Effective date: 1 April 2026 · Last updated: 7 April 2026
This Privacy Policy explains how BEVA Direct Services CC(trading as “TravelFlow”), a close corporation registered in the Republic of South Africa (“we”, “us”, or “our”), collects, uses, stores, shares, and protects your personal information when you access or use the TravelFlow platform, including all associated websites, applications, APIs, and services (collectively, the “Platform”).
This Policy is prepared in accordance with the Protection of Personal Information Act, 2013 (Act 4 of 2013)(“POPIA”) of South Africa and, where applicable, the General Data Protection Regulation (EU) 2016/679(“GDPR”). By using the Platform, you acknowledge that you have read, understood, and agree to the practices described in this Policy.
For the purposes of POPIA, the responsible party is:
BEVA Direct Services CC
Trading as: TravelFlow
Jurisdiction: Republic of South Africa
Information Officer: privacy@travelflow.co.za
General Enquiries: support@travelflow.co.za
We collect the following categories of personal information, depending on your role and use of the Platform:
Full name, initials, surname, email address, telephone number, physical address, job title, position, and department. For travellers: passport number, date of birth, nationality, and frequent flyer numbers.
Email address, hashed password, multi-factor authentication (MFA) enrolment status, session identifiers, login timestamps, IP addresses, and browser user-agent strings.
Bank account details (encrypted at rest using AES-256-GCM), payment card information (processed by PayU — we do not store card numbers), invoice and payment records, commission data, and transaction histories.
Flight itineraries, hotel reservations, car rental bookings, travel dates, destinations, passenger manifests, special requests, meal preferences, and loyalty programme details.
Organisation name, department structures, cost centres, budget codes, approval hierarchies, travel policies, and inter-departmental relationships.
Device type, operating system, browser type, screen resolution, pages visited, features used, error logs, performance metrics, and analytics data. This data is collected automatically when you interact with the Platform.
Messages sent through the in-platform messaging system, support ticket content, and email correspondence related to bookings or account management.
We process your personal information on the following legal grounds under POPIA Section 11:
For EU/EEA data subjects, we additionally rely on Article 6(1) of the GDPR with corresponding legal bases.
We share your personal information with the following categories of third parties, strictly on a need-to-know basis and subject to appropriate data protection agreements:
RateHawk (Emerging Travel Group), Amadeus IT Group, Sabre Corporation, and Travelport. Booking data (passenger names, travel dates, destinations) is transmitted to fulfil reservations. These providers operate under their own privacy policies.
PayU South Africa (PaymentsOS Enterprise API) processes payment transactions. We transmit the minimum information required to process payments. We do not store full credit or debit card numbers on our systems.
Google Firebase (Cloud Firestore, Firebase Authentication, Cloud Storage) and Vercel Inc. host the Platform infrastructure. Data may be stored in data centres outside South Africa. See Section 8 (Cross-Border Transfers) for details.
Airlines, hotels, car rental companies, transfer operators, and other travel suppliers receive the information necessary to fulfil your booking (passenger names, dates, special requirements).
Sentry (Functional Software, Inc.) may receive anonymised error and performance data to help us identify and resolve technical issues. No personally identifiable information is intentionally transmitted.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
We implement the following technical and organisational measures to protect your personal information:
Your personal information may be transferred to, stored in, or processed in countries outside the Republic of South Africa, including the United States and the European Economic Area, where our infrastructure providers (Google, Vercel) and GDS partners maintain data centres.
In accordance with POPIA Section 72, we ensure that such transfers are subject to appropriate safeguards, including:
We retain your personal information only for as long as necessary to fulfil the purposes described in this Policy, or as required by law:
When personal information is no longer required, it is securely deleted or anonymised so that it can no longer be associated with you.
Under POPIA (and GDPR where applicable), you have the following rights in relation to your personal information:
To exercise any of these rights, contact our Information Officer at privacy@travelflow.co.za. We will respond within 30 days of receiving your request, as required by POPIA.
The Platform uses browser session storage to maintain your booking basket and session state during your visit. We use Firebase Authentication tokens stored in browser memory for secure authentication. We do not use third-party advertising or tracking cookies.
Analytics data, if collected, is used solely for service improvement and is not shared with advertisers. You may configure your browser to block cookies or clear local storage at any time, though this may affect Platform functionality.
The Platform is not directed at children under the age of 18. We do not knowingly collect personal information from children. Where a booking includes minor travellers, the responsible adult provides the child's information and assumes responsibility for its accuracy and the consent to process it. If we become aware that we have inadvertently collected personal information from a child without appropriate parental consent, we will take steps to delete it promptly.
In the event of a security breach that compromises your personal information, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, in accordance with POPIA Section 22. Notification will include a description of the breach, the categories of information affected, the likely consequences, and the measures taken or proposed to address the breach.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Platform features. Material changes will be communicated through the Platform (via notification or prominent notice) and by updating the “Last updated” date at the top of this page. Your continued use of the Platform after such changes constitutes acceptance of the revised Policy.
For privacy enquiries, data subject requests, or complaints:
Information Officer — BEVA Direct Services CC
Email: privacy@travelflow.co.za
General Support: support@travelflow.co.za
Information Regulator (South Africa)
Email: complaints.IR@justice.gov.za
Website: www.justice.gov.za/inforeg/