Template document — pending legal review
This page is a working template drafted for a Solana payment platform. It has not been reviewed or approved by a qualified lawyer, and it is not legal advice. It must be reviewed by counsel before Saref launches or relies on it.
Privacy Policy
What Saref collects, why we collect it, who processes it on our behalf, and the rights you have over it.
Last updated 21 July 2026
1. Who we are
Saref provides checkout and payment-operations software for businesses. For merchant account data — the people who sign up, log in, and run a Saref workspace — Saref is the data controller.
For the customer data a merchant collects through their own pay pages and receipts, the merchant is the controller and Saref acts as a processor on their behalf. The legal entity name, registered address, and any data protection representative are placeholders in this template and must be completed before launch.
2. Data we collect
Merchant account and workspace data:
- Account identity: email address, display name, password hash (managed by our authentication provider), and optional profile avatar.
- Business details: business and legal name, currency, timezone, contact email, phone number, website, and uploaded logo.
- Team data: team member emails, invitations, and role assignments (owner, admin, sales, read-only).
- Billing data: plan, billing cycle, subscription status, and payment records for your Saref subscription.
- Wallet configuration: the public receiving addresses you configure. We never ask for, and never store, private keys or seed phrases.
Transaction and customer data processed on a merchant’s behalf:
- Order and subscription records: line items, amounts, currency, status, timestamps, and public order or charge codes.
- Payment records: on-chain transaction signatures, payer wallet addresses observed on-chain, token, network, and confirmation times.
- Optional customer contact details: an email address, where the customer supplies one for a receipt or renewal reminder.
- Refund records and their status.
Technical data:
- Session cookies, IP address, user agent, and request logs used for authentication, rate limiting, abuse prevention, and debugging.
Blockchain data is public by nature. Wallet addresses and transaction amounts recorded on Solana are visible to anyone and cannot be deleted or amended by us.
3. Why we use it and our legal bases
- To provide the service and perform our contract with you — accounts, checkout, confirmation, receipts, webhooks, and support.
- For our legitimate interests — securing the platform, preventing fraud and abuse, and improving reliability.
- To comply with legal obligations — tax, accounting, and record-keeping requirements.
- With your consent — optional marketing email, which you can withdraw at any time.
We do not sell personal data, and we do not use it to train third-party advertising profiles.
4. Data processors we use
We share data with a small set of vendors who process it strictly on our instructions:
- Supabase — database, authentication, and file storage for accounts, orders, and uploaded assets.
- Resend — transactional email delivery for receipts, invitations, and renewal reminders.
- Our hosting and CDN provider — serving the application and storing request logs.
- Solana RPC providers — reading public chain state to confirm payments. No merchant personal data is sent to them beyond the public addresses and references involved in a transfer.
Some of these vendors process data outside the UK and EEA. Where they do, transfers are covered by Standard Contractual Clauses or the UK International Data Transfer Addendum. The definitive vendor list and transfer mechanisms must be confirmed by counsel before launch.
5. Your rights (UK GDPR / GDPR)
If you are in the UK or EEA, you have the right to:
- Access the personal data we hold about you and receive a copy.
- Have inaccurate data corrected.
- Request erasure, where we are not required to keep the data by law.
- Restrict or object to processing carried out under legitimate interests.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
- Complain to a supervisory authority — in the UK, the Information Commissioner's Office.
To exercise any of these, email privacy@saref.co. We aim to respond within one month. If your request concerns data a merchant collected about you as their customer, we will pass it to that merchant, who is the controller.
Personal data written to a public blockchain — for example a payer wallet address — cannot be erased or rectified by us. That is a technical property of the network, not a policy choice.
6. Cookies
We use a small number of cookies. Strictly necessary cookies keep you signed in, maintain your selected business, and protect forms against cross-site request forgery; these cannot be turned off without breaking the product. A local preference is also stored for your light or dark theme.
We do not use advertising cookies or cross-site tracking pixels. If analytics are added later, this section and a consent mechanism must be updated first.
7. Retention
- Account and workspace data: kept while the account is active, then deleted or anonymised within a reasonable period after closure.
- Order, payment, refund, and invoice records: retained for the period required by tax and accounting law in the relevant jurisdiction (commonly six to seven years).
- Request and security logs: retained for a short rolling window for debugging and abuse prevention.
- Marketing consent records: kept until consent is withdrawn, plus a short record of the withdrawal.
8. Security
Access to production data is restricted and role-based. Payment pages are rate limited and use unguessable codes, webhooks are HMAC-signed, and payment status is verified server-side against the chain rather than trusted from the browser. No system is perfectly secure; if a breach affects your rights we will notify you and the relevant regulator as required.
9. Contact
Privacy questions and rights requests: privacy@saref.co. General support: support@saref.co.