Privacy policy

Last Updated: September 2026

At City Of Rain Hotel & SPA, we believe that trust is the foundation of hospitality. When you share your personal information with us, whether to book a spa retreat, enquire about a room, or simply browse our website, we take that responsibility seriously. This policy explains how we collect, use, store, and protect your data in line with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable laws.

Who We Are

City Of Rain Hotel & SPA is a boutique hotel and wellness retreat located at the corner of R25 and R42 Delmas Road, Bronkhorstspruit, 1020, Gauteng, South Africa. We are the party responsible for the processing of your personal information.

You can contact us at:

  • Email: reception@cityofrain.co.za
  • Telephone: +27 12 883 8850
  • Address: Bronkhorstspruit, 1020, Gauteng, South Africa
  • Location: Cnr. of R25 & R42 Delmas Road, Bronkhorstspruit, 1020, Gauteng, South Africa

What Information We Collect

We only collect information that we genuinely need to provide you with exceptional service. We may collect the following categories of personal information:

  • Contact Details: Your name, email address, phone number, physical address, and company affiliation.
  • Demographic Data: Date of birth, nationality, and government-issued identifiers such as passport numbers where required for reservations or by law.
  • Financial Details: Payment and billing information, including payment card information, where applicable, which is processed through secure payment channels.
  • Guest Stay Information: Details of your stay, spa treatments, preferences, room type requests, amenities used, and any special requests.
  • Technical Information: Your IP address, browser type, device information, and how you navigate our website.
  • Social Media Details: Information from your social media accounts where you choose to connect with us or share content.
  • Your Feedback: Comments, complaints, survey responses, and reviews you voluntarily provide.
  • CCTV and Surveillance: Images and visual recordings collected through closed circuit television systems in public areas of our hotel and property for your safety and security, where permitted by law.
  • Other Data: Any other information you voluntarily choose to provide to us.

Special Personal Information

From time to time, you may provide or we may collect what is considered special personal information under POPIA. This may include health information, religious affiliation, or disability information so that we can accommodate you during your stay or spa visit.

We only process special personal information where permitted by POPIA and other applicable law, including where an applicable exception under POPIA applies or where the required consent has been obtained. Unless otherwise required by law, you are not required to provide us with any special personal information. Where the provision of such information is necessary for the safe provision of a particular treatment or service, choosing not to provide it may mean that we are unable to provide that treatment or service.

Lawful Processing

We process personal information only where permitted by POPIA and other applicable law. Depending on the circumstances, this may include processing necessary to perform a contract, comply with a legal obligation, pursue a legitimate interest, obtain consent, or otherwise process information where POPIA permits it.

Specifically, we process your personal information where:

  • It is necessary to perform a contract with you, or to take steps at your request to enter into a contract. For example, to manage your booking, process payment, or provide the services you have requested.
  • It is necessary to comply with a legal or regulatory obligation that applies to us, such as tax, accounting, or law enforcement requirements.
  • It is necessary for our legitimate interests as a responsible party, provided that your privacy, rights, and interests are not overridden. This includes providing customer service, ensuring security, preventing fraud, and improving our services.
  • You have given your consent, for example to receive marketing communications or to process special personal information for your spa treatment.
  • It is otherwise permitted by POPIA, such as where processing is necessary to protect your vital interests or for public interest reasons.

How We Use Your Information

We use your personal information to:

  • Fulfil our agreement with you and deal with your booking, including processing your reservation, sending your itinerary, and managing your stay.
  • Update you on changes to your booking or stay.
  • Manage your wider travel or service requirements, including liaising with airlines, transport providers, or other facilitators where you ask us to arrange these.
  • Process payments for your booking, fulfil requests for refunds, and for accounting or audit purposes.
  • Personalise the service and offers you receive, from remembering your room preferences to tailoring spa treatment recommendations.
  • Communicate and interact with you at different times throughout your journey.
  • Communicate with service providers regarding your experience, preferences, compliments, or complaints.
  • Improve the products and services we offer or help us to create new ones.
  • Conduct guest satisfaction surveys so that we can obtain a better understanding of how we can continue to improve.
  • Market our products and services to you where you have consented or where otherwise permitted by applicable law.
  • Comply with legal, regulatory, and tax obligations.

