Privacy Policy
Last updated: 2026-07-09
1. Information We Collect
When you use DMARC Shield, we may collect:
- Account information — name, email address, and billing details you provide at signup or in settings.
- Domain and email authentication data — domain names you monitor, related DNS authentication records, and DMARC or TLS reports we process on your behalf to provide the service.
- Usage data — how you use the marketing site and customer portal (for example pages visited and features used), collected through privacy-oriented analytics. See our Cookie Policy.
- Support content — messages you send via contact forms or support email.
2. How We Use Your Information
- Provide, maintain, and improve DMARC Shield (monitoring, status reports, alerts, Fix Assist projects, and the customer portal).
- Process payments and manage subscriptions through our payment service provider. We do not store full card numbers on our systems.
- Send transactional email (account notices, security alerts, status reports, and service messages).
- Detect, prevent, and address technical or security issues and abuse.
3. Legal Basis (POPIA, and GDPR / UK DPA where applicable)
We process personal data under:
- Contractual necessity — to deliver the service you subscribed to.
- Legitimate interests — platform security, fraud prevention, and service improvement, balanced against your rights.
- Consent — where you opt in to optional marketing (you may withdraw at any time).
4. Data Sharing
We do not sell your personal data. We share data only with service providers needed to operate the product, under appropriate agreements, including:
- Infrastructure and security — hosting, content delivery, and edge security for the website and application.
- Payment processing — PayFast for card payments and tokenisation in South Africa.
- Email delivery — transactional email for account and service messages.
- Product analytics — privacy-oriented analytics to improve the product (see Cookie Policy).
We may also disclose information if required by law or to protect the rights, safety, or integrity of the service.
5. Data Retention
- Account data — for the life of the account, then for a limited period after cancellation (for reinstatement and legal obligations as required).
- Monitoring and report data — retained according to your plan’s retention window, then deleted or anonymised.
- Usage analytics — retained only as long as needed for product improvement and security analysis.
6. Your Rights
Depending on applicable law (including POPIA and, where relevant, GDPR), you may have rights to access, rectify, erase, restrict, object, port data, or withdraw consent. Contact privacy@dmarcshield.app. We aim to respond within 30 days.
7. Data Security
We implement technical and organisational measures appropriate to the risk, including encryption in transit, access controls and separation of customer data, secure session handling for the portal, rate limiting, and edge security controls. No method of transmission or storage is perfectly secure.
8. International Transfers
Infrastructure may process data in more than one region. Where international transfers occur, we rely on appropriate safeguards offered by our service providers (such as Standard Contractual Clauses where applicable).
9. Children’s Privacy
DMARC Shield is a business service and is not directed at children under 16. We do not knowingly collect personal data from children.
10. Changes
We may update this policy from time to time. Material changes will be posted on this page with an updated date and, where appropriate, notified by email or in-product notice.
11. Contact
Email: privacy@dmarcshield.app
Operator: S-Tech Solutions, South Africa
Questions? privacy@dmarcshield.app · Contact form