Privacy
Last updated 26 July 2026
This notice explains what 3L Group Consulting (PTY) LTD collects when you use mearef, and why.
What we collect
- Request logs. For every API call we record the time, host, path, HTTP status, response time and user agent. Source IP addresses are masked before storage — the final octet is removed, so an individual address is not retained. Logs exist to operate the service, detect abuse and diagnose faults.
- API key records. If you buy prepaid credit we store a hashed key, a label, your remaining balance and a call count. Keys are stored as a SHA-256 hash, never in clear text.
- Purchase details. Card payments are handled by our payment provider as merchant of record. We never see or store your card details. We receive the purchase email address and order reference so we can issue your key and handle support.
- On-chain payments. Payments made over the x402 protocol settle publicly on the Base blockchain. Blockchain records are public and outside our control.
What we do not do
We do not sell or rent your data, we do not run advertising or third-party analytics trackers on the API, and we do not build profiles of API callers.
Retention
Operational logs are retained only as long as useful for diagnostics and abuse detection. API key records are retained while the key is active and for as long as needed for accounting and tax obligations.
Your rights
You may request access to, correction of, or deletion of the personal data we hold about you, and you may ask us to stop processing it. Email api@3l-groupconsulting.co.za and we will respond within two business days. Deleting your account data will deactivate any API key associated with it.