Privacy policy
Draft. It has not been legally reviewed yet.
Who we are
IronMark is operated by ATS All Technology Solutions (Pty) Ltd, the responsible party under the Protection of Personal Information Act (POPIA). Information Officer: Donovan Hoare, donovan@atstech.co.za. ATS is the controller of your information wherever you use IronMark.
IronMark is for adults. You must be 18 or older to use it.
What we collect
- Your phone number, confirmed by SMS when you sign in.
- Your contacts' names and phone numbers, if you allow it in the app. We use them to work out which name belongs to a number. We never show anyone who saved a name, or what you saved.
- Spam reports and name suggestions you make.
- Numbers you look up, only as counts for rate limiting.
We do not read your call history, messages, location or anything else on your phone.
If you let IronMark read your contacts, it also uses them on your phone, without sending them to us, to search from the keypad and to recognise callers you have saved. If you make IronMark your phone app, it handles your calls while they happen, and it still does not read your phone's call history.
What we use it for
To show a caller's name and a spam warning when someone who doesn't have the number saved gets a call, and to protect the service against abuse. We do not sell personal information, and we do not use it for advertising.
If your number is in our database
Your number may be listed because another IronMark user saved it. You can unlist your number at any time. Unlisting deletes everything we hold about it and stops anything new being stored.
Your rights
You can remove the contacts you uploaded, and keep your account, in the app under Me → Remove my uploaded contacts. You can delete your IronMark account in the app under Me, or at /delete-account. That removes your account and everything you contributed. You can ask us what we hold about you, ask us to correct it, or object to how we process it, by contacting the Information Officer. You may also complain to the Information Regulator (South Africa).
Why we are allowed to use it
- Your phone number and account: to provide the service you signed up for.
- Your contacts: only with your consent, which you give in the app and can withdraw at any time by turning sharing off and removing what you uploaded.
- Names and spam reports about numbers of people who do not use IronMark: our and our users' legitimate interest in knowing who is calling and avoiding fraud and nuisance calls. Anyone can object by unlisting their number.
- Rate limits and abuse checks: our legitimate interest in keeping the service secure.
Who we share it with
IronMark users see the name and spam status worked out for a number that calls them or that they look up. They never see who saved or suggested a name. Google Firebase and our SMS provider receive your phone number to send your sign-in code. On the unlist and account-deletion pages, a South African number gets its code from our SMS provider and the page loads nothing from Google. For any other number, Google Firebase sends the code, and the page loads Google's Firebase and reCAPTCHA, which receive your number and information about your browser. Our hosting is run by ATS itself. We do not sell personal information, share it for advertising, or give it to data brokers.
How long we keep it
Until you remove it, delete your account or unlist the number. Deletion from the live service is immediate. Copies in our backups are removed as those backups expire.
Where it is kept
On IronMesh servers operated by ATS in South Africa. If you use IronMark from another country, your information is transferred to and processed in South Africa, whose data protection law (POPIA) may differ from the law where you live.
If you are outside South Africa
Wherever you live, you can use everything under "Your rights" above, and you can contact the Information Officer to ask for a copy of your information, to have it corrected or deleted, to restrict or object to how we use it, or to withdraw consent. We answer within 30 days and never charge for it or treat you differently for asking. We make no decisions about you by automated means that have a legal effect on you.
- United Kingdom, Ireland, Malta and the rest of the EEA: you have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR and UK GDPR. You may complain to your data protection authority: the ICO (UK), the Data Protection Commission (Ireland) or the IDPC (Malta).
- United States: we do not sell or share personal information as those terms are used in the California Consumer Privacy Act and similar state laws, and we do not use sensitive personal information for anything except providing the service. You have the right to know, delete and correct, and not to be discriminated against for using these rights.
- Canada: you may complain to the Office of the Privacy Commissioner of Canada.
- Australia and New Zealand: you may complain to the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner.
- Kenya, Nigeria, Ghana, Uganda, Tanzania, Zambia, Zimbabwe, Botswana, Namibia, Mauritius, Seychelles and other African countries: you may complain to your national data protection authority, for example the Office of the Data Protection Commissioner (Kenya) or the Nigeria Data Protection Commission.
- Singapore: you may contact the Personal Data Protection Commission.
- Jamaica, Trinidad & Tobago, the Bahamas and Belize: you may complain to your national information or data protection commissioner where one exists.
Changes
We will post any change to this policy here. Last updated 30 September 2026.