logo
  • Home
  • Chalets
  • Gallery
  • Stories
logo
  • About Us
  • Contact Us
  • Location
Mountain Aloe Den Logo
Mountain Aloe Den

Luxury Mountain Retreat

Experience authentic African luxury in the breathtaking Makhonjwa Mountains. Unique chalets with modern amenities and unforgettable views.

Contact Info

+27 (0) 72 088 7098

+27 (0) 72 820 4024

stay@mountainaloeden.co.za

55 Josefsdal Barberton, 1300 Barberton, South Africa

Quick Links

  • Home
  • Chalets
  • Gallery
  • Location
  • Contact Us

© 2026 Mountain Aloe Den (Pty) Ltd. All rights reserved.

Privacy PolicyTerms & ConditionsBooking Policy
Back to Home

Privacy Policy

How Mountain Aloe Den collects, uses, and protects your personal information in compliance with the Protection of Personal Information Act (POPIA).

Effective: April 2026  ·  Last updated: April 2026

Contents

  1. 1Who We Are
  2. 2What Personal Information We Collect
  3. 3Why We Collect It & Our Legal Basis
  4. 4Who We Share Your Information With
  5. 5Cookies & Tracking
  6. 6How Long We Keep Your Data
  7. 7Your Rights Under POPIA
  8. 8How We Protect Your Information
  9. 9Changes to This Policy
  10. 10Contact Us
Section 1

Who We Are

Mountain Aloe Den (Pty) Ltd is a luxury mountain retreat situated in the Makhonjwa Mountains, Barberton, South Africa (55 Josefsdal, Barberton, 1300, South Africa).

We are a Responsible Party as defined under the Protection of Personal Information Act, 4 of 2013 (“POPIA”). This means we determine the purpose and means of processing your personal information.

Information Officer

Our designated Information Officer is responsible for ensuring our compliance with POPIA. You can reach them at:

stay@mountainaloeden.co.za
Section 2

What Personal Information We Collect

We only collect information that is necessary for providing our services. This includes:

Booking Information

  • Full name
  • Email address
  • Phone number
  • Dates of stay
  • Guest counts
  • Meal preferences

Payment Information

  • Booking total
  • Payment reference ID (Yoco)
  • Discount codes used
  • No card details are stored by us

Contact / Enquiry

  • Full name
  • Email address
  • Phone number
  • Your message
  • Preferred dates (if provided)

Usage & Technical

  • IP address (rate limiting only)
  • Browser type (analytics)
  • Pages visited (Google Analytics)
  • Referral source
Section 3

Why We Collect It & Our Legal Basis

Under POPIA, we must have a lawful basis to process your personal information. We rely on the following:

Performance of Contract

When you make a booking, we need your name, email, phone number, and stay details to confirm your reservation, send you a confirmation email, and manage your guest experience.

Legitimate Interest

We may contact you about your upcoming or past stay to ensure your satisfaction, and we use anonymised data to improve our services.

Legal Obligation

We retain financial records (including booking totals and payment references) for a minimum of 5 years to comply with SARS and other South African regulations.

Consent

Where you have given explicit consent (e.g., accepting cookies), we use Google Analytics to understand how visitors use our website. You may withdraw this consent at any time.

Section 4

Who We Share Your Information With

We do not sell your personal information. We only share it with trusted third-party operators to deliver our services:

Yoco Technologies (Pty) Ltd

Their Policy ↗

Secure payment processing. Yoco acts as an independent data controller for card transactions. No card details are stored on our servers. Their privacy policy applies to payment data.

Google LLC (Google Analytics)

Their Policy ↗

Website analytics — understanding how visitors use our site. Only activated with your explicit cookie consent. Data may be transferred to Google servers in the United States.

Email Service Provider (NPSA / Nodemailer)

Transactional emails including booking confirmations, payment reminders, and enquiry responses are sent via our SMTP provider.

UploadThing

Their Policy ↗

PDF invoice storage. Invoice documents containing booking details may be stored on UploadThing's cloud infrastructure.

Section 5

Cookies & Tracking

Our website uses cookies and similar tracking technologies. Cookies are small text files stored on your device.

CookiePurposeTypeDuration
mad_cookie_consentRemembers your cookie preferenceEssential1 year
_ga, _ga_*Google Analytics — measures website usageAnalytics (opt-in)2 years
next-auth.session-tokenAdmin session authenticationEssentialSession

You can manage or withdraw your cookie consent at any time using the cookie banner (which can be re-triggered by clearing your browser's local storage or cookies).

Section 6

How Long We Keep Your Data

We retain your personal information only for as long as necessary for the purpose it was collected, or as required by law:

Booking Records5 yearsFinancial record-keeping (SARS compliance)
Enquiries (not converted to bookings)12 monthsFollow-up and record of communication
Analytics Data24 monthsWebsite improvement (Google Analytics default)
Payment References5 yearsFinancial audit trail
Section 7

Your Rights Under POPIA

As a data subject under POPIA, you have the following rights. To exercise any of these rights, contact us at stay@mountainaloeden.co.za. We will respond within 30 days.

Right to Access

Request a copy of the personal information we hold about you (PAIA Form 2).

Right to Correction

Ask us to correct or update inaccurate personal information.

Right to Deletion

Request deletion of your personal information, subject to legal retention obligations.

Right to Object

Object to the processing of your personal information for direct marketing purposes.

Right to Withdraw Consent

Withdraw cookie consent or any other consent given at any time, without affecting prior lawful processing.

Right to Complain

Lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.

Section 8

How We Protect Your Information

We implement reasonable technical and organisational measures to protect your personal information against loss, theft, and unauthorised access, including:

  • Encrypted HTTPS connections on all pages
  • Payment processing handled entirely by PCI-compliant Yoco (card data never touches our servers)
  • Rate limiting on booking APIs to prevent abuse
  • Server-side input validation on all form submissions
  • Admin access protected by hashed credentials and session tokens
  • Environment-variable-based secrets (no credentials in source code)

No method of transmission over the internet is 100% secure. In the event of a data breach, we will notify the Information Regulator and affected data subjects as required by POPIA.

Section 9

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. The effective date at the bottom of this page will be updated accordingly.

We encourage you to review this page periodically. Continued use of our website after any changes constitutes acceptance of the updated policy.

Section 10

Contact Us

For any privacy-related requests, questions, or complaints, please contact our Information Officer:

Email

stay@mountainaloeden.co.za

Address

55 Josefsdal, Barberton, 1300, South Africa

Regulator

inforegulator.org.za ↗

Questions about this policy? Email us at stay@mountainaloeden.co.za

Policy effective April 2026. Governed by the laws of the Republic of South Africa.