Privacy Policy
Last updated June 2026
Who we are
makers.studio builds done-for-you web platforms for South African makers. This site is our own marketing site — it is separate from any individual maker's storefront we build. We process personal information in line with South Africa's Protection of Personal Information Act (POPIA). Contact: hello@makersstudio.co.za.
What we collect
"Map your flow" form. Craft type, business name, social links, how you sell, integrations wanted, and — at the final step only — your name, email, and phone, so we can scope and quote your build. We also record how you heard about us (e.g. the guide, the readiness check, a referral) to understand what's working.
The guide's "email me a copy" capture. Just your email address. It's entirely optional — the guide itself is fully readable without it.
Contact form. Your name, email, and message.
If you become a customer. We additionally hold your business name, domain, and the records needed to invoice you: subscription tier, billing dates, invoice and payment history. We never store card details ourselves — payments are currently arranged manually (e.g. bank transfer) and, once live, recurring card payments will be handled entirely by PayFast, a PCI-DSS-compliant payment processor; your card number never touches our servers or database.
None of the above is sold or shared with third parties.
Analytics (self-hosted, no third-party trackers)
Like the platforms we build for makers, this site runs its own self-hosted analytics — not Google Analytics or any third-party tool. We record the page viewed, referring site, approximate country and device type, and a one-way hashed visitor identifier (the original value never leaves your browser in readable form). We never store your IP address. This data is automatically deleted after 13 months. We also log when known search or AI crawlers (e.g. Googlebot, GPTBot) visit, so we can tell whether the site is being indexed.
Emails we send
If you request the guide by email or submit "Map your flow," we may send a small number of related emails — confirming your request, or checking in if you started something and didn't finish. Every one of those emails includes an unsubscribe link, or you can email us directly to opt out at any time. We do not send unrelated marketing.
Cookies
We use first-party cookies only — no third-party advertising or tracking cookies:
- mssess — session cookie (cleared when you close your browser); keeps the "Map your flow" form secure and your flash messages working.
- ms_lead — up to 30 days; lets "Map your flow" auto-save and resume where you left off.
- ms_src — up to 30 days; remembers how you first arrived (e.g. which link or search), so we can tell what's working.
- ms_vid — up to 12 months; a random identifier for our own analytics (see above) — only its one-way hash is ever stored on our servers.
- ms_demo — a couple of hours; isolates your "try the admin" sandbox from other visitors'.
"Try the admin" sandbox
If you try the admin demo, we store a random, unguessable token in a cookie purely to keep your sandbox separate from other visitors'. No personal information is collected by the sandbox itself, and its contents are automatically deleted after a short expiry.
How long we keep information
Leads and customer records are kept for as long as needed to respond to your enquiry or deliver and support your platform, plus a reasonable period after. Invoices and payment records are kept for at least 5 years in line with South African tax record-keeping requirements. Analytics and crawler-visit data is deleted automatically after 13 months.
Your rights
Under POPIA, you can ask us what information we hold about you, request a copy, ask us to correct or delete it, or withdraw consent to further contact — email hello@makersstudio.co.za and we'll act on it. If you're unsatisfied with our response, you may lodge a complaint with South Africa's Information Regulator (inforegulator.org.za).
Security
Admin access is password-protected (passwords are hashed, never stored in plain text), forms are protected against cross-site request forgery, and — as above — no card details are ever stored on our servers.
Changes to this policy
If this policy changes, we'll update the date at the top of this page.