Privacy Policy

Effective date: 20 February 2026

This Privacy Policy explains how Cape.it.is collects, uses, shares, and protects personal information in line with the Protection of Personal Information Act 4 of 2013 (POPIA). It applies to information collected through our website, enquiries, bookings, hosting enquiries, and related communications.

1. Who we are

Cape.it.is is the responsible party for the personal information we process.

Responsible party: Cape.it.is

Address: [insert physical address]

Email: [insert email address]

Information Officer: [insert name or role and email]

2. What personal information we collect

We may collect the following categories of personal information, depending on your interaction with us:

Identification and contact details

Name, surname, email address, phone number, nationality, and preferred language

Booking and stay details

Check in and check out dates, number of guests, property preferences, special requests, and communications related to your stay

Hosting and property owner details

Owner contact details, property address, property details, compliance and operational information needed to manage the property, and owner communications

Payment related information

We may receive limited payment confirmation details from payment service providers. We do not store full card details on our systems if payments are processed by a third party provider

Technical and usage data

Device information, browser type, pages viewed, and general site usage data through cookies and similar technologies

Marketing preferences

Your preferences regarding receiving updates and marketing communications

3. Where we collect information from

We collect personal information directly from you when you submit forms, make enquiries, request a quote, book a stay, enquire about hosting, or communicate with us.

We may also collect information from third parties where needed to deliver services, for example booking platforms, payment providers, and service partners, where permitted by law and your settings with those platforms.

4. Why we collect personal information

We process personal information for the following purposes:

  • To respond to enquiries and provide quotes
  • To facilitate bookings, stays, and guest support
  • To manage properties on behalf of owners
  • To coordinate services related to stays, such as cleaning, maintenance, check in support, and guest communication
  • To provide curated experiences where requested
  • To send service related messages, confirmations, and updates
  • To improve our website and user experience
  • To comply with legal and regulatory obligations
  • To prevent fraud, manage risk, and secure our systems
  • To send marketing communications where you have consented or where permitted by law, and always with a clear unsubscribe option

5. Lawful grounds for processing

We process personal information based on one or more of the lawful grounds recognised by POPIA, including:

Processing necessary to perform a contract with you, or to take steps at your request before entering a contract

Processing necessary to comply with a legal obligation

Processing to protect a legitimate interest of you or Cape.it.is, where this does not override your rights

Consent, where required, for example for certain marketing communications

6. Mandatory or voluntary supply of information

Supplying personal information is generally voluntary. However, if you do not provide certain information, we may not be able to process a booking, manage a property, or provide certain services.

7. Who we share personal information with

We may share personal information with trusted operators and service providers who help us deliver our services, such as:

  • Booking and property management tools
  • Payment service providers
  • Cleaning, maintenance, and property support teams
  • Experience partners, guides, and transport providers when you request an experience
  • Website hosting providers and analytics providers
  • Professional advisers such as accountants, auditors, or legal advisers
  • Regulators or law enforcement where required by law

We only share what is necessary for the specific purpose, and we require appropriate confidentiality and security measures.

8. Cross border transfers

Some of our service providers may process or store information outside South Africa. Where cross border transfers occur, we take reasonable steps to ensure your information is protected in line with POPIA requirements for cross border transfers, including ensuring adequate protection, contractual safeguards, or relying on another lawful basis where applicable. 

9. Cookies and similar technologies

We may use cookies and similar technologies to improve website performance, understand traffic patterns, and enhance user experience. You can control cookies through your browser settings. Disabling certain cookies may affect website functionality.

10. Security safeguards

We take appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised access, or unlawful processing. This includes access controls, secure systems, and limiting access to authorised persons only. No system is completely secure, but we work to maintain strong safeguards.

11. Retention of personal information

We keep personal information only as long as necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. We also retain certain records for operational, legal, tax, and dispute resolution purposes.

12. Your rights under POPIA

You have rights regarding your personal information, including:

  • The right to access your personal information
  • The right to request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained
  • The right to object to processing in certain circumstances
  • The right to withdraw consent where processing is based on consent
  • The right to opt out of direct marketing at any time
  • The right to lodge a complaint with the Information Regulator

POPIA requires that data subjects are informed of certain matters when information is collected, including the purpose, recipients, and complaint rights. 

To exercise your rights, contact us using the details in section 1. We may need to verify your identity before processing requests.

13. Direct marketing

If you receive marketing from us, you can unsubscribe at any time using the link in the message or by contacting us directly. POPIA also provides protections relating to unsolicited direct marketing. 

14. Children

Our services are intended for adults. If you believe a child has provided us with personal information without appropriate consent, please contact us so we can address it.

15. Complaints and the Information Regulator

If you have concerns about how we process personal information, please contact us first so we can try to resolve the matter.

You may also lodge a complaint with the Information Regulator of South Africa:

  • Information Regulator South Africa
  • Website: inforegulator.org.za
  • Email: enquiries@inforegulator.org.za
  • Telephone: 010 023 5200
  • Postal address: PO Box 31533, Braamfontein, Johannesburg, 2017 

16. Changes to this policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date.

17. Contact us

For questions, requests, or concerns regarding privacy and POPIA, contact:

Email: [insert email address]

Address: [insert physical address]

Information Officer: [insert name or role and email]