Privacy Policy — Sandus
Effective date:
1. Identity of the controller and contact details
| Item | Details |
|---|---|
| Legal name | TALAL ABDULLAH MOHAMMED ALJEHANI |
| National address | JGAA7364, P.O. 23761, Jeddah, Kingdom of Saudi Arabia |
| Product | Sandus, an application distributed through the Salla App Store |
| Platform domain | platform.sandus.app |
| Marketing domain | sandus.app |
| Privacy contact email | support@sandus.app |
All enquiries and requests relating to personal data are sent to support@sandus.app.
2. Scope and dual role
This policy applies to the processing of personal data across the Sandus platform and its related services.
Sandus acts in two distinct roles, and different rules apply to each.
2.1 Sandus as controller
For merchant and team-user account data (name, email address, role), and for product usage analytics and error diagnostics data, Sandus determines the purpose and the means of processing. Sandus is therefore the controller for that data and is directly answerable for it to the data subject.
2.2 Sandus as processor
For end-customer data received from the merchant's Salla store orders, the merchant is the controller, and Sandus processes that data on the merchant's behalf, on the merchant's instructions, and only for the purpose of fulfilling the order.
Consequently:
- An end customer should direct requests about their personal data to the merchant they bought from, first.
- Sandus assists the merchant so that the merchant can respond to those requests.
- Sandus does not use end-customer data for its own purposes, and not for marketing.
3. Categories of personal data processed
3.1 Merchant and team-user data
- Name.
- Email address.
- Role within the account (owner or operator).
- Activation status, password-set date, last-seen date.
- Business name and logo.
- Login identity data (email address, password hash, sessions) held by the database and authentication provider.
- A hashed form of the email address used for login rate limiting.
Sandus does not collect a phone number for account users.
3.2 End-customer data received from Salla
- Customer name, phone number, and email address, as captured in the order snapshot.
- Shipping city and shipping address.
- Order notes.
- Free text entered by the customer in product options, such as instructions and measurements.
- Final production instructions, quality-check notes, receiving notes, and issue notes attached to a production unit.
- Data derived from the order that appears in production batch documents and print sheets, and in CSV exports.
Raw payload storage: Sandus stores the raw payloads received from Salla verbatim, with no redaction at the time of writing. These payloads contain the customer's name, email address, phone number, city, and address. Raw copies of store events, subscription events, Salla catalog events, and authorization events are also stored.
End customers do not have Sandus accounts and never log in to Sandus.
3.3 Workshop contact data
- Workshop contact name.
- Phone number.
- Notes attached to the workshop record.
3.4 Technical and usage data
- Error diagnostics and performance tracing data.
- Product usage analytics: a pre-defined allowlist of events describing use of the platform's functions, not linked to an individual user identity.
- The Internet Protocol (IP) address of the device used to access the platform. This address reaches the error monitoring and usage analytics providers as part of the network connection, and is retained by them.
- Browser session replay within the error-monitoring tool, with all text masked and all media blocked.
- The cookies described in section 13.
- Audit logs and operational status-change history.
3.5 Data not collected
Sandus does not collect payment card data, bank account details, national identity numbers, or biometric, health, or religious data.
4. Source of collection
- Merchant and team-user data is collected from the user directly at sign-up and during use, and through the install and authorization flow of the Salla App Store.
- End-customer data is not collected from the data subject. Sandus receives it from the merchant's store on the Salla platform, through Salla's APIs and event notifications (webhooks), after the merchant grants the application access.
- Workshop contact data is entered by the merchant or their team users.
- Technical data is generated automatically through use of the platform.
The categories of data received from that source, and the source itself, are set out in sections 3.2 and 4 of this policy, and this policy is made publicly available for that purpose.
5. Purposes of processing and the legal basis for each
| Purpose | Legal basis |
|---|---|
| Creating and activating the merchant account, managing access and roles | PDPL Article 6(2): performance of an agreement to which the data subject is a party |
| Receiving store orders from Salla, converting them into production orders, and running them through to handover | Article 6(2): performance of the merchant's subscription agreement, and to fulfil the end customer's order |
| Creating prep lists, production batches, print sheets, and export files | Article 6(2) |
| Updating order status back to Salla | Article 6(2) |
| Sending operational email to merchant account users, such as the entry link and prep-list-ready notice | Article 6(2) |
| Managing the subscription, access state, and billing through Salla | Article 6(2) |
| Platform security, fraud and abuse prevention, login rate limiting, and verification of inbound events | Article 6(4): legitimate interest of the controller |
| Error diagnostics, fault monitoring, and stability improvement | Article 6(4): legitimate interest |
| Product usage analytics and service improvement | Article 6(4): legitimate interest |
| Maintaining audit logs and status-change history | Articles 6(2) and 6(4) |
Where legitimate interest is relied on, a documented assessment is required and must precede the processing. It covers the purpose, its legitimacy, its necessity, the potential effect on the data subject, and the mitigation measures, in line with Article 16(3) of the Implementing Regulation.
