Privacy Policy
Effective 5 September 2026
Sailo is operated by Khaleel Musleh, a sole proprietor based in San Bruno, California. This policy explains what the service collects, why it needs it, and what you can ask us to do about it. It describes the software as it is actually built, not a template.
Section 1. The short version
- We do not sell your personal information, and we never have. We do not rent it, trade it, or hand it to advertisers or data brokers.
- We do not use your data to build advertising profiles, and there are no third-party advertising or analytics trackers on any Sailo page.
- We do not store visitors’ IP addresses. Nothing Sailo runs on a storefront follows anyone across the web — and if a seller connects marketing tools of their own, those load only after you accept them on that shop.
- We never see card numbers. Payments run through Stripe’s own pages and Stripe’s own systems.
- A small number of vendors run parts of the service and process data strictly on our instructions. They are all named in section 6.
Section 2. Who is responsible for what
Sailo is a platform. Sellers use it to run their own shops, and buyers order from those shops. That split matters for privacy, because it decides who answers your request.
For seller accounts, Sailo is the controller. We decide what an account needs in order to exist, and we answer directly for it.
For buyer and order data, the seller is the controller and Sailo is their processor. When you buy from a shop, you are giving your details to that shop; we hold them on the shop’s behalf so it can fulfil the order. If you want a shop to delete your details, ask the shop. If they do not respond, write to us at privacy@sailo.store and we will help.
Section 3. What we collect
If you open a Sailo account. Your name, your email address, and a password. Passwords are stored only as a salted hash; we cannot read yours, and neither can anyone who obtains the database. We also keep sign-in session records, which include the IP address and browser the session was created from, so you can see and end sessions you do not recognise.
What you put in your shop. Your shop name, description, location, contact details, social links, currency, product catalogue and images. If you enable bank transfer or cash on delivery, the payout instructions you write are stored so buyers can read them at checkout. Anything you put in your shop is published to anyone who opens its link, which is the point of it.
If you place an order with a shop. Your name, and whichever of email or phone you provide. If the order is being delivered, the delivery address. Any note you add, the items ordered, the total, and the payment method and status. If you leave a review, the name you sign it with and what you wrote.
If you simply visit a shop. One page-view record, so the shop’s owner can see whether anyone is reading their link. It contains the page that referred you, any campaign tags in the link, an approximate country, region and city resolved at our host’s network edge, your device type, operating system and browser family, and a visitor identifier described below.
We do not store your IP address with that record, and we no longer put anything on your device to count you. The visitor identifier is derived for each shop, each day, by hashing your address and browser string together with the date — then your address is discarded. It cannot be reversed into you, it is different at the next shop you open, and it is different tomorrow. The cost of that is honest: “unique visitors” means unique that day, not unique forever.
Location is approximate and derived at the network edge, not from GPS, and it is never precise enough to identify a household.
Section 4. Why we are allowed to hold it
If the GDPR or UK GDPR applies to you, these are our lawful bases. If it does not, this section still tells you honestly why we hold each thing.
- Contract. Account details, shop content and order details. Without them there is no service to provide.
- Legitimate interests. Page-view counts, rate limiting and abuse prevention. Sellers need to know whether their link works, and the service needs to stay standing. We have kept this to the minimum that achieves it, which is why no IP address is stored. This also covers the small number of emails we send account holders about setting up and using Sailo itself — sent because you opened an account, capped at a handful, and every one of them carries a one-click unsubscribe that stops them for good without touching your order, billing or account email.
- Legal obligation. Invoices and payment records, which tax law requires us and sellers to retain.
- Consent. Anything you volunteer that the service did not ask for, and any marketing email you opt into. You can withdraw it at any time.
Section 5. Payments, and why we never see your card
Card details are entered on Stripe’s own hosted pages and are transmitted to Stripe. They do not pass through Sailo’s servers and are never stored by us. We hold a Stripe customer reference and the last status Stripe reported, and nothing more.
When a seller accepts card payments, they do so through their own Stripe account connected to the platform. The charge is created on that account, the money moves from the buyer to it, and Sailo does not hold seller funds at any point.
Sailo does take a fee. 1–3% of the goods on each card sale reaches us as a Stripe application fee, and the record of it — the amount, the order it belongs to and the account it came from — is data we hold. It is stated here because a privacy policy that describes the flow of money inaccurately describes the flow of data inaccurately too. The Terms set out how the fee is calculated.
