Skip to main content

Shumba Valley Lodge

Legal

Privacy policy

What we collect, why we collect it, who we share it with, how long we keep it,
and what you can ask us to do with it.

Last updated 28 August 2026

Shumba Valley Hotel respects your privacy. This policy explains what personal information we collect, why we collect it, whether you have to give it to us, who we share it with, how long we keep it, and what you can ask us to do with it.
We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

Who we are

Shumba Valley Hotel is the party responsible for the personal information described in this policy.
Trading nameShumba Valley Hotel
Registered nameShumba Valley Lodge and Conference Centre
Registration number1999/007215/07
Address53 Boeing Street, Lanseria, 1748, Gauteng
Telephone+27 (0)11 790 8000
Information OfficerGodfrey Noge, IT Manager
Privacy enquiriesprivacy@shumbavalley.co.za
PAIA manualhttps://inforegulator.org.za/paia/

privacy@shumbavalley.co.za is monitored for privacy, POPIA and PAIA matters only. For bookings, enquiries or anything else, please use info@shumbavalley.co.za or call us.

Who this policy applies to

This policy applies to you if you visit our website, enquire with us, book with us, stay with us, attend a conference or function here, use our facilities, or deal with us as a travel agent, corporate client or event organiser.

Personal information means information that identifies you or can be linked back to you. Under POPIA it also includes information about a company, close corporation or trust, so if you deal with us on behalf of your organisation, your organisation’s information is protected too.

Personal information does not include:

  • information that has been de-identified to the point where it cannot be re-identified
  • aggregate statistics that do not identify anyone

Information you have posted publicly, such as a review on a booking platform or a comment on our social media, is still your personal information. If we read, respond to or analyse it, we are processing it, and we do so on the basis of our legitimate interest in understanding and responding to guest feedback (section 11(1)(f)). We do not add people to marketing lists because they reviewed us.

What this policy does not cover. Applying for a job with us, and supplying goods or services to us, are covered by separate notices. Ask us and we will send you the relevant one.

Other people’s information. If you give us information about someone else, such as a fellow guest, a delegate or a family member, please make sure they know and are comfortable with it. We remain responsible for how we handle their information, and we will give them this policy if they ask.

What we collect, why, and whether you have to give it to us

What we collect depends on how you deal with us. In each section below we tell you whether the information is required or optional, and what happens if you do not give it to us.

3.1 When you book or stay with us

Required. We cannot accommodate you without it.

What we collectWhy
Name, email address, telephone number and addressTo confirm and hold your reservation and contact you about your stay
Identity or passport number, nationality, residence status, residential address and signature, and a copy of your identity document or passportTo keep the guest register the law requires us to keep
Names of everyone staying in your party, including childrenSame register requirement
Arrival and departure dates, room type, rate and chargesTo prepare your room, bill you correctly and issue an invoice
Payment detailsTo take payment and process any refund

Our legal basis. Performing our contract with you (section 11(1)(b)); complying with obligations imposed by law (section 11(1)(c)), specifically section 40 of the Immigration Act 13 of 2002 read with regulation 36 of the Immigration Regulations, which requires lodges to keep a register of everyone who is given accommodation, to record the particulars listed above, and to safeguard that register through a person we authorise for the purpose; and tax and company law record-keeping obligations. Where the register includes a child, we rely on section 35(1)(b) of POPIA, because keeping the register is a legal obligation.

If you do not provide it, we cannot check you in. This is not a commercial choice on our part. Section 40 makes it an offence for both the establishment and the guest.

Optional. Your stay goes ahead without it.

What we collectWhy
Dietary requirements and food allergiesSo the kitchen can cater for you safely
Accessibility and mobility needsSo we can allocate a suitable room and assist you
Other special requestsSo we can try to meet them
Vehicle registration numberOnly if you park on the property, for security and access control

Our legal basis. Your consent (sections 11(1)(a) and 27(1)(a)).

