Privacy Policy
Last updated: June 2026
1. Who we are
TourCraft is operated by IT Genie (Pty) Ltd, a private company registered in South Africa under registration number 2015/227654/07, with its principal place of business at 7 Henry Road, Northvale AH, Muldersdrift, 1739.
In this policy “we”, “us”, and “our” mean IT Genie (Pty) Ltd trading as TourCraft. “You” or “your” means the person whose personal information is being processed — either a TourCraft subscriber (someone with a paid or trial account) or a visitor to a website that uses a TourCraft tour.
Information Officer: Paul Grobler. Reach the Information Officer at privacy@itgenie.co.za.
This policy describes how we collect, use, share, store, and protect your personal information in line with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and other applicable data-protection laws.
2. Two roles — when we are responsible, and when the subscriber is
TourCraft processes personal information in two distinct roles. Understanding which one applies to you matters because it changes who is legally responsible for which decisions.
When you are a subscriber. You signed up for an account, you log in, you build tours, you pay us. For the personal information attached to that relationship (your email, name, billing details, account activity), we are the Responsible Party as defined in POPIA. We decide what to collect, why, and how long to keep it — and we answer to the Information Regulator for those decisions. The rest of this policy is mostly about this role.
When you are a visitor to a subscriber’s site. A TourCraft tour may appear on a third-party website (one of our customers’ sites), shown by our widget. Any personal information that tour captures belongs to the website operator, not us. They are the Responsible Party; we act as their Operator, processing on their instructions only. Privacy questions about a specific tour should go to the operator of the site you were visiting — they chose what to ask, why, and what to do with it.
3. What information we collect
About our subscribers
- Account information: email address, password (stored as a one-way hash, never in plaintext), the project name and slug you choose at signup, your age confirmation, and your acceptance of these terms.
- Billing information: subscription plan, payment status, recurring billing dates. Card details themselves are processed by PayFast (our payment processor) and never touch our systems — we receive only a vault token.
- Technical information: IP address (at signup, login, and key actions), browser type and version, device information, and timestamps.
- Communication preferences: whether you have opted in to marketing emails, and the audit history of every change.
- Consent records: a row in our consent register every time you grant, change, or revoke a consent decision — including the IP address and user agent you used at the time. This is POPIA evidence; we keep it to demonstrate compliance.
- Audit and security logs: API-key generation events, login attempts, MFA enrolment, account-deletion events, and other security-relevant actions.
- Support correspondence: anything you send to support@tourcraft.com or privacy@itgenie.co.za.
Is this information required? Your email address, password, project name, age confirmation, and acceptance of these terms are mandatory — we cannot create or run your account without them, so declining to provide them means you cannot sign up. Billing details are mandatory only if you choose a paid plan. Technical information (such as your IP address) is collected automatically as a necessary part of providing and securing the Service. Everything else — your marketing opt-in and any support correspondence — is voluntary: declining it does not affect your access to TourCraft (you simply won’t receive marketing emails).
About end-visitors to a subscriber’s site
When a subscriber embeds the TourCraft widget on their own site, our widget may transmit to us:
- Anonymous interaction events: which tour was shown, which steps were viewed, whether the visitor completed or skipped the tour.
- A short-lived session identifier so we can correlate the steps of a single tour view.
We do not collect names, email addresses, or other directly-identifying information about end-visitors unless the subscriber’s tour deliberately asks for them. Where it does, those collections are governed by the subscriber’s own privacy policy — not this one.
4. Why we use it — our lawful basis
We process the personal information of subscribers for the following purposes, each with a POPIA-recognised lawful basis:
- Providing the service — account creation, login, project management, tour rendering, billing. Lawful basis: performance of a contract (POPIA s11(1)(b)). We cannot run TourCraft for you without these.
- Protecting the service — rate-limiting, fraud detection, audit trails, security incident investigation. Lawful basis: legitimate interest (s11(1)(d)) in protecting the service and our customers, balanced against your interest in privacy.
- Communicating with you — service notices, security alerts, trial expiry reminders, password resets, billing receipts. Lawful basis: performance of a contract (s11(1)(b)). These are operational, not marketing.
