Introduction
This Privacy Notice explains how Arms and Legs (Pty) Ltd ("Arms and Legs", "we", "us", "our") collects, uses, stores, and shares personal information when you use our platform at armsandlegs.co.za.
We are committed to protecting your personal information and complying with the Protection of Personal Information Act 4 of 2013 ("POPIA") and other applicable South African law.
This notice applies to anyone who uses the platform — whether you are booking an adventure as a customer, listing adventures as a provider, or browsing without an account.
Please read this notice carefully. If you have questions, contact us at privacy@armsandlegs.co.za.
Who is responsible for your personal information
Arms and Legs (Pty) Ltd is the Responsible Party for personal information collected through the platform, as defined under POPIA.
Our Information Officer is Johan Punt, contactable at infoofficer@armsandlegs.co.za.
What personal information we collect
The information we collect depends on how you use the platform. Below is a summary of what we collect and why.
If you create a customer account
- Identity: full name, email address, phone number, date of birth (for age-gated adventures)
- Login credentials: encrypted password
- Profile: optional profile photo, optional bio
If you book an adventure
- Booking details: the adventure, date, time slot, number of participants
- Participant information: name, age, and any medical conditions relevant to safe participation for each participant on the booking
- Emergency contact: name, relationship, and phone number of an emergency contact
- Payment information: payment is processed by Paystack — we receive confirmation of payment success and a transaction reference. We do NOT receive or store your card number, CVV, or full card details.
If you register as a provider
In addition to the customer information above, we collect information necessary to verify your identity and pay you correctly:
- Business identity: trading name, business registration number if applicable
- Legal identity: government-issued ID number, physical address
- Banking details: account holder name, bank, branch, account number (for payouts of your commissions)
- Insurance and licensing: proof of relevant public liability insurance, activity-specific licences or permits
- Content you publish: listings, photographs, descriptions, availability schedules, pricing, cancellation policies
If you contact us or use the platform's messaging feature
- Your messages to us or other users through the platform's in-platform messaging system
- Records of your communications with our support team
Automatically collected information
When you visit the platform, we automatically collect certain technical information:
- Device and browser: IP address (hashed for our records), browser type and version, device type, operating system
- Usage: pages visited, features used, timestamps
- Cookies and similar technologies: see the Cookie Policy for full detail
Special personal information
Under POPIA §26, certain categories of personal information receive additional protection. We collect health information in one specific circumstance: when you or a person you are booking for discloses medical conditions relevant to safe participation in an adventure. This information is disclosed to the relevant Provider only for the purpose of ensuring safe delivery of that specific booking, and is retained per our Retention Schedule.
We do not collect any other categories of special personal information (religious beliefs, political persuasion, biometric data, criminal history) except where legally required.
Why we collect your personal information
We process your personal information for the following purposes:
- To operate the platform — creating and managing your account, displaying adventures, processing bookings, facilitating payments and refunds
- To communicate with you — booking confirmations, payment receipts, cancellations, reschedules, service announcements, replies to your queries
- To keep you safe — sharing safety-relevant information with providers, enforcing our safety and misconduct frameworks
- To comply with the law — tax records, POPIA compliance, dispute records, court orders where applicable
- To improve the platform — analysing anonymised usage patterns to guide product improvements
- For marketing (only with your consent) — sending newsletters, promotional communications, and platform updates. You can opt out at any time.
We only process your personal information for these purposes, and only for as long as necessary.
Who we share your personal information with
We share your personal information only when necessary to operate the platform, deliver the service you have requested, or comply with the law.
Providers on the platform
When you book an adventure, the Provider running that adventure receives:
- Your name and the participant details (name, age, medical conditions where relevant to safe participation, emergency contact)
- Your booking details (date, time, number of participants, amount paid)
We do NOT share your email address, phone number, ID number, banking information, or details of your other bookings with the Provider. All communication between you and the Provider before and after the booking happens through the platform's in-platform messaging system.