If you book on behalf of others, you confirm that you have their permission to share their information with us and that they are aware of this policy.

Sharing Your Information and Cross-Border Transfers

We do not sell your personal information to anyone. We only share it where necessary and lawful:

  • Service Providers: With trusted third parties who help us run our business, such as payment processors, IT support, data hosting providers, marketing platforms, and fraud detection services. These providers are bound by contractual obligations to process personal information only in accordance with our prior written instructions and to use appropriate measures to protect the confidentiality and security of such information.
  • Government and Regulatory Authorities: When required by law, or to respond to valid legal claims, summons, or regulatory orders.
  • Legal Proceedings: Where it is necessary for the purposes of, or in connection with, actual or threatened legal proceedings or the establishment, exercise, or defence of legal rights.
  • Wellness Practitioners: With spa practitioners, wellness practitioners, and other service providers where necessary to provide a treatment or service you have requested, and where such disclosure is lawful.
  • Business Transfers: In the event that we sell, reorganise, merge, or transfer all or any portion of our business or assets, your personal information may be transferred as a business asset. The new owner may process your personal information for legitimate business purposes, subject to applicable law and any applicable consent or objection requirements.
  • Social Media and Plugins: Our website may include links to, or features provided by, social media platforms. Where these features are used, the relevant platform may process information in accordance with its own privacy policy.

The personal information that we collect from you may be transferred to, and stored at, a destination outside the Republic of South Africa. It may also be processed by staff or service providers operating outside South Africa who work for us or for one of our suppliers. Some of our service providers may process personal information outside South Africa, including providers of booking, payment, hosting, customer relationship management, analytics, communications, and other technology services.

We will only transfer personal information outside South Africa where permitted by POPIA and applicable law and, where required, will implement appropriate safeguards. A copy of these safeguards can be obtained by contacting us at the details provided in Section 16.

Cookies and Similar Technologies

Our website uses cookies and similar technologies to function properly and to give you the best possible experience. A cookie is a small file that is placed on your device when you visit our site.

When you first visit our website, a cookie consent banner will appear to allow you to manage your preferences. You may accept all cookies, decline non-essential cookies, or adjust your settings. Essential cookies cannot be declined as they are necessary for the site to function.

The types of cookies we may use include:

  • Essential Cookies: These are necessary for the website to work, such as remembering your booking selections and keeping you logged in to secure areas. These are typically session cookies that are deleted when you close your browser.
  • Analytics Cookies: These help us understand how visitors interact with our site, which pages are most popular, and where we can improve. These may be persistent cookies that remain on your device for up to 12 months.
  • Functionality Cookies: These allow us to remember your preferences, such as language settings and display choices. These may persist for up to 12 months.
  • Marketing Cookies: These help us deliver relevant advertisements and measure their effectiveness. These may persist for up to 12 months.

You can control cookies through your browser settings and through our cookie consent banner. Most browsers allow you to refuse or delete cookies. Please note that if you disable certain cookies, some parts of our website may not function as intended.

A detailed cookie inventory, including specific cookie names, providers, purposes, and durations, is maintained separately and is available on request.

How We Protect Your Data

We have implemented reasonable technical and organisational measures to keep your information safe. This includes access controls, confidentiality requirements for our staff and service providers, and appropriate security measures for online transactions. While we take every reasonable precaution, no internet transmission is completely secure. We cannot guarantee the absolute security of information transmitted to us online.

Should a breach occur, we undertake to contain the breach, assess the nature and extent of the compromise, take appropriate remedial measures, and notify you and/or the Information Regulator where required by law.

