Privacy Policy for Health & Beauty Businesses

Effective Date: 21 August 2026

Last Updated: 21 August 2026

Prepared in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA)

1. Introduction

Booket ("Booket", "we", "us", or "our") provides booking and payment software used by health and beauty businesses ("Merchants") in South Africa, and by the customers of those Merchants ("Customers", "you") to make bookings and payments for services.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, who we share it with, and the rights you have in relation to it. It applies to our website, our mobile and web applications, our merchant dashboard, and any other service that links to this policy (together, the "Platform").

This Policy is issued in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA"), and, where applicable, other South African laws governing electronic communications, payments and consumer protection, including the Electronic Communications and Transactions Act, 25 of 2002 and the Consumer Protection Act, 68 of 2008.

Booket generally acts as the "Operator" (processor) of Customer personal information on behalf of Merchants, who are the "Responsible Party" for their own customer relationships. Booket is the Responsible Party for information it processes for its own purposes, such as Merchant account administration and Platform security. Section 4 explains this in more detail.

2. Who This Policy Applies To

This Policy applies to:

  • Customers who use the Platform (directly or via a Merchant's booking page) to browse services, make bookings, or make payments.
  • Merchants and their staff who use the Booket dashboard to manage bookings, clients, calendars, and payments.
  • Visitors to our marketing website, even if they do not create an account.

If you are a Merchant, you also act as a Responsible Party under POPIA for the personal information of your own clients that you capture, view, or manage through Booket, and you must have your own lawful basis and privacy notice for your clients, in addition to Booket's role described here.

3. Information We Collect

3.1 Information you give us directly

  • Account details: name, surname, email address, mobile number, and password (stored in hashed form).
  • Booking details: service selected, preferred date and time, notes to the Merchant, and booking history.
  • Business details (Merchants): trade name, registration number, business address, business category, operating hours, and staff details.
  • Identity and verification details (Merchants): ID or passport number, proof of address, and other information required for merchant onboarding and Know Your Customer (KYC) checks.
  • Banking details (Merchants): bank name, account holder, account number, and branch code, used to pay out settlement funds.
  • Payment card details (Customers): card number, expiry date, and cardholder name, collected and processed via our payment service provider (see section 6).
  • Communications: messages you send us via support, chat, email, or in-app forms.

3.2 Health and beauty related information

Because Booket is used to book health and beauty services, bookings may include information about the service requested (for example, a specific treatment, therapy, or consultation type) which could, depending on the nature of the Merchant's business, constitute "special personal information" under POPIA (for example, information concerning health). We and our Merchants treat this information with additional care, as set out in section 7.

3.3 Information collected automatically

  • Device and log information: IP address, device type, operating system, browser type, and app version.
  • Usage information: pages viewed, features used, buttons clicked, session duration, and crash or error reports.
  • Location information: approximate location derived from your IP address, or precise location if you grant the app permission (for example, to find nearby Merchants).
  • Cookies and similar technologies: used on our website and web app for functionality, analytics, and (where you consent) marketing. See section 12.

3.4 Information from third parties

  • Payment processors and payment gateways, confirming successful or failed transactions.
  • Identity verification and credit bureau services, for Merchant KYC and fraud prevention.
  • Google Places and mapping services, for business address and location lookups.
  • Analytics and crash-reporting providers.

4. Our Role: Responsible Party and Operator

POPIA distinguishes between a "Responsible Party" (the entity that determines the purpose and means of processing personal information) and an "Operator" (an entity that processes personal information on behalf of, and under the instruction of, a Responsible Party).

When a Customer books a service with a Merchant, the Merchant is the Responsible Party for that Customer's personal information, and Booket is the Operator, processing the information only to provide the booking and payment service to the Merchant.

Booket is the Responsible Party for information it processes for its own purposes, including Merchant account creation and billing, Platform security and fraud prevention, product analytics, and direct marketing about Booket's own services (subject to your consent and opt-out rights).

If you are a Customer with a query about how a specific Merchant uses your information (for example, whether they retain your booking history, or how they contact you), you should also refer to that Merchant's own privacy notice, which they are responsible for providing.

5. How We Use Your Information

We use personal information for the following purposes, each with a lawful basis under POPIA:

5.1 To perform our contract with you

  • Creating and managing your Customer or Merchant account.
  • Processing bookings, cancellations, reschedules, and reminders.
  • Processing payments and payouts, and reconciling settlements.
  • Providing customer support.

5.2 For our legitimate business interests

  • Improving and developing the Platform, including testing new features.
  • Monitoring Platform performance, security, and preventing fraud or abuse.
  • Understanding usage trends through aggregated, de-identified analytics.

5.3 To comply with legal obligations

  • Verifying Merchant identity and banking details (KYC/FICA-aligned checks).
  • Retaining transaction records for tax, accounting, and financial regulatory purposes.
  • Responding to lawful requests from regulators, law enforcement, or the courts.

5.4 With your consent

  • Sending marketing communications about Booket or, where you have opted in, about a Merchant's promotions.
  • Using precise location data to suggest nearby Merchants.
  • Non-essential cookies and similar tracking technologies.

You may withdraw consent at any time as described in section 10, without affecting the lawfulness of processing carried out before withdrawal.

