1. Introduction
BookerBot is a WhatsApp-based booking platform operated by White Wolf Studio ZA (Pty) Ltd ("we", "us", "BookerBot"), a company registered in South Africa. We provide service businesses (such as salons, barbers, biokineticists, nail technicians, and similar) with a platform to receive bookings from their customers via WhatsApp, manage staff schedules, send automated reminders, and grow their customer relationships.
This Privacy Policy explains how we collect, use, store, share, and protect personal information processed through BookerBot, in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA) and the Electronic Communications and Transactions Act, 25 of 2002 (ECTA).
2. Two Layers of Data — Who Is the Responsible Party?
BookerBot involves two distinct categories of personal information, with different legal responsibilities for each:
2.1 Personal Information of Business Owners (our direct customers)
When a business signs up to BookerBot, we (White Wolf Studio ZA) are the Responsible Party for that business owner's personal information. We decide what we collect, why, and how we use it.
2.2 Personal Information of the Business's End Customers (the people who book appointments)
When a salon's customer books an appointment via WhatsApp, the salon (our customer) is the Responsible Party for that customer's personal information. The salon decides why they want bookings, what data they need, and how they engage with their customers. We act as the Operator, processing the data on the salon's behalf.
This distinction matters: end customers should direct privacy questions to the business they booked with first. We facilitate the platform but the relationship is between the business and its customer.
3. Personal Information We Process
3.1 Information about Business Owners (our direct customers)
When you sign up to BookerBot:
- Full name, business name, email address, phone number
- Business address and operating details (e.g., service categories, opening hours)
- Banking details for payment processing (handled by Paystack — see Section 7)
- Account credentials and authentication data
- Subscription tier, billing history, and usage patterns
- Communication history with our support team
- Activity logs and audit trails
3.2 Information about End Customers (your customers)
When a person books with a BookerBot-enabled business:
- Full name and WhatsApp phone number
- Booking details (service requested, date, time, staff member chosen)
- Booking history (previous appointments, no-shows, repeat visits)
- Optional notes provided by the customer or the business (e.g., service preferences, allergies)
- Communication history (booking confirmations, reminders, follow-ups)
3.3 Information about Staff Members
When a business adds staff members to BookerBot:
- Full name, email, phone number
- Role and service specializations
- Schedule and availability
- Performance metrics (booking volume, customer ratings if applicable)
3.4 Technical Information
When you (or your customers) interact with BookerBot:
- Device type, browser, operating system
- IP address and approximate location (country/region only)
- WhatsApp message metadata (delivery status, read receipts)
- Usage logs (page views, actions taken, timestamps)
- Crash reports and performance diagnostics
4. WhatsApp Business API and Meta
BookerBot uses the WhatsApp Business API, provided by Meta Platforms Inc. This is core to how the service works. As a result:
- Meta processes the messages sent through BookerBot, including delivery, encryption, and routing
- Meta's privacy policies apply alongside ours — see WhatsApp's Privacy Policy and Meta Business Terms
- Message content is encrypted in transit between WhatsApp users and the WhatsApp service
- We use Meta-approved message templates for automated reminders and notifications
- Customers must initiate or opt-in to communications, in line with WhatsApp Business API rules
If a person does not consent to WhatsApp messaging, they cannot use BookerBot. The platform is built around the WhatsApp channel.
5. How We Use Personal Information
We process personal information to:
- Deliver core platform features (booking management, reminders, follow-ups, analytics)
- Authenticate users and maintain account security
- Process subscription payments via Paystack
- Send opted-in notifications and platform alerts
- Provide customer support
- Improve platform reliability and performance
- Comply with legal, regulatory, and tax obligations
- Send service announcements (e.g., feature updates, maintenance notices) to business owners
- With your consent, send relevant product communications to business owners
We do not use personal information for:
- Selling, renting, or licensing data to third parties
- Profiling for advertising purposes
- Training AI models on customer or end-customer data
- Any purpose unrelated to delivering BookerBot
6. Legal Basis for Processing
Our processing is grounded in the following POPIA conditions for lawful processing:
- Section 11(1)(a) – Consent: Where users have explicitly opted in (e.g., to use BookerBot, to receive notifications)
- Section 11(1)(b) – Contractual necessity: Where processing is necessary to deliver the service businesses have subscribed to
- Section 11(1)(c) – Legal obligation: Where processing is required to comply with applicable laws (e.g., financial record-keeping, tax obligations)
- Section 11(1)(f) – Legitimate interests: For platform security, fraud prevention, and audit logging, where these interests do not override the rights of data subjects
7. Data Sharing and Sub-Processors
We share personal information only with carefully selected service providers needed to operate BookerBot. Each is bound by data protection agreements:
| Sub-processor | Purpose | Data location |
|---|---|---|
| Meta Platforms (WhatsApp Business API) | Message routing, delivery, end-user communication | Global (encrypted in transit) |
| Railway (PostgreSQL) | Application database | EU / US |
| Railway | Application hosting and infrastructure | EU / US |
| Railway Buckets (powered by Tigris) | Object storage for business logos and media | EU / US |
| Cloudflare | DNS, CDN, and DDoS protection | Global |
| Paystack | Payment processing for business subscriptions | South Africa / Nigeria |
| Sentry / observability providers | Error tracking and platform reliability | EU / US |
We do not share end customer booking data with payment providers — only business-level subscription billing data is shared with Paystack.
