Privacy Policy
Version 1.4 Effective date: effective date, e.g. 1 September 2026 — to be confirmed
This policy explains how HuntBook SA collects, uses, shares and protects your personal information, and what rights you have. It is written to meet the Protection of Personal Information Act 4 of 2013 ("POPIA").
Please read it together with our Terms of Service.
1. Who we are
HuntBook SA operates the HuntBook SA website and mobile application, a platform that connects hunters with hunting farms in South Africa.
We are the responsible party for the personal information described in this policy, which means we decide why and how it is processed.
| Legal entity | registered company name, e.g. HuntBook SA (Pty) Ltd — to be confirmed |
| Registration number | CIPC registration number — to be confirmed |
| Physical address | street address, town, province, postal code — to be confirmed |
| Website | https://huntbooksa.co.za |
| General contact | support email address — to be confirmed |
Information Officer
Every responsible party must have an Information Officer. Ours is:
| Name | full name of the Information Officer — to be confirmed |
| privacy email address, e.g. privacy@huntbooksa.co.za — to be confirmed | |
| Telephone | contact number — to be confirmed |
Contact the Information Officer about anything in this policy, to exercise your rights, or to complain.
2. Who this policy applies to
This policy applies to everyone who uses HuntBook SA:
- Hunters who browse farms, save listings, use the assistant and contact farms.
- Farmers and farm operators who list properties, game and accommodation.
- Visitors who use the app or website without an account.
It also covers information about people who do not use the platform themselves — for example, a professional hunter or contact person whose details a farmer adds to a farm listing. If you provide someone else's personal information, you must have the right to do so and must tell them we hold it.
3. Children
HuntBook SA is not for children. You must be 18 or older to create an account. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, contact the Information Officer and we will delete it.
4. What personal information we collect
4.1 Information you give us
When you create an account
- Name and surname
- Email address
- Password (stored only as a bcrypt hash — we never see or store your actual password)
- Role — hunter or farmer
- Phone number, where you provide one
- Province
If you sign in with Google or Apple
- The verified identity information the provider returns to us: a unique
identifier, your email address, and your display name where available. We do not receive your Google or Apple password.
- Your name and email address are sent to us by the provider only the first
time you authorise HuntBook SA. If you sign in again later, we rely on what we already hold.
Sign in with Apple additionally lets you choose Hide My Email. If you do, Apple gives us a private relay address ending in `@privaterelay.appleid.com` instead of your real address, and forwards our email to you without us ever seeing where it goes. Two things follow from that, and they are worth knowing before you choose it:
- The relay address is the only address we hold for you, so it is the address
we use to verify who you are when you ask to access, correct or delete your information.
- If you turn off forwarding in your Apple ID settings, or delete your Apple ID,
we lose the only way we have of reaching you. We cannot send you a sign-in link, a payment receipt or a reply to a privacy request, and we have no way of knowing that our email is no longer arriving.
Hunter profile and preferences
- Species you are interested in, budget range, preferred provinces, hunting
style and similar preferences
- Your saved farms and listings
- Your location, if you choose to share it, so we can show nearby farms
Farmer and farm information
- Farm name, description, physical address and GPS coordinates
- Contact person, contact phone number and contact email for the farm
- Professional hunter details where supplied
- Game species, pricing, accommodation, hides, roads and map features
- Photographs of the property, accommodation and game
- Cellphone reception information
Verification documents
To display a farm as verified we ask for supporting documents, which may include:
- Proof of the owner's identity, such as an identity document
- Proof of land ownership or land access rights
- Proof of hunting rights
- Proof of address
- Permits
- Contact confirmation
These documents are sensitive. Section 8 explains the extra care we take with them.
Reviews and evaluations
- Reviews you write about farms
- Replies farmers write to reviews
- Evaluations farmers write about hunters who have hunted with them
- Moderation status, the reason for a rejection, and the administrator and
time associated with a moderation decision
Evaluations are personal information about the hunter concerned. That hunter has the right to ask what has been recorded about them — see section 11.
Payments
- Your subscription plan, status and renewal date
- Records of payment events
We never see or store your card number. Card details are entered on PayFast's own payment pages and never reach our systems.
