Privacy Policy
Effective date: 14 August 2026 · JBNC Solutions, South Africa
This policy explains how JBNC Solutions ("JBNC", "we", "us") handles personal information in our software, including the JBNC Management System mobile and web application (also known as Campsite Tracker), our public booking portals, and guest welcome pages, together "the Services". We are committed to compliance with South Africa's Protection of Personal Information Act, 2013 (POPIA).
Who is responsible for your information
The Services are business software used by accommodation providers such as caravan parks, campsites and resorts ("Operators"). In most cases the Operator you book with or work for is the responsible party for your personal information, and JBNC processes that information on the Operator's behalf as an operator/processor under POPIA. Each Operator's data is stored in its own isolated environment. For information about our own website visitors and business contacts, JBNC is the responsible party.
What we collect
If you are a guest of an Operator
- Booking details — your name, phone number, email address, vehicle details where required by the park, number of guests, and stay dates. This is entered by you via a booking portal or by the Operator's staff.
- Billing records — invoices, payments recorded against your stay, and purchases made on your account at the Operator's shop. The app records payment entries (e.g. "paid by card"); it does not capture or store card numbers, and no card payments are processed inside the app.
- Welcome pack access — if the Operator sends you a personalised welcome link or QR code, it is tied to your booking so the page can greet you and show your stay details.
If you are an Operator's staff member
- Account details — your name, email address and role, created for you by your administrator (there is no public self-registration).
- Activity records — the system keeps an audit trail of booking changes and sales you process, attributed to your account. This protects both guests and staff and is visible to your administrators.
- Voice audio — if your site uses the built-in staff radio (push-to-talk), your voice transmissions are relayed to the channel's members while you hold the talk button, and may be retained in a channel archive according to your Operator's settings. The microphone is only used while you actively transmit.
Technical data
- Crash and diagnostic data — the app uses Firebase Crashlytics to collect crash reports and basic device information (model, OS version) so we can fix faults.
- Website analytics — our marketing site uses Google Analytics to measure visits. Our application itself does not run advertising or ad-tracking of any kind.
How we use information
- Operating the Services: managing bookings, check-ins, billing, stock and reporting for the Operator.
- Sending transactional messages, such as booking confirmations and pre-arrival reminders, on the Operator's behalf and from the Operator's own email address.
- Maintaining security, preventing misuse, and investigating faults via audit trails and crash reporting.
- Providing support to Operators.
We do not sell personal information, use it for third-party advertising, or share it with anyone other than the service providers below and the Operator whose Services you use.
Where information is stored
The Services run on Google Firebase (Google Cloud Platform). Data is encrypted in transit and stored on Google's infrastructure, which may be located outside South Africa. Where personal information is transferred across borders, it is protected by Google Cloud's contractual and security commitments, in line with section 72 of POPIA.
How long we keep it
- Booking and financial records are retained for as long as the Operator requires them, including retention required by South African tax law.
- Booking audit-trail entries are automatically deleted after 24 months.
- Staff radio archives are retained according to each Operator's channel settings.
- When an Operator leaves the platform, its environment (including guest data) is removed on conclusion of the engagement.
Your rights
Under POPIA you may request access to, correction of, or deletion of your personal information. Guests should direct requests to the Operator they booked with (the responsible party), who can action them in the system; you may also contact us directly and we will assist or forward your request. Staff accounts and their data can be corrected or deleted by your administrator, or by us on request.
If you believe your information has been handled unlawfully, you have the right to lodge a complaint with the Information Regulator (South Africa) — inforegulator.org.za.
Requesting deletion of your data
To ask us to delete your personal information, email info@jbncsolutions.co.za with the subject line “Data deletion request” and include:
- your full name;
- the park or campsite you stayed at, or work for;
- the email address or phone number used for the booking or staff account; and
- whether you want everything deleted, or only specific information.
We acknowledge requests within 5 working days and complete them within 30 days. Where the request concerns a guest booking, the park is the responsible party and we act on their instruction — we will tell you if they need to authorise it first.
What is deleted: your contact details, guest profile, booking history, welcome-pack access, staff account, and any stored signature or uploaded image associated with you.
What we must keep: South African tax law requires accommodation providers to retain financial records — invoices, payments and sales — for five years. Where a record must be retained for that reason, we remove or de-identify the personal details attached to it wherever possible and keep only what the law requires. Booking audit-trail entries are deleted automatically after 24 months.
Staff accounts can also be deleted at any time by your site administrator from inside the application, without contacting us.
Security
Access to the Services requires authentication, and access within an Operator's environment is role-based. Each Operator's data is isolated. We maintain audit trails of booking changes, database-level protections against destructive operations, and point-in-time recovery backups.
Children
The Services are business tools and are not directed at children. Guest records may include the number of children in a party as entered by the booking guest or Operator; we do not knowingly collect personal information directly from children.
Changes to this policy
We may update this policy from time to time. The current version will always be available at this address, with its effective date shown above.
Contact
JBNC Solutions
Email: info@jbncsolutions.co.za
Website: www.jbncsolutions.co.za