Waypoint Adventures (Pty) Ltd respects your privacy. This Privacy Policy explains what personal information we collect when you use our website and services, why we collect it, who we share it with, and the rights you have under South Africa's Protection of Personal Information Act, 2013 (POPIA).
By using this site, booking a trip, subscribing to our newsletter, or contacting us, you consent to the practices described here.
1. Who we are
Waypoint Adventures is a South African tour operator. Our registered address, contact number, and email are listed in the footer of every page on this site. For any privacy-related question or request, write to letsgo@waypoint-adventures.co.za.
2. Information we collect
We collect only the personal information we need to run our tours safely and to keep you informed. Depending on how you use the site, that may include:
- Account details — name, surname, email address, phone number, and a password (or authentication token from Google if you sign in with Google).
- Booking details — trip selected, pricing tier, number of adults / children, passenger names and ID or passport numbers, dietary requirements, allergies, medical conditions and medications, blood type, medical aid details, emergency contact, and vehicle details for self-drive tours.
- Payment details — the fact that a payment was made, its amount, method, and reference. Card details are never stored by us; they are handled directly by our payment gateway (PayFast or PayPal). Bank transfer details you send us are stored securely and used only for reconciliation.
- Communications — enquiries, support tickets, comments, and reviews you submit through the site.
- Automatically collected — IP address, browser type, pages visited, and other basic analytics (see the Cookie Policy).
3. Why we collect it (purpose)
- To create and manage your account so you can book, log in, and access your trip details.
- To process bookings and payments, and to send you booking confirmations, invoices, and the pre-trip LET'S GO briefing pack.
- To keep you safe on tour — dietary, allergy, medical, and emergency contact information is shared with the tour guide leading your trip.
- To respond to enquiries you send us.
- To send you occasional newsletters or trip announcements — only if you opt in.
- To meet our legal, accounting, and safety obligations.
4. POPIA §18 notice — what happens with your data
In line with section 18 of POPIA, this section tells you exactly what we do with the personal information you give us:
- Responsible party: Waypoint Adventures (Pty) Ltd.
- Purpose of collection: as described in section 3 above.
- Whether it is voluntary or mandatory: account creation is voluntary. Booking-related information (passenger names, IDs, medical and emergency contacts, dietary requirements) is mandatory in order for us to accept the booking and run the tour safely.
- Consequences of not providing it: we cannot confirm a booking without the required booking-related information.
- Law under which we collect: POPIA, the Consumer Protection Act, and general contract and safety obligations for tour operators in South Africa.
- Recipients: the operators, service providers, and processors listed in section 5.
- Cross-border transfers: some of our processors (Firebase, PayPal, Google) may store data outside South Africa. See section 6.
- Your rights: access, correction, deletion, objection, and complaint — see section 8.
5. Who we share it with
We share your personal information only with the parties we need to in order to deliver your trip and run the business:
- Payment gateways — PayFast (South Africa) and PayPal (international) process card payments. They see the payment amount and contact details; card details never touch our servers.
- Firebase Authentication (Google) — used for optional Google sign-in. Firebase stores your login token and email.
- Zoho CRM — our office team manages bookings and customer records in Zoho. Your contact, booking, and payment records are synchronised with Zoho.
- Xero — used by our finance team for invoicing and bank reconciliation.
- Tour guides — the guide leading your trip receives your passenger list, dietary / allergy / medical needs, and emergency contact so they can keep you safe on tour.
- Email delivery — our transactional emails (bookings, receipts, password resets) are sent via our hosting provider's mail servers.
- WordPress hosting — the site itself is hosted by our hosting provider, which processes access logs.
We never sell your personal information. We never share it with marketing lists or advertisers.
6. Cross-border transfers
Some of our processors (Firebase / Google, PayPal, and analytics providers) are based outside South Africa. Where personal information is transferred across borders, we rely on those processors' contractual safeguards and their compliance with equivalent data-protection standards (GDPR or similar). By using the site you consent to these transfers.
7. How long we keep it
- Account details — for as long as your account is active. If you close your account we anonymise personal identifiers but keep booking history for accounting and tax purposes for the periods required by South African law (typically 5 years).
- Booking, payment, and invoice records — for the retention periods required by SARS and the Companies Act.
- Enquiries and support tickets — up to 3 years after last activity.
- Marketing consent — until you unsubscribe.
8. Your rights under POPIA
You have the right to:
- Access the personal information we hold about you.
- Correct any information that is inaccurate, out of date, or incomplete.
- Request deletion of your personal information (subject to legal retention obligations).
- Object to further processing.
- Withdraw your marketing consent at any time.
- Complain to the Information Regulator if you believe we have mishandled your data. Contact details: https://inforegulator.org.za/, complaints@inforegulator.org.za, +27 10 023 5200.
To exercise any of these rights, email letsgo@waypoint-adventures.co.za. We aim to respond within 30 days.
9. How we protect your data
- Passwords are stored one-way hashed; nobody at Waypoint (not even the developer) can read them.
- API keys shared with third parties are stored as one-way SHA-256 hashes.
- All traffic to the site uses HTTPS/TLS.
- Access to customer records is limited to authorised staff and is logged.
- Payment card details never touch our servers — they go directly to PayFast or PayPal.
10. Cookies and tracking
See our separate Cookie Policy for the cookies we set and why.
11. Changes to this policy
We may update this Privacy Policy from time to time. The date at the top of the page shows when it was last changed. Material changes will be flagged on the site or by email where practical.
12. Contact us
Any privacy-related question or request: letsgo@waypoint-adventures.co.za.