4×4 Epic Tours
Your Privacy Matters

Privacy Policy

How we collect, use, protect and share your personal information — and the rights you have over it under South Africa's POPIA and the EU/UK GDPR.

Last updated: 29 June 2026

Draft — not yet launch-ready. The following legal details still need confirming before this policy goes live, and the whole document should then be checked by a qualified attorney:
  • Legal entity name
  • Company registration number
  • Registered address
  • Information Officer
  • EU/UK representative (Art. 27)
  • EU/UK supervisory authority
  • Cross-border transfer safeguard
Fields still to confirm are marked [TO CONFIRM] in the text below. Supply them via the environment variables in .env.example — see the launch checklist in docs/GDPR-POPIA-LAUNCH-CHECKLIST.md.

1. Who we are

[TO CONFIRM: 4x4 Epic Tours (Pty) Ltd] (“we”, “us”) operates 4x4 Epic Tours (4x4epictours.com). We are the responsible party under POPIA and the data controller under the GDPR for the personal information described here.

  • Registration number: [TO CONFIRM: company registration no.]
  • Registered address: [TO CONFIRM: registered address, Cape Town, South Africa]
  • Information Officer (POPIA): [TO CONFIRM: Information Officer name] privacy@4x4epictours.com
  • EU/UK representative (GDPR Art. 27, if applicable): [TO CONFIRM: EU/UK representative, or state "not required"]

2. What we collect

  • Contact & identity: name, email, phone/WhatsApp number, country.
  • Booking details: tour and departure chosen, number of guests, currency, special requests, booking reference and status.
  • Proof of payment: the document you upload to confirm an EFT deposit. We do not process card payments or store card details.
  • Enquiries & chat: messages you send via our forms or the on-site booking assistant.
  • Technical & usage: with your consent, anonymous analytics about how the site is used (see our Cookie Policy).

3. Why we use it & our lawful basis

We process your personal information for these purposes:

  • Managing your booking (quotes, confirmation, payment matching, trip logistics) — lawful basis: performance of a contract (GDPR Art. 6(1)(b)); POPIA s11(1)(b).
  • Replying to enquiries — lawful basis: legitimate interests / your request (GDPR Art. 6(1)(f)); POPIA s11(1)(f).
  • Marketing (trip ideas, dates, offers by email/WhatsApp/SMS) — lawful basis: your consent (GDPR Art. 6(1)(a)); POPIA s69. We send these only if you opt in, and you can withdraw at any time via the unsubscribe link or by emailing us.
  • Legal & financial records (tax, accounting, SATSA/consumer protection) — lawful basis: legal obligation (GDPR Art. 6(1)(c)); POPIA s11(1)(c).
  • Improving the site via analytics — lawful basis: your consent.

4. Who we share it with

We never sell your personal information. We share it only with operators (processors) who help us run the business, under contract and only as needed:

  • Website hosting: Hostinger (VPS) — stores everything you submit.
  • Analytics:Google Analytics 4 (Google) — only if you allow analytics cookies. We also use Google Search Console for SEO, which doesn’t track you on the site.
  • Email:sent from our own mailbox through our domain host’s mail servers, so a reply to a booking email reaches us directly.
  • WhatsApp: Meta (WhatsApp Business Platform) — to send booking messages and, if you opt in, trip news. We do not send marketing SMS.
  • Online card payments:PayFast (PayFast (Pty) Ltd), if you choose to pay a deposit by card or instant EFT. You enter your card details on PayFast’s own secure pages. They never reach our website, and we never see or store them. We send PayFast only your booking reference and the amount due, not your name, email or phone number. PayFast is certified to PCI-DSS Level 1.
  • Guest and staff accounts: WorkOS (WorkOS, Inc., United States), which runs the sign-in for guest accounts and our staff admin. It holds your email address, your name, and when you last signed in, and records your IP address and browser in its security log.
  • On-site chat assistant: OpenRouter, which routes your message to the DeepSeek AI model. Please don’t share sensitive personal details in the chat — use it for tour questions only.
  • Regulators, banks, our accountant or advisors where the law requires it.

You can still pay your deposit by ordinary EFT or bank transfer directly to our bank, with no payment processor involved. Paying online by card is optional.

