POPIA-Compliant Booking Software

Allsorts Bookings is built by a South African company, for South African businesses, with the Protection of Personal Information Act (POPIA) in mind from the ground up — not bolted on afterward.

Lawful, minimal data collection

The public booking form only asks for what's needed to confirm and manage an appointment: name, email, phone number, and the service/staff/time selected. No unrelated personal data is collected.

Encryption of sensitive fields

Connected API keys and payment credentials (your own PayFast merchant details, CRM and QR Code Pro API keys) are encrypted at rest using AES-256-GCM, not stored as plain text.

Tenant data isolation

Every booking, service, and staff record is scoped to your organization through a single server-side session check on every request — no business can see another business's customer data.

Your customers' rights

A customer can contact your business directly (using the details on their booking confirmation) to request their information be corrected or removed. As the data controller for your own customer bookings, you're able to action such a request directly from your dashboard.

A note on responsibility

Allsorts Bookings provides the technical safeguards described above, but as the business collecting bookings from your own customers, you remain the responsible party (the "responsible party" under POPIA) for how that data is used in your business — for example, what you tell customers about how their details will be used at booking time. We built the platform to make meeting your POPIA obligations straightforward, not to replace your own compliance responsibilities.