Privacy policy

Last updated: 30 September 2026.

This policy describes the personal information iShack Innovation Consultancy collects on this website and in the product behind it. The company is registered in South Africa, so the Protection of Personal Information Act (POPIA) applies. We also serve clients in the UK and Europe, so the UK GDPR and the EU GDPR apply to those people.

Privacy requests go to richardb@ishack.co.za. The registered office is 1st floor, 49 Middle Road, Morningside, Johannesburg, South Africa. The responsible party is iShack Innovation Consultancy CC, registration 2005/030329/23.

Who is responsible

The responsible party is iShack Innovation Consultancy CC, registration 2005/030329/23, VAT 4420222087, at 1st floor, 49 Middle Road, Morningside, Johannesburg, South Africa.

What we collect, and why

Account registration

If you create an account we store the organisation name, a contact person, a physical address you type in, your email address, a password hash (not the password itself), an optional brand colour and logo URL, and the plan you selected. We use this to create the account, to take payment, and to run the product. The lawful basis is contract.

Free site audit

The audit form sends a website URL and, if you provide them, a region, a keyword, a competitor URL and an email address. The server may fetch that URL to read the public page, and may ask a third-party SEO data provider for public ranking and traffic estimates. If an email address is included, we store it with the domain, the keyword and the audit score so we can follow up. The basis is legitimate interests in responding to a request you made, or contract if you then buy a plan.

Free SEO and AI visibility check

The check form stores your name, email address, company, country and website domain, and a record that you agreed to be emailed. When the live lookup is switched on, we may also store the search summary we showed you. We use it to send the report and to reply. The basis is consent, and steps toward a contract if you then ask for a proposal.

AI visibility review

The review form stores your name, email address, an optional website, an optional company name, and your message. We use it only to reply and to decide whether a managed engagement makes sense. The basis is legitimate interests, or steps toward a contract.

Agency partnership form

The white-label form sends your name, email, company, size, goal and message by email to the people who handle partnerships. Use it only if you want that conversation.

Onboarding content plan

The onboarding flow stores the website you enter, notes about the business, keywords and article titles you approve, and your email address. It is a lead record for that flow, not a published testimonial.

Embedded audit widget

If an agency embeds our widget, the widget can send a client domain and email address to our server, tied to that agency’s account. The agency is responsible for telling its own clients about that collection.

Payments

Card payments are taken by Paystack. We do not store the card number. We store a payment status on the account and, in Paystack’s metadata, the account id, the domain and the plan. Paystack’s own policy applies to the card data.

Analytics

Google Analytics 4 (G-P9GQSTNHHS) loads only after you choose “Allow analytics” on the cookie banner. Until then the analytics script is not added to the page. If you agree, Google may set cookies and receive your IP address, the pages you open, and a client identifier. We use it to see which pages are used. You can refuse on the banner, or block it in your browser. We do not use it to build a profile for sale.

What we store in your browser

After login, the product stores an authentication token and some account display details in local storage so the app can stay signed in. That is not a marketing cookie. The cookie banner stores your analytics choice (allowed or refused) in local storage under the key ishack_analytics. That choice is not sent to us as a form.

What we do not do

We do not sell personal information. We do not run a mailing list from this site. We do not ask for information about children, and this site is not aimed at anyone under 18.

Who we share it with

Hosting and the database are provided by our infrastructure suppliers (the public site is deployed with Vercel; the application and database run on Railway). Email is sent through the mail service configured for the product. Payments go through Paystack. Analytics go through Google. SEO lookups may go through a data provider such as Semrush when an audit runs. Each of those parties processes the information to provide that service.

Some of those suppliers store data outside South Africa and outside the United Kingdom. Where POPIA requires it, we rely on the supplier’s contractual safeguards for a cross-border transfer. Where the UK GDPR or EU GDPR requires it, we rely on the supplier’s standard contractual clauses or an adequacy decision, as applicable to that supplier.

How long we keep it

Account data is kept while the account is open and for as long as we need it for tax, disputes or security after it closes. Review and audit leads are kept while the enquiry is open and then for a limited period so we can see what was already discussed. We do not keep them as a permanent marketing database.

Your rights

Depending on where you live, you can ask us to:

  • confirm whether we hold information about you, and for a copy of it;
  • correct it;
  • delete it, or restrict how it is used, where the law allows;
  • object to processing based on legitimate interests;
  • ask for portability of information you gave us, where the processing is automated and based on contract or consent;
  • complain to a regulator.

In South Africa you may complain to the Information Regulator. In the United Kingdom you may complain to the ICO. In the EU you may complain to your local supervisory authority. We ask that you write to us first so we can fix the issue.

Security

Passwords are stored as hashes. Access to the product is limited to signed-in accounts. No method of transmission or storage is perfect; we will tell you if a breach creates a risk that the law says you must hear about.

Changes

If we change what we collect, we will update this page and the date at the top.