Sandus does not rely on consent as the legal basis for processing order data. Sandus sends no marketing messages to end customers.
6. Whether provision of data is mandatory or optional
- Mandatory to operate the service: merchant and team-user account data, and order data received from Salla. Without it, the account cannot be created, orders cannot be fulfilled, and the service cannot be provided.
- Mandatory for the integration: the permissions the merchant grants the application on their Salla store. Without them, Sandus receives no orders.
- Optional: workshop contact data, free-text notes, the business logo, and the print-sheet settings that control which fields are shown. The service runs without them, with reduced functionality.
- Technical and analytics data: generated automatically through use. It can be limited through browser controls, as described in section 13.
7. Disclosure and sub-processors
Sandus uses only the service providers listed below. Sandus does not sell personal data and does not use it for advertising.
| Provider | Role | What it receives | Processing location |
|---|---|---|---|
| Salla | Source platform for orders and store data, and the party that handles subscription and billing | Store and order data, and updated order status | Kingdom of Saudi Arabia |
| Supabase | Database, authentication, and storage | All categories of data set out in section 3 | Australia — Sydney |
| Vercel | Application hosting and request processing | Request data during processing, transiently | Application compute pinned to Australia — Sydney. Request routing and static content delivery run through edge locations worldwide |
| Sentry | Error monitoring and performance tracing | Error and performance data only: the error type and its sanitised message, the execution path, and release and environment data. Cookies, request headers, URL parameters, request bodies, the user's identifier and the user's email address are not sent. Browser session replay runs with all text masked and all media blocked. The device's IP address arrives as part of the network connection, not as part of the message content, and is retained by it | United States |
| PostHog | Product usage analytics | A pre-defined allowlist of usage events, with their properties sanitised. No person profiles are created, events are not linked to an individual user identity, no automatic capture of clicks or on-screen text takes place, and browser sessions are not recorded. The device's IP address arrives as part of the network connection, not as part of the message content, and is retained by it | United States |
| Resend | Sending operational email | Email addresses of merchant account users only; no email is sent to end customers | Outside the Kingdom |
Sandus may also disclose personal data where required to do so by applicable law, or by an order of a competent judicial or supervisory authority.
8. Transfer and processing outside the Kingdom
Personal data is stored and processed outside the Kingdom of Saudi Arabia. This section states that plainly.
- The primary storage location is Australia — Sydney. The Sandus database, authentication data, and stored files are held with Supabase in the Sydney region.
- Application compute is pinned to Australia — Sydney. The server-side functions that run the application's business logic and read from and write to the database execute in the same geographic region as the database. Request routing, session-cookie refresh, and static content delivery are not covered by that pin: they run at edge locations worldwide, so request data — including the session cookie — may be handled in another country, and some requests are answered at an edge location without reaching the Sydney compute at all.
- Error monitoring, usage analytics, and operational email are also processed outside the Kingdom — specifically in the United States for error monitoring and usage analytics. What is transferred to those two services includes the device's IP address on every connection.
- The purpose relied on for the transfer: the operations necessary for central processing that enable the controller to conduct its activities, and to provide the service to the data subject.
- Measures applied: Sandus applies technical and organisational measures to transferred data, including encryption of communication channels, encryption of Salla credentials at rest, row-level isolation of each merchant's data in the database, and access restriction by role and subscription state.
Sandus does not rely on any adequacy decision regarding the level of protection in the receiving country, and does not claim any approval or accreditation from the Saudi Data and AI Authority for its transfers.
9. Retention and destruction
- While the application is installed: Sandus retains data for as long as the application is installed on the merchant's store, to the extent needed to run the service, fulfil orders, and maintain the operational record.
- On uninstall: a grace period of 30 days begins. During that period, reinstalling the application restores the account and cancels the scheduled destruction job.
- After the grace period: an anonymization in place process is executed:
- Personal fields are scrubbed to null: customer name, phone, email, city and address, free-text fields, measurements, quality-check, receiving and issue notes, and final production instructions.
- Raw payloads and inbound event records are redacted; their content is replaced with a marker indicating that they were redacted.
- Salla access credentials (access and refresh tokens) are destroyed.
- What is retained: operational and financial records are retained in anonymized form for accounting and audit purposes. These include order counts and dates, monetary totals, status-change history, and audit logs.
- Rows are not deleted. The destruction mechanism used is anonymization and redaction in place, not physical deletion of rows.
- Backups: data may remain present in the hosting provider's backups until the end of the applicable backup retention cycle.
Merchant and team-user account data and workshop data are not covered by this process. They are handled through an account-closure request sent to support@sandus.app.
10. Data subject rights
Under Article 4 of the Personal Data Protection Law, a data subject has the following rights, and only these:
- The right to be informed of the legal basis for collecting their personal data and the purpose of that collection.
- The right to access their personal data held by the controller.
- The right to obtain a copy of their personal data in a clear and readable format.
- The right to request correction, completion, or updating of their personal data.
- The right to request destruction of their personal data where it is no longer necessary, within the limits set by the law.