Support and diagnostics
- Messages you send us
- Diagnostics logs you choose to submit from the app, which contain recent app
activity and device information
4.2 Information we collect automatically
- Technical information — IP address, device type, operating system, app
version and browser
- Usage information — screens visited, searches run, farms viewed, and
similar activity
- Assistant conversations — the questions you ask the in-app assistant and
the answers given
- Security records — sign-in attempts, two-factor events, and audit records
of significant actions
- Push notification tokens, if you enable notifications
- Error reports, when something in the app or on our servers fails. These
contain the technical details of the fault — what broke, where in the code, which screen or request it happened on, and your account identifier so we can tell whether a fault affected one person or everybody. They deliberately exclude your name, email address, passwords, security codes and the contents of anything you uploaded. We use them only to find and fix faults, and they are deleted after 90 days.
4.3 Information from others
- Google or Apple, when you use their sign-in
- PayFast, when it confirms the outcome of a payment
- Weather, astronomy and mapping providers, which supply general data about
places rather than about you
5. Why we process your information, and our lawful basis
POPIA requires us to have a lawful justification for every use. Ours are:
| What we do | Why | Justification under POPIA |
| Create and run your account | To give you the service you asked for | Performance of a contract with you |
| Show you farms, listings and search results | Core function of the platform | Performance of a contract with you |
| Show nearby farms using your location | To make results useful | Your consent, which you can withdraw at any time |
| Verify farms and their documents | To keep the marketplace trustworthy and protect users from misrepresentation | Our legitimate interests, and legal obligation where applicable |
| Process subscription payments | To bill you for a plan you chose | Performance of a contract with you |
| Send service emails — password resets, security alerts, billing notices | To operate your account safely | Performance of a contract, and our legitimate interests |
| Send marketing emails | To tell you about features and offers | Your consent, given separately and withdrawable at any time |
| Provide the in-app assistant | To answer your questions about farms and hunting | Performance of a contract with you |
| Prevent fraud, abuse and unauthorised access | To protect users and the platform | Our legitimate interests, and our obligations under POPIA section 19 |
| Scan uploaded files for malware | To protect everyone using the platform | Our legitimate interests |
| Review user photographs, reviews and review replies before publication | To prevent abuse and keep the marketplace trustworthy | Our legitimate interests, performance of our contract, and legal obligation where applicable |
| Restrict and preserve content reasonably suspected to be illegal, and report or disclose it to authorities | To protect people, comply with law and preserve evidence | Legal obligation and our legitimate interests |
| Understand how the platform is used and improve it | To build a better product | Our legitimate interests |
| Keep records and respond to legal claims | To meet our obligations and defend our rights | Legal obligation, and our legitimate interests |
Where we rely on your consent, you may withdraw it at any time. Withdrawing consent does not affect processing that already happened, and some features simply will not work without the information — for example, we cannot show nearby farms without a location.
6. What we do not do
- We do not sell your personal information.
- We do not share your personal information with third parties for their own
marketing.
- We do not use your information to make automated decisions that have a legal
or similarly significant effect on you.
- We do not share your assistant conversations with other users.
7. Who we share your information with
7.1 Other users of the platform
- Farm information is public. A farm listing, its photographs, description,
location and the contact details supplied for it are visible to anyone using the platform, including people who are not signed in.
- Reviews you write are shown with your first name only after approval.
- Replies farmers write to reviews are shown only after approval.
- Content waiting for approval, and rejection reasons, are visible only to its
author and administrators. A farm does not see a pending or rejected review written about it.
- When you contact a farm, you leave the platform for WhatsApp or a phone
call. Anything you share in that conversation is between you and the farm, and is no longer covered by this policy.
- Verification documents are never shown to other users. Only our
administrators can see them.
7.2 Service providers (operators)
We use the following providers to run the platform. Each processes personal information only on our instructions and under a written agreement requiring them to keep it confidential and secure, as POPIA sections 20 and 21 require.
| Provider | What it does | Where it processes data |
| Hetzner Online GmbH | Hosts our servers, database and file storage | Germany / European Union |
| PayFast (Payfast (Pty) Ltd) | Processes subscription payments | South Africa |
| Resend | Sends our transactional email | United States |
| MapTiler AG | Supplies map tiles and satellite imagery | Switzerland / European Union |
| Cloudflare, Inc. | Provides bot protection on our registration form | United States and global network |
| Google LLC | Google Sign-In, and push notification delivery | United States |
| Apple Inc. | Sign in with Apple | United States |
| OpenAI, L.L.C. | Powers the in-app assistant | United States |
| Functional Software, Inc. (Sentry) | Records technical error reports so we can find and fix faults | European Union (Germany) |
We review this list as our providers change. The current list is always the one published here.
