POPIA

Privacy notice

What we collect, why we need it, and what we do to keep it safe.

Who we are

South African Vacation Guide (SAVG) operates a South African holiday-letting marketplace. We are the responsible party under the Protection of Personal Information Act for the personal information described here. Listing owners are separately responsible for anything you send them directly. For any privacy question, write to contact@savg.co.za.

What we deliberately do not collect

We do not ask guests for an ID or passport number, and we do not store one. Holding identity numbers for every guest in the country would make our database far more damaging to lose than it needs to be, so we designed it out rather than encrypting our way around it.

A few listings sit inside estates with controlled access, where the gate register genuinely needs guest details. Where that applies it is stated on the listing, and the owner asks you by email after booking. Those details go to the people who need them and are not kept by us.

We also do not ask guests for a home address. Billing works from your email address.

What we collect from guests

Name, email address and phone number
To create your account, confirm your booking, and let you and the owner reach each other about the stay.
Town, province and postal code
Optional, and only used to make search results more relevant. Leave them blank and nothing stops working.
Booking details
Dates, guest numbers and anything you tell us in the special requests box. Please do not put health or other sensitive information there — send it to the owner directly instead.
Payment details
We never see or store your card details. Payments are processed by PayFast, who handle the card data directly. We store only the amount, the date and PayFast’s transaction reference.
Technical information
Your IP address is used briefly for rate limiting and to prevent spam and abuse on our forms, and is recorded in our audit log when a booking is made.

What we collect from listing owners

Owners give us more than guests do, because we pay them money and are obliged to know who they are.

Banking details
Where payouts go. Encrypted at rest with AES-256-GCM, shown masked by default, and revealed to an administrator only on an explicit click that is logged. Changing them pauses payouts until a person re-verifies — an account takeover that swaps the banking details is the classic marketplace fraud, and the pause is what stops it paying out.
Identity and verification documents
An ID copy, proof of address, a bank confirmation letter, and where relevant a company or trust registration. Stored outside the public web root and served only to an authenticated administrator. Used to confirm that the person we are paying owns the property, and for nothing else.
Property details
The exact address is kept private unless the owner chooses to publish it. Public maps show a deliberately imprecise position, and photographs have their embedded location data stripped on upload.

Who we share it with

We share the minimum necessary, and only with:

  • The owner of the place you book — your first name and surname initial and your stay dates while the booking is ahead. Full contact details are released to them only around the time of the stay, so they can reach you about arrival, and that release is logged.
  • PayFast — your name and email address, to process your payment.
  • Axxess — our email provider, to deliver booking email to you.
  • Hostinger — our hosting provider, who operate the server the site runs on.

We do not sell your personal information, and we do not share it for anyone else’s marketing.

How we protect it

  • Owner banking details are encrypted at rest with AES-256-GCM, using a key held outside the database.
  • Passwords are hashed with bcrypt and are never recoverable.
  • The site is served over HTTPS only.
  • Owner documents are stored outside the public web root and cannot be fetched by URL.
  • Access to guest and owner records is limited to our administrators, and sensitive lookups are written to an audit log.

How long we keep it

Booking and payment records are kept for five years to meet South African tax and accounting requirements. Owner payout records are kept for the same period. Your account details are kept while your account is open. If you ask us to close your account, we delete or anonymise everything we are not legally required to keep.

Where it is kept

Our servers and email are hosted with providers operating in Europe and South Africa. Where personal information leaves South Africa, it goes only to providers subject to data-protection law comparable to POPIA, as section 72 requires.

Your rights

Under POPIA you may:

  • Ask what personal information we hold about you.
  • Ask us to correct anything that is wrong.
  • Ask us to delete information we no longer have a lawful reason to keep.
  • Object to direct marketing at any time.
  • Complain to the Information Regulator (South Africa) if you believe we have mishandled your information.

To exercise any of these, email contact@savg.co.za. We will respond within 30 days.

Marketing

We only send marketing email if you opted in. Booking confirmations, payment receipts, arrival information and payout notices are not marketing — we send those because you have a booking or a listing with us. You can opt out of marketing at any time by replying to any such email.