Please note what this information is. Allergies and mobility needs are health information. Dietary requirements can reveal religious or philosophical belief. Under POPIA these are special personal information (section 26), which the law protects more strictly than ordinary information. We therefore collect it only with your consent, use it only to deliver the service you asked for, never for marketing, and restrict access to the staff who need it to look after you: the kitchen, housekeeping and front office. You can withdraw your consent at any time by telling us, and we will delete it.

If you do not provide it, we cannot cater to your dietary needs, cannot guarantee an allergy-safe meal, and cannot prepare an accessible room. Please tell us if any of this matters to you.

A note on payment cards.

We do not store your full card number. Card payments are processed by our payment provider, which returns a secure token to us. We handle card payments in line with the Payment Card Industry Data Security Standard (PCI DSS). Please do not send us card details by email, WhatsApp or fax. If you do, we will delete them and ask you to use our secure payment link instead.

3.2 When you enquire with us

What we collect

  • Name, email address and telephone number
    The dates, room type or package you are asking about
  • The content of your messages, by web form, email, WhatsApp, Facebook, Instagram or telephone
  • Your answers, where you complete a lead form on one of our Facebook or Instagram advertisements

Why

To answer your enquiry, send you the information, quote or package you asked for, and follow up with you about that enquiry.

Our legal basis. Taking steps at your request before entering into a contract (section 11(1)(b)), and our legitimate interest in responding to people who contact us (section 11(1)(f)). Where you ask us to follow up on WhatsApp, we do so on the consent you give on the form.

Required or optional. Your contact details are required, because we cannot answer you without them. Everything else is optional.

We will only contact you about the enquiry you made. Following up on your enquiry is not marketing. If you would also like to hear about our specials and offers, we will ask you separately, and you are free to say no without it affecting your enquiry. See section 6.

3.3 When you book a conference, function or event

What we collect

  • Your name, job title, company name and business contact details
  • Delegate names and numbers, where you or your organiser give them to us
  • Delegate dietary and accessibility requirements
  • Billing, VAT and purchase order details for your organisation

Why

To quote for, plan and run your event, cater for delegates, allocate rooms and invoice your organisation.

Our legal basis. Performing our contract with you or your organisation (section 11(1)(b)). Delegate dietary and accessibility information is special personal information and is handled as described in section 3.1, on the consent of the delegate concerned.

Required or optional. Contact and billing details are required. Delegate dietary and accessibility requirements are optional, but without them we cannot cater safely.

If you are an organiser, please make sure your delegates know their details are being shared with us and that this policy is available to them.

3.4 When you use our website

What we collect

  • IP address, device type, browser and operating system
  • The page that referred you, the pages you viewed and how long you spent on them
  • Whether you started or completed a booking
  • Cookie and pixel data, described in sections 4 and 5

Why

To keep the site and booking engine working, to understand how people find and use the site, and, where you have accepted advertising cookies, to measure and target our advertising.

Our legal basis. Our legitimate interest in operating and securing the website (section 11(1)(f)), and your consent for anything beyond what is strictly necessary (section 11(1)(a)).

Required or optional. Essential cookies are required for the site and booking engine to work. Analytics and advertising cookies are optional and are switched off until you accept them.

3.5 When you use our guest Wi-Fi

What we collect

  • The details you enter to log in, which are our username and password
  • A device identifier such as an IP address, MAC address or device name, assigned automatically when you connect
  • Connection records: device type, and the dates, times and duration of your sessions

What we do not collect

We do not read, record or store the content of anything you send or receive, not your emails, messages, calls or files, and we do not monitor which sites you visit for marketing purposes.

Why

To run and secure the network, manage bandwidth and troubleshoot faults.

Our legal basis. Performing our contract with you as a guest (section 11(1)(b)), and our legitimate interest in the security and proper functioning of our network (section 11(1)(f)).

Required or optional. Logging in is required to use the network. You are free not to use it.

If the portal asks for your email address, we will not add it to any marketing list unless you separately tick the marketing box on the login screen itself.