7.3 Others
We may share personal information where we are legally required to, or where it is necessary to:
- comply with a law, court order or lawful request from a public authority;
- investigate or prevent fraud, abuse or a threat to someone's safety;
- establish, exercise or defend a legal claim; or
- complete a merger, acquisition or sale of the business, in which case we will
tell you before your information becomes subject to a different policy.
7.4 Administrator access to your account
To investigate a fault you have reported, or one we have found, an administrator may open your account and see it as you see it. This is a support tool, not a routine one, and it works under the following limits:
- Only an administrator can do it, and only after entering a current code from
their own two-factor authenticator at that moment.
- It lasts at most thirty minutes and cannot be extended without entering a
fresh code.
- It is read-only by default. An administrator who needs to correct
something — a farm detail, a map, a listing, a photo — must switch editing on as a separate, separately recorded step.
- Some things are never possible this way, however the session is configured:
payments and subscriptions, changing your password or two-factor settings, deleting your account, submitting or deleting verification documents, writing a review or a hunter evaluation in your name, and recording consent on your behalf.
- **Everything done during such a session is recorded in our audit log against
the administrator personally, not against you**, together with the fact that they were acting on your account. It is never possible for an administrator's action to appear in our records as though you had taken it.
If you would prefer we did not use this to investigate something you have reported, tell us and we will ask you for the details instead.
8. Verification documents and other sensitive information
Identity documents and proof of land rights deserve more care than an email address, and we treat them accordingly:
- They are stored in encrypted object storage, separate from the main database.
- They are readable only by administrators reviewing a specific verification,
and every access is recorded in an audit log.
- They are never shown to other users, never included in public farm listings,
and never used for marketing.
- Every uploaded file is scanned for malware before it is stored.
- They are deleted when they are no longer needed — see section 10.
If you would rather not upload a particular document, contact us and we will tell you what alternatives are acceptable for verification.
9. Sending information outside South Africa
Some of our providers are outside South Africa, as the table in section 7.2 shows. POPIA section 72 allows this where certain conditions are met. We rely on the following:
- European providers (Hetzner, MapTiler) operate under the General Data
Protection Regulation, which provides protection substantially similar to POPIA.
- United States providers (Resend, Cloudflare, Google, Apple, Sentry and our
AI provider) are bound by written agreements imposing conditions materially similar to POPIA's requirements, including obligations on onward transfer.
- Where a transfer is needed to perform our contract with you — for example,
sending a password reset email — POPIA permits it on that basis.
10. How long we keep your information
| Information | How long we keep it |
| Account and profile information | While your account is open, then deleted or anonymised within 30 days of you deleting the account |
| Farm listings and photographs | While the farm is listed, then 30 days after removal |
| Verification documents | Until verification is decided, then up to 12 months to support the verification decision, then deleted |
| Payment and subscription records | 5 years from the end of the financial year, as tax and company law require |
| Assistant conversations | 12 months, then deleted |
| Security and audit records | 12 months, then deleted automatically. These include the IP address and browser or app the action came from |
| Diagnostics logs | 90 days |
| Error reports | 90 days |
| Reviews and evaluations | While the account is open. When you delete your account, reviews you wrote remain but are anonymised, so other users keep useful information without it being linked to you |
| Ordinary rejected uploads | While the account or listing remains open, unless you remove them sooner. We do not yet run an automatic 30-day deletion process |
| Content reasonably suspected to be illegal | Access is blocked and the evidential copy is kept only as long as required for reporting, investigation, prosecution, a preservation direction or a related legal claim; it is not deleted through the ordinary account-deletion process while that duty applies |
| Marketing consent records | For as long as you are subscribed, plus 3 years after withdrawal, so we can prove we had consent |
Where a longer period is required by law, or where information is needed for a legal claim that is under way, we keep it for as long as necessary and no longer.
