Legal

Privacy Policy

RJCSQUARED INVESTMENTS PTY LTD · Last updated 28 June 2026

01

Introduction

RJCSQUARED INVESTMENTS PTY LTD (“we”, “us”, “our”) operates the Ryve Africa Property Management System (“Ryve”, “the Service”) available at ryveafrica.co.za. We are committed to protecting the privacy and personal information of all individuals who interact with our platform, in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and applicable South African law.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have in relation to your information. By using Ryve Africa, you acknowledge that you have read and understood this policy.

This policy applies to:

  • Lodge owners and property managers who use Ryve Africa to manage their properties (“Operators”)
  • Guests whose booking and access information is managed through Ryve Africa (“Guests”)
  • Visitors to our website at ryveafrica.co.za
02

Information We Collect

2.1 Lodge Owner and Staff Data

When an Operator registers and uses Ryve Africa, we collect:

  • Identity information: Full name, email address, phone number
  • Account credentials: Email address and encrypted password, or Google OAuth token
  • Business information: Property name, address, city, province, contact details
  • Billing information: Subscription plan details (payment is handled by third-party processors — we do not store card numbers)
  • Usage data: Actions taken in the dashboard, login times, IP addresses, browser and device information

2.2 Guest Data

Guest information is entered into Ryve Africa by Operators as part of the booking process. We process the following guest data on behalf of Operators:

  • Identity information: First name, last name
  • Contact details: Phone number (used for WhatsApp check-in notifications), email address (optional)
  • Identification: South African ID number or passport number, where collected by the Operator for legal compliance
  • Booking details: Check-in date, check-out date, room assigned, number of guests, booking source, booking status

2.3 Smart Lock Access Data

Ryve Africa integrates with TTLock smart lock hardware to manage property access. We collect and process:

  • Access codes (PINs): Time-limited numeric codes generated for individual guest stays and staff members
  • Lock event logs: Door open/close events, access code usage, failed access attempts, timestamp of each event, and which PIN was used
  • Device status: Lock battery levels and online/offline status

2.4 Usage and Technical Data

When you use the Ryve Africa dashboard or website, we automatically collect log data (IP address, browser type, pages visited, time of access), device information (device type, operating system), and session data (duration and feature usage patterns used to improve the product).

03

How We Use Information

We use personal information only for the purposes for which it was collected, or compatible purposes, as permitted by POPIA.

3.1 Property Management Operations

We use Operator and Guest data to provide the core Service: managing bookings, tracking occupancy, generating reports, and giving Operators a unified view of their property.

3.2 Smart Lock Access Control

Guest and staff data is used to generate time-limited access codes, deliver them through the correct channels, and sync them to physical TTLock smart locks. Lock event data is stored to give Operators a complete access audit trail.

3.3 Guest Check-In Notifications (WhatsApp)

With Operator configuration, we use a Guest's phone number to send automated WhatsApp messages containing their room access code and check-in instructions. These messages are sent at or near the time of check-in. Guests may be notified of this practice through the Operator's own guest-facing communications.

3.4 Security Monitoring and Anomaly Detection

We analyse lock event data to automatically detect and flag potentially abnormal access patterns, including access after guest checkout, repeated failed PIN attempts, unusual access times for staff, and rapid repeated door events. These alerts are surfaced to Operators in the dashboard. No automated action is taken without Operator review.

We will never sell personal information to third parties or use it for purposes unrelated to operating the Service.

04

Data Storage and Security

4.1 Location

All data processed by Ryve Africa is stored in South Africa using Google Cloud Platform's africa-south1 region (Johannesburg). We do not transfer personal data to servers outside South Africa without appropriate safeguards in place.

4.2 Encryption

  • All data in transit is protected using TLS 1.2 or higher
  • Data at rest is encrypted using AES-256 (managed by Google Cloud)
  • Sensitive fields such as TTLock account passwords and access codes are additionally encrypted at the application level before storage

4.3 Access Controls

Operator accounts are protected by password authentication and optional Google OAuth. JWT-based session tokens expire after 15 minutes. Staff access within a property is role-based: only authorised staff can view guest data, access logs, and lock controls. Our engineering team accesses production data only through authenticated, audited database connections.

05

Third-Party Services

We share personal information with the following third parties solely to deliver the Service:

5.1 TTLock

TTLock (Sciener Technology Co. Ltd) provides the smart lock hardware and cloud API that Ryve Africa integrates with. Guest access codes and lock event data are transmitted to and from TTLock's European API endpoint. TTLock processes this data according to their own privacy policy.

5.2 WhatsApp Business API (Meta)

Guest phone numbers and message content are transmitted to Meta Platforms, Inc. via the WhatsApp Business API to deliver check-in notifications. We use only pre-approved message templates and do not share guest data with Meta beyond what is necessary to deliver the notification.

5.3 Google

Operators may authenticate using Google OAuth. In this case, their Google account email and profile name are shared with Google as part of the authentication flow. Google's use of this information is governed by Google's Privacy Policy.

5.4 Infrastructure Providers

  • Google Cloud Platform — hosting, database, and storage (South Africa region)
  • Amazon Web Services — message queue services (af-south-1 region)
  • Vercel — hosting of the front-end application
  • Sentry — error monitoring
06

Data Retention

We retain personal information only for as long as necessary for the purpose for which it was collected, or as required by law.

CategoryRetention period
Operator account dataDuration of the active subscription
Guest personal information3 years from the guest's last stay
Lock event logs3 years from the date of the event
Access codes (PINs)Deleted at checkout; history retained 3 years
Usage and log data12 months
Data following account terminationDeleted within 30 days of closure

Upon account termination, we will delete or anonymise all personal data associated with the account within 30 days, unless we are required by law to retain it for a longer period.

07

Your Rights Under POPIA

As a data subject under POPIA, you have the following rights. To exercise any of these rights, contact us at info@ryveafrica.co.za.

7.1 Right to Access

You have the right to request a copy of the personal information we hold about you, and to be informed of how it is being used.

7.2 Right to Correction

If any of your personal information is inaccurate or incomplete, you have the right to request that we correct it.

7.3 Right to Deletion

You have the right to request that we delete your personal information, subject to legal and contractual limitations. Where deletion is not possible, we will inform you and explain the reason.

7.4 Right to Object to Processing

You have the right to object to the processing of your personal information in certain circumstances, including where processing is based on our legitimate interests.

7.5 Right to Lodge a Complaint

If you believe we have handled your personal information improperly, you may lodge a complaint with the Information Regulator of South Africa:

  • Website: inforegulator.org.za
  • Email: complaints.IR@justice.gov.za
  • Phone: 012 406 4818

We will respond to all valid requests within 30 days.

08

Cookies

The Ryve Africa dashboard and website use session-based authentication tokens stored in browser sessionStorage — not cookies. We do not use advertising cookies or cross-site tracking technologies.

We may use minimal analytics tools in future. If we do, we will update this policy and provide opt-out mechanisms where required.

09

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or the Service. When we make material changes, we will:

  • Update the “Last updated” date at the top of this page
  • Notify active Operators by email at least 14 days before the change takes effect
  • Publish the updated policy at ryveafrica.co.za/privacy

Continued use of the Service after notice of changes constitutes acceptance of the updated policy.

10

Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or your personal information:

RJCSQUARED INVESTMENTS PTY LTD

Operating as: Ryve Africa

Email: info@ryveafrica.co.za

Website: ryveafrica.co.za

We aim to respond to all inquiries within 5 business days.

© 2026 RJCSQUARED INVESTMENTS PTY LTD

Terms of Service →