3.6 When you telephone us
We do not record telephone calls. If that ever changes, we will tell you at the start of the call and update this policy.
3.7 When you are on the property

What we collect

CCTV footage in reception, restaurant, bar, terrace, pool area and main gate entrance of the lodge. Cameras are not placed in bedrooms, bathrooms, changing areas or any other place where you would reasonably expect privacy. Signs are displayed at each monitored area.

Why

The safety and security of guests, staff and property, and investigating incidents. Never for marketing. Not shared except with law enforcement, or where we need it to establish or defend a legal claim.

Our legal basis. Our legitimate interest in the security of the property and the people on it (section 11(1)(f)).

3.8 Where else we get your information

Most of what we hold, you give us. We also receive personal information from:

  • online travel agents and booking platforms, including Booking.com, Expedia, Hotels.com, TripAdvisor and Airbnb
  • our booking engine and property management system
  • Meta, when you complete a lead form on one of our advertisements
  • your employer, travel agent, conference organiser or event planner
  • anyone else in your party who books on your behalf

Cookies and tracking

Our website uses cookies. Some are necessary for the site and booking engine to work. Others help us understand how the site is used and let us advertise as described in section 5.
TypeWhat it doesNeeds your consent
EssentialKeeps the site working and holds a booking in progressNo
AnalyticsTells us how visitors find and move through the siteYes
AdvertisingMeasures our advertising and lets us show you our ads againYes

Analytics and advertising cookies do not run until you accept them. You can accept or decline them in the banner when you arrive, and change your mind at any time through the cookie settings link in the footer. You can also clear or block cookies in your browser, but blocking essential ones may stop parts of the site, including the booking engine, from working.

Our full cookie policy is at www.shumbavalleylodge.co.za

Advertising, retargeting and audience matching

We advertise on Facebook, Instagram and Google. Some of that advertising is targeted. We explain how below, because it is the part of our processing that is least visible to you.

Advertising to people who have visited our website. If you accepted advertising cookies, the Meta Pixel and Google’s advertising tags record that you visited and which pages you viewed. We can then ask Meta or Google to show our advertising to you again. We do not learn your name this way, and we do not receive a list of who saw our ads.

Matching our lists to advertising platforms. We may upload email addresses and phone numbers we already hold to Meta or Google, so they can show our advertising to those people or to people whose interests resemble theirs. Contact details are converted into a coded form before they are sent, so the platform cannot read them and uses them only to find a match against accounts it already has. That coded form is still your personal information, and we remain responsible for it, so we do this only where you have agreed to receive marketing from us. You can ask us to remove you from any audience list at any time.

Lead advertising on Facebook and Instagram. Some of our advertisements carry a form you can complete without leaving the app. Meta passes your answers to us and we contact you about your enquiry. Meta also keeps a copy under its own privacy policy, at facebook.com/privacy/policy.

What we do not do

  • We do not use automated processing to decide what you are charged or whether you can book
  • We do not sell your personal information
  • We do not combine CCTV footage or Wi-Fi records with marketing data
  • We do not track your location when you are not on the property
  • We do not use dietary, allergy, accessibility or health information for advertising

How to stop it. Decline advertising cookies on our site, or change your choice through the cookie settings link in the footer. You can also limit targeted advertising in your Facebook, Instagram and Google account settings, which applies to every advertiser and not only us. To come off our audience lists, write to privacy@shumbavalley.co.za.

Marketing, and how to stop it

We send marketing by email, WhatsApp or SMS only where:

  • you have agreed to receive it, or
  • you are an existing customer, we obtained your details when you booked or stayed with us, and the marketing relates to services similar to those you have already booked.

 

Every marketing message carries a free and easy way to opt out. We ask for your agreement separately from your booking or enquiry, and saying no makes no difference to either. Not replying is not agreement.

Telephone calls. When we call you about an enquiry you made, that is not marketing and we will keep to the subject. We will not make marketing calls to you unless you have agreed to them.

Withdrawing at any time, at no cost. Use the unsubscribe link in any email, reply STOP to a WhatsApp or SMS, or write to privacy@shumbavalley.co.za. We keep an internal do-not-contact list so that a refusal is honoured across every channel, not just the one you used to tell us.