Stripe processes payment data as an independent controller under its own privacy policy. If a seller offers bank transfer or cash on delivery, the payment happens entirely outside Sailo; we record only that the seller marked it settled, and any reference the buyer typed in.
Section 6. Who else processes data, and why
This is the complete list. Every party below runs part of the service and may use what it processes only to deliver that service back to us. None of them is permitted to use it for their own purposes, and none of them is an advertising network.
| Provider | What they do | What they see | Where |
|---|---|---|---|
| Vercel | Application hosting, content delivery, and file storage for uploaded images | Requests to the site, and any product photo or file a seller uploads | United States, with a global edge network |
| Neon | The managed Postgres database the service runs on | Everything stored: accounts, shops, catalogues, orders and analytics | United States |
| Stripe | Subscription billing for paid Sailo plans, and card payments a seller chooses to accept through their own connected Stripe account | Billing contact details, and payment details the payer enters on Stripe’s own pages | United States, with global processing |
| Resend | Sending email: order notifications, password resets and invoices; a seller's own marketing to contacts who opted in; and Sailo's own onboarding email to account holders | Recipient email address and the contents of that message | United States |
| Upstash Redis | Short-lived rate-limit counters that keep the service from being flooded. Optional, and the service runs without it | A hashed request key and a count. No account or order data | United States |
Vercel
- What they do
- Application hosting, content delivery, and file storage for uploaded images
- What they see
- Requests to the site, and any product photo or file a seller uploads
- Where
- United States, with a global edge network
Neon
- What they do
- The managed Postgres database the service runs on
- What they see
- Everything stored: accounts, shops, catalogues, orders and analytics
- Where
- United States
Stripe
- What they do
- Subscription billing for paid Sailo plans, and card payments a seller chooses to accept through their own connected Stripe account
- What they see
- Billing contact details, and payment details the payer enters on Stripe’s own pages
- Where
- United States, with global processing
Resend
- What they do
- Sending email: order notifications, password resets and invoices; a seller's own marketing to contacts who opted in; and Sailo's own onboarding email to account holders
- What they see
- Recipient email address and the contents of that message
- Where
- United States
Upstash Redis
- What they do
- Short-lived rate-limit counters that keep the service from being flooded. Optional, and the service runs without it
- What they see
- A hashed request key and a count. No account or order data
- Where
- United States
We will update this list before adding a new provider. Material changes are announced by email to account holders.
Section 7. Sending data outside your country
Every provider in the table above is in the United States. If you are in the United Kingdom, the European Economic Area or Switzerland, that means your data leaves your country to be processed.
We rely on the European Commission’s Standard Contractual Clauses, and the UK Addendum where the UK GDPR applies, in our contracts with each of them. Where a provider is certified under the EU–US Data Privacy Framework we rely on that as well, but we do not rely on it alone: certifications have been struck down twice, and a policy that depends on one is a policy with a countdown on it.
We have assessed the transfer, and the practical position is that the data is ordinary commercial information — names, addresses, order lines — held by large providers with published government-request reports. If you want the detail of the safeguards for a particular provider, ask at privacy@sailo.store and we will send what we have.
Section 8. What we promise sellers, as their processor
For the buyer data in a seller’s shop, the seller is the controller and Sailo is the processor. This clause is the written agreement the GDPR requires between the two of us, and it applies to every account without anything further to sign.
- We process buyer data only on the seller’s documented instructions, which for these purposes are the actions available in the product itself, plus anything the law obliges us to do. If a law compels something else, we will tell the seller unless that law forbids it.
- Everyone with access is bound to confidentiality, and access is limited to the people who need it to run the service.
- We apply the security measures described in section 13, and will not lower them during the agreement.
- The providers in section 6 are the authorised sub-processors. We will give notice before adding one, so a seller who objects has time to leave, and each is bound by terms no weaker than these.
- We will help the seller answer a buyer’s access, correction or deletion request, and help with a data protection impact assessment or a regulator’s enquiry, so far as the buyer data we hold allows.
- On the account closing, we delete buyer data on the schedule in section 11, except what tax law requires us to keep.
- We will make available what a seller reasonably needs to satisfy themselves that we are doing the above, and accept an audit where a regulator requires one.
Section 9. How we approach the GDPR
There is no such thing as a GDPR certificate, and any service claiming to hold one is selling something. So rather than assert compliance, this section says what we actually do, and the rest of this policy is where each of them is set out in full.
- A lawful basis is recorded for every category we hold, in section 4 — not a blanket “legitimate interests” covering everything.
