Privacy Policy
Effective 29 August 2026 · Version 1.1
This policy explains what personal information High Tea collects about you, why we collect it, how we look after it, who we share it with, and the rights you have over it. It is written to meet our obligations under the Protection of Personal Information Act, 2013 (POPIA). We’ve kept it plain on purpose — if anything here is unclear, ask us and we’ll explain.
In this policy, High Tea (we, us, our) means the High Tea members’ association at 20 Station Road, Rondebosch. You means a member or someone applying for membership.
Who is responsible for your information
High Tea is the responsible party for your personal information under POPIA. Our Information Officer oversees how we handle it and is your point of contact for anything in this policy, including any request or complaint.
Reach the Information Officer at privacy@hightealounge.com, or by post at the address above.
What we collect
We collect only what we need to run the membership and the lounge. When you apply for membership and use the platform, we collect:
- your name, and the email address and phone number you give us;
- your date of birth, which we use to confirm you are old enough to be a member;
- your account login details — your email, and a password we never see in plain form, stored only as a secure one-way hash by our authentication provider;
- your member number and membership status;
- your orders and collections — what you reserved, the amounts, and the dates;
- records of the consent you gave at sign-up, with the date and the version of the terms you agreed to;
- any preferences you set, and any notes from a bespoke-blend consultation if you have one;
- your Bud Journal entries — the scores you give a strain, the journal fields you fill in, anything you write, and any photograph you upload;
- your referrals — the member who invited you, and the people you invite, so that qualifying referrals can be credited;
- a record of your visits to the lounge, used to maintain your membership tier;
- the name and email address of any guest you bring in on a guest pass, which you give us on their behalf;
- basic technical records needed to keep your account secure, including session records and, in our security audit log, the IP address a sensitive action came from.
We collect this information directly from you. We do not buy personal information about you from anyone else, and we do not build advertising profiles.
Giving us this information is voluntary, but some of it is necessary: without your name, email, and date of birth we cannot verify you or open a membership, so we would not be able to sign you up.
Why we collect it, and our lawful grounds
We use your personal information to:
- confirm you are 18 or older and eligible for membership;
- create and administer your membership and account;
- take and prepare your orders for collection or in-lounge service, and keep you updated about them;
- send you the account emails you need — sign-up confirmation, password resets, order and collection confirmations;
- process referrals and apply the credits and gifts they earn;
- record your lounge visits, which we use to maintain your membership tier;
- send a guest you brought a single follow-up email after their visit;
- publish your Bud Journal content, attributed to you or anonymised, as set out in the Terms of Membership;
- keep the platform secure and investigate misuse;
- keep the financial and membership records the law requires us to keep;
- answer you when you contact us.
Our lawful grounds under POPIA are your consent given at sign-up, the performance of our membership agreement with you, compliance with our legal obligations such as tax record-keeping, and our legitimate interest in running and securing the association. You can withdraw your consent at any time — see "Your rights" below — though doing so may mean we can no longer keep your membership open.
We do not use your information for automated decision-making that has legal or similarly significant effects on you.
Who we share it with
We do not sell your personal information, and we do not share it with anyone for their own marketing.
We use a small number of trusted service providers (operators under POPIA) to run the platform. They process your information only on our instructions, under contract, and only to provide their service to us:
- our database and authentication provider, which stores your account and membership data;
- our hosting provider, which runs the website;
- our email provider, which delivers your account emails;
- our payment provider, for online payments once that is enabled — card details are handled by the payment provider, not stored by us.
Some of these providers process or store data outside South Africa — our database is hosted in the European Union, and some providers operate in the United States. Where your information is transferred outside South Africa, it is protected by laws or contractual safeguards that provide a level of protection comparable to POPIA, as required by section 72 of the Act. The European Union’s data-protection regime, in particular, offers protection substantially similar to POPIA.
Bud Journal content you post may be published — on the platform, in the lounge, or in our own communications — either attributed to you or anonymised, as set out in the Terms of Membership. Nothing else from your account is published alongside it.
If you bring a guest, we use the name and email address you give us only to send that guest a single follow-up email after their visit. We do not share guest details with anyone else and we do not add guests to a mailing list.
We may also disclose information where the law requires it — for example, to a regulator, court, or authority acting within its powers.
How long we keep it
We keep your personal information only as long as we need it.
While you are a member, we keep your account information for as long as your membership is active. When you close your membership, we delete or anonymise your personal identifiers — your name, contact details, date of birth, login, preferences and consultation records are removed or scrubbed.
Bud Journal entries are kept while you are a member, or until you delete them — whichever comes first. A guest’s name and email address are deleted 30 days after the follow-up email for that visit.
We are required by tax law (the Tax Administration Act) to keep financial and transaction records for five years. So after you leave, a record that an order happened — the amount and the date — is kept in de-identified form for five years from your last transaction. That record no longer points to a named, contactable person. Once the five years lapse, it is purged.
How we protect it
We take the security of your information seriously. Access to the database is controlled row-by-row so members can only see their own data; connections are encrypted in transit; administrative access is limited to those who need it; and sensitive actions are logged. Passwords are stored only as secure hashes, and we enforce a minimum password strength and screen for known-compromised passwords.
No system is perfectly secure, but we work to protect your information and to meet our obligations if anything ever goes wrong, including notifying you and the Information Regulator where the law requires it.
Your rights
Under POPIA you have the right to:
- ask what we hold about you and get a copy of it;
- correct or update information that is wrong or out of date;
- delete or destroy your personal information — we remove or anonymise your identifiers, keeping only the de-identified financial records the law requires us to retain for five years;
- object to certain processing, and withdraw consent you have given;
- complain to us, and to the Information Regulator, if you think we have mishandled your information.
To exercise any of these, email privacy@hightealounge.com. We will confirm your identity first — to protect you, we only act on requests we can verify come from you — and we will respond within a reasonable time, and in any event within 30 days of a verified request.
You can lodge a complaint with the Information Regulator (South Africa) through its eService Portal at inforegulator.org.za. General enquiries: enquiries@inforegulator.org.za. We’d ask you to raise it with us first so we can put it right.
Cookies
We use only the cookies the platform needs to work. An age-verification cookie remembers, for thirty days, that you confirmed you are over 18, so you are not asked on every visit. A session cookie keeps you signed in. We do not use advertising cookies. To understand how the site is used we use a privacy-friendly, cookieless analytics tool that counts visits and page views in aggregate — it sets no cookies, does not identify you, and does not track you across other sites.
Age
High Tea is for adults. You must be at least 18 years old to be a member, and the platform is not intended for anyone under 18. We do not knowingly collect information from people under 18; if we learn we have, we delete it.
Changes to this policy
If we change how we handle your information, we will update this policy and change the version and date above. Where a change is significant, we will tell you.
Contact us
Questions, requests, or complaints about your personal information:
High Tea — Information Officer. privacy@hightealounge.com. 20 Station Road, Rondebosch, Cape Town, 7700.
See also our Terms of Membership.