Privacy Policy
Last updated August 2026
1. Who we are
simdar is a business operations platform that helps small service businesses manage customer conversations, quotes, deposits, invoices, and jobs — primarily over WhatsApp and similar messaging channels. This Privacy Policy explains what data we collect, why we collect it, how we use it, who we share it with, and what rights you have.
This policy applies to everyone who interacts with simdar: business owners who use the platform ("users"), their customers who receive documents or communicate through simdar-connected channels ("end customers"), and visitors to our website.
2. Our guiding principle: data minimisation
We collect the minimum data required to provide the service. We do not collect data speculatively, we do not build profiles for advertising, and we do not monetise your data or your customers' data in any way.
What we hold depends on three things: which plan tier you use, which channels you connect, and what information you choose to enter. A business on the free tier with no channel connected generates almost no data beyond a phone number and the documents it creates.
3. What data we collect and why
We organise the data we handle into categories so you can see exactly what applies to you.
3.1 Account data
When you create an account, we collect:
- Your phone number — used for authentication via one-time verification codes. This is the only mandatory field at registration.
- Your preferred language — detected from your device or chosen explicitly, used to display the interface in Arabic or English.
We do not collect your name, email address, or any other personal information at registration. If you later add a business name, address, or tax identification number, you do so voluntarily to appear on your invoices and documents.
3.2 Business data you enter
To use simdar, you may enter:
- Business details — name, address, tax registration numbers, logo. Displayed on your invoices and quotes.
- Customer records — names, phone numbers, and optionally nicknames. Used to address documents and route conversations.
- Jobs — descriptions, assignments, statuses. Used to organise your work.
- Quotes, deposits, and invoices — line items, amounts, tax categories, dates, terms. Used to generate shareable documents.
- Team members — names of people work is assigned to. Displayed on job records.
- Job types — categories you define for your trade. Used for organisation.
All of this data is entered by you, stored for your use, and visible only to your business (enforced at the database level by row-level security). simdar does not pre-populate, enrich, or augment your data from external sources.
3.3 Messaging data
On plans that connect a messaging channel (WhatsApp, Telegram), simdar processes:
- Inbound messages — text content, sender identifiers, timestamps. Stored so your inbox and conversation threads work.
- Outbound messages — text content you compose or that simdar generates (document links, templates). Stored for your records.
- Message metadata — delivery status, platform message IDs, session window state. Used to manage channel rules and delivery.
simdar does not store customer media. Photos, voice notes, videos, and documents that your customers share through messaging channels remain on those platforms' servers. simdar records only that a media message was received and its type. This is the single most significant privacy protection in the architecture: simdar holds no customer media at all.
3.4 Webhook and platform data
When messaging platforms deliver events to simdar (new messages, delivery receipts, status updates), we store the raw webhook payload in an append-only log. This log exists for debugging, replay, and audit purposes. It is not accessible to any user — it is an internal operations record with no client-facing access.
3.5 Authentication delivery data
To deliver your login verification code over your preferred channel (WhatsApp or Telegram instead of SMS), simdar maintains a mapping of phone numbers to channel identifiers. This mapping is created when you first interact with our bot on that channel and is used exclusively for authentication delivery.
3.6 Document view data
When your customer opens a quote, invoice, or deposit link, we record a single timestamp (viewed_at). We do not track the customer's IP address, browser, location, or any other identifying information beyond the fact that the link was opened. This timestamp exists so you know your document was seen.
3.7 Technical and usage data
Our hosting providers (Vercel, Supabase) automatically collect standard technical data such as IP addresses, request timestamps, and response codes in their infrastructure logs. simdar does not add its own analytics, tracking pixels, or behavioural tracking. We do not use cookies for advertising or tracking — the only cookies are session cookies required for authentication.
4. How we use your data
We use data exclusively to operate and improve the service:
- Authentication — verifying your identity when you log in
- Service delivery — generating documents, delivering messages, displaying your inbox and records
- Conversation management — threading messages, resolving customer identities across channels, managing session windows
- Tax compliance support — applying the correct tax regime based on your country, supporting VAT category calculations
- Platform operations — monitoring system health, debugging issues, preventing abuse
- Product improvement — understanding usage patterns in aggregate (never individual behaviour) to prioritise features
We do not use your data or your customers' data for advertising, profiling, selling, or any purpose other than providing the service you signed up for.
5. Who we share data with
We share data only with the infrastructure providers necessary to operate the service. We do not sell, rent, or trade data with anyone.
5.1 Infrastructure providers
- Supabase — database hosting, authentication, real-time subscriptions. Your data is stored in Supabase's managed PostgreSQL infrastructure. Supabase's security practices and compliance certifications are detailed on their trust page.