Operators (service providers that help us run the platform)
We use trusted third-party service providers ("operators" under POPIA) to deliver core platform functions. Each operator processes personal information on our behalf under a written data processing agreement, and only for the purpose we have contracted them for.
| Operator | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database, storage | Ireland (EU) |
| Vercel | Hosting and content delivery | Multiple regions incl. EU and US |
| Sentry | Error monitoring and diagnostics | Germany (EU) |
| Resend | Transactional email delivery | United States |
| Paystack | Payment processing | South Africa |
| Google Workspace | Business email and productivity | Multiple regions incl. EU |
Where required by law, we sign additional agreements (Data Processing Addendums, Standard Contractual Clauses, or equivalent) to protect your personal information at these operators.
When you request it
If you consent to us sharing your information with a specific party, we will do so for that specific purpose.
When the law requires it
We may disclose your personal information if we are compelled to do so by a competent court, regulator, or law enforcement authority, or where required to prevent fraud, protect our rights, or protect the safety of any person.
Business transfers
If Arms and Legs is ever acquired, merged, or restructured, your personal information may be transferred as part of that transaction. In that event, we will notify you and ensure the new party is bound by protections at least as strong as this notice.
Cross-border transfers of personal information
Some of our operators are located outside South Africa. When your personal information is transferred outside South Africa, we ensure appropriate safeguards are in place under POPIA §72:
- Transfers to the European Union (Supabase, Sentry, Vercel EU, Google Workspace EU) — the EU maintains a level of protection substantially similar to POPIA under the GDPR, and we have signed Data Processing Agreements with each operator.
- Transfers to the United States (Resend, Vercel US regions where applicable) — protected by contractual safeguards including Data Processing Addendums with Standard Contractual Clauses or equivalent.
If you would like more information about the specific safeguards for a particular transfer, please contact privacy@armsandlegs.co.za.
How long we keep your personal information
We retain your personal information only for as long as necessary to fulfil the purposes we collected it for, unless a longer period is required by law.
| Data category | Retention period | Basis |
|---|---|---|
| User account details | Until you request deletion or until 3 years of account inactivity | POPIA §14 + user consent |
| Booking transaction records | 5 years post-transaction | Tax Administration Act |
| Provider KYC (identity, banking) | 5 years post-relationship termination | Financial Intelligence Centre Act, Tax Administration Act |
| Payment records | 5 years post-transaction | SARS, payment processor requirements |
| Complaint records | 3 years post-resolution | POPIA + operational necessity |
| Security incident records | 5 years post-incident | POPIA §22 + risk management |
| Marketing consent records | Until withdrawn + 3 years | POPIA §69 |
| In-platform messages | 90 days visible, retained for 3 years for dispute purposes | Operational necessity |
When we no longer need your personal information, we securely delete, destroy, or de-identify it.
When you delete your account
You can request deletion of your account at any time from Settings → Security → Delete Account.
When your account is deleted:
- Your personal information is anonymised: your name is replaced with "Deleted User", your email is hashed, your phone number and ID number are removed, your banking details are deleted, and your profile is removed from the platform.
- Historical transaction records are retained in anonymised form for the periods described above, as required by South African tax and financial law.
- If you have pending or upcoming bookings, you will be asked to resolve them (complete or cancel) before deletion.
- Your session is terminated immediately upon deletion.
Once deleted, this action cannot be undone.
Your rights under POPIA
Under POPIA, you have the following rights regarding your personal information:
- Right to be notified that we hold your personal information and what we do with it (this notice fulfils that role)
- Right of access to the personal information we hold about you
- Right to correction of personal information that is inaccurate, misleading, or incomplete
- Right to deletion of personal information that is no longer necessary, excessive, unlawfully obtained, or where you withdraw consent
- Right to object to the processing of your personal information for direct marketing or other reasonable grounds
- Right to withdraw consent at any time where processing is based on your consent
- Right to lodge a complaint with the Information Regulator of South Africa
To exercise any of these rights, contact infoofficer@armsandlegs.co.za. We will respond to your request within a reasonable time and no later than as required by POPIA.
