Privacy Policy
Protection of Personal Information Policy of Hospitality Insights (Pty) Ltd t/a Seatly, in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).
Last updated: 9 September 2026
1. About this policy
Hospitality Insights (Pty) Ltd t/a Seatly ("Seatly", "we", "us" or "our") provides booking, event, payment-support and venue management services through our website, venue portal, WhatsApp booking service and related systems. This policy explains what personal information we process, why we process it, who receives it, how long we keep it and the rights available to data subjects under POPIA.
This policy applies to guests, adult booking holders, venue owners, venue staff and other people who interact with Seatly. It is a notice about our processing practices and does not replace any consent that POPIA requires us or a venue to obtain separately.
2. Who is responsible for personal information
POPIA distinguishes between a Responsible Party, which determines why and how personal information is processed, and an Operator, which processes personal information for a Responsible Party under an agreement or mandate.
- The venue is generally the Responsible Party for guest information processed to provide that venue's bookings, events, services, guest communications and venue marketing.
- Seatly acts as an Operator when it processes that information on the venue's instructions to provide the platform.
- Seatly is also a Responsible Party for processing where Seatly determines the purpose and means, including platform account administration, subscription billing, fraud prevention, security, legal compliance, service performance and Seatly's own permitted business communications.
If a request concerns information controlled by a venue, we may refer the request to that venue and assist it in responding.
3. Seatly and our Information Officer
Responsible entity: Hospitality Insights (Pty) Ltd t/a Seatly
Registered or physical address: 207 Milner Road, Claremont, Cape Town, 7708
Information Officer: Ken Walton
Privacy email: privacy@seatly.co.za
4. Personal information we collect
Guest and booking information
- Name of the adult booking holder or guest
- Telephone number, including the WhatsApp number used to contact us
- Email address, where provided or required for a ticket or confirmation
- Booking, ticket, attendance and transaction history
- Booking preferences, special requests and communications
- Optional allergy or dietary information supplied by the guest
- Payment status and payment-provider transaction references
- Technical and delivery records needed to operate and secure the service
Participant ages
Seatly does not request or record the names of child participants. Where a venue's price or participation rules depend on age, the adult booking holder may be asked to confirm a participant's age or age band. This information is used only to calculate the applicable price or confirm booking eligibility. Seatly does not create a separate child profile or use participant ages for marketing.
Venue account information
- Names, work contact details and account roles of venue users
- Venue identity, address, contact details and booking configuration
- Subscription, invoice and payment-provider account information
- Support, audit, security and account activity records
5. Where information comes from and whether it is required
We obtain personal information:
- directly from guests, adult booking holders, venue owners and venue staff;
- from the relevant venue when it creates or updates a booking;
- from WhatsApp, email, web forms and other channels used to contact Seatly;
- from payment and service providers when they report a transaction or delivery status; and
- automatically from platform use, including security, audit and technical logs.
Information identified during a booking as required must be provided so that we and the venue can identify the booking holder, calculate the correct price, check availability, complete the booking and send essential confirmations. If it is not provided, the booking or requested service may not be available. Optional information, such as allergy details, dietary preferences and marketing consent, does not have to be provided.
6. Why we process personal information
We process personal information where reasonably necessary to:
- search for venues, services and events;
- create, manage, change or cancel bookings and event tickets;
- calculate prices and apply age-based or participation rules;
- send confirmations, tickets, reminders, service notices and booking updates;
- pass guest requests to the relevant venue and enable venue messaging;
- facilitate payments through the venue's payment provider;
- provide and administer venue accounts, subscriptions and support;
- prevent fraud, protect the platform and keep appropriate audit records;
- measure and improve service reliability and functionality using appropriately limited information;
- comply with legal and regulatory obligations; and
- send direct marketing only where POPIA permits it.
7. Lawful grounds for processing
Depending on the purpose, processing may be justified because:
- it is necessary to conclude or perform a contract to which the data subject is a party, including completing a requested booking;
- it protects a legitimate interest of the data subject, the venue or Seatly, provided that the processing is proportionate and lawful;
- it is necessary to comply with an obligation imposed by law;
- the data subject or a competent person has given valid consent; or
- another ground permitted by POPIA applies.
We do not treat ordinary use of Seatly as blanket consent to every form of processing. Where consent is required, it must be voluntary, specific and informed, and it may be withdrawn subject to applicable legal and record-keeping requirements.
8. Allergy and dietary information
Allergy information may constitute health information and therefore special personal information under POPIA. Providing allergy or dietary information is optional. When a guest deliberately provides it for use with a booking, we process it to record the request on the guest profile and relevant booking records and to make it available to the relevant venue so that the venue can consider the request.
Access is limited to authorised Seatly personnel, service providers and authorised users of the relevant venue who need it for the stated purpose. Seatly and the venue cannot guarantee that an allergen-free environment or particular dietary accommodation will be available. Guests should raise any safety-critical allergy directly with the venue when attending.
A guest may ask us to correct or remove saved allergy or dietary information. Removal may be limited where a record must lawfully be retained, in which case processing will be restricted where required.
9. Information relating to child participants
A person under 18 is a child for purposes of POPIA. Seatly does not ask for or store a child participant's name. An adult booking holder who supplies a participant's age or age band must be authorised to provide it. Seatly uses that limited information only where necessary to calculate the price or apply the venue's participation rules and does not use it for profiling or marketing.
10. Payments and financial information
Where a venue requires payment, the payment is processed by the venue's integrated payment provider. Seatly may create the payment request and receive the resulting payment status and transaction reference, but does not store card numbers, CVVs or online-banking credentials. Venue subscription payments are processed by the applicable subscription payment provider.