A data subject also has the right to withdraw consent at any time in those cases where consent is the legal basis for the processing.
The right of access or destruction may be subject to restrictions set by law, including data that must be retained to meet a legal requirement or in connection with a live claim. Where a request is refused in whole or in part, the reasons are given.
Response time: Sandus responds to a request within 30 days of receiving it. That period may be extended once, by a further 30 days, with prior notice stating the reasons for the extension.
11. How to exercise rights
- Route for end customers: if you are a customer who bought from a store that uses Sandus, the merchant is the controller of your data. Please direct your request to the merchant first. Where Sandus receives a request directly from an end customer, it refers the request to the relevant merchant and assists the merchant in acting on it.
- Route for merchants and account users: send requests to support@sandus.app, stating the right you wish to exercise and the data concerned.
- Identity verification: Sandus verifies the identity of the requester before acting on a request, in order to protect the data from unauthorized disclosure. Additional information may be requested for that purpose only.
- Documentation: all requests are documented and recorded, including oral requests.
- Repetitive requests: requests that are repetitive, manifestly unfounded, or that would require disproportionate effort may be refused, with reasons given.
12. Complaints
If you believe that the processing of your personal data breaches the law, you may contact us first at support@sandus.app.
You also have the right to lodge a complaint with the Saudi Data and AI Authority within 90 days of the incident or of becoming aware of it, through the National Data Governance Platform: https://dgp.sdaia.gov.sa/wps/portal/pdp/services/reportscomplaints
13. Cookies and similar technologies
| Type | Purpose | Classification |
|---|---|---|
Session and authentication cookie (sb-...-auth-token) | Maintaining and securing the login session | Strictly necessary |
Analytics cookie (ph_...) | Measuring product usage and improving the service | Analytics |
| Browser session replay within the error-monitoring tool | Fault diagnosis. Recording runs with all text masked and all media blocked | Operational and diagnostic |
There is currently no cookie consent banner or consent interface in the platform. Strictly necessary cookies rely on their necessity for providing the service; analytics and error diagnostics rely on legitimate interest under Article 6(4).
How to object or limit them: you can configure your browser to block or delete cookies, or to warn you before one is stored, through the browser's privacy settings. Most browsers also support a "Do Not Track" signal and private browsing modes. Blocking strictly necessary cookies will break login and make the platform unusable.
14. Data security
Sandus applies the following measures:
- Encryption of Salla credentials at rest: Salla access and refresh tokens are stored encrypted, with support for encryption key rotation.
- Row-level tenant isolation: every operational record is bound to a business identifier, and row-level isolation policies are applied in the database.
- Verification of inbound events: the platform verifies the HMAC-SHA256 signature of events received from Salla before accepting them, and applies idempotency handling to external events.
- Transport encryption: all communication with the platform takes place over encrypted channels.
- Restriction of what is sent to error monitoring: cookies, request headers, URL parameters, request bodies, and user information are not sent. Error messages are sanitised before transmission, and interface interaction trails are dropped entirely.
- No identification in analytics: no person profiles are created, analytics events are not linked to an individual user identity, and no automatic capture of clicks or on-screen text takes place.
- Session replay content masking: browser session replay in the error monitoring tool runs with all text masked and all media blocked.
- Access control: access within a merchant account is governed by two roles, owner and operator.
No information system can be guaranteed to be absolutely secure. Sandus exercises due care, but the transmission of data over the internet and its electronic storage carry residual risks that cannot be entirely eliminated.
In the event of a breach or accidental destruction of personal data that could cause harm to the data or to data subjects, Sandus notifies the competent authority within the statutory period, and notifies the data subject without undue delay where harm or an impact on their rights is possible.
15. Children
The Sandus service is directed at commercial businesses and their users, and is not directed at children. Sandus does not knowingly collect personal data of children. If such data is found to have been received, appropriate steps are taken to address it in accordance with the law. To report this, please contact support@sandus.app.
16. Sensitive data
Sandus does not intentionally collect sensitive personal data within the meaning of Article 1(11) of the Personal Data Protection Law, and the service does not require such data.
Notice to merchants and their account users: the platform contains free-text fields, including order notes, production instructions, quality-check and receiving notes, and workshop notes. No sensitive data should be entered into these fields. This includes health data, data indicating religious belief or affiliation, biometric or genetic data, national identity data, and financial data. Responsibility for what is entered into these fields rests with the merchant as the controller of that data.
17. Changes to this policy
This policy may be updated from time to time to reflect changes to the service or to legal requirements. The updated version is published on this page with an updated effective date. Where a material change affects the rights of data subjects, merchants are notified by email or by an in-platform notice.
Effective date: 9 September 2026
18. Contact
For any enquiry, request, or complaint about this policy or about the processing of personal data:
Email: support@sandus.app
TALAL ABDULLAH MOHAMMED ALJEHANI — JGAA7364, P.O. 23761, Jeddah, Kingdom of Saudi Arabia
See also Terms and Conditions · Support