Visit Us
060 265 5559
14 Ease Centre
C/O Jean Avenue & Gerhard Street
Die Hoewes, Centurion
0157

Privacy Policy

How Vamos Osteria respects and protects your personal information.

This policy explains how Vamos Osteria handles personal information through the Vamos Osteria website, Android app, client account, online ordering, reservations, vouchers, event tickets, payments and direct communications. It is written for South Africa and should be read with the Protection of Personal Information Act 4 of 2013 (POPIA).

1. Who We Are

Vamos Osteria is operated by Vamos Osteria and is the responsible party for the personal information described in this policy.

Address: South Africa

Email and Information Officer contact: info@vamososteria.co.za

Phone: 060 265 5559

2. Information We Collect

Depending on how you use Vamos, we may collect:

  • Account and profile details such as your name, surname, email address, phone number, date of birth and password hash.
  • Billing and transaction details, including invoice information, payment references, payment status and VAT records. We do not receive or store your full payment-card number when PayFast processes payment.
  • Order, voucher, event ticket and reservation details, including recipient information you provide for a gift.
  • Delivery information such as an address, suburb and access instructions when delivery is available.
  • Messages and contact details submitted through support, contact or booking forms.
  • Technical and security information such as IP address, browser or app user agent, request identifiers, login history, device registration, session records and security events.
  • Push-notification tokens and delivery status when app notifications are enabled.
  • Cookie, analytics and advertising measurement data where optional tracking is enabled and you have made the applicable privacy choice.

If you provide another person's details, for example when buying a gift voucher, you must have permission to provide that information and should tell them how it will be used.

3. How and Why We Use Information

We process personal information only where there is a lawful and reasonable purpose, including to:

  • Create and secure your account, authenticate sign-ins and help recover account access.
  • Process orders, vouchers, tickets, reservations, invoices and payments and provide the service you requested.
  • Send confirmations, receipts, operational updates, reminders and security messages.
  • Meet tax, accounting, consumer-protection and other legal obligations.
  • Prevent fraud, abuse, unauthorised access, duplicate transactions and attacks against our systems.
  • Respond to enquiries, complaints, access requests and deletion requests.
  • Improve service reliability and understand website or app use where optional analytics consent applies.
  • Measure advertising conversions where optional advertising consent applies.

The applicable basis may be performance of a contract, compliance with law, your consent or a legitimate interest that does not unjustifiably interfere with your privacy.

4. When Information Is Shared

We do not sell personal information. We share only what is reasonably necessary with:

  • PayFast and relevant financial institutions to initiate, verify and reconcile payments.
  • Hosting, email, security, analytics, advertising and push-notification service providers acting under appropriate instructions or terms.
  • Delivery or operational personnel who need information to fulfil an order or reservation.
  • Professional advisers, auditors, insurers, regulators, law-enforcement bodies or courts where lawfully required.
  • A lawful successor if the business is reorganised or transferred, subject to appropriate confidentiality and data-protection safeguards.

Some providers may process information outside South Africa. Where this occurs, we take reasonable steps to use a lawful transfer basis and require protection that is substantially similar to POPIA where applicable.

5. Cookies, Analytics and Advertising

Essential storage is used for security, sessions, shopping or booking flow and your privacy choices. Optional analytics and advertising technologies are controlled by the consent choices shown on the website. You can reject optional categories or review the privacy choices shown when optional tracking is enabled. Changing a choice does not affect processing already completed lawfully.

6. Mobile App and Device Security

The Vamos Osteria app may register an installation, create device-bound sessions and store encrypted local state needed for sign-in and purchasing. Authentication tokens and push tokens are treated as credentials. They are not displayed publicly and are revoked or removed when no longer valid, when you sign out, after relevant security events or when account deletion is completed.

7. Security

We use layered administrative, technical and organisational safeguards appropriate to the information and risk. These include encrypted transport, password hashing, access controls, least-privilege database access, prepared database statements, rate limiting, request validation, audit trails and credential revocation. No internet service can guarantee absolute security. If we identify a security compromise that triggers a legal notification duty, we will follow the applicable POPIA process.

8. How Long We Keep Information

We keep personal information only for as long as reasonably needed for the purpose collected, a valid dispute or security need or a legal retention duty.

  • Active account details are kept while the account is used and are anonymised when a verified deletion request is completed, except for lawfully retained records.
  • One-time verification and reset tokens expire quickly and are invalidated after use.
  • Order, voucher, ticket and reservation records are kept for fulfilment, support, reconciliation, disputes and fraud prevention.
  • VAT invoices, payment evidence and accounting records are generally retained for at least five years where South African tax law requires this.
  • Security and audit records are retained for a proportionate period based on risk, legal requirements and the need to investigate abuse.
  • Privacy-request records are retained as evidence that the request was verified and handled.

Where deletion is not legally permitted, the retained information is restricted from normal account use and kept only for the documented purpose.

9. Your POPIA Rights

Subject to POPIA and other applicable law, you may ask us to:

  • Confirm whether we hold personal information about you and request access to it.
  • Correct or update inaccurate, incomplete, misleading or outdated information.
  • Delete or destroy information that we are no longer authorised to retain.
  • Object to certain processing or withdraw consent where consent is the basis.
  • Stop direct marketing communications.
  • Lodge a complaint with the Information Regulator.

We may need to verify your identity before acting. Verification information will be limited to what is reasonably necessary. A verified account deletion request can be started at our account deletion page. We provide a written outcome within the applicable response period.

10. Account Deletion and Retained Transactions

When deletion is completed, the sign-in account is disabled, active access is revoked, device push tokens are removed and removable profile fields are anonymised. The deleted account can no longer be used to view purchases.

We may retain restricted invoice, payment, order, voucher, ticket, reservation, security and privacy-request records where required for tax, accounting, fulfilment, consumer disputes, chargebacks, fraud prevention or legal claims. These records are not kept for ordinary marketing or continued account access and are removed or anonymised when the retention reason ends.

11. Children and Age-Restricted Items

The account and online purchasing services are intended for adults. Age-restricted menu items require the customer to meet the applicable age requirement and may require identification at fulfilment. We do not knowingly seek personal information from a child without a lawful basis and appropriate guardian involvement.

12. Changes to This Policy

We may update this policy when our services, providers or legal duties change. The current version and effective date will remain on this page. Material changes will be communicated through an appropriate channel where required.

13. Contact and Complaints

Send privacy questions or rights requests to info@vamososteria.co.za. Please do not email passwords, payment-card details or identity documents unless we specifically request a secure verification method.

You may also complain to South Africa's Information Regulator through its official complaints service, by emailing POPIAComplaints@inforegulator.org.za or by calling 010 023 5200.

Get In Touch