Ideal Client AllianceIdeal Client AllianceICA Pro Hub: Learn it. Build it. Apply it.
HomeWhat's IncludedMember StoriesFAQ
Member Login

Ideal Client Alliance

Privacy Policy

Effective Date: 27 August 2026 · Last Updated: 27 August 2026

1. Who we are

This Privacy Policy applies to the ICA Pro membership, Affiliate Program, websites, member areas, affiliate tools and related online services operated by LR Mobi, registration number 2026/174534/07, trading as Ideal Client Alliance (“ICA”, “we”, “us” or “our”).

LR Mobi is a South African business operating from Cape Town, South Africa.

For purposes of the Protection of Personal Information Act 4 of 2013 (“POPIA”), LR Mobi is the responsible party in respect of personal information for which it determines the purpose and means of processing.

This Privacy Policy explains what personal information we collect, why we process it, how we use and protect it, when it may be shared, how long it may be retained and the rights available to you.

2. Our approach to privacy

ICA processes personal information only where there is a lawful basis to do so.

Depending on the circumstances, we may process personal information because:

  • it is necessary to provide a membership, account, Affiliate service or other service requested by you;
  • it is necessary to perform or administer an agreement with you;
  • you have given consent;
  • processing is required or authorised by law;
  • processing protects a legitimate interest of ICA, you or another person where permitted by law; or
  • another lawful basis applies.

We do not sell your personal information.

Marketing consent is not a condition of purchasing ICA Pro membership.

3. Information we collect

3.1 Account and profile information

When you purchase ICA Pro, receive access to an account or complete or update your profile, we may collect:

  • first name;
  • surname;
  • email address; and
  • phone number.

We use this information to create and administer your account, provide membership access, communicate with you and personalise relevant ICA and Affiliate functionality.

3.2 Membership and transaction information

When you purchase, receive or maintain an ICA membership, we may process and retain information relating to:

  • membership status;
  • membership plan;
  • subscription status;
  • payment status;
  • payment dates;
  • service periods;
  • transaction amounts;
  • transaction currency;
  • payment or subscription identifiers;
  • payment-processing fees where relevant;
  • refunds;
  • reversals;
  • disputes; and
  • other records reasonably necessary to administer membership and maintain accurate financial records.

Payments are processed through third-party payment providers such as PayPal.

ICA does not directly store complete payment-card numbers, CVV numbers or equivalent full card credentials supplied to a payment processor.

Payment providers may process additional payment information under their own terms and privacy practices.

4. Affiliate information

ICA Pro includes Affiliate functionality.

Where you become an Affiliate, ICA may create and maintain records relating to:

  • Affiliate status;
  • Affiliate identifier;
  • unique referral code;
  • referral links;
  • applicable commission information;
  • attributed transactions;
  • conversions;
  • commission records;
  • pending, approved and paid commission;
  • payout history;
  • payout status;
  • payout references;
  • Affiliate account activity; and
  • payment information reasonably required to process Affiliate payouts.

Affiliate financial, attribution and audit records may be retained after membership or Affiliate participation ends where reasonably necessary for accounting, taxation, fraud prevention, dispute resolution, audit, legal compliance or the establishment or defence of legal rights.

5. Affiliate referral and attribution data

When a visitor follows a valid ICA Affiliate referral link, ICA may create a referral record so that a later qualifying transaction can be attributed correctly.

Information processed for this purpose may include:

  • the applicable Affiliate referral code;
  • a unique click identifier;
  • date and time information;
  • attribution status;
  • relevant transaction information; and
  • privacy-protected technical information used for security, fraud prevention and attribution.

IP-address protection

For ICA Affiliate click and checkout controls, ICA does not store the visitor’s raw IP address in its Affiliate tracking database.

The IP address is processed server-side using a cryptographic HMAC process and the resulting protected value is used for relevant attribution, rate-limiting and fraud-prevention functions.

Internet, hosting, network and infrastructure providers may necessarily process IP addresses and other network information when transmitting, securing or delivering their services.