How Long We Keep Your Information

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. This typically includes the duration of your stay, plus a reasonable period for accounting, tax, and legal purposes.

In some circumstances we may store your personal information for longer periods of time, for example, where we are required to do so in accordance with legal, regulatory, tax, or accounting requirements, or if we reasonably believe there is a prospect of litigation or a complaint relating to your personal information or dealings.

Where we no longer need your information, we will securely destroy or permanently anonymise it.

If you apply for employment with us, your personal information will be processed in accordance with the applicant privacy provisions set out on our Careers page.

Your Rights

Under POPIA and applicable data protection laws, you have the right to:

  • Be informed of the personal information we hold about you, why we hold it, and how it is used.
  • Access your personal information.
  • Request correction of any inaccurate, incomplete, or outdated information.
  • Request deletion of your information, where we are not legally required to retain it.
  • Object, on reasonable grounds relating to your particular situation, to certain processing of your personal information, where permitted by POPIA.
  • Lodge a complaint with the Information Regulator if you believe your rights have been violated.

Depending on the circumstances and applicable law, you may also have additional rights relating to restriction of processing or portability.

To exercise any of these rights, please contact us at reception@cityofrain.co.za . We may request reasonable information to confirm your identity and for security purposes before disclosing personal information to you. We will not ask you to provide sensitive information such as your full credit card number or password to verify your identity.

If we cannot reasonably verify your identity, we may be unable to fulfil the request until sufficient information has been provided to verify your identity.

You may also exercise your rights via an authorised agent. The agent must provide evidence of their entitlement, such as written permission demonstrating that they have authority to make the request on your behalf, and the agent must verify their own identity directly with us.

If you think we have not complied with a data protection law, you have the right to lodge a complaint with the Information Regulator of South Africa:

The Information Regulator (South Africa)

Woodmead North Office Park
54 Maxwell Drive, Woodmead, Johannesburg, 2191
P.O. Box 31533, Braamfontein, Johannesburg, 2017
Telephone: 010 023 5200
Email: enquiries@inforegulator.org.za
Website: www.inforegulator.org.za

Children’s Privacy

Our website and online booking services are not intended for independent use by children. Children staying at the property must be accompanied and supervised by a parent or guardian. Parents or guardians may provide information relating to children where necessary to make or manage a booking.

If you are a minor, please do not provide personal information through our website without the involvement of a parent or guardian.

Direct Marketing, Profiling and Analytics

We may use your personal information to let you know about our products and services that we think may be of interest to you. This may be based on your preferences, stay history, and interactions with us. We may contact you by email, SMS, or other messaging platforms in accordance with section 69 of POPIA and other applicable direct marketing laws, where you have consented or where POPIA permits direct marketing to existing customers subject to the applicable requirements.

You may withdraw your consent to direct marketing, or opt out of further direct marketing where POPIA permits it, at any time. You can do this by clicking the unsubscribe link at the bottom of any marketing email you receive from us, or by emailing us at reception@cityofrain.co.za at any time. Please note that even if you unsubscribe from marketing communications, you will still receive operational and transactional messages related to your bookings and enquiries.

We may also aggregate personal information and remove identifying elements to analyse patterns, improve our marketing, and understand our guests better. We may use analytics tools for this purpose. You can manage your preferences for analytics and marketing cookies through our cookie consent banner.

Accuracy of Your Information

If your personal information changes, please let us know so that we can keep our records accurate and up to date.

PAIA and Regulatory Information

Our PAIA Manual is available on request using the contact details in Section 16.

Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or in the law. Any material changes will be posted on this page. The date this policy was last revised is identified at the top of the page. Where appropriate, we will notify you of material changes through our website or other suitable communication channels. We encourage you to review this policy periodically.

Contact Us

If you have any questions, complaints, objections, requests to restrict processing, or any other queries regarding your personal information, please reach out to us: