Privacy Policy
How we collect, use, and protect personal information across spike-r.com and apps we publish.
Effective 28 April 2026
1. About this policy
This policy explains how Spike Reality Development (“Spike,” “we,” “us”) handles personal information when you visit spike-r.com or use any mobile or desktop application that we publish under our own developer accounts on Google Play, the Apple App Store, or other distribution platforms.
Apps we build for clients that are published under the client's own developer account are governed by that client's privacy policy, not this one. If you are unsure which policy applies to a specific app, the app's store listing will identify the publisher.
2. Who we are
Spike Reality Development is a software consultancy based in South Africa. You can reach us at [email protected]. For privacy-specific questions, please use the same address and put “Privacy” in the subject line.
Information Officer. The Information Officer for Spike Reality Development is the head of the organisation, contactable at [email protected] with the subject line “Information Officer”. Requests under sections 23, 24, and 25 of the Protection of Personal Information Act (POPIA) — access, correction, and deletion — and requests under the Promotion of Access to Information Act (PAIA) may be directed to the same address. A PAIA Manual is available on request.
3. Information we collect
On the website
- Contact form: name, email address, and the message you submit.
- AI assistant chat: the conversation text you send and the IP address used to apply rate limits. Any contact details you choose to share inside the chat are forwarded to our team so we can follow up.
- Server logs: standard technical logs including IP address, user agent, timestamp, and the URL requested. Used to operate and secure the site.
In apps we publish
- Account information (where the app offers accounts): email address, display name, and a hashed password or third-party sign-in identifier.
- Device and technical data: operating system version, device model, language and country, app version, and an anonymised installation identifier.
- Crash and diagnostic logs used to find and fix bugs.
- Aggregated usage analytics to understand which features are used and how the app performs.
- Permission-gated data (camera, microphone, location, photos, contacts, files, calendar, health, etc.) only after you grant the relevant operating system permission and only for the feature that requires it.
- Advertising identifiers only where the app explicitly displays ads, and on iOS only after you grant permission through App Tracking Transparency.
4. How we use information
We use the information described above to respond to your enquiries, deliver and improve our website and apps, prevent abuse, comply with legal obligations, send transactional messages such as account or support emails, and analyse usage to fix bugs and prioritise improvements.
5. Legal basis
We process personal information on the following bases: performance of a contract (for example, providing an account-based feature you signed up for), our legitimate interests in operating and securing our services, your consent (for optional permissions, marketing, and tracking where applicable), and to comply with legal obligations.
For users in South Africa, processing is conducted in accordance with the Protection of Personal Information Act (POPIA). For users in the European Union or United Kingdom, the equivalent legal bases under the GDPR and UK GDPR apply.
6. Sharing with third parties
We share personal information only with service providers that help us operate the website and apps, and only for the purposes described in this policy. Current providers include:
- Anthropic — powers the AI assistant on the website. Conversation contents are sent to the Anthropic API so that responses can be generated.
- ZeptoMail (Zoho) — transactional email delivery for contact form submissions and any account emails.
- Hosting and infrastructure providers — operate the servers and content delivery network that run spike-r.com and our backend services.
- Apple and Google — handle app distribution, in-app purchases, and subscription billing for apps we publish on their stores.
- Crash reporting and analytics — for example Firebase or equivalent providers, where used by a specific app.
- Advertising partners — only in apps that explicitly display ads, and only with the consent required by the relevant platform.
We may also disclose information when required to do so by valid legal process or to protect our rights, users, or third parties. We do not sell personal information.
7. Children's privacy
Apps we publish are not directed at children under the age of 13 (or under 16 in jurisdictions where that is the threshold). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us and we will delete it.
8. Data retention
Contact form submissions are retained while a potential or active engagement is relevant, and for a reasonable period afterward to maintain a record of communications. AI assistant conversations are not persisted on our servers beyond the active session. Account data is retained until you delete the account or request deletion. Backups are rolled forward on a normal operational schedule and removed in due course.
9. Security
We use TLS for data in transit, encryption at rest where supported by the storage provider, principle-of-least-privilege access for staff, and reasonable industry-standard controls. No system is perfectly secure, and we cannot guarantee the absolute security of personal information.
10. Security incidents
If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the South African Information Regulator and affected data subjects in writing as soon as reasonably possible after discovery, in accordance with section 22 of POPIA, unless a public body responsible for criminal investigations directs otherwise. The notification will describe what happened, what information was involved, what we are doing to respond, and what steps you can take to protect yourself.
11. International transfers
Personal information may be processed outside South Africa — for example in the United States or European Union — by our service providers. Where we transfer personal information outside South Africa, we do so only on a ground permitted by section 72 of POPIA: typically because (i) you have consented, (ii) the transfer is necessary to perform our contract with you, or (iii) we have entered into binding agreements with the recipient that uphold principles substantially similar to those in POPIA.
12. Your rights
Depending on where you live, you have the right to access, correct, delete, port, restrict, or object to the processing of your personal information, and to withdraw any consent you have given. You also have the right to complain to a supervisory authority — in South Africa, the Information Regulator (inforegulator.org.za); in the EU or UK, your local data protection authority.
To exercise any of these rights, email [email protected].
13. Account and data deletion
You can request deletion of your account and associated personal information at any time. Where the app you use offers an in-app delete-account flow, that flow is the recommended way to delete your account. You can also request deletion by emailing [email protected] with the subject line “Delete my account” and the email address associated with the account.
We aim to action deletion requests within 30 days. Some information may be retained where required by law (for example, financial records for tax compliance) or to resolve disputes and enforce our agreements; that information is kept only for as long as legally necessary.
14. Cookies and similar technologies
The website uses essential cookies only — for example to keep your session state consistent. We do not use analytics cookies, advertising cookies, or tracking pixels on spike-r.com. Apps may use platform-standard local storage that is not “cookies” in the web sense.
15. Push notifications and tracking transparency
Apps that send push notifications request permission through the operating system; you can revoke that permission at any time in your device settings. iOS apps respect Apple's App Tracking Transparency framework: we only request the tracking permission when an app actually performs cross-app or cross-website tracking, and we do not track without your consent.
16. California privacy rights
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to know what personal information we collect, the right to request deletion, the right to correct inaccurate information, and the right not to be discriminated against for exercising your rights. We do not sell or share personal information for cross-context behavioural advertising. To exercise these rights, contact us at [email protected].
17. Changes to this policy
We may update this policy from time to time. Material changes will be flagged on this page and, where appropriate, in-app. The effective date at the top of the page will be updated when we do.
18. Contact
Questions about this policy or our handling of personal information can be sent to [email protected].