Yamo is a travel journal and trip marketplace run from South Africa. This policy explains what we collect when you use yamo.travel, the Yamo app, Agency OS and Yamo HQ, why we collect it, who sees it, and the choices you have. We wrote it to be read; if anything is unclear, ask us.
1. Who we are
Yamo ("we", "us") operates the yamo.travel websites and apps. For the purposes of the Protection of Personal Information Act (POPIA) and, where it applies, the GDPR, Yamo is the responsible party for the personal information described here. Contact: hello@yamo.travel.
2. What we collect
When you say hello on the website
If you use "Talk to Yamo", the "Message Yamo" button or a contact form, we store what you type: your name if you give it, your WhatsApp number or email address, where you said you'd like to go, roughly when, who is coming, any message, the page you were on and the fact that you agreed to be contacted. We use this to reply to you about that trip. We do not add you to a newsletter.
When you create an account
Your name, email address, a password (stored hashed, never in plain text) or the identity a sign-in provider gives us (Google, Facebook, TikTok, Apple), your profile photo if you add one, and the country you sign up from.
When you use the journal
The countries you mark as visited, journal entries, photos you upload, ratings, wishlists and the friends you add. When you scan a passport page the photo is sent to our reading service once, the stamps it reads are returned to you to confirm, and the photo of the page is not stored. Only the visits you confirm are saved.
When you join or request a trip
Your booking details, the number of spots you request, payments the agency records against your booking, documents you sign (such as an indemnity) and the brief you give Ask Yamo for a tailored trip. Money is handled by the agency, not by Yamo; we do not see your card details.
Automatically
Standard server logs (IP address, browser, pages requested, time) kept for security and to rate-limit abuse, and the technical settings your browser stores locally so the app works (your session token, your last-used screen). We do not run third-party advertising trackers.
3. Why we use it
- To run the service you asked for: your journal, your bookings, your requests.
- To reply to you when you ask us to, by WhatsApp or email.
- To let an agency serve you, only as far as described in section 4.
- To keep the service safe: fraud prevention, rate limiting, security investigations.
- To improve Yamo, using aggregate numbers that do not identify you.
- To meet legal obligations.
Our legal grounds are performance of a contract with you, your consent where we ask for it (for example, the tick box when you leave a number), and our legitimate interest in running a safe service. You can withdraw consent at any time by telling us.
4. Who sees your information
Travel agencies on Yamo see you only through your own actions: a booking you make with them, a join request you send them, or a tailored request Yamo HQ assigns to them. There is no directory of travellers that agencies can browse. An agency sees your name, contact details, the members of your booking and what you tell them; it does not see your journal, your photos or your other trips.
Other travellers see your name and photo when you are on the same trip or when you have accepted them as a friend. Public trip pages show other travellers only as initials. Anything you share by link (a trip page, a share card) is visible to whoever has the link.
Service providers who host or process data for us: our hosting and database providers, email delivery, and the AI service that reads passport pages and powers Ask Yamo. They process data only on our instructions. Passport photos are sent for reading and not retained by us; see the provider's terms for their retention.
Authorities, when the law requires it.
We do not sell personal information.
5. International transfers
Our servers and providers may be located outside South Africa (for example in the European Union or the United States). Where we transfer information abroad we rely on providers that offer adequate protection or on contractual safeguards, as POPIA and the GDPR require.
6. How long we keep it
- Website leads (a number or email you left): until we have replied and for up to 12 months after, unless you become a member or ask us to delete it sooner.
- Your account and journal: for as long as your account exists. Delete your account from your profile and it is removed within 30 days, except records we must keep for bookings, tax or disputes.
- Booking and payment records: as long as the agency and the law require, typically five years.
- Server logs: up to 90 days.
7. Your rights
You can ask us to show you what we hold about you, correct it, delete it, restrict or object to how we use it, or give it to you in a portable form. You can withdraw consent to WhatsApp or email contact at any time by replying "stop" or writing to us. Email hello@yamo.travel and we will answer within 30 days. You may also complain to the Information Regulator (South Africa) at inforegulator.org.za.
8. Children
Yamo is for people aged 18 and over. A parent or guardian books for children on family trips; we do not knowingly create accounts for anyone under 18.
9. Cookies and local storage
The website sets no tracking cookies. The apps store your sign-in session and a few preferences in your browser's local storage so you stay signed in; clearing your browser data signs you out. Third-party sign-in (Google, Facebook, TikTok, Apple) is subject to those providers' own policies.
10. Security
Traffic is encrypted in transit. Passwords are hashed. Access to production data is limited to the Yamo team and logged. No system is perfectly secure; if we learn of a breach affecting you we will tell you and the regulator as the law requires.
11. Changes
When we change this policy we update the date at the top and, for material changes, tell you in the app or by email.