You will not be discriminated against for exercising these rights.
Direct marketing
We may from time to time send you marketing communications about new features, adventures you may be interested in, or platform improvements.
We will only send marketing communications:
- To existing customers, and only about similar products and services, unless you have opted out
- To non-customers, only where you have given us specific opt-in consent
Every marketing communication includes a clear unsubscribe mechanism. You can opt out at any time by clicking the unsubscribe link, updating your preferences in your account settings, or contacting privacy@armsandlegs.co.za.
We do not sell your personal information to third parties for their own marketing purposes.
Children under 18
The platform is not directed at children under 18 as account holders. However, minors will often be participants in adventures booked by their parents or legal guardians (family fishing trips, kids' surf lessons, etc.).
Where a booking includes a minor as a participant:
- The competent adult making the booking is responsible for obtaining any necessary parental consent
- The competent adult acknowledges and consents to the processing of the minor's personal information (including safety-relevant medical information) for the purpose of that booking
- The minor's personal information is subject to the same protections as adult personal information under POPIA §35
If you become aware that a child under 18 has created an account on the platform without competent adult consent, please contact privacy@armsandlegs.co.za so we can address it.
Cookies and tracking
We use cookies and similar technologies to operate the platform, remember your preferences, and understand how the platform is used. Full detail is in our Cookie Policy.
You can control cookie behaviour through your browser settings or through the cookie consent banner presented on your first visit.
Content you upload to the platform
Certain content you upload to the platform — including profile photos, adventure listings, adventure photographs, and reviews — may be used by Arms and Legs for platform operation and, where applicable, promotional purposes such as marketing materials, social media, and advertising campaigns.
The specific terms of how your content may be used are set out in our Website Terms and Conditions (Intellectual Property section). If you have concerns about a specific piece of your content being used in active marketing, contact privacy@armsandlegs.co.za and we will consider a reasonable request for removal from that specific use.
Automated decision-making
We use automated tools in some operational functions, including:
- Content moderation — automated screening of listing text and images for prohibited content
- Fraud prevention — automated checks on unusual booking patterns
- Support triage — automated categorisation of support enquiries
Where an automated decision could significantly affect you, you have the right to request human review of that decision under POPIA §71. Contact infoofficer@armsandlegs.co.za.
How we protect your personal information
We implement appropriate technical and organisational measures to protect your personal information against loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of sensitive data at rest
- Access controls and authentication for staff and operators
- Regular security reviews and system monitoring
- Written data processing agreements with all operators
- Staff confidentiality obligations
If we ever become aware of a security compromise involving your personal information, we will notify you and the Information Regulator as required by POPIA §22.
How to complain
If you are unhappy with how we have handled your personal information, please contact us first at privacy@armsandlegs.co.za. We will do our best to resolve your concern.
You also have the right to complain to the Information Regulator of South Africa:
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 Complaints email: POPIAComplaints@inforegulator.org.za General enquiries: enquiries@inforegulator.org.za Website: https://www.justice.gov.za/inforeg/
Changes to this notice
We may update this Privacy Notice from time to time to reflect changes in our practices, legal requirements, or platform features.
Material changes will be notified to you by email and displayed prominently on the platform at least 14 business days before the effective date.
Non-material changes (drafting clarifications, typos, updated contact details) may take effect immediately upon publication.
The current version of this notice is always available at armsandlegs.co.za/privacy. The version number and effective date at the top of this document identify which version applies.
Contact us
For any privacy-related questions, requests, or concerns:
Email: privacy@armsandlegs.co.za Information Officer: Johan Punt — infoofficer@armsandlegs.co.za Postal: 32 Perlemoen Avenue, Stilbaai, Western Cape, 6674
*This notice was prepared to comply with the Protection of Personal Information Act 4 of 2013 and other applicable South African law. It should be read alongside our Website Terms and Conditions and our Cookie Policy.*