This does not affect a booking you have already made. We will still send you confirmations, invoices and arrival details.

The national opt-out registry. Separately from anything you tell us, you can register a pre-emptive block with the National Consumer Commission’s opt-out registry, which stops direct marketing from every registered marketer in South Africa. If you are on that registry, we will not market to you, whatever you may have agreed to before.

We do not sell your personal information, and we do not give it to third parties for their own marketing.

Who we share it with

Only where we need to, and only with parties who are bound by a written agreement to keep your information confidential, to process it on our instructions, to keep it secure, and to tell us immediately if anything goes wrong with it.
WhoWhy
HTI Nebula CRS, our booking engine and property management system providerTo hold and manage your reservation
ABSA, our payment processor, and our bankTo take payment and process refunds
Online travel agents and booking platformsTo manage a booking made through them
Meta Platforms (Facebook and Instagram)Advertising, lead forms and audience matching
GoogleWebsite analytics, our Google Business Profile and advertising
marketing@shumbavalley.co.za, our email marketing platformTo send marketing you have agreed to receive
Suppliers who deliver part of your stay, such as team-building facilitators, transfer operators and event contractorsTo provide what you booked
Our accountants, auditors and legal advisorsProfessional advice and statutory compliance
The South African Police Services law enforcement, regulators and courtsWhere the law requires it, or to protect the safety of guests and staff

If the hotel is ever sold or merged, personal information may transfer to the new owner. We will post notice of this on our website, and you may ask us to delete your information instead.

Sending information outside South Africa

Some of the providers we use, including Meta, Google and our email marketing platform, store and process personal information on servers outside South Africa, including in the United States and the European Union.

South Africa does not publish a list of countries that are treated as safe for this purpose, so we do not rely on one. Instead, before personal information leaves the country, we put a binding written agreement in place with the provider that requires it to protect your information on principles substantially similar to those in POPIA, and that controls whether and how it can pass the information on again. This is what section 72(1)(a) of POPIA requires.

Where a transfer is instead necessary to perform our contract with you, or where you have specifically consented to it, we will say so. We do not rely on your consent alone to justify a transfer that has nothing else behind it.

How long we keep it

We keep personal information only as long as we need it for the purpose we collected it for, or as long as the law requires, and then we delete it.
WhatHow long
Booking, guest and payment records5 years from the end of your stay. Tax law requires five years from the date we submit the relevant return, and longer where a return is outstanding or an audit, objection or appeal is under way. The Companies Act requires seven years for company records. We use the longer period so that one rule covers both.
Guest register entries and copies of identity documents or passportsTwo years from the end of your stay. This is the period the Immigration Regulations require, and the register is safeguarded by a named person we authorise for that purpose, separately from our general records
Dietary, allergy, accessibility and health informationDeleted 30 days after you check out, unless you ask us to keep it on file, so you do not have to tell us again
Enquiries that did not become bookings12 months from your last contact with us
Marketing contact detailsUntil you unsubscribe, or 24 months of no engagement, whichever comes first
Record of your unsubscribe or objectionKept indefinitely, so that we do not contact you again by mistake
Advertising audience lists held by Meta or GoogleRefreshed at least every 6 months, and you are removed when you unsubscribe
Tokenised card referencesDeleted at check-out / kept for the duration of the booking guarantee only
CCTV footage15 days, unless kept longer for a specific incident or investigation
Guest Wi-Fi connection records6 months
Call recordings, if we record calls6 months

One exception to all of the above. Where information is relevant to a complaint, an insurance claim, a legal claim, an investigation or a request from a regulator or the police, we keep it until that matter is finally resolved, even if the period in the table has passed. We do not keep it for any other purpose in the meantime.

How we keep it secure

We take reasonable technical and organisational steps to prevent loss, damage and unauthorised access to your information. These include limiting access to the staff who need it, individual user accounts and passwords on our systems, encrypted transmission of payment details, secure hosting, restricted handling of identity documents and health-related information, confidentiality obligations on staff, and written security obligations on every supplier who handles personal information for us.

