Privacy Policy
Last updated: 21 September 2026
Who we are
HAMI / ICRA is the Independent Consumer Rights Association complaint service. ICRA receives consumer complaints through supported intake channels, including Instagram, and uses that information to operate a controlled complaint-handling service.
What information we collect
Depending on the channel and what you provide, ICRA may collect the following kinds of information:
- Sender or account identifiers
- Usernames when Meta provides them
- Message text
- Attachments
- Message and event identifiers
- Timestamps
- Contact details you volunteer, such as an email address or phone number
- Complaint and case information
- Authorised staff notes made while handling a case
How we use information
ICRA uses this information only as needed to:
- Take in and record a complaint
- Help prevent duplicate cases
- Assess the complaint
- Contact the complainant
- Carry out controlled mediation
- Contact a seller only through the approved workflow
- Protect the service, keep an audit trail, and operate ICRA
Closed Instagram acceptance
During closed Instagram acceptance, only messages from explicitly approved tester sender identifiers are processed. Rejected senders are not intentionally written to the case database.
Controlled website pilot
ICRA is currently operating a small, invitation-only website pilot. Complaints are accepted only from people who have been personally invited, and only through the website complaint form. The service is operated from Australia during this pilot. Complaints are reviewed by a person, not decided automatically, and are not published. Taking part is voluntary, and you may ask ICRA to stop handling your complaint and delete your information at any time.
Who may handle information
Relevant information may be handled by authorised ICRA staff and by necessary service providers, such as Meta (for Instagram messages) and infrastructure and storage providers that host the service.
What we do not do
ICRA does not sell complaint information and does not use it for advertising targeting.
Security
ICRA uses practical safeguards such as encrypted transport, staff sign-in with two-factor authentication, role-based access, private storage for evidence, verification of Instagram webhook requests, and audit logging. These measures reduce risk, but no online service can guarantee perfect security.
How long we keep information
ICRA keeps information only as long as reasonably necessary for the purposes described on this page. For the current pilot, ICRA's working retention targets are: abandoned draft complaints for 90 days; complaints that were not accepted for 182 days after closure; completed pilot complaints for 730 days after closure; evidence, messages, and any automated outputs for the same period as the complaint they belong to; security, audit, and consent records for 730 days; and backups on a rolling 30 to 90 day cycle. During the pilot, deletion at the end of these periods is carried out by ICRA staff as a reviewed manual step rather than automatically. Limited information may be kept longer when reasonably necessary for security, fraud prevention, audit integrity, dispute handling, or legal obligations.
Access, correction, and deletion
You may ask ICRA to access, correct, or delete personal information it holds about you. Email the privacy contact below and include enough detail for ICRA to verify who you are and identify the relevant case or account. Do not send passwords, tokens, or unnecessary sensitive documents. ICRA will verify identity, assess the request, and then provide access, make a correction, or delete or de-identify eligible information as appropriate. The data deletion page explains how deletion requests are handled.
Contact
Privacy questions and requests should be sent to the address below.
Where information is processed
The current controlled service is operated from Australia. Service providers may process data in other locations.