5. Sending data outside South Africa / the EEA

Some operators are located outside South Africa and the EEA, so your information may be transferred across borders (POPIA s72; GDPR Chapter V):

  • United States — OpenRouter, Google and Meta. Safeguard: [TO CONFIRM: Standard Contractual Clauses / provider DPA terms, per provider].
  • United States (accounts)— WorkOS stores account data in the United States and offers no European hosting option. Safeguard: WorkOS’s data processing addendum, which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
  • Payments — PayFast is based in Cape Town but reserves the right to process data in another country, and publishes no specific safeguard. This matters less than it might sound: the only things we send them are your booking reference and the amount, so there are no personal details of yours in that transfer.
  • China — the DeepSeek AI model processes the messages you send to our chat assistant. China is not covered by an adequacy decision, so this is a higher-risk transfer; we rely on [TO CONFIRM: Standard Contractual Clauses / provider DPA terms, per provider] and/or your consent, and we limit what the assistant handles. Avoid entering sensitive details in chat.
  • European Union — Hostinger (hosting). The EU benefits from a POPIA-comparable framework.

5a. Health and dietary information

If you book a trip, we may ask about food allergies and dietary requirements so the guides can cater for you and keep you safe on a remote route. Health information is treated as a special category under the GDPR (Art. 9) and POPIA (s26), which means stricter rules than the rest of this policy.

  • We ask only when you have a booking, and only what the guides need to run your trip safely. Every question is optional.
  • Our lawful basis is your explicit consent (GDPR Art. 9(2)(a); POPIA s27). We ask for it separately, on the form itself. It is not bundled into accepting our terms, and it is not the same as agreeing to receive marketing. You can withdraw it at any time.
  • These answers are encrypted on our own servers and are never sent to our sign-in provider, our payment provider, or the on-site chat assistant. Only the owners and the guides running your trip can read them.
  • We delete them after your trip, rather than keeping them for the longer period that applies to booking and financial records.

6. How long we keep it

  • Marketing contacts with no booking: removed after about 36 months of inactivity, or sooner if you unsubscribe and ask us to delete you.
  • Booking & financial records: kept for the period required by South African tax and consumer-protection law (typically 5 years), after which personal details are anonymised.
  • Proof-of-payment files: deleted once no longer needed for the booking or our legal record.

7. Your rights

Under POPIA and the GDPR you can ask us to:

  • access a copy of the personal information we hold about you;
  • correct or update anything inaccurate;
  • delete your information (where we don’t need to keep it by law);
  • object to or restrict certain processing, including marketing;
  • receive your data in a portable format;
  • withdraw consent at any time (without affecting prior processing).

To exercise any of these, email privacy@4x4epictours.com. We respond within the timeframes the law requires (POPIA: a reasonable time; GDPR: within one month). We may need to verify your identity first.

8. Cookies & local storage

We use a small number of cookies and browser-storage items — essential ones to run the site, plus optional functional and analytics storage you control. Full details are in our Cookie Policy. You can change your choices any time: .

9. Security

We protect your information with HTTPS across the site, access controls on our admin tools, and by limiting who can see your data. No system is perfectly secure, but we take reasonable, appropriate technical and organisational measures as POPIA s19 and GDPR Art. 32 require.

10. Children

Our services are aimed at adults. We don’t knowingly collect personal information from children under 18 without a competent person’s consent.

11. Complaints

Please contact us first and we’ll try to put things right. You also have the right to complain to a regulator:

  • South Africa: Information Regulator — inforegulator.org.za
  • EU/UK: your local data-protection supervisory authority — [TO CONFIRM: EU/UK supervisory authority, if applicable].

12. Changes

We may update this policy from time to time. The “last updated” date above shows the current version; material changes will be highlighted on the site.

Owner TODO before launch (full version in docs/GDPR-POPIA-LAUNCH-CHECKLIST.md):
  • Fill every [TO CONFIRM] field via the environment variables in .env.example (entity, reg no., address, officers, EU representative, transfer safeguards).
  • Register the Information Officer with the SA Information Regulator and publish a PAIA manual.
  • Sign operator/processor agreements with each third party listed in §4.
  • Confirm retention periods with your accountant and SATSA obligations.
  • Have a qualified attorney review this policy and the Cookie Policy.
La newsletter · jamais de spam

Field Notes dans votre boîte mail

Des récits de route, les dates de départ disponibles et quelques photos de la piste. Un e-mail par mois.

En vous abonnant, vous acceptez de recevoir des e-mails marketing. Désabonnement à tout moment via le lien présent dans chaque e-mail.