6. Cookies and similar technologies

ICA uses a limited set of cookies and related technologies needed to operate and secure the service.

Authentication cookies

Authentication cookies help securely maintain a user’s signed-in session.

Affiliate attribution cookie

When a visitor follows a valid Affiliate referral link, ICA may place a signed attribution cookie.

The Affiliate attribution period is currently 30 days.

This enables ICA to determine whether a subsequent qualifying purchase should be attributed to an Affiliate.

Checkout-session cookie

During checkout, ICA may use a short-lived secure cookie containing an opaque checkout-session identifier.

This enables the service to associate a browser with the correct checkout process without placing the customer’s personal information or payment status in the browser URL.

The checkout-session cookie is currently designed to expire after approximately two hours.

Advertising and analytics tracking

ICA Pro does not currently use Google Analytics, Meta Pixel, TikTok Pixel, Microsoft Clarity, Hotjar or similar third-party advertising or behavioural analytics trackers.

If ICA materially changes its use of cookies or introduces additional tracking technologies, applicable disclosures and consent mechanisms will be updated where required by law.

7. Authentication and account security

ICA uses Supabase for account authentication and related database infrastructure.

Passwords are handled through the authentication system and are not stored by ICA in readable plain text.

ICA may process authentication and security information where reasonably necessary to:

  • authenticate users;
  • maintain secure sessions;
  • provide password recovery;
  • provide security features such as multi-factor authentication;
  • prevent unauthorised account access;
  • investigate suspicious activity; and
  • protect ICA, its systems and its users.

Authentication credentials and session information are handled through secure session mechanisms designed to reduce unauthorised client-side access.

8. How we use personal information

ICA may process personal information to:

  • create and administer accounts;
  • activate and manage ICA Pro membership;
  • provide access to member areas;
  • provide and personalise Affiliate functionality;
  • generate and administer Affiliate referral links;
  • attribute qualifying referrals;
  • calculate and administer Affiliate commissions;
  • process and record Affiliate payouts;
  • process and reconcile membership payments;
  • administer recurring subscriptions;
  • maintain financial and accounting records;
  • maintain account and system security;
  • detect and investigate fraud or abuse;
  • detect potential self-referral or attribution manipulation;
  • respond to customer and Affiliate support requests;
  • send necessary service and account communications;
  • provide password recovery and security communications;
  • comply with legal, regulatory, tax and accounting obligations;
  • establish, exercise or defend legal rights;
  • maintain and improve the security and reliability of the service; and
  • send marketing communications where legally permitted.

ICA will not process personal information for a materially incompatible purpose without an appropriate lawful basis.

9. Fraud prevention and review

ICA uses technical and organisational controls to identify potential fraud, security risks, self-referral, unusual click behaviour and other activity that may affect the integrity of the membership or Affiliate Program.

Certain activity may be automatically flagged for review.

An automated flag does not by itself establish that fraud or misconduct occurred.

Where a commission, transaction or account activity requires review, an authorised person may review the relevant information before a final decision is made.

ICA does not rely solely on an automated fraud flag to make the final Affiliate commission review decision.

Fraud and security records may be retained where reasonably necessary to protect ICA, its members, Affiliates, customers and systems.

10. Service and account communications

ICA may send communications reasonably necessary to administer your account or provide services requested by you.

These may include:

  • account creation and welcome messages;
  • password reset messages;
  • authentication or security communications;
  • membership information;
  • billing or payment information;
  • material service changes;
  • Affiliate account information;
  • commission or payout information;
  • legal or policy notices; and
  • support correspondence.

These communications are separate from promotional marketing.

11. Marketing communications

Where permitted by applicable law, ICA may send information about ICA products, services, tools, updates, offers, promotions or related opportunities.

Where consent is required, ICA will provide an appropriate marketing opt-in mechanism.

Marketing consent is optional.

You may withdraw consent or object to direct marketing where permitted by applicable law.

Electronic marketing communications will include an appropriate method to unsubscribe or opt out where legally required.