Deleting your account does not immediately erase the security and audit records of what was done on it. Those rows record the action, the time, the IP address and the e-mail address the action was taken under, and they are what allows us to investigate a security incident or answer a dispute about a booking or a payment. They are deleted on the twelve-month schedule above like any other audit record. Consent records are removed with the account, because their purpose ends when the account does.
11. Your rights
Under POPIA you have the right to:
- Be told what personal information we hold about you, and where we got it.
- Get a copy of that information.
- Correct or delete information that is inaccurate, irrelevant, excessive,
out of date, incomplete, misleading or obtained unlawfully.
- Object to processing based on our legitimate interests, on reasonable
grounds relating to your situation.
- Withdraw consent where our processing relies on it.
- Object to direct marketing at any time.
- Not be subject to a decision based solely on automated processing that has
a legal effect on you.
- Complain to the Information Regulator.
How to exercise them
- Delete your account yourself in the app, under Profile.
- Change your details yourself in the app, under Profile.
- Turn marketing emails off in the app, under Profile, or by using the
unsubscribe link in any marketing email.
- For anything else, email the Information Officer at
privacy email address — to be confirmed.
We will respond within 30 days. There is no fee for a request about your own information, unless a request is manifestly unfounded or excessive, in which case we will tell you the fee before doing the work. We may ask you to confirm your identity first, so that we do not disclose your information to someone else.
If we refuse a request we will tell you why and how to challenge it.
12. How we protect your information
POPIA section 19 requires us to take appropriate and reasonable technical and organisational measures. Ours include:
- Encryption in transit. All traffic uses HTTPS with modern TLS.
- Encryption at rest. Uploaded files and sensitive database fields are
encrypted with keys held separately from the data.
- Database-level isolation. Row-level security is enforced in the database
itself, so one user's records cannot be read through another user's session even if application code were flawed.
- Strong password storage. Passwords are hashed with bcrypt and are never
recoverable, by us or anyone else.
- Two-factor authentication. Available to every user and mandatory for
administrators.
- Malware scanning. Every uploaded file is scanned before storage.
- Access control and audit logging. Administrative access is restricted and
significant actions are recorded. Where an administrator opens your account to investigate a fault (section 7.4), the record names the administrator, not you.
- Backups, held encrypted and separately from the live system.
- Rate limiting and bot protection on sign-in and registration.
No system is perfectly secure, and we do not claim otherwise. What we do promise is that we take these obligations seriously and review them as the platform grows.
13. If something goes wrong
If personal information is accessed or acquired by an unauthorised person, POPIA section 22 requires us to notify the Information Regulator and every affected person as soon as reasonably possible after discovering it. We will tell you what happened, what information was involved, what we are doing about it, and what you can do to protect yourself.
14. Cookies and similar technologies
On the web we use a small number of browser storage items, all of them necessary for the app to work:
| What | Why |
| Session cookies | Keep you signed in. They are `HttpOnly`, so no script can read them, and `Secure`, so they only travel over HTTPS |
| CSRF token cookie | Protects against forged requests from other websites |
| Local storage | Keeps your sign-in state in step across browser tabs, so signing out of one tab signs out of all of them |
We do not use advertising or third-party tracking cookies. Because every item we set is strictly necessary to provide a service you asked for, we do not show a cookie consent banner. Blocking these will stop you from signing in.
Our Cookie and Storage Notice names every individual cookie and storage item, what each one does, how long it lasts, and which third parties may set their own. Read it at https://app.huntbooksa.co.za/legal/cookie-policy.html. If we ever add anything that is not strictly necessary, we will ask for your consent before it runs.
15. Links to other places
Farm listings may include links to other websites, and contacting a farm takes you to WhatsApp or your phone app. We are not responsible for how those services handle your information. Read their policies.
16. Changes to this policy
We will update this policy when the platform changes. The version number and effective date at the top always tell you which version you are reading.
If a change materially affects your rights or how we use your information, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.
Previous versions are available from the Information Officer on request.
17. Complaints
Please speak to us first — email the Information Officer at privacy email address — to be confirmed and we will try to resolve it.
You also have the right to complain directly to:
The Information Regulator (South Africa)
| Address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 |
| Postal | P.O. Box 31533, Braamfontein, Johannesburg, 2017 |
| Complaints | complaints.IR@justice.gov.za |
| General enquiries | enquiries.IR@justice.gov.za |
| Website | https://inforegulator.org.za |