Funds paid for a venue booking or event are settled according to the venue's payment arrangement. Refund decisions and processing are handled through the applicable venue refund workflow.
11. When we share information
We may disclose relevant personal information:
- to the venue selected by the guest, so it can provide and manage the requested booking or event;
- to authorised venue users and Seatly personnel who require access for their duties;
- to Operators and service providers necessary to deliver, secure and support Seatly;
- where required by law, legal process or a competent authority;
- to protect the rights, safety or security of data subjects, venues, Seatly or others; or
- as part of a lawful merger, financing, acquisition or sale, subject to appropriate safeguards.
We do not sell personal information. We do not share guest information with unrelated venues for their own use.
12. Service providers
Provider categories used to operate Seatly include:
- Database and hosting — including Supabase and Railway;
- Messaging and email — including Meta/WhatsApp and Resend;
- Payments — including Yoco and Paystack where configured;
- Artificial intelligence — including Anthropic for the booking assistant; and
- Security, monitoring and support — providers used to keep the service reliable and secure.
Providers must process personal information only for authorised purposes and under appropriate contractual and security safeguards. A provider may also process limited information as an independent Responsible Party where the law or its own service terms require it.
13. Cross-border processing
Some service providers may process personal information outside South Africa. Before such a transfer, the relevant Responsible Party must ensure that section 72 of POPIA is satisfied, including through an applicable law, binding corporate rules, a binding agreement, valid consent or another permitted ground that provides an adequate level of protection.
Special personal information and limited participant-age information receive the additional safeguards required by POPIA. Where a proposed transfer requires prior authorisation from the Information Regulator, it will not begin until the applicable requirements have been met.
14. Security
Seatly uses reasonable technical and organisational safeguards that are appropriate to the nature of the information and the risks of unauthorised access, loss, damage, destruction or disclosure. These measures include:
- encrypted network communications;
- authentication, role-based access and tenant separation controls;
- database access controls, including row-level security where applicable;
- restricted administrative access and audit records;
- security and availability monitoring; and
- periodic review and improvement of safeguards and service-provider controls.
No online service can guarantee absolute security. Users and venues must protect their credentials and promptly report suspected unauthorised access to privacy@seatly.co.za.
15. Security compromises
If there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the Responsible Party will investigate, contain and mitigate the incident and notify the Information Regulator and affected data subjects as soon as reasonably possible where POPIA requires notification. Notification may be delayed only where lawful grounds permit it.
Where Seatly acts as an Operator, Seatly will notify the applicable Responsible Party immediately after discovering an unauthorised access or acquisition, as required by POPIA and the applicable Operator agreement.
16. Retention and deletion
We retain personal information only for as long as the purpose for which it was collected continues, or for a longer period where required or permitted by law, contract, legitimate operational needs or valid consent. Different categories of information may therefore have different retention periods.
A guest may ask Seatly at any time to remove the contact details and other personal information held in their Seatly profile. When the request is made through the WhatsApp number on file, Seatly provides a secure, time-limited process for the guest to confirm the request. Once confirmed, Seatly clears or de-identifies the profile details and removes associated marketing permissions.
Past booking, event, payment, refund, delivery, security and audit records may be retained by Seatly or the relevant venue where there is a lawful operational, financial, fraud-prevention, dispute or regulatory reason to preserve them. Access to retained records is restricted and the information will be deleted or de-identified when there is no longer a lawful reason to retain it.
17. Data-subject rights
Subject to POPIA and PAIA, a data subject may:
- ask whether Seatly or the relevant venue holds personal information about them;
- request access to that personal information;
- request correction, deletion or destruction of inaccurate, excessive, outdated, incomplete, misleading or unlawfully obtained information;
- object on reasonable grounds to processing based on specified lawful grounds;
- withdraw consent where processing relies on consent;
- object at any time to direct marketing;
- ask that processing be restricted where POPIA requires it; and
- complain to Seatly, the relevant venue or the Information Regulator.
Requests may be sent to privacy@seatly.co.za. We may take reasonable steps to verify the requester's identity and authority before disclosing or changing information. Where the venue is the Responsible Party, Seatly may forward the request to that venue and assist with the response.
18. Direct marketing
Booking confirmations, tickets, payment notices, reminders, service messages and responses to a guest's request are operational communications rather than direct marketing.
Seatly or a venue may send electronic direct marketing only where the recipient has given the required consent or POPIA's existing-customer exception lawfully applies. Marketing consent is separate from completing a booking, is recorded for the applicable sender and channel, and may be withdrawn at any time. Every electronic marketing communication will identify the sender and provide a reasonable, free way to opt out. Opt-outs are recorded and respected.
19. Artificial intelligence and automated processing
Seatly's booking assistant uses artificial intelligence to interpret guest messages and help search for, create and manage bookings. The assistant may process contact details, conversation content, booking details, venue information and availability needed for that purpose.
Seatly does not use the assistant to make a decision based solely on automated profiling that produces legal consequences or similarly significant effects for a data subject. A booking is confirmed only after the booking system successfully applies the relevant venue rules, availability and guest confirmation.
20. Changes to this policy
We may update this policy when our services, processing practices or legal obligations change. The updated policy will be published with a revised date. Where a change materially affects how personal information is used, we will provide an additional notice where reasonably practicable or legally required. A policy update does not create consent where POPIA requires consent to be obtained separately.
21. Questions and complaints
Privacy questions, rights requests and complaints may be sent to Seatly's Information Officer at privacy@seatly.co.za.
A data subject may also lodge a complaint with the Information Regulator of South Africa:
- Website: inforegulator.org.za
- POPIA complaints: popiacomplaints@inforegulator.org.za
- Telephone: 010 023 5200