If you opt out of marketing, ICA may continue sending necessary transactional, membership, billing, security, legal and other service communications.

ICA does not sell your contact information to third parties for their own independent marketing.

12. When we share personal information

ICA may disclose or make personal information available to third parties only where reasonably necessary and lawfully permitted.

This may include:

Payment providers

Payment providers such as PayPal may receive and process information necessary to administer membership payments, subscriptions, refunds, disputes and Affiliate payouts.

Supabase

Supabase provides authentication, database and related infrastructure services.

Railway

Railway provides hosting and application infrastructure used to operate ICA Pro.

Professional advisers

ICA may disclose relevant information to authorised lawyers, accountants, auditors, tax advisers, insurers or other professional advisers where reasonably necessary and subject to appropriate confidentiality obligations.

Authorities and legal processes

ICA may disclose information where required or authorised by law, court order, lawful regulatory request, tax requirement or other binding legal process.

Information may also be disclosed where reasonably necessary to establish, exercise or defend legal rights or to protect ICA, its users or another person against fraud, unlawful conduct or security threats.

13. Service providers and operators

ICA uses third-party providers to support its online services.

Current principal technology and payment providers include:

  • PayPal — payment and subscription processing and current Affiliate payout processing;
  • Supabase — authentication, database and related infrastructure; and
  • Railway — application hosting and infrastructure.

ICA may add, replace or change service providers where reasonably necessary to operate or improve the service.

Where another party processes personal information on ICA’s behalf, ICA will take reasonable steps to ensure that appropriate privacy, confidentiality and security protections apply as required by applicable law.

Where a change materially affects how personal information is processed, ICA will update its disclosures where required.

14. International and cross-border processing

ICA uses technology and payment providers that may process or store information outside South Africa.

ICA will transfer personal information outside the Republic of South Africa only where permitted by applicable law.

Where POPIA applies, a cross-border transfer will be made only where an applicable basis under section 72 exists.

This may include circumstances where:

  • the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection;
  • the data subject has lawfully consented to the transfer;
  • the transfer is necessary for performance of a contract with the data subject or for appropriate pre-contractual measures;
  • the transfer is necessary for a contract concluded in the interests of the data subject; or
  • another basis expressly permitted by applicable law applies.

ICA will take reasonable steps to ensure appropriate protection for personal information processed internationally.

International users may also have additional mandatory privacy rights under laws applicable to them.

Nothing in this Privacy Policy is intended to remove a mandatory privacy right that cannot lawfully be excluded.

15. How we protect personal information

ICA uses reasonable technical and organisational safeguards intended to protect personal information against loss, damage, unauthorised access, interference, misuse, alteration, disclosure or destruction.

Measures used within the ICA Pro system may include:

  • role-based access controls;
  • database row-level security;
  • restricted administrative functions;
  • server-side financial and security controls;
  • secure authentication;
  • protected session cookies;
  • restricted Affiliate access to their own records;
  • controlled Owner and Admin permissions;
  • audit records for sensitive actions;
  • controlled commission and payout workflows;
  • server-side verification of payment events; and
  • cryptographic protection of IP-derived information used for Affiliate and fraud controls.

Access to personal information is limited according to role and legitimate operational need.

No internet-connected system can be guaranteed to be completely secure.

16. Security compromises

If ICA has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, ICA will investigate the incident and take appropriate steps to contain and address it.

Where notification is required under applicable law, ICA will notify the South African Information Regulator and affected data subjects in accordance with the applicable requirements.

Where appropriate or required, affected persons may be given information concerning the nature of the compromise and reasonable steps they may take to protect themselves.

17. Data retention

ICA retains personal information only for as long as reasonably necessary for the purpose for which it was collected or for another lawful purpose.

Retention periods may vary according to the nature and purpose of the information.

ICA may retain:

  • active account information while an account remains in use;
  • membership and transaction records for accounting, taxation and legal compliance;
  • Affiliate commission and payout records for financial and audit purposes;
  • transaction and attribution evidence for legitimate commission disputes;
  • fraud and security records where necessary to prevent or investigate abuse;
  • consent and opt-out records where necessary to demonstrate marketing compliance;
  • support correspondence where reasonably required; and
  • records necessary to establish, exercise or defend legal rights.

