Privacy Policy
Last updated: December 2024
Introduction
Salia is a referral and loyalty management platform designed for business owners (B2B). This Privacy Policy explains how we collect, use, and protect personal data when you use our service. By using Salia, you acknowledge that you have read and understood this policy.
Data Controller
Salia is operated by an independent founder/company based in Switzerland. As the data controller, we are responsible for how your personal data is processed.
For any questions regarding your data, contact us at: contact@salia.io
Data We Collect
We collect different types of data depending on how you interact with Salia:
Business Owners (Customers)
- Email address and name (via Google OAuth or magic link authentication)
- Business name and related information
- Billing information processed through Stripe (we do not store full payment card details)
Referral Data
- Referrer and friend identifiers
- Codes created, shared, and used
- Offers redeemed and their status
- Estimated revenue generated (no sensitive personal categories)
Technical & Analytics Data
- Server logs (IP addresses, timestamps, requests)
- Anonymised analytics events via Posthog
- Device and browser information for security purposes
Purposes & Legal Basis
We process your data for the following purposes:
- Providing and maintaining the Salia service
- Managing your account and authentication
- Processing payments and billing
- Product analytics and service improvement
- Security and fraud prevention
- Communicating important updates about the service
Legal Bases
- Contract: Processing necessary to provide the service you signed up for
- Legitimate interests: Analytics, security, and service improvement
- Legal obligations: Tax records, accounting requirements
Processors & Third Parties
We work with trusted third-party service providers to operate Salia. These processors only access data necessary for their specific function:
- Vercel – Hosting and infrastructure
- Neon – PostgreSQL database
- Stripe – Payment processing
- Posthog – Product analytics (anonymised)
- Email service provider – Transactional emails
International Transfers
Some of our service providers may process data outside of Switzerland or the European Economic Area. When this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions, to protect your data in accordance with applicable data protection laws.
Data Retention
We retain your data for as long as your account is active. After account deletion, we may retain certain data for a limited period to comply with legal and accounting obligations (typically up to 10 years for financial records). After this period, data is deleted or anonymised.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access – Request a copy of your data
- Rectification – Correct inaccurate data
- Deletion – Request deletion of your data
- Portability – Receive your data in a portable format
- Restriction – Limit how we process your data
- Objection – Object to certain processing activities
To exercise any of these rights, please contact us at contact@salia.io. We will respond within 30 days.
Security
We implement reasonable technical and organisational measures to protect your data, including encryption in transit and at rest, secure authentication, and regular security reviews. However, no system is completely secure, and we cannot guarantee absolute security.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you via email or through the service. Your continued use of Salia after changes constitutes acceptance of the updated policy.
Disclaimer
This Privacy Policy is provided for informational purposes and does not constitute legal advice. If you have specific legal questions about data protection, we recommend consulting a qualified legal professional.