7.1 Within the business community
Within a BookerBot-enabled business:
- Authorised business owners and admins can see their own customer data
- Staff members see only the bookings assigned to them or visible per their role
- End customers see only their own booking history
7.2 Legal disclosure
We may disclose personal information if required by:
- A court order or lawful subpoena
- Law enforcement acting under proper legal authority
- A regulatory body with statutory authority
We will notify the affected business or user as soon as legally permissible if such a disclosure is made.
8. International Data Transfers
Some sub-processors store data outside South Africa. Where this happens:
- We only use providers with adequate data protection standards comparable to POPIA
- Data transferred internationally remains encrypted in transit and at rest
- We do not transfer data to jurisdictions that lack legal protections for personal information
If your business requires data residency exclusively within South Africa, contact us to discuss alternative arrangements.
9. Data Security
We protect personal information through:
- Encryption in transit (TLS 1.2+) for all data transmitted between devices and our servers
- Encryption at rest for all stored personal information
- Role-based access control with business-scoped data isolation
- Multi-factor authentication available for business owner accounts
- Audit logging of administrative actions
- Regular security reviews, dependency monitoring, and incident response procedures
- Backup and disaster recovery procedures with encrypted offsite backups
- WhatsApp end-to-end encryption for messages between BookerBot and end customers
While we apply industry-standard protections, no system is entirely secure. We continuously improve our security posture and respond to evolving threats.
10. Data Retention
| Data type | Retention period |
|---|---|
| Active business owner accounts | While the subscription is active |
| End customer booking data | Controlled by the business owner; we retain it while the subscription is active and for a reasonable period thereafter for business records |
| Cancelled / inactive accounts | 90 days after cancellation, then anonymised or deleted |
| Communication records | Up to 3 years after the conversation ends, unless a longer retention is required by law |
| Financial and billing records | 5 years (as required by South African tax law) |
| Audit logs | 12 months minimum, longer where required for security investigations |
| Backup copies | Retained in encrypted backups for up to 90 days after deletion from active systems |
When data is no longer required, we delete or anonymise it. Business owners may instruct us to delete data sooner via the relevant data subject request process.
11. Your Rights Under POPIA
You have the following rights regarding your personal information:
11.1 Right of access
You can request a copy of the personal information we hold about you. Business owners can access their data via their dashboard. End customers should contact the business they booked with first.
11.2 Right of correction
You can update your account information at any time from your dashboard. Inaccurate booking data should be corrected through the business that hosts the booking.
11.3 Right of deletion
Business owners can cancel their subscription and request deletion of their data at any time. End customers can request deletion of their booking history by contacting the business they booked with.
Please note: certain records (financial records, audit logs) may be retained after deletion to the extent required by law.
11.4 Right to object to processing
You can object to processing of your personal information for purposes other than those described in this policy. Submit objections to hello@bookerbot.co.za.
11.5 Right to lodge a complaint
If you are unhappy with how BookerBot has handled your personal data:
1. First, contact our Information Officer at dhashin@whitewolfstudio.co.za 2. If unresolved, lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za or by emailing complaints.IR@justice.gov.za
12. Cookies and Tracking
BookerBot uses minimal cookies and similar technologies, limited to:
- Essential cookies: Required for authentication and security (e.g., session tokens)
- Functional cookies: Remembering your preferences (e.g., language, dashboard layout)
We do not use:
- Advertising cookies
- Cross-site tracking
- Third-party analytics that profile users
- Behavioural advertising trackers
Where we use any analytics, they are configured to be privacy-respecting (e.g., IP anonymisation, no cross-site tracking).
13. Marketing Communications
If you are a business owner, we may send you:
- Service announcements (e.g., maintenance, security updates)
- Account-related notifications (e.g., billing reminders, subscription renewals)
- Product updates (where you have opted in)
You can opt out of marketing communications at any time via your dashboard or by emailing hello@bookerbot.co.za. Service announcements and account-related notifications cannot be opted out of while you have an active subscription.
We do not send marketing communications to end customers — that relationship is owned by the business they booked with.
14. Data Breach Notification
In the event of a security compromise involving your personal information, we will:
- Notify affected business owners as soon as reasonably possible after confirming the breach
- Notify the Information Regulator of South Africa as required under POPIA
- Notify affected data subjects directly where the breach poses a reasonable risk to their rights
- Provide details of the incident, the data affected, and the steps taken to mitigate harm
We maintain an internal data breach response procedure to ensure rapid containment, investigation, and notification.
15. Information Officer
Our designated Information Officer under POPIA is:
Dhashin Reddy Director, White Wolf Studio ZA (Pty) Ltd Email: dhashin@whitewolfstudio.co.za
The Information Officer is responsible for ensuring our compliance with POPIA, handling data subject requests, and serving as the contact point for the Information Regulator.
16. Children's Personal Information
BookerBot is intended for use by businesses and adult customers. We do not knowingly collect personal information from children under 18. If a parent or guardian becomes aware that a child has provided personal information to BookerBot through a business they engage with, please contact the business directly (or hello@bookerbot.co.za) and we will work to delete that information.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:
- The "Last updated" date at the top will be revised
- We will notify business owners via email or in-app notification at least 30 days before changes take effect (where practical)
- Continued use of BookerBot after changes take effect constitutes acceptance of the updated policy
18. Contact Us
For privacy-related questions:
- Business owner support: hello@bookerbot.co.za
- End customer questions: contact the business you booked with first
- BookerBot Information Officer: dhashin@whitewolfstudio.co.za
Postal address: White Wolf Studio ZA (Pty) Ltd 1058 Olivewood Estate Christo Avenue, Olivedale Randburg 2188 South Africa
_BookerBot is a product of White Wolf Studio ZA (Pty) Ltd, registered in South Africa._