Expiry of a 30-day Affiliate attribution cookie does not require legitimate financial, transaction, attribution, security or audit records associated with a completed transaction to be deleted at the same time.

When ICA is no longer authorised or required to retain personal information, it will take appropriate steps to delete, destroy or de-identify the information in accordance with applicable law.

18. Account deletion

You may request deletion of your ICA account through the account facilities made available by ICA or by contacting us.

ICA may require reasonable verification or confirmation before processing an account deletion request to help prevent accidental, fraudulent or unauthorised deletion.

Deletion of an account does not necessarily require every related record to be erased immediately.

ICA may retain limited information where reasonably necessary or legally permitted for purposes including:

  • completed financial transactions;
  • taxation and accounting;
  • Affiliate commissions and payouts;
  • fraud prevention;
  • dispute resolution;
  • legal and regulatory obligations;
  • enforcement or defence of legal rights; and
  • other lawful recordkeeping requirements.

Information ICA is no longer lawfully entitled or required to retain will be deleted, destroyed or de-identified as appropriate.

19. Your privacy rights

Subject to applicable law and appropriate identity verification, you may have the right to:

  • ask whether ICA holds personal information about you;
  • request access to personal information held about you;
  • request correction of inaccurate, incomplete, misleading or outdated information;
  • request deletion or destruction of personal information that ICA is no longer authorised to retain;
  • object to processing in circumstances permitted by law;
  • object to direct marketing;
  • withdraw consent where processing relies on consent;
  • request appropriate action concerning unlawful processing; and
  • lodge a complaint with the South African Information Regulator.

These rights may be subject to lawful limitations and exceptions.

For example, ICA may be required or permitted to retain certain financial, tax, security, fraud, contractual or audit information after an account deletion request.

Privacy requests may be submitted to:

nathan@idealclientalliance.com

ICA may request reasonable information to verify your identity before disclosing, correcting or deleting personal information.

20. Information Officer

LR Mobi has a registered Information Officer in accordance with applicable South African data-protection requirements.

Privacy enquiries and requests concerning personal information may be directed to:

nathan@idealclientalliance.com

21. Complaints

If you believe ICA has processed your personal information unlawfully, you may contact ICA so that the matter can be investigated.

You also have the right to lodge a complaint with the:

Information Regulator (South Africa)

Official complaint and contact channels are available through the Information Regulator’s official website and electronic services.

22. Children’s privacy

ICA Pro and the Affiliate Program are intended for persons who are 18 years of age or older.

ICA does not knowingly offer ICA Pro membership or Affiliate participation to children.

If ICA becomes aware that a child’s personal information has been collected or processed in circumstances where ICA is not legally authorised to process it, ICA will take appropriate action in accordance with applicable law.

23. Changes to this Privacy Policy

ICA may update this Privacy Policy where reasonably necessary because of changes to:

  • its services;
  • technology;
  • payment or infrastructure providers;
  • processing practices;
  • security requirements;
  • legislation; or
  • regulatory requirements or guidance.

The updated Privacy Policy will display a revised “Last Updated” date.

Where a material change requires additional notice or consent under applicable law, ICA will provide that notice or obtain that consent.

An amendment to this Privacy Policy does not retrospectively create consent where consent is legally required.

24. Company and contact information

LR Mobi
Trading as Ideal Client Alliance
Registration Number: 2026/174534/07
Cape Town, South Africa

Privacy and Information Officer enquiries:
nathan@idealclientalliance.com

ICA’s statutory business, contact and service information applicable to electronic transactions is made available through the Legal or Company Information section of the ICA website.


Effective Date: 27 August 2026 · Last Updated: 27 August 2026

Ideal Client AllianceLearn it. Build it. Apply it.
Privacy PolicyDisclaimerTerms of Use

www.idealclientalliance.com