Privacy Policy
Last updated: 05 April 2026
TopStay, operated by Able Systems & Products (Pty) Ltd ("we", "us", "our"), is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, store, and share your personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable South African legislation.
1. Information We Collect
We collect the following categories of personal information:
- Account Information: Name, email address, password (encrypted), organisation name, and contact details provided during registration.
- Booking & Property Data: Enquiry details, guest information, booking records, owner details, property listings, and financial data entered into the platform by your organisation.
- Payment Information: Subscription plan, billing frequency, and transaction references. Payment card details are processed exclusively by our payment partner, PayFast (Pty) Ltd, and are never stored on our servers.
- Usage Data: Browser type, IP address, pages visited, timestamps, and other analytics data collected automatically through cookies and server logs.
2. How We Use Your Information
We process your personal information for the following purposes:
- To create and manage your user account and organisation.
- To provide, maintain, and improve the TopStay platform and its features.
- To process subscription payments and manage licences.
- To send transactional emails such as verification, invoices, and booking notifications.
- To provide customer support and respond to enquiries.
- To comply with legal obligations and enforce our terms of service.
3. Legal Basis for Processing (POPIA)
We process your personal information under one or more of the following conditions as defined in POPIA:
- Consent: You have given us consent (e.g., accepting these terms at sign-up).
- Contract: Processing is necessary to fulfil our contractual obligations to you.
- Legitimate Interest: Processing is necessary for our legitimate business interests, provided your rights are not overridden.
- Legal Obligation: Processing is required to comply with applicable law.
4. Data Sharing
We do not sell your personal information. We may share data with:
- PayFast: Our payment processor, for subscription billing.
- Hosting Providers: Our hosting infrastructure (Kinsta / Google Cloud Platform) to store and deliver the application.
- Law Enforcement: If required by law, regulation, or valid court order.
All third-party service providers are contractually obligated to protect your information and may only use it for the specific purposes we direct.
5. Data Storage and Security
Your data is stored on secured servers. We implement appropriate technical and organisational measures including:
- Encryption of data in transit (TLS/SSL) and at rest.
- Role-based access controls within the platform.
- Regular security updates and vulnerability monitoring.
- Multi-tenant data isolation to ensure organisations cannot access each other's data.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the platform's services. If you cancel your subscription, your data will be retained for a reasonable period (typically 90 days) before deletion, unless a longer retention period is required by law.
7. Your Rights Under POPIA
As a data subject, you have the right to:
- Access: Request confirmation of whether we hold your personal information and request a copy.
- Correction: Request that inaccurate or incomplete personal information be corrected.
- Deletion: Request the deletion of your personal information, subject to legal and contractual limitations.
- Object: Object to the processing of your personal information on reasonable grounds.
- Data Portability: Request your data in a structured, commonly used format.
- Withdraw Consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at the details provided below.
8. Cookies
We use cookies and similar technologies to:
- Maintain your session and authentication state.
- Remember your preferences.
- Analyse usage patterns to improve the platform.
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect platform functionality.
9. Children's Privacy
TopStay is a business-to-business platform and is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of the platform after changes constitutes acceptance of the revised policy.
11. Information Officer & Contact
For any privacy-related queries, requests, or complaints, please contact:
Able Systems & Products (Pty) Ltd
Email: info@ablesystems.co.za
South Africa
You also have the right to lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.