Privacy Policy
RJCSQUARED INVESTMENTS PTY LTD · Last updated 28 June 2026
Introduction
RJCSQUARED INVESTMENTS PTY LTD (“we”, “us”, “our”) operates the Ryve Africa Property Management System (“Ryve”, “the Service”) available at ryveafrica.co.za. We are committed to protecting the privacy and personal information of all individuals who interact with our platform, in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and applicable South African law.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have in relation to your information. By using Ryve Africa, you acknowledge that you have read and understood this policy.
This policy applies to:
- Lodge owners and property managers who use Ryve Africa to manage their properties (“Operators”)
- Guests whose booking and access information is managed through Ryve Africa (“Guests”)
- Visitors to our website at ryveafrica.co.za
Information We Collect
2.1 Lodge Owner and Staff Data
When an Operator registers and uses Ryve Africa, we collect:
- Identity information: Full name, email address, phone number
- Account credentials: Email address and encrypted password, or Google OAuth token
- Business information: Property name, address, city, province, contact details
- Billing information: Subscription plan details (payment is handled by third-party processors — we do not store card numbers)
- Usage data: Actions taken in the dashboard, login times, IP addresses, browser and device information
2.2 Guest Data
Guest information is entered into Ryve Africa by Operators as part of the booking process. We process the following guest data on behalf of Operators:
- Identity information: First name, last name
- Contact details: Phone number (used for WhatsApp check-in notifications), email address (optional)
- Identification: South African ID number or passport number, where collected by the Operator for legal compliance
- Booking details: Check-in date, check-out date, room assigned, number of guests, booking source, booking status
2.3 Smart Lock Access Data
Ryve Africa integrates with TTLock smart lock hardware to manage property access. We collect and process:
- Access codes (PINs): Time-limited numeric codes generated for individual guest stays and staff members
- Lock event logs: Door open/close events, access code usage, failed access attempts, timestamp of each event, and which PIN was used
- Device status: Lock battery levels and online/offline status
2.4 Usage and Technical Data
When you use the Ryve Africa dashboard or website, we automatically collect log data (IP address, browser type, pages visited, time of access), device information (device type, operating system), and session data (duration and feature usage patterns used to improve the product).
How We Use Information
We use personal information only for the purposes for which it was collected, or compatible purposes, as permitted by POPIA.
3.1 Property Management Operations
We use Operator and Guest data to provide the core Service: managing bookings, tracking occupancy, generating reports, and giving Operators a unified view of their property.
3.2 Smart Lock Access Control
Guest and staff data is used to generate time-limited access codes, deliver them through the correct channels, and sync them to physical TTLock smart locks. Lock event data is stored to give Operators a complete access audit trail.
3.3 Guest Check-In Notifications (WhatsApp)
With Operator configuration, we use a Guest's phone number to send automated WhatsApp messages containing their room access code and check-in instructions. These messages are sent at or near the time of check-in. Guests may be notified of this practice through the Operator's own guest-facing communications.
3.4 Security Monitoring and Anomaly Detection
We analyse lock event data to automatically detect and flag potentially abnormal access patterns, including access after guest checkout, repeated failed PIN attempts, unusual access times for staff, and rapid repeated door events. These alerts are surfaced to Operators in the dashboard. No automated action is taken without Operator review.
We will never sell personal information to third parties or use it for purposes unrelated to operating the Service.
Data Storage and Security
4.1 Location
All data processed by Ryve Africa is stored in South Africa using Google Cloud Platform's africa-south1 region (Johannesburg). We do not transfer personal data to servers outside South Africa without appropriate safeguards in place.
4.2 Encryption
- All data in transit is protected using TLS 1.2 or higher
- Data at rest is encrypted using AES-256 (managed by Google Cloud)
- Sensitive fields such as TTLock account passwords and access codes are additionally encrypted at the application level before storage
4.3 Access Controls
Operator accounts are protected by password authentication and optional Google OAuth. JWT-based session tokens expire after 15 minutes. Staff access within a property is role-based: only authorised staff can view guest data, access logs, and lock controls. Our engineering team accesses production data only through authenticated, audited database connections.
Third-Party Services
We share personal information with the following third parties solely to deliver the Service:
5.1 TTLock
TTLock (Sciener Technology Co. Ltd) provides the smart lock hardware and cloud API that Ryve Africa integrates with. Guest access codes and lock event data are transmitted to and from TTLock's European API endpoint. TTLock processes this data according to their own privacy policy.
5.2 WhatsApp Business API (Meta)
Guest phone numbers and message content are transmitted to Meta Platforms, Inc. via the WhatsApp Business API to deliver check-in notifications. We use only pre-approved message templates and do not share guest data with Meta beyond what is necessary to deliver the notification.
5.3 Google
Operators may authenticate using Google OAuth. In this case, their Google account email and profile name are shared with Google as part of the authentication flow. Google's use of this information is governed by Google's Privacy Policy.
5.4 Infrastructure Providers
- Google Cloud Platform — hosting, database, and storage (South Africa region)
- Amazon Web Services — message queue services (af-south-1 region)
- Vercel — hosting of the front-end application
- Sentry — error monitoring
Data Retention
We retain personal information only for as long as necessary for the purpose for which it was collected, or as required by law.
| Category | Retention period |
|---|---|
| Operator account data | Duration of the active subscription |
| Guest personal information | 3 years from the guest's last stay |
| Lock event logs | 3 years from the date of the event |
| Access codes (PINs) | Deleted at checkout; history retained 3 years |
| Usage and log data | 12 months |
| Data following account termination | Deleted within 30 days of closure |
Upon account termination, we will delete or anonymise all personal data associated with the account within 30 days, unless we are required by law to retain it for a longer period.
Your Rights Under POPIA
As a data subject under POPIA, you have the following rights. To exercise any of these rights, contact us at info@ryveafrica.co.za.
7.1 Right to Access
You have the right to request a copy of the personal information we hold about you, and to be informed of how it is being used.
7.2 Right to Correction
If any of your personal information is inaccurate or incomplete, you have the right to request that we correct it.
7.3 Right to Deletion
You have the right to request that we delete your personal information, subject to legal and contractual limitations. Where deletion is not possible, we will inform you and explain the reason.
7.4 Right to Object to Processing
You have the right to object to the processing of your personal information in certain circumstances, including where processing is based on our legitimate interests.
7.5 Right to Lodge a Complaint
If you believe we have handled your personal information improperly, you may lodge a complaint with the Information Regulator of South Africa:
- Website: inforegulator.org.za
- Email: complaints.IR@justice.gov.za
- Phone: 012 406 4818
We will respond to all valid requests within 30 days.
Cookies
The Ryve Africa dashboard and website use session-based authentication tokens stored in browser sessionStorage — not cookies. We do not use advertising cookies or cross-site tracking technologies.
We may use minimal analytics tools in future. If we do, we will update this policy and provide opt-out mechanisms where required.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or the Service. When we make material changes, we will:
- Update the “Last updated” date at the top of this page
- Notify active Operators by email at least 14 days before the change takes effect
- Publish the updated policy at ryveafrica.co.za/privacy
Continued use of the Service after notice of changes constitutes acceptance of the updated policy.
Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or your personal information:
RJCSQUARED INVESTMENTS PTY LTD
Operating as: Ryve Africa
Email: info@ryveafrica.co.za
Website: ryveafrica.co.za
We aim to respond to all inquiries within 5 business days.
© 2026 RJCSQUARED INVESTMENTS PTY LTD
Terms of Service →