simdar
عربيEN

Privacy Policy

Last updated August 2026

1. Who we are

simdar is a business operations platform that helps small service businesses manage customer conversations, quotes, deposits, invoices, and jobs — primarily over WhatsApp and similar messaging channels. This Privacy Policy explains what data we collect, why we collect it, how we use it, who we share it with, and what rights you have.

This policy applies to everyone who interacts with simdar: business owners who use the platform ("users"), their customers who receive documents or communicate through simdar-connected channels ("end customers"), and visitors to our website.

2. Our guiding principle: data minimisation

We collect the minimum data required to provide the service. We do not collect data speculatively, we do not build profiles for advertising, and we do not monetise your data or your customers' data in any way.

What we hold depends on three things: which plan tier you use, which channels you connect, and what information you choose to enter. A business on the free tier with no channel connected generates almost no data beyond a phone number and the documents it creates.

3. What data we collect and why

We organise the data we handle into categories so you can see exactly what applies to you.

3.1 Account data

When you create an account, we collect:

  • Your phone number — used for authentication via one-time verification codes. This is the only mandatory field at registration.
  • Your preferred language — detected from your device or chosen explicitly, used to display the interface in Arabic or English.

We do not collect your name, email address, or any other personal information at registration. If you later add a business name, address, or tax identification number, you do so voluntarily to appear on your invoices and documents.

3.2 Business data you enter

To use simdar, you may enter:

  • Business details — name, address, tax registration numbers, logo. Displayed on your invoices and quotes.
  • Customer records — names, phone numbers, and optionally nicknames. Used to address documents and route conversations.
  • Jobs — descriptions, assignments, statuses. Used to organise your work.
  • Quotes, deposits, and invoices — line items, amounts, tax categories, dates, terms. Used to generate shareable documents.
  • Team members — names of people work is assigned to. Displayed on job records.
  • Job types — categories you define for your trade. Used for organisation.

All of this data is entered by you, stored for your use, and visible only to your business (enforced at the database level by row-level security). simdar does not pre-populate, enrich, or augment your data from external sources.

3.3 Messaging data

On plans that connect a messaging channel (WhatsApp, Telegram), simdar processes:

  • Inbound messages — text content, sender identifiers, timestamps. Stored so your inbox and conversation threads work.
  • Outbound messages — text content you compose or that simdar generates (document links, templates). Stored for your records.
  • Message metadata — delivery status, platform message IDs, session window state. Used to manage channel rules and delivery.

simdar does not store customer media. Photos, voice notes, videos, and documents that your customers share through messaging channels remain on those platforms' servers. simdar records only that a media message was received and its type. This is the single most significant privacy protection in the architecture: simdar holds no customer media at all.

3.4 Webhook and platform data

When messaging platforms deliver events to simdar (new messages, delivery receipts, status updates), we store the raw webhook payload in an append-only log. This log exists for debugging, replay, and audit purposes. It is not accessible to any user — it is an internal operations record with no client-facing access.

3.5 Authentication delivery data

To deliver your login verification code over your preferred channel (WhatsApp or Telegram instead of SMS), simdar maintains a mapping of phone numbers to channel identifiers. This mapping is created when you first interact with our bot on that channel and is used exclusively for authentication delivery.

3.6 Document view data

When your customer opens a quote, invoice, or deposit link, we record a single timestamp (viewed_at). We do not track the customer's IP address, browser, location, or any other identifying information beyond the fact that the link was opened. This timestamp exists so you know your document was seen.

3.7 Technical and usage data

Our hosting providers (Vercel, Supabase) automatically collect standard technical data such as IP addresses, request timestamps, and response codes in their infrastructure logs. simdar does not add its own analytics, tracking pixels, or behavioural tracking. We do not use cookies for advertising or tracking — the only cookies are session cookies required for authentication.

4. How we use your data

We use data exclusively to operate and improve the service:

  • Authentication — verifying your identity when you log in
  • Service delivery — generating documents, delivering messages, displaying your inbox and records
  • Conversation management — threading messages, resolving customer identities across channels, managing session windows
  • Tax compliance support — applying the correct tax regime based on your country, supporting VAT category calculations
  • Platform operations — monitoring system health, debugging issues, preventing abuse
  • Product improvement — understanding usage patterns in aggregate (never individual behaviour) to prioritise features

We do not use your data or your customers' data for advertising, profiling, selling, or any purpose other than providing the service you signed up for.

5. Who we share data with

We share data only with the infrastructure providers necessary to operate the service. We do not sell, rent, or trade data with anyone.

