Legal
Privacy policy
Last updated 26 September 2026. This is a template written for the Protection of Personal Information Act (POPIA); have it reviewed by a South African lawyer before launch.
Who is responsible
[to be added before launch] ("we") runs IsCarTi. Our Information Officer is [to be added before launch]. Contact us at [to be added before launch].
What we collect
- Account: your email address, used to sign you in with a link.
- Vehicle records you add: car nicknames and details, service records, dates, odometer readings, costs, and the documents and photos you upload (invoices, receipts, service book pages). These can contain personal details such as names, addresses and registration numbers.
- Marketplace listings: title, price, city, description, photos and the WhatsApp number you choose to publish.
- Workshops: business name, registration number, city, phone and services; confirmations you make; quotes and invoices you create, including your customers' names and contact details.
- Payments: we record what you bought, the amount, the date and its status. Cards and bank details are entered on PayFast's own page and never reach us; PayFast is responsible for them under its own privacy policy.
- Technical data: basic logs kept by our hosting providers for security.
Why we use it
To run the service: store your records, show them to people you share them with, let workshops confirm them, run the marketplace and directory, and administer plans and support requests. We do not sell your personal information and we do not show advertising.
What is public
- Your documents are private. Only you can open them.
- A car's history is public only through a share link you switch on, and you can hide costs. Switch sharing off and the link stops working.
- Marketplace listings and the contact number on them are public.
- Approved workshops chosen for the directory are public.
- A workshop that confirms a record appears by business name on that record.
Blockchain timestamps
To make records tamper-evident we send a one-way hash (a fingerprint) of each record to public OpenTimestamps servers, which anchor it on the Bitcoin blockchain. The hash contains no readable personal information, but it cannot be removed from the blockchain. If you delete a record or your account, the underlying data is deleted; only the meaningless fingerprint remains.
Who else handles your data
We use Supabase (database, sign-in and file storage), PayFast (payments) and our website host to run the service. Invoice photos are read on your own device when you use "Read details from photo"; the photo is only uploaded when you save. When you use a WhatsApp link, WhatsApp handles that message under its own terms. Some of these providers store data outside South Africa; we rely on their security and contractual protections for cross-border transfers.
How long we keep it
Until you delete it or your account. Marketplace listings you remove stay hidden in our records only as long as needed to handle abuse reports.
Your rights
You can access, correct and delete your information. Download everything we hold about you, or permanently delete your account and all its data, on your account page. For anything else, email [to be added before launch]. You can also complain to the Information Regulator (South Africa) at inforeg.org.za.
Security
Data is encrypted in transit, documents are stored in private storage, and access rules are enforced in the database so users can only reach their own data. No system is perfectly secure; tell us at once if you suspect a problem.
Cookies
We use only the cookies needed to keep you signed in. No advertising or tracking cookies.
Changes
If we change this policy we will update the date above and, for significant changes, tell you in the app.