- Direct marketing — product update emails, feature announcements, tour-building tips. Lawful basis: your specific opt-in consent (s11(1)(a) and s69). The marketing box at signup is unchecked by default; you must actively tick it. You can revoke this consent at any time, and the audit row in our consent register proves when you did.
- Complying with the law — keeping financial records for SARS, responding to lawful information requests, demonstrating POPIA compliance. Lawful basis: legal obligation (s11(1)(c)).
We do not sell your personal information. We do not share it with advertising platforms. We do not use it to train AI models.
5. Who we share it with — our operators
We rely on the following sub-processors (“operators” in POPIA terms) to deliver the service. Each operator processes your information only on our written instructions and is bound by appropriate security and contractual obligations.
- Supabase Inc. — database, authentication, file storage. Stores your account record, projects, tours, and consent history. Hosted in Frankfurt, Germany (eu-central-1).
- Vercel Inc. — application hosting. Runs the TourCraft web application and APIs. Hosted in Frankfurt, Germany (fra1).
- Mailjet SAS — transactional and marketing email delivery. Receives your email address and the body of the messages we send you. Based in France (EU).
- PayFast (Pty) Ltd — payment processing for paid subscriptions. Receives your billing email and subscription metadata; processes your card details directly without exposing them to us. Based in South Africa.
- Anthropic PBC — AI assistance for internal admin tooling. Does not process your tour data; used only by our team for operational queries. Based in the United States. We have agreed that none of your personal information is used to train Anthropic’s models.
We do not use any other sub-processors. If we ever add one, we will update this list before the new processing begins.
6. Where it’s stored — cross-border transfers
Most of your personal information is stored in the European Union, primarily in Frankfurt, Germany. POPIA s72 permits transfers outside South Africa where the recipient is bound by laws, contractual obligations, or binding corporate rules that provide a level of protection substantially similar to POPIA. The General Data Protection Regulation (GDPR), which applies to all EU-resident operators we use, meets that bar.
A limited subset of our internal admin tooling routes through the United States (Anthropic). We have contractually constrained this use so that it does not include subscriber personal information or end-visitor data.
If you would prefer a copy of your information not to be transferred outside South Africa, contact us — we will discuss alternatives, though some service features may become unavailable.
7. How long we keep it — retention
We retain personal information only for as long as we need it for the purpose we collected it, with the following standard windows:
- Account record: while your account is active, plus 30 days after deletion for cleanup and dispute resolution.
- Consent records: 5 years from the date of revocation (POPIA evidence requirement).
- Billing records: 5 years for general audit; 7 years for financial records (SARS requirement).
- Audit log (security events): 24 months for routine entries; 5 years for security-incident-related entries.
- PII access log: 5 years (POPIA s19 requirement to demonstrate appropriate access controls).
- Analytics events: 12 months for raw events; aggregated counts retained indefinitely.
- Support correspondence: 3 years.
When you delete your account through Settings → Danger Zone → Delete my account, we immediately remove your account record, projects, tours, and tour steps. Records we are legally required to retain (consent, billing for SARS, security incidents) remain in place until their statutory window elapses, after which they are automatically purged by our nightly retention job.
8. Your rights under POPIA
POPIA gives you the following rights over your personal information. We respond to all valid requests within 30 days as required by s23(1)(b).
- Access (s23) — see what we hold about you. Use Settings → Privacy → Download my data, or email privacy@itgenie.co.za.
- Correction (s24) — fix inaccurate or incomplete data. Use Settings → Account for the fields exposed there, or email us for anything else.
- Deletion (s24) — request erasure of your data. Use Settings → Danger Zone → Delete my account, or email us.
- Objection (s11(3)) — object to a specific use of your data. Email us.
- Withdraw consent (s11(2)(b)) — for marketing, use Settings → Account → Email preferences. For other consents, email us.
- Direct marketing opt-out (s69) — use Settings → Account → Email preferences, or the unsubscribe link in any marketing email.
- Complaint to the Information Regulator (s74) — see section 15 below for the Regulator’s contact details.
