Privacy notice
What we collect when you book, why, who else sees it, and what you can ask us to do about it. Written to meet the Protection of Personal Information Act 4 of 2013 (POPIA).
Last updated 6 September 2026
Who is responsible
Magical Cabin in the Woods, 22 Steenbok Street, Van Dyks Bay, Kleinbaai, 7220, Western Cape. We are the responsible party for your information under POPIA.
For anything on this page, write to hello@magicalcabininthewoods.co.za. A real person reads it.
What we collect
When you send a booking request: your name, email address, phone number, the dates you want, how many guests, whether you are bringing a pet, and anything you write in the message box.
A promotion code, if you used one, so we know which campaign brought you.
A one-way hash of your IP address, kept for up to 24 hours, purely to stop the booking form being abused by scripts. We deliberately do not store the address itself — the hash cannot be reversed to identify you.
If you book on an age-related rate: the fact that you confirmed someone in the party meets the age, when you confirmed it, and the age itself. We do not ask for, receive or store an ID number, a copy of a document, or anyone’s date of birth. Where we check at all, we look at ID on arrival and hand it straight back.
That is all. There is no analytics, no advertising pixel and no third-party tracker anywhere on this website. We do not know how you got here unless you tell us.
Why we collect it
To answer your request, hold your dates, and run your stay. That is the whole purpose.
The lawful basis is that we need the information to perform the booking you asked for, and for our legitimate interest in keeping the form free of abuse.
We keep booking records for five years after your stay because tax law requires it.
Who else sees it
Resend, our email provider, which delivers the confirmation emails. Your name, email address and booking details pass through it.
Cloudflare, which hosts this website and its database. Your booking is stored there.
Nobody else. We do not sell your information, we do not share it with the booking platforms, and we do not hand it to marketers.
Some of these providers process data outside South Africa. POPIA permits that where the receiving country or the provider offers comparable protection, and both operate under contractual data-protection terms.
Marketing
We do not have a mailing list and we do not send marketing. If we ever start, it will be something you opt into deliberately, and one click will get you out again.
Your rights
You can ask us what we hold about you, and we will tell you.
You can ask us to correct anything wrong, or to delete what we no longer need to keep. Where tax law requires us to retain a booking record, we will say so and tell you when it can go.
You can object to how we are using your information.
None of this costs anything and none of it needs a form. Email us.
If we handle it badly, you may complain to the Information Regulator of South Africa at enquiries@inforegulator.org.za.
Keeping it safe
The site is served only over HTTPS. Booking data sits in a database that is not reachable from the public internet.
The links we use to confirm or cancel a booking are protected by long random tokens rather than a password, and the calendar feed we publish to the platforms contains dates only — never a guest’s name or contact details.
If information is ever lost or exposed in a way that could harm you, we will tell you and the Information Regulator, as POPIA requires.
Cookies
We set no cookies and there is nothing to consent to.
Your browser stores two small things locally, and neither leaves your device or identifies you: whether you have dismissed the promotion popup, and a promotion code if you arrived through a partner link.