DRAFT — for attorney review. Not yet approved for publication or use.
This Privacy Policy explains how [STAYHUB LEGAL ENTITY NAME] (“StayHub”, “we”, “us”) collects, uses, shares, and protects personal information through the StayHub platform, in accordance with Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] and its regulations, including the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024.
This Policy covers three groups of people whose data StayHub touches: Guests (travellers booking accommodation), Hotel staff users (staff of Hotels using the hotel management portal), and platform team members (StayHub’s own employees using the Super Admin platform). Where a rule applies to only one group, that’s stated explicitly.
For most personal data described in this Policy, StayHub is the data controller. For a Guest’s booking and stay data specifically, the Hotel you book with is the data controller, and StayHub acts as a data processor on that Hotel’s behalf — the terms of that processing relationship are set out in StayHub’s Data Processing Agreement with each Hotel, not repeated here. This Policy still tells you what StayHub does with your data as the processor, even where the Hotel is legally the controller.
Data Protection Officer: [DPO NAME / "to be appointed"] — [DPO CONTACT EMAIL]. StayHub [is / intends to become] registered as a data controller with the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), the Data Protection Authority designated under the Cyber and Data Protection Act.
From Guests:
From Hotel staff users:
From platform team members:
Processing is carried out on the basis of: performance of a contract (your booking), your consent (marketing communications, SMS opt-in), StayHub’s or a Hotel’s legitimate interests (fraud prevention, service improvement, security monitoring), and compliance with legal obligations. Where consent is the basis, you may withdraw it at any time without affecting processing already carried out.
Some of the processors listed in Section 5 are located outside Zimbabwe (for example, payment processors headquartered in the United States, Ireland, South Africa, or Nigeria). The Cyber and Data Protection Act restricts transferring personal data outside Zimbabwe unless the receiving country ensures an adequate level of protection or appropriate safeguards are in place. Where we transfer data internationally, we rely on [contractual safeguards with each processor / the necessity of the transfer for performing your booking contract — attorney to confirm the specific mechanism relied on for each processor category and whether POTRAZ has issued or will need to issue an adequacy determination or transfer approval].
The Service sets essential cookies: session and authentication cookies that keep you signed in and the Service working, and short-lived cookies used only during a sign-in redirect (e.g. Google). None of these require consent under applicable law, and are disclosed, not gated, in the cookie preference control available on every page. The marketing site (stayhub.co.zw) also uses Google Analytics, a non-essential analytics cookie, to understand site usage — it is off by default and is only set if you affirmatively opt in through that same control; declining or ignoring the control means it is never set. We do not use marketing/advertising cookies. If that changes, this section will be updated first.
Subject to the Cyber and Data Protection Act, you have the right to:
To exercise these rights, contact [PRIVACY CONTACT EMAIL], or use the self-service data tool on a Hotel's booking page (verified using your booking confirmation code and email) to download a copy of your data or submit a deletion request directly to that Hotel. Where your data is held by a Hotel as controller, we will forward your request to the relevant Hotel where appropriate and assist as required by the Data Processing Agreement.
We use technical and organisational measures (encryption in transit, access controls, audit logging, and role-based permissions) to protect personal data, consistent with the security obligations under the Cyber and Data Protection Act. No system is completely secure; see the Data Processing Agreement for breach notification commitments.
The Service is not directed at children. Guest accounts and bookings are made by adults; children may be included in a travel party but are not themselves users of the Service.
We may update this Policy from time to time. Material changes will be notified through the Service or by email before they take effect.
[STAYHUB LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
Data Protection Officer: [DPO CONTACT EMAIL]
General privacy queries: [PRIVACY CONTACT EMAIL]