5.1 Infrastructure providers

  • Supabase — database hosting, authentication, real-time subscriptions. Your data is stored in Supabase's managed PostgreSQL infrastructure. Supabase's security practices and compliance certifications are detailed on their trust page.
  • Vercel — application hosting and edge delivery. Serves the web application and handles serverless function execution.
  • Meta / WhatsApp — message delivery for WhatsApp-connected channels. Messages are transmitted through WhatsApp's Cloud API. Your use of WhatsApp is subject to Meta's own data policies.
  • Telegram — message delivery for Telegram-connected channels. Messages are transmitted through Telegram's Bot API.

Each provider processes data under its own privacy policy and security commitments. We select providers with strong security postures and do not use providers whose business model depends on monetising the data they process for us.

5.2 Legal obligations

We may disclose data if required by law, regulation, legal process, or governmental request. We will notify you before doing so unless prohibited by law. Where we have discretion, we will challenge overbroad requests.

5.3 Business transfers

If simdar is acquired, merged, or its assets are transferred, your data may be part of that transaction. We will notify you before your data becomes subject to a different privacy policy.

6. Data security

We implement multiple layers of security to protect your data:

  • Row-level security (RLS) — every tenant table in the database is protected by policies that restrict access to the business that owns the data. This is enforced at the database level, not the application level, meaning even a bug in the application cannot leak data across tenants.
  • Encryption in transit — all data transmitted between your device and simdar, and between simdar and its infrastructure providers, is encrypted using TLS.
  • Encryption at rest — your data is encrypted at rest in Supabase's managed infrastructure.
  • Authentication — phone-based OTP with no passwords to leak, steal, or reuse. Verification codes are short-lived and single-use.
  • Least privilege — the application uses different database clients with different privilege levels. Browser-facing code uses the least privileged client; only specific server-side operations use elevated access, and only after verifying tenancy.
  • No customer media storage — by not storing photos, voice notes, or documents, we eliminate an entire class of data breach risk.

No system is perfectly secure. We continuously review and improve our security measures, and we will notify affected users promptly if a data breach occurs.

7. Data retention and deletion

We retain data for as long as your account is active and the data is needed to provide the service. Specifically:

  • Account and business data — retained while your account is active. Deleted upon account closure and verified deletion request.
  • Customer records, jobs, quotes, invoices — retained while your account is active. Tax-related documents (invoices) may be retained for the period required by applicable tax law, even after account closure.
  • Messages and conversations — retained while your account is active. Deleted upon account closure.
  • Webhook logs — retained for operational purposes. Periodically purged.
  • Authentication delivery mappings — retained while the associated account exists.
  • Infrastructure logs (Vercel, Supabase) — retained according to those providers' policies, typically 30–90 days.

To request deletion of your data, contact us at the email below. We will delete your data within 30 days, subject to any legal retention requirements. Deletion is permanent and cannot be undone.

8. Your rights

Depending on your jurisdiction, you may have some or all of the following rights:

  • Access — request a copy of the data we hold about you
  • Correction — request that we correct inaccurate data
  • Deletion — request that we delete your data
  • Portability — request your data in a structured, machine-readable format
  • Restriction — request that we limit how we process your data
  • Objection — object to certain types of processing
  • Withdrawal of consent — where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at the email below. We will respond within 30 days. We will not discriminate against you for exercising your rights.

If you are a customer of a business that uses simdar (an "end customer"), your data controller is that business. Please direct data requests to the business first. If you need our help, contact us and we will assist.

9. International data transfers

simdar's infrastructure providers are based in the United States. Your data may be processed and stored in the United States or other countries where our providers operate. These countries may have data protection laws different from your own.

We rely on our providers' security commitments and standard contractual terms to ensure your data receives adequate protection regardless of where it is processed.

10. End customers

If you are a customer of a business that uses simdar — for example, you received an invoice link or your messages are part of a conversation managed through simdar — the business you interact with is the controller of your data. simdar processes your data on their behalf.

What we may hold about you as an end customer: your name and phone number (as entered by the business), messages you sent to the business through a connected channel, and the fact that you viewed a document link. We do not hold your media, your location, your device information, or any data beyond what is described here.

To exercise your data rights, contact the business directly. If you cannot reach them or need our help, contact us at the email below.

11. Children

simdar is a business tool and is not directed at children under 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect data from children. If you believe a child has provided data to us, contact us and we will delete it.

12. Cookies and tracking

simdar uses only essential cookies — specifically, session cookies required for authentication. We do not use advertising cookies, analytics trackers, tracking pixels, or any third-party tracking technology.

We do not participate in any advertising network. We do not build behavioural profiles. We do not share any data with advertisers.

13. Changes to this policy

We may update this policy as the service evolves. When we make material changes, we will notify you by email or through a prominent notice within the service at least 15 days before the changes take effect.

The date at the top of this page reflects the latest version. Previous versions are available upon request.

Contact & data requests

To request access to, correction of, or deletion of your data, email us. We act on verified requests within 30 days.

privacy@simdar.app