When you exercise any of these rights, we may need to verify your identity before responding — usually by confirming you can log in to the account in question. We will not charge you a fee for exercising your rights.
9. Cookies and analytics
We use cookies and similar technologies only where necessary:
- Authentication cookies set by Supabase to keep you logged in. Strictly necessary; no consent required (POPIA s11(1)(b)).
- Session storage for keeping you logged in across page reloads.
- Your API key (for subscribers) is stored in the database server-side; it is never set as a cookie in your browser.
We do not use third-party analytics cookies (Google Analytics, Mixpanel, Segment, or similar) on the TourCraft web application. Internal usage analytics use first-party logging without persistent identifiers.
The TourCraft widget that subscribers embed on their own sites uses a short-lived session identifier per tour view — not a tracking cookie. End-visitor analytics is anonymous: we record that a tour was shown and which steps were viewed, but not who the visitor was.
10. Children’s personal information
TourCraft is intended for use by people aged 18 or older. We require you to confirm your age at signup. We do not knowingly process the personal information of children under 18 in our subscriber relationship.
Subscribers who build tours for sites that may reach children are contractually responsible for obtaining parental consent and complying with POPIA s34 — see clause 7 of our Terms of Service.
If you believe a child under 18 has provided personal information to us directly, contact privacy@itgenie.co.za and we will delete the information promptly.
11. Special personal information
“Special personal information” under POPIA s26 means information about a person’s religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour.
We do not deliberately collect any special personal information from our subscribers. If you happen to mention any of the above in a support request, we will handle it under the additional safeguards POPIA s27 requires and will not retain it longer than necessary to resolve your enquiry.
Subscribers may not use the TourCraft widget to collect special personal information from their end-visitors without obtaining the s27 authorisations — see clause 7 of our Terms of Service for the warranty terms.
12. Security
We protect your information through a combination of technical and organisational measures, including:
- TLS encryption for all data in transit
- Encryption at rest for the database and backups
- Row-level security policies on every table containing personal information
- Multi-factor authentication available on every account, required for admin staff
- Per-IP rate limiting on authentication, password reset, and account-deletion endpoints
- A formal POPIA-aligned security incident response procedure, including notification to the Information Regulator and affected data subjects in the form and timeframe required by s22
- Regular dependency security review and a per-pull-request security audit gate
- Service-role credentials kept out of client-side code and rotated on incident
No security regime is infallible. If you become aware of a security issue, please email security@itgenie.co.za. Responsible disclosure is appreciated.
13. Direct marketing
We will only send you direct marketing emails about TourCraft features and tips if you have explicitly opted in. The marketing-consent checkbox at signup starts unchecked; you must actively tick it to consent.
You can withdraw your consent at any time via Settings → Account → Email preferences, or via the unsubscribe link in any marketing email. We will stop sending you direct marketing within a reasonable time of receiving your withdrawal — typically within 7 days.
Service-related emails (receipts, security notices, trial expiry, password resets) are not direct marketing. We will continue to send these for as long as you have an active account, because they are essential to running the service for you.
14. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices or in the law. The “Last updated” date at the top of this page shows the most recent change.
Material changes — for example, adding a new sub-processor or changing how we use your data — will be announced by email in advance. You will have a chance to review the changes and exercise your rights before they take effect.
The text of every prior version is retained internally for at least 5 years; if you would like a copy of a previous version, email privacy@itgenie.co.za.
15. How to contact us — and the Information Regulator
For any privacy question, complaint, or request, contact our Information Officer:
Paul Grobler
IT Genie (Pty) Ltd
7 Henry Road, Northvale AH
Muldersdrift, 1739
South Africa
Email: privacy@itgenie.co.za
We respond to all enquiries within 30 days.
If you are not satisfied with our response, you have the right to complain to the South African Information Regulator:
The Information Regulator of South Africa
JD House, 27 Stiemens Street
Braamfontein, Johannesburg, 2001
Email: POPIAComplaints@inforegulator.org.za
General enquiries: inforeg@justice.gov.za
Phone: +27 (0)10 023 5200
Online complaint form: inforegulator.org.za/popia-complaint