Effective Date: 21 August 2026
Last Updated: 21 August 2026
Prepared in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA)
Booket ("Booket", "we", "us", or "our") provides booking and payment software used by health and beauty businesses ("Merchants") in South Africa, and by the customers of those Merchants ("Customers", "you") to make bookings and payments for services.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, who we share it with, and the rights you have in relation to it. It applies to our website, our mobile and web applications, our merchant dashboard, and any other service that links to this policy (together, the "Platform").
This Policy is issued in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA"), and, where applicable, other South African laws governing electronic communications, payments and consumer protection, including the Electronic Communications and Transactions Act, 25 of 2002 and the Consumer Protection Act, 68 of 2008.
Booket generally acts as the "Operator" (processor) of Customer personal information on behalf of Merchants, who are the "Responsible Party" for their own customer relationships. Booket is the Responsible Party for information it processes for its own purposes, such as Merchant account administration and Platform security. Section 4 explains this in more detail.
This Policy applies to:
If you are a Merchant, you also act as a Responsible Party under POPIA for the personal information of your own clients that you capture, view, or manage through Booket, and you must have your own lawful basis and privacy notice for your clients, in addition to Booket's role described here.
Because Booket is used to book health and beauty services, bookings may include information about the service requested (for example, a specific treatment, therapy, or consultation type) which could, depending on the nature of the Merchant's business, constitute "special personal information" under POPIA (for example, information concerning health). We and our Merchants treat this information with additional care, as set out in section 7.
POPIA distinguishes between a "Responsible Party" (the entity that determines the purpose and means of processing personal information) and an "Operator" (an entity that processes personal information on behalf of, and under the instruction of, a Responsible Party).
When a Customer books a service with a Merchant, the Merchant is the Responsible Party for that Customer's personal information, and Booket is the Operator, processing the information only to provide the booking and payment service to the Merchant.
Booket is the Responsible Party for information it processes for its own purposes, including Merchant account creation and billing, Platform security and fraud prevention, product analytics, and direct marketing about Booket's own services (subject to your consent and opt-out rights).
If you are a Customer with a query about how a specific Merchant uses your information (for example, whether they retain your booking history, or how they contact you), you should also refer to that Merchant's own privacy notice, which they are responsible for providing.
We use personal information for the following purposes, each with a lawful basis under POPIA:
You may withdraw consent at any time as described in section 10, without affecting the lawfulness of processing carried out before withdrawal.
We do not sell personal information. We share personal information only as follows:
We require all third parties who process personal information on our behalf to maintain confidentiality and security measures consistent with POPIA and this Policy.
POPIA places additional restrictions on processing "special personal information", which includes information about a person's health, among other categories. Where a booking made through Booket relates to a treatment or service that reveals health-related information (for example, a medical aesthetics consultation), we and our Merchants process that information only:
We limit our own access to such information to what is necessary to operate the Platform (for example, displaying the service name in a booking record) and we do not use special personal information for marketing or profiling without your explicit consent.
Card payment details are collected and processed through a Payment Card Industry Data Security Standard (PCI DSS) compliant payment service provider. Booket does not store full card numbers, and where card details are held to enable future bookings, this is done by our payment partner under tokenisation, not by Booket directly.
Merchant banking details (account number and branch code) are used solely to facilitate settlement payouts and are stored using access-controlled, encrypted systems. They are never shared with Customers or other Merchants.
We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, including:
When personal information is no longer required, we securely delete, anonymise, or de-identify it.
Subject to POPIA, you have the right to:
To exercise any of these rights, contact us using the details in section 16. We may need to verify your identity before actioning a request, and we will respond within the timeframes required by POPIA.
We implement reasonable technical and organisational measures to protect personal information against loss, unauthorised access, interference, modification, or disclosure, including:
No system is completely secure, and we cannot guarantee absolute security. If we become aware of a security compromise that has, or may have, resulted in unauthorised access to personal information, we will notify the Information Regulator and affected data subjects as required by section 22 of POPIA.
Our website and web application use cookies and similar technologies to:
You can manage cookie preferences through your browser settings or, where available, through our cookie consent banner. Disabling strictly necessary cookies may affect the functioning of the Platform.
Some of our service providers (for example, cloud hosting or analytics providers) may process personal information outside South Africa. Where this occurs, we take reasonable steps to ensure the recipient is subject to a law, binding corporate rules, or agreement that provides an adequate level of protection, substantially similar to POPIA, before the transfer takes place, in line with section 72 of POPIA.
The Platform is intended for use by adults. We do not knowingly collect personal information from children (as defined in POPIA) without the consent of a competent person (such as a parent or legal guardian). If we become aware that we have collected personal information from a child without appropriate consent, we will take reasonable steps to delete it.
If you have concerns about how we process your personal information, please contact us first using the details in section 16 so we can try to resolve the matter. If you are not satisfied with our response, you may lodge a complaint with the Information Regulator (South Africa):
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints email: complaints.IR@justice.gov.za
General enquiries: enquiries@inforegulator.org.za
Website: www.justice.gov.za/inforeg
For any questions about this Privacy Policy, or to exercise your rights under POPIA, please contact our Information Officer:
Attention: Information Officer
Email: frederick@letsbooket.com
Postal address: 299 Pendoring Road, Blackheath, 2165
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on the Platform with a revised "Last updated" date. Where changes are material, we will provide additional notice (for example, by email or an in-app notification).
This Policy was last reviewed on 21 August 2026.