USA (AWS) |
| Paystack (Stripe) | Payment processing | Nigeria / USA |
| Resend Inc. | Transactional email delivery | USA |
| Vercel Inc. | Website hosting and server functions | USA |
These providers are bound by their own privacy policies and, where applicable, data processing agreements.
6. Cross-border transfers
Some of our service providers store and process personal data outside South Africa. Where this occurs, we use providers that maintain appropriate safeguards, including standard contractual clauses or comparable frameworks, as contemplated by section 72 of POPIA. By using our website and making a booking, you acknowledge that your information may be transferred to these countries.
7. Security
We implement appropriate technical and organisational measures to protect your personal information, including:
- Encrypted connections (HTTPS) on all pages
- Access controls limiting who can view personal data
- Row-level security on our database (records are not publicly readable)
- No storage of card details on our servers
No method of internet transmission is completely secure. If you believe your information has been compromised, please contact us immediately.
8. Your rights
Under POPIA, you have the right to:
- Access: request a copy of the personal information we hold about you
- Correction: request that inaccurate information be corrected
- Deletion: request that your information be deleted, subject to our legal retention obligations
- Objection: object to specific processing of your information
To exercise any of these rights, email us at hanlie@rooibergwander.co.za. We will respond within 30 days.
9. Cookies and analytics
Our website uses no advertising cookies and no cross-site tracking. If we use analytics, it is privacy-friendly, consent-aware and does not share your personal data with third parties for advertising purposes.
10. Complaints
If you are not satisfied with how we handle your personal information, you may lodge a complaint with the Information Regulator (South Africa):
- Website: www.inforegulator.org.za
- Email: POPIAComplaints@inforegulator.org.za
We would, however, appreciate the opportunity to address your concern directly first.
11. Changes to this policy
We may update this policy from time to time. The date at the top of this page indicates when it was last revised. Continued use of our website following a material change constitutes acceptance of the updated policy.