Scam Check
Home

Privacy Policy

Last updated 4 October 2026

Scam Check (“we”, “us”) is a free, non-commercial consumer-protection service that helps people in South Africa recognise phishing and scams. This policy explains, in plain language, what information we handle and how we protect it. We are committed to the principles of the Protection of Personal Information Act, 2013 (POPIA).

The short version

  • We do not sell your data, ever.
  • We do not store your phone number. On WhatsApp we keep only a one-way, salted hash that cannot be reversed back to your number.
  • We do not ask for passwords, PINs, OTPs or banking details — and you should never send them to anyone.
  • We never open suspicious links on your behalf; they are inspected in a secure sandbox.

What we collect

When you check a link on the website: the link or domain you submit, so we can look it up. We don’t require an account and we don’t ask for your name or contact details.

When you use the WhatsApp assistant: the message you forward (so we can analyse the scam), and a salted hash of your WhatsApp number — a scrambled value we use only to prevent abuse (rate-limiting) and duplicate processing. We cannot turn the hash back into your number, and we do not store the number itself.

Basic technical data: standard request information (such as approximate region and timestamps) that our infrastructure logs to keep the service secure and reliable.

How we use it

  • To tell you whether a link or message looks like a known scam.
  • To build and improve our picture of scams targeting South Africans, so we can warn others.
  • To detect and prevent abuse of the service.

Forwarded scam content may be stored and shown publicly as a scam example (for instance a screenshot of a fake page), but always with any personal details removed and links defanged so they cannot be clicked.

Where our information comes from

We combine reports from the public with established threat-intelligence sources, including urlscan.io, OpenPhish, PhishTank, phishunt and community reports shared by security researchers. Suspicious pages are scanned using urlscan.io, which captures them safely without us visiting the page directly.

What we never do with stolen data

Where we detect a place that a scam is leaking victims’ information, we report its location to the affected brand or a CERT so they can act. We do not download, store or process those stolen credentials ourselves.

Sharing

We may share scam indicators (such as malicious domains) with banks, telecommunications providers and recognised anti-fraud bodies to help protect the public. We use trusted infrastructure providers (including Cloudflare) to run the service. We do not sell or rent personal information to anyone.

How long we keep it

We keep scam intelligence for as long as it is useful for protecting people. Salted hashes and short-term technical logs are kept only as long as needed for abuse prevention and security, then removed.

Your rights under POPIA

You have the right to ask what personal information we hold about you, to have it corrected or deleted, and to object to its processing. Because we deliberately avoid storing identifying information, we may be unable to link a request to a specific person — but we will always help where we can. To make a request, email hello@scamcheck.co.za.

You may also lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.

Children

The service is intended for general public use and is not directed at children under 18.

Changes

We may update this policy as the service evolves. We’ll change the “last updated” date above when we do.

This page is provided for transparency and is written in plain language. It is not legal advice. If you have questions, contact us at hello@scamcheck.co.za.