6. How We Share Information

We do not sell personal information. We share personal information only as follows:

  • With the Merchant you book with: your name, contact details, and booking details are shared with the relevant Merchant so they can fulfil your booking.
  • With payment service providers and banks: to process card payments, EFT payments, and payouts to Merchants.
  • With service providers acting on our behalf: cloud hosting, customer support tooling, analytics, SMS/email delivery, and identity verification providers, each bound by contract to protect personal information and use it only for the purposes we specify.
  • For legal reasons: where required by law, regulation, court order, or to protect the rights, property, or safety of Booket, our users, or the public.
  • In a business transaction: if Booket is involved in a merger, acquisition, investment, or sale of assets, personal information may be transferred as part of that transaction, subject to equivalent protections.

We require all third parties who process personal information on our behalf to maintain confidentiality and security measures consistent with POPIA and this Policy.

7. Special Personal Information

POPIA places additional restrictions on processing "special personal information", which includes information about a person's health, among other categories. Where a booking made through Booket relates to a treatment or service that reveals health-related information (for example, a medical aesthetics consultation), we and our Merchants process that information only:

  • With your consent (for example, by making the booking and providing the relevant details); or
  • Where necessary for the establishment, exercise, or defence of a right or obligation in law; or
  • Where another justification under sections 26 to 33 of POPIA applies.

We limit our own access to such information to what is necessary to operate the Platform (for example, displaying the service name in a booking record) and we do not use special personal information for marketing or profiling without your explicit consent.

8. Payment Information

Card payment details are collected and processed through a Payment Card Industry Data Security Standard (PCI DSS) compliant payment service provider. Booket does not store full card numbers, and where card details are held to enable future bookings, this is done by our payment partner under tokenisation, not by Booket directly.

Merchant banking details (account number and branch code) are used solely to facilitate settlement payouts and are stored using access-controlled, encrypted systems. They are never shared with Customers or other Merchants.

9. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, including:

  • Active account information: for as long as your Booket or Merchant account remains active, plus a reasonable period thereafter to allow for account recovery.
  • Transaction and financial records: generally for five years, to meet South African tax, accounting, and financial record-keeping requirements.
  • Support communications: for as long as reasonably necessary to resolve your query and for a limited period afterwards for quality and training purposes.
  • Marketing preferences: until you opt out or withdraw consent.

When personal information is no longer required, we securely delete, anonymise, or de-identify it.

10. Your Rights

Subject to POPIA, you have the right to:

  • Be notified that your personal information is being collected, and why.
  • Access the personal information we hold about you, free of a nominal fee where applicable.
  • Request correction, updating, or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, or unlawfully obtained.
  • Object, on reasonable grounds, to the processing of your personal information.
  • Withdraw consent to processing that is based on consent, at any time.
  • Object to your information being used for direct marketing, including by using the "unsubscribe" link in any marketing communication.
  • Not be subject to a decision based solely on automated processing, including profiling, which affects you in a significant way, without an opportunity to make representations.
  • Lodge a complaint with the Information Regulator (see section 15) if you believe your rights under POPIA have been infringed.

To exercise any of these rights, contact us using the details in section 16. We may need to verify your identity before actioning a request, and we will respond within the timeframes required by POPIA.

11. How We Protect Your Information

We implement reasonable technical and organisational measures to protect personal information against loss, unauthorised access, interference, modification, or disclosure, including:

  • Encryption of data in transit (TLS) and, where appropriate, at rest.
  • Access controls limiting personal information access to staff and service providers who need it to perform their role.
  • Use of PCI DSS compliant payment processors for card data.
  • Regular review of our security practices as the Platform evolves.

No system is completely secure, and we cannot guarantee absolute security. If we become aware of a security compromise that has, or may have, resulted in unauthorised access to personal information, we will notify the Information Regulator and affected data subjects as required by section 22 of POPIA.

12. Cookies and Similar Technologies

Our website and web application use cookies and similar technologies to:

  • Keep you logged in and remember your preferences (strictly necessary).
  • Understand how the Platform is used, so we can improve it (analytics).
  • Where you consent, personalise marketing content.

You can manage cookie preferences through your browser settings or, where available, through our cookie consent banner. Disabling strictly necessary cookies may affect the functioning of the Platform.

13. Cross-Border Transfer of Information

Some of our service providers (for example, cloud hosting or analytics providers) may process personal information outside South Africa. Where this occurs, we take reasonable steps to ensure the recipient is subject to a law, binding corporate rules, or agreement that provides an adequate level of protection, substantially similar to POPIA, before the transfer takes place, in line with section 72 of POPIA.

14. Children's Information

The Platform is intended for use by adults. We do not knowingly collect personal information from children (as defined in POPIA) without the consent of a competent person (such as a parent or legal guardian). If we become aware that we have collected personal information from a child without appropriate consent, we will take reasonable steps to delete it.

15. Complaints and the Information Regulator

If you have concerns about how we process your personal information, please contact us first using the details in section 16 so we can try to resolve the matter. If you are not satisfied with our response, you may lodge a complaint with the Information Regulator (South Africa):

Information Regulator (South Africa)

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Complaints email: complaints.IR@justice.gov.za

General enquiries: enquiries@inforegulator.org.za

Website: www.justice.gov.za/inforeg

16. Contact Us / Information Officer

For any questions about this Privacy Policy, or to exercise your rights under POPIA, please contact our Information Officer:

Booket

Attention: Information Officer

Email: frederick@letsbooket.com

Postal address: 299 Pendoring Road, Blackheath, 2165

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on the Platform with a revised "Last updated" date. Where changes are material, we will provide additional notice (for example, by email or an in-app notification).

This Policy was last reviewed on 21 August 2026.