- Vercel — application hosting and edge delivery. Serves the web application and handles serverless function execution.
- Meta / WhatsApp — message delivery for WhatsApp-connected channels. Messages are transmitted through WhatsApp's Cloud API. Your use of WhatsApp is subject to Meta's own data policies.
- Telegram — message delivery for Telegram-connected channels. Messages are transmitted through Telegram's Bot API.
Each provider processes data under its own privacy policy and security commitments. We select providers with strong security postures and do not use providers whose business model depends on monetising the data they process for us.
5.2 Legal obligations
We may disclose data if required by law, regulation, legal process, or governmental request. We will notify you before doing so unless prohibited by law. Where we have discretion, we will challenge overbroad requests.
5.3 Business transfers
If simdar is acquired, merged, or its assets are transferred, your data may be part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
6. Data security
We implement multiple layers of security to protect your data:
- Row-level security (RLS) — every tenant table in the database is protected by policies that restrict access to the business that owns the data. This is enforced at the database level, not the application level, meaning even a bug in the application cannot leak data across tenants.
- Encryption in transit — all data transmitted between your device and simdar, and between simdar and its infrastructure providers, is encrypted using TLS.
- Encryption at rest — your data is encrypted at rest in Supabase's managed infrastructure.
- Authentication — phone-based OTP with no passwords to leak, steal, or reuse. Verification codes are short-lived and single-use.
- Least privilege — the application uses different database clients with different privilege levels. Browser-facing code uses the least privileged client; only specific server-side operations use elevated access, and only after verifying tenancy.
- No customer media storage — by not storing photos, voice notes, or documents, we eliminate an entire class of data breach risk.
No system is perfectly secure. We continuously review and improve our security measures, and we will notify affected users promptly if a data breach occurs.
7. Data retention and deletion
We retain data for as long as your account is active and the data is needed to provide the service. Specifically:
- Account and business data — retained while your account is active. Deleted upon account closure and verified deletion request.
- Customer records, jobs, quotes, invoices — retained while your account is active. Tax-related documents (invoices) may be retained for the period required by applicable tax law, even after account closure.
- Messages and conversations — retained while your account is active. Deleted upon account closure.
- Webhook logs — retained for operational purposes. Periodically purged.
- Authentication delivery mappings — retained while the associated account exists.
- Infrastructure logs (Vercel, Supabase) — retained according to those providers' policies, typically 30–90 days.
To request deletion of your data, contact us at the email below. We will delete your data within 30 days, subject to any legal retention requirements. Deletion is permanent and cannot be undone.
8. Your rights
Depending on your jurisdiction, you may have some or all of the following rights:
- Access — request a copy of the data we hold about you
- Correction — request that we correct inaccurate data
- Deletion — request that we delete your data
- Portability — request your data in a structured, machine-readable format
- Restriction — request that we limit how we process your data
- Objection — object to certain types of processing
- Withdrawal of consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at the email below. We will respond within 30 days. We will not discriminate against you for exercising your rights.
If you are a customer of a business that uses simdar (an "end customer"), your data controller is that business. Please direct data requests to the business first. If you need our help, contact us and we will assist.
9. International data transfers
simdar's infrastructure providers are based in the United States. Your data may be processed and stored in the United States or other countries where our providers operate. These countries may have data protection laws different from your own.
We rely on our providers' security commitments and standard contractual terms to ensure your data receives adequate protection regardless of where it is processed.
10. End customers
If you are a customer of a business that uses simdar — for example, you received an invoice link or your messages are part of a conversation managed through simdar — the business you interact with is the controller of your data. simdar processes your data on their behalf.
What we may hold about you as an end customer: your name and phone number (as entered by the business), messages you sent to the business through a connected channel, and the fact that you viewed a document link. We do not hold your media, your location, your device information, or any data beyond what is described here.
To exercise your data rights, contact the business directly. If you cannot reach them or need our help, contact us at the email below.
11. Children
simdar is a business tool and is not directed at children under 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect data from children. If you believe a child has provided data to us, contact us and we will delete it.
12. Cookies and tracking
simdar uses only essential cookies — specifically, session cookies required for authentication. We do not use advertising cookies, analytics trackers, tracking pixels, or any third-party tracking technology.
We do not participate in any advertising network. We do not build behavioural profiles. We do not share any data with advertisers.
13. Changes to this policy
We may update this policy as the service evolves. When we make material changes, we will notify you by email or through a prominent notice within the service at least 15 days before the changes take effect.
The date at the top of this page reflects the latest version. Previous versions are available upon request.
Contact & data requests
To request access to, correction of, or deletion of your data, email us. We act on verified requests within 30 days.