Skip to content
Sola

Privacy policy

Last updated: 5 June 2026

This policy explains what data we collect, why we collect it, and what you can do about it. We wrote it in plain language on purpose.

Who we are

Sola is a solo travel app built for women, operated by Bokang Sibolla Digital Pty Ltd, a company registered in South Africa.

  • Registered address: 34 Shortmarket Street, Cape Town City Centre, 8001, South Africa
  • Website: solatravel.app
  • Contact: team@solatravel.app

Sola serves users globally. We comply with South Africa's Protection of Personal Information Act (POPIA), the EU General Data Protection Regulation (GDPR), and other applicable privacy laws in the regions where our users are located.

If you have any questions about this policy or your data, email us. We will respond within 30 days.

What we collect and why

Account information

When you create an account, we collect:

  • Email address to identify your account, send you important updates, and let you log in.
  • Display name to show other users who you are in the community.
  • Profile photo (optional) to personalize your profile.

You can sign up with email and password or with Apple Sign-In. If you use Apple Sign-In, we receive the email address and name you choose to share through Apple's authentication flow.

Identity verification (optional)

To help women in the community know they are talking to a real person, we offer optional identity verification. If you choose to verify, we ask you to take a selfie.

  • What we collect — a single selfie photograph. We do not create or store a faceprint, a facial template, or any other biometric identifier, and we do not use facial recognition or any automated face matching.
  • How we use it — a member of our team looks at your selfie alongside your profile photo and confirms you are a real person. This is a manual human review, usually completed within 24 hours. Its only output is a verification status on your account. Your selfie is never shown to other users.
  • Who can see it — your selfie is stored privately and is not shared with any third party for facial recognition or identity processing. It is held in our access-controlled storage (Supabase, hosted on AWS in Mumbai) and is readable only by you and our review process.
  • How long we keep it — we delete your selfie as soon as the review is complete, usually within 24 hours. We keep only the resulting verification status. If a selfie has not yet been reviewed, it is deleted when you delete your account.

Verification is optional. You can use Sola without it, and we never require a passport or government ID.

Travel preferences

During onboarding, we ask about your travel preferences (interests, travel style, experience level). This helps us show you relevant destinations, content, and recommendations within the app.

Community content

Anything you post in community discussions, direct messages to other users, or travel group conversations is stored so the features work. Other users can see your public posts. Direct messages are only visible to the participants in that conversation.

Trip plans and itineraries

If you use the trip planning features, we store your itineraries, saved places, and trip notes. This data is private to you unless you choose to share a trip with another user.

Location data

We want to be clear about this: we do not track your location in the background. We do not use GPS tracking. We do not follow where you go.

The only time location is relevant is when you search for a city or country in the app, or view a destination page. That is a deliberate action you take, not passive tracking.

Device and crash data

We use Sentry for error tracking. When the app crashes or encounters an error, Sentry collects basic device information (device model, operating system version, app version) and the error details. This helps us fix bugs. Sentry does not collect your name, email, or personal content.

Usage analytics

We use PostHog to understand how people use the app. Which screens are popular, where people get stuck, how features are used. This data is anonymized. We use it to make the app better, not to build advertising profiles.

What we do NOT do

  • We do not sell your data. Not to advertisers, not to data brokers, not to anyone. Ever.
  • We do not use your data for advertising. We do not show ads in Sola.
  • We do not run facial recognition. Verification selfies are reviewed by a person, never by face-matching software, and we store no biometric data.
  • We do not track your physical location. No background GPS, no location history, no geofencing.
  • We do not share your personal information with third parties for their own purposes.

Third-party services

We use a small number of third-party services to run the app. Here is exactly what each one receives:

Each of these services has their own privacy policy and acts as a data processor under our instructions. They do not use your data for their own purposes.

How we use your data

We use the data we collect to:

  • Provide the service — show you destinations, let you plan trips, connect with other travelers, participate in the community.
  • Improve the app — understand which features work well and which need fixing.
  • Send you notifications — trip reminders, messages from other users, and important account updates. You can turn off push notifications in your device settings at any time.
  • Provide support — if you contact us with a problem, we may look at your account data to help resolve it.

We do not use your data for automated decision-making or profiling.

Data retention

  • While your account is active: We keep your data for as long as you have an account.
  • Verification selfies: Deleted as soon as our team completes the review, usually within 24 hours. We keep only your verification status. A selfie that has not yet been reviewed is deleted when you delete your account.
  • After account deletion: When you delete your account, we delete all your personal data within 30 days. This includes your profile, posts, messages, trip plans, and any uploaded photos.
  • Anonymized analytics: Aggregated, anonymized analytics data may be retained after account deletion because it cannot be linked back to you.

Deleting your account

You can delete your account from within the app (Profile > Settings > Delete Account). This triggers a complete deletion of your data from our systems, including any verification selfie. The deletion process is automated and handled by a server-side function.

If you have trouble deleting your account through the app, email us at team@solatravel.app and we will do it for you.

Your rights

Depending on where you are located, you have rights under applicable data protection laws, including POPIA (South Africa), GDPR (EU/EEA), CCPA (California), and LGPD (Brazil). These include:

  • Access — You can ask us for a copy of all the data we hold about you.
  • Rectification — If any of your data is wrong, you can ask us to correct it (or update it yourself in the app).
  • Erasure — You can ask us to delete all your data. The easiest way is to delete your account in the app.
  • Data portability — You can ask us for your data in a machine-readable format so you can take it elsewhere.
  • Restriction — You can ask us to temporarily stop processing your data while we resolve a concern.
  • Objection — You can object to how we process your data in certain circumstances.
  • Withdraw consent — Where we rely on your consent, you can withdraw it at any time.

To exercise any of these rights, email team@solatravel.app. We will respond within 30 days.

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Regulator of South Africa, your local EU supervisory authority, or the relevant data protection authority in your jurisdiction.

Legal basis for processing

Under POPIA, GDPR, and other applicable laws, we process your data on the following bases:

  • Contract — Most of our data processing is necessary to provide you with the service you signed up for (your account, trip planning, community features).
  • Legitimate interest — We use anonymized analytics to improve the app. We believe this is a reasonable use that does not override your privacy rights.
  • Consent — Push notifications are opt-in. You can withdraw consent by disabling notifications in your device settings.

Data security

We take reasonable measures to protect your data:

  • All data in transit is encrypted using TLS.
  • Our database uses row-level security policies, meaning users can only access data they are authorized to see.
  • Authentication tokens are stored securely on your device using encrypted storage.
  • We do not store passwords in plain text. Authentication is handled by Supabase Auth, which uses industry-standard hashing.

No system is perfectly secure. If we ever discover a data breach that affects your personal information, we will notify you and the relevant authorities as required by law.

Children

Sola is not intended for anyone under 18 years old. We do not knowingly collect data from anyone under 18. If we discover that we have collected data from someone under 18, we will delete it promptly.

Cookies

The Sola mobile app does not use cookies. If you visit our website (solatravel.app), we may use essential cookies for basic functionality. We do not use advertising or tracking cookies on our website.

Changes to this policy

If we make significant changes to this policy, we will notify you through the app or by email before the changes take effect. Minor wording updates that do not affect your rights will be made without notification.

You can always find the current version of this policy at solatravel.app/privacy.

Contact

Bokang Sibolla Digital Pty Ltd

Trading as Sola

34 Shortmarket Street, Cape Town City Centre, 8001, South Africa

Email: team@solatravel.app

Website: solatravel.app