No system is completely secure. If we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator, and we will notify you as well. We will do so as soon as reasonably possible after we discover it. We will only hold back from telling you if we genuinely cannot identify you, or if the police or the Information Regulator tell us that notifying you would get in the way of a criminal investigation, in which case we will tell you as soon as they allow.

When we notify you, we will tell you what happened, what it could mean for you, what we have done about it, and what we recommend you do to protect yourself.

Keeping it accurate

Please tell us if anything we hold about you is wrong or out of date. You can correct your details:

We may verify your identity before making changes. There is no charge.

Children

We collect a child’s personal information only where a parent, guardian or other competent person gives it to us as part of a booking, or where the law requires us to record it in the guest register. We do not market to children, and we do not use a child’s information for advertising.

If you believe we hold a child’s information without the consent of a competent person, and it is not information the register requires, write to privacy@shumbavalley.co.za and we will delete it.

Your rights

Under POPIA you may:

  • ask whether we hold personal information about you. Confirming this is free of charge
  • ask for a copy of the personal information we hold about you
  • ask us to correct or update anything inaccurate, misleading or out of date
  • ask us to delete information we no longer have a lawful reason to keep
  • object to our processing, on reasonable grounds relating to your situation
  • withdraw consent you have given, including consent to marketing, at any time and at no cost
  • ask to be removed from any advertising audience list we have shared with Meta or Google
  • object to direct marketing at any time, free of charge
  • not be subject to a decision based solely on automated processing that significantly affects you (section 71). We do not make decisions this way
  • be told if your information is involved in a security compromise (section 22)
  • complain to the Information Regulator

 

How to exercise them. Email privacy@shumbavalley.co.za, write to us at the address in section 1, call us on +27 (0)11 790 8000, or send a WhatsApp or SMS to 062 611 5759. If you call, we will make a recording of the request and give you access to it if you ask. All of this is free.

There are prescribed forms for some of these, and we will send you the right one and help you complete it:

  • Form 1 for an objection to processing
  • Form 2 for a request to correct, delete or destroy information
  • the PAIA Form 2 for a request for access to a record

 

How long we take. We respond to requests for correction or deletion within 30 days. Requests for access to records are dealt with under the Promotion of Access to Information Act 2 of 2000, which gives us 30 days from receipt, extendable once by up to a further 30 days where the request is complex, in which case we will tell you.

Fees. Confirming whether we hold information about you is free. If you request access to records about yourself, no request fee is payable, though a fee for copies and search time may apply and we will tell you what it is before we start. Our PAIA manual, which sets out the full procedure and fee schedule, is at https://inforegulator.org.za/paia/.

Identity. We may ask you to confirm your identity before we act, so that we do not disclose your information to someone else.

Complaints

Please raise it with us first, at privacy@shumbavalley.co.za. Most things are quicker to fix directly, and we would rather know.

You may also complain to the Information Regulator using Form 5, available on their website.

Information Regulator (South Africa) Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone: 010 023 5200 | Toll free: 0800 017 160
Enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
PAIA complaints: PAIAComplaints@inforegulator.org.za
www.inforegulator.org.za

If your complaint is about marketing you did not ask for, you can also contact the National Consumer Commission.

Changes to this policy

We may update this policy. The current version is always at www.shumbavalleylodge.co.za, and the date at the top tells you when it last changed.

Where a change materially affects how we use your personal information, we will post notice on our website at least 30 days before it takes effect, and tell you directly where we hold your email address. Where the law requires your consent to a change, we will ask for it. We will not treat your continued use of our website as agreement.

Contact us

Shumba Valley Lodge
53 Boeing Street, Lanseria, 1748, Gauteng
Attention: The Information Officer, Godfrey Noge
privacy@shumbavalley.co.za | 011 790 8000

Questions about anything on this page? Write to privacy@shumbavalley.co.za or call +27 (0)11 790 8000.

Whatsapp Us