Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains how Howzit handles personal data. It is written to be useful to both the Shopify merchants who use Howzit and the customers of those merchants whose data flows through Howzit. Please read it alongside the privacy policy of the store you shop with, which remains the primary point of contact for your data.
Who Howzit is and its role
Howzit is a South-Africa-focused SMS marketing application for Shopify. It is operated by Mika Dekker, trading as AskMario (website askmario.co.za, contact mika@askmario.co.za).
Howzit acts as a data processor (an operator, under POPIA). The Shopify merchant who installs Howzit is the data controller (the responsible party) for their own customers' personal data. Howzit processes that data only on the merchant's behalf and under the merchant's instructions, to provide the features described below.
The personal data Howzit processes
Howzit processes the following categories of personal data:
- Customer first and last name.
- Mobile phone number, in E.164 format.
- SMS marketing consent state, and consent records (source and timestamp).
- Optional email address.
- Limited order data (order total and checkout token), used for abandoned-checkout recovery and revenue attribution.
- Inbound SMS replies sent by the customer.
Howzit does not process payment details or postal addresses.
How and why Howzit uses data (purposes)
Howzit uses personal data for the following purposes only:
- Sending SMS marketing, including campaigns and automations (abandoned-checkout recovery, welcome, post-purchase, and winback messages).
- Providing a two-way conversational inbox for customer service.
- Capturing and managing marketing consent.
- Revenue attribution and reporting for the merchant.
Legal basis and consent (POPIA and GDPR)
Howzit only sends SMS marketing to contacts who are subscribed. Consent is the legal basis for marketing messages under both POPIA (South Africa) and the GDPR (EU/EEA). An optional double opt-in flow (reply YES to confirm) can be used to strengthen the record of consent, and Howzit records the source and timestamp of consent as proof.
Howzit does not carry out automated decision-making that produces legal or similarly significant effects. Processing of order data to support the merchant's marketing and reporting is carried out on the merchant's instruction as the controller.
Who Howzit shares data with (subprocessors)
Howzit relies on a small number of subprocessors to deliver the service. Each processes data only to perform its function:
- Shopify — the underlying platform and source of the data.
- SMSPortal — SMS gateway, based in South Africa.
- Neon — managed PostgreSQL database, hosted on AWS in eu-central-1 (Frankfurt), encrypted at rest including backups.
- Fly.io — application hosting, in Frankfurt (region 'fra').
Data residency is EU (Frankfurt) and South Africa, aligned to POPIA and GDPR.
International data transfers
Howzit's infrastructure spans the EU (Frankfurt, via Neon and Fly.io) and South Africa (via the SMSPortal gateway). Personal data may therefore be transferred between South Africa and the EU as part of normal operation. These regions are chosen to keep data residency aligned with both POPIA and GDPR requirements.
How long data is kept (retention)
Howzit runs an automated nightly purge that enforces the following retention periods:
- Unconfirmed contacts are deleted after 30 days.
- Opted-out contacts have their personal information scrubbed 30 days after opt-out; the legal consent record is retained as proof of the opt-out.
- Delivery and engagement events are kept for 365 days.
- Webhook receipts are kept for 7 days.
- Data-request exports are kept for 90 days.
- Completed message jobs are kept for 180 days.
- Inbound SMS replies are kept for 180 days.
- Campaign recipient records are kept for 180 days.
- Pending checkout records are kept for 30 days.
- Attributed-order records have the phone number and contact link stripped after 180 days, and the record itself is deleted after 2 years.
- Suppression entries (STOP and Do-Not-Contact) are kept for as long as the store uses Howzit. They hold a one-way hash of the number rather than the number itself, and are deliberately not removed on an erasure request — removing one would start the messages again.
- Uninstalled shops are purged after 35 days.
How data is secured
Howzit applies the following security measures:
- TLS encryption in transit everywhere (sslmode=require to the database, HTTPS/force_https to the app, and HTTPS to SMSPortal).
- AES-256 encryption at rest via Neon, including backups.
- Secrets stored in Fly secrets, never in code.
- Phone numbers are stored only as SHA-256 hashes in the suppression list.
- Outbound message text is URL-stripped so that only Howzit's own tracked link is sent (anti-phishing).
- Admin access is via authenticated Shopify session tokens.
- Cron endpoints use a timing-safe shared secret and fail closed.
- Individual accounts with 2FA on Shopify, Neon, and Fly, and no shared logins.
- Test and production data are separate: production uses a dedicated Neon project, while development uses synthetic data and SMSPortal test mode.
- Access to customer data flows through Shopify's Admin API (logged by Shopify), plus Fly and Neon platform logs.
In the event of a suspected security breach, Howzit will rotate or revoke affected credentials (Fly secrets, Neon role, Shopify API secret), assess the scope from logs, and notify affected merchants and the South African Information Regulator within the applicable window.
Your data subject rights
Depending on your location, you have rights to access, correct, and delete your personal data, and to opt out of marketing. Howzit honours these rights through Shopify's mandatory privacy webhooks:
- Data request (customers/data_request) — Howzit compiles an export of the data it holds.
- Customer redact (customers/redact) — Howzit deletes a customer's data.
- Shop redact (shop/redact) — Howzit deletes all of a shop's data.
Because Howzit is a processor, the fastest route to exercise these rights is usually through the store you shop with, which will trigger the relevant request. You can also contact Howzit directly at mika@askmario.co.za. Howzit's automated retention purge additionally enforces data minimisation over time.
Opting out of SMS
Every marketing message includes a free opt-out. Reply STOP to any message to unsubscribe. Doing so suppresses future messages and writes the opt-out back to Shopify. Our network provider applies WASPA Do-Not-Contact screening to outbound traffic, and merchants can additionally suppress specific numbers inside Howzit.
Howzit never sells your data
Howzit never sells personal data, and does no automated decision-making with legal or similarly significant effects.
Compliance
Howzit is built to align with POPIA (South Africa), the GDPR (EU/EEA), and CPA and WASPA rules for SMS marketing. The governing law of this policy is that of South Africa.
Changes to this policy
Howzit may update this Privacy Policy from time to time. When it does, the "Last updated" date at the top of this page will change. Material changes will be communicated to merchants where appropriate.
Contact
Questions? Contact mika@askmario.co.za.