Skip to content

Legal

Privacy Policy

How Saldo Metrics collects, uses and protects personal data.

Last updated: October 2026

Controller

Al-Khwarizmi Consulting LTD., Horeca Building, 3rd Floor, Triq l-Imgarr, Xewkija XWK 9012, Malta, trading as Saldo Metrics, is the controller for the processing described here. Company number C 105305 (Malta Business Registry); the full company details are in the imprint. Email: hello@saldometrics.com We have not appointed a data protection officer: our processing does not meet the threshold in Art. 37 GDPR. Data-protection requests sent to the address above reach the person responsible directly.

Our two roles

For our website, your account and our outreach, we are the controller and this policy applies. For the commerce data you connect — your orders, customers, products and costs — you remain the controller and we act as your processor under Art. 28 GDPR. We process it on your instructions to produce your analytics. A data processing agreement is part of our terms and available on request.

Data we process

Account data: name, email address, password hash, organisation and role. If you sign in with Google, we receive your email address and basic profile from Google (scopes: openid, email, profile). Commerce data: what a connected store, advertising or email platform returns (orders, customers, products, costs, ad spend), including personal data of your customers. Connection credentials: API keys and tokens for the platforms you connect, stored encrypted. If you connect Google Drive or Sheets for report delivery, we store the refresh token Google issues for it. Usage and server data: IP address, browser user agent, requested URL and timestamp, processed to keep the service available and secure. Correspondence: what you send us by email or through support.

Legal bases

Art. 6(1)(b) GDPR to provide the service you signed up for. Art. 6(1)(f) GDPR for our legitimate interests in operating and securing the service, and in contacting businesses that fit our product. Art. 6(1)(a) GDPR where you consent — optional cookies, product emails — which you can withdraw at any time with effect for the future. Art. 6(1)(c) GDPR where the law requires us to keep records, such as invoices.

Cookies and consent

By default we set only cookies the site needs to work. Analytics and preference cookies stay off until you turn them on in the banner, and you can change your mind any time through Cookie settings in the footer. For signed-in users we log the choice as proof of consent: the categories, the policy version, your browser user agent, a keyed hash of your IP address and the timestamp. The cookie policy lists each cookie, its purpose and how long it lasts.

Who we share data with

Scaleway SAS, Paris, France — hosting, managed database and transactional email. Proton AG, Switzerland — the mailbox we use for correspondence and outreach. Anthropic, only if you switch on document extraction and have not configured a provider of your own: we then use our own Anthropic account. The deterministic pipeline runs first, and the model sees at most one page of a document plus up to 25 candidate SKUs — never the whole document, never your catalogue. Extraction is off unless you switch it on, and you can switch it off again at any time. If you configure your own provider instead — Anthropic, OpenAI or Amazon Bedrock under your own account, or an OpenAI-compatible endpoint from our approved list (OpenAI, Mistral, Groq, OpenRouter, Together) — that provider works under your contract with it and is not our sub-processor. Google, only for features you use: Sign in with Google, and delivering reports to your Google Drive or Sheets. Scaleway, Proton and Anthropic act as our processors under Art. 28 contracts. We do not sell personal data and we share nothing with advertising networks.

Where data is stored

The application, the database and its backups run in Scaleway's Paris region, inside the EU. Correspondence sits with Proton in Switzerland, which the European Commission has recognised as providing an adequate level of protection. Data leaves that perimeter only in two ways. One is the optional AI extraction described above: it is yours to enable, and the transfer is covered by that provider's Art. 46 safeguards. The other is deliveries you configure yourself: reports to Google Drive or Sheets or to an FTP server you name, alerts and digests to Slack, and reports emailed to the addresses you enter.

How long we keep data

Account data: for as long as the account exists, then deleted, except records tax law requires us to keep. Uploaded cost documents: a per-organisation retention window, 90 days by default. The document's text is never stored; we keep only the cost lines extracted from it. Behavioural pixel events: a per-organisation window, 365 days by default, after which the events are anonymised in place — the identifiers are erased and only the aggregate remains. Raw platform payloads awaiting processing: deleted 3 days after processing; payloads of rows that failed permanently are scrubbed after 30 days. Generated export files (CSV/XLSX): a per-organisation retention window, 7 days by default, after which the file is deleted and must be exported again. Organisation deletion: an admin can delete an organisation in Settings, after confirming their identity again and typing the organisation's identifier. Deletion runs 14 days after the request (the daily job can take up to a day longer) and can be cancelled until it starts. In the meantime members can still view and export the data, nothing else can be changed, and connected stores stop sending data. It removes every row of the organisation's data and every uploaded document and generated export file, including stored versions, revokes access to connected platforms where the platform allows it, and deletes stored credentials. User accounts are not deleted along with the organisation. Store data deletion: an admin who disconnects a store in Settings can also have its data deleted, after confirming their identity again. Deletion runs 14 days after the request (the daily job can take up to a day longer) and can be cancelled until it starts; until then the data stays visible. It removes the store's orders, products, customers, pixel events, staged payloads and the cost documents that belonged to that store only, including stored versions. Catalogue entries another store still relies on, such as a product linked to its marketplace copy, are kept. A record of the deletion, with no store data in it, stays until the organisation is deleted. Deletion record: kept indefinitely; it names the organisation, who requested the deletion, the dates and row counts, and contains no store data. Store pairing log: when a store module was paired, re-paired or disconnected, who approved or disconnected it, the store's address and a keyed hash of the requesting IP address (never the address itself); kept 365 days, then deleted. Database backups: taken every 12 hours and kept for 14 days on a rolling basis, so data deleted from the live database can remain in a backup for up to 14 days. Session cookie: 8 hours. Consent cookie: 12 months. Consent log: kept as evidence that consent was given. Prospect data: as described below.

Security

Data is encrypted in transit, isolated per customer at the database layer by row-level security rather than by application code alone, and reachable only by the people and jobs that need it. Credentials for connected platforms are stored encrypted and are never returned to the browser.

Prospect and outreach data

When we contact a store owner about Saldo Metrics for the first time, we work from business contact details that are publicly available: your name, your professional email address, your store's URL and the e-commerce platform it runs on. We collect these from public sources such as your website's legal notice, public registers and directories, and process them on the basis of legitimate interest (Art. 6(1)(f) GDPR) in offering a product relevant to your business. The first message tells you all of this, as Art. 14 GDPR requires. If you object, we delete your record and keep two things on a suppression list so that the objection can be honoured: your email address and your store's domain. The domain is what stops a later crawl from collecting a different address at the same shop. Otherwise prospect data is deleted 12 months after the last contact if there has been no reply.

Your rights

You can request access, rectification, erasure, restriction and portability of your personal data. You can object at any time to processing based on legitimate interest (Art. 21 GDPR), and to direct marketing without giving a reason — we stop. You can withdraw consent at any time, which does not affect processing that already happened. Write to hello@saldometrics.com and we answer within one month. You can also complain to a supervisory authority: ours is the Information and Data Protection Commissioner (IDPC), Floriana, Malta, and you may equally go to the authority where you live or work.

Automated decision-making

The product computes metrics and suggests actions, and a person decides what to do with them. We make no decisions producing legal or similarly significant effects on you by automated means alone, within the meaning of Art. 22 GDPR, and we do not profile you for that purpose.

Changes to this policy

We update this policy when the product or the law changes. The date at the top says when. If a change materially affects you, we announce it in the application or by email before it takes effect.