Skip to content

Legal

Privacy Policy

How Saldo Metrics collects, uses and protects personal data.

Last updated: September 2026

Controller

Al-Khwarizmi Consulting LTD., Horeca Building, 3rd Floor, Triq l-Imgarr, Xewkija XWK 9012, Malta, trading as Saldo Metrics, is the controller for the processing described here. Company number C 105305 (Malta Business Registry); the full company details are in the imprint. Email: hello@saldometrics.com We have not appointed a data protection officer: our processing does not meet the threshold in Art. 37 GDPR. Data-protection requests sent to the address above reach the person responsible directly.

Our two roles

For our website, your account and our outreach, we are the controller and this policy applies. For the commerce data you connect — your orders, customers, products and costs — you remain the controller and we act as your processor under Art. 28 GDPR. We process it on your instructions to produce your analytics. A data processing agreement is part of our terms and available on request.

Data we process

Account data: name, email address, password hash, organisation and role. Commerce data: what a connected store, advertising or email platform returns (orders, customers, products, costs, ad spend), including personal data of your customers. Connection credentials: API keys and tokens for the platforms you connect, stored encrypted. Usage and server data: IP address, browser user agent, requested URL and timestamp, processed to keep the service available and secure. Correspondence: what you send us by email or through support.

Legal bases

Art. 6(1)(b) GDPR to provide the service you signed up for. Art. 6(1)(f) GDPR for our legitimate interests in operating and securing the service, and in contacting businesses that fit our product. Art. 6(1)(a) GDPR where you consent — optional cookies, product emails — which you can withdraw at any time with effect for the future. Art. 6(1)(c) GDPR where the law requires us to keep records, such as invoices.

Cookies and consent

By default we set only cookies the site needs to work. Analytics and preference cookies stay off until you turn them on in the banner, and you can change your mind any time through Cookie settings in the footer. For signed-in users we log the choice as proof of consent: the categories, the policy version, your browser user agent, a hashed IP address and the timestamp. The cookie policy lists each cookie, its purpose and how long it lasts.

Who we share data with

Scaleway SAS, Paris, France — hosting, managed database and transactional email. Proton AG, Switzerland — the mailbox we use for correspondence and outreach. An AI provider of your choice, only if you switch on document extraction: Anthropic, Amazon Bedrock, OpenAI or your own endpoint. The deterministic pipeline runs first, and the model sees at most one page of a document plus up to 25 candidate SKUs — never the whole document, never your catalogue. You can disable it entirely per organisation. All of them act as processors under Art. 28 contracts. We do not sell personal data and we share nothing with advertising networks.

Where data is stored

The application, the database and its backups run in Scaleway's Paris region, inside the EU. Correspondence sits with Proton in Switzerland, which the European Commission has recognised as providing an adequate level of protection. The only route out of that perimeter is the optional AI extraction described above, and it is yours to enable, with the transfer covered by that provider's Art. 46 safeguards.

How long we keep data

Account data: for as long as the account exists, then deleted, except records tax law requires us to keep. Uploaded cost documents: a per-organisation retention window, 90 days by default; extracted document text is not stored unless the organisation turns that on. Behavioural pixel events: a per-organisation window, 365 days by default, after which the events are anonymised in place — the identifiers are erased and only the aggregate remains. Raw platform payloads awaiting processing: deleted 3 days after processing; payloads of rows that failed permanently are scrubbed after 30 days. Generated export files (CSV/XLSX): a per-organisation retention window, 7 days by default, after which the file is deleted and must be exported again. Session cookie: 8 hours. Consent cookie: 12 months. Consent log: kept as evidence that consent was given. Prospect data: as described below.

Security

Data is encrypted in transit, isolated per customer at the database layer by row-level security rather than by application code alone, and reachable only by the people and jobs that need it. Credentials for connected platforms are stored encrypted and are never returned to the browser.

Prospect and outreach data

When we contact a store owner about Saldo Metrics for the first time, we work from business contact details that are publicly available: your name, your professional email address, your store's URL and the e-commerce platform it runs on. We collect these from public sources such as your website's legal notice, public registers and directories, and process them on the basis of legitimate interest (Art. 6(1)(f) GDPR) in offering a product relevant to your business. The first message tells you all of this, as Art. 14 GDPR requires. If you object, we delete your record and keep two things on a suppression list so that the objection can be honoured: your email address and your store's domain. The domain is what stops a later crawl from collecting a different address at the same shop. Otherwise prospect data is deleted 12 months after the last contact if there has been no reply.

Your rights

You can request access, rectification, erasure, restriction and portability of your personal data. You can object at any time to processing based on legitimate interest (Art. 21 GDPR), and to direct marketing without giving a reason — we stop. You can withdraw consent at any time, which does not affect processing that already happened. Write to hello@saldometrics.com and we answer within one month. You can also complain to a supervisory authority: ours is the Information and Data Protection Commissioner (IDPC), Floriana, Malta, and you may equally go to the authority where you live or work.

Automated decision-making

The product computes metrics and suggests actions, and a person decides what to do with them. We make no decisions producing legal or similarly significant effects on you by automated means alone, within the meaning of Art. 22 GDPR, and we do not profile you for that purpose.

Changes to this policy

We update this policy when the product or the law changes. The date at the top says when. If a change materially affects you, we announce it in the application or by email before it takes effect.