- Data minimisation is a design decision, not a promise. We do not store visitors’ IP addresses, and the analytics identifier is derived per shop per day rather than stored on the device.
- Transfers out of the UK and EEA run on Standard Contractual Clauses, section 7.
- The Article 28 processor terms sellers need are in section 8, binding without anything further to sign.
- Retention is stated per category with an actual period, section 11, including the one category we cannot erase on request and why.
- Subject rights are answered within 30 days and free, section 12, and you can complain to your own regulator, section 14.
- Breaches are reported within 72 hours where the law requires it, section 14.
Where we fall short of something here, the honest thing is to fix it rather than to reword it. If you find a gap, write to privacy@sailo.store and it will be read by the person who can change the code.
Section 11. How long we keep things
- Account and shop data for as long as the account exists, then deleted within 30 days of a deletion request.
- Orders and invoices for seven years, because tax and accounting rules require it. This survives account deletion, and it is the one category we cannot erase on request.
- Page-view records for as long as the shop’s plan can display them, up to three years, then removed.
- Rate-limit counters for seconds to minutes. They expire on their own.
Deleting an account deletes its shop, catalogue, images, reviews and analytics. Buyer records attached to completed orders are retained under the rule above and are unlinked from the account.
Section 12. Your rights, and how to use them
Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. Write to privacy@sailo.store. We answer within 30 days and we do not charge for it.
If you are in California (CCPA, as amended by the CPRA), you may request the categories and specific pieces of personal information we have collected, the sources, the purpose, and the categories of third parties it was disclosed to; you may request deletion and correction; and you may not be discriminated against for asking. You may also opt out of the sale or sharing of personal information and limit the use of sensitive personal information. We have nothing for you to opt out of: we do not sell or share personal information as those terms are defined, and we do not collect sensitive personal information. In the twelve months before this policy’s effective date, we sold or shared none.
If you are in the EU, the EEA, the UK or Switzerland (GDPR and UK GDPR), you additionally have the right to data portability, the right to restrict processing, and the right to lodge a complaint with your supervisory authority. Data is processed in the United States; transfers rely on our providers’ Standard Contractual Clauses and equivalent safeguards.
An authorised agent may act for you if you say so in writing. We may need to verify your identity before acting, which usually means proving control of the email address on the record.
Section 13. How the data is kept
The database is private and reachable only by the application, over TLS, with credentials held as encrypted environment secrets. It is not exposed to the public internet and is not browsable by anyone outside the operator. All traffic to and from the service is encrypted in transit, and provider storage is encrypted at rest.
- Passwords are salted and hashed. Nobody, including the operator, can read them.
- Card details never reach our servers. That risk sits with Stripe, which is PCI DSS Level 1 certified.
- Access to production data is limited to the operator, and the internal staff panel is restricted to an explicit list of email addresses checked on every request.
- Download links for digital goods are unguessable, expiring and limited by use count.
- Scheduled jobs authenticate with a secret compared in constant time.
- Write endpoints are rate limited, and the limiter stores a counter, never a request body.
No system is perfect, and we will not claim otherwise. If a breach affects you, we will tell you and the relevant authority without undue delay and, where required, within 72 hours of becoming aware of it. If you believe you have found a vulnerability, please write to privacy@sailo.store before disclosing it publicly.
Section 14. If something goes wrong, and what we never do automatically
A breach. If personal data is exposed, we will tell the relevant supervisory authority within 72 hours of becoming aware where the law requires it, and tell the people affected without undue delay where the risk to them is high. Sellers whose buyer data is involved are told as controllers, with enough detail to make their own notification. We would rather report an incident that turns out to be nothing than sit on one.
Automated decisions. Nothing here profiles you, scores you, or decides anything about you with legal or similarly significant effect by machine alone. We run automated checks for fraud and abuse — rate limits, and signals that a shop is being used for something it should not be — but a suspension or closure under the Terms is a decision a person takes and a person will review. If one is made about you, you can ask for it to be looked at again by writing to privacy@sailo.store.
Complaining about us. You can complain to your own data protection authority — in the UK the Information Commissioner’s Office, in the EEA the authority for the country you live in. We would ask you to write to us first, but nothing requires you to.
Section 15. Children
Sailo is not intended for anyone under 16, and we do not knowingly collect their information. If you believe a child has given us data, write to privacy@sailo.store and we will delete it.
Section 16. Changes to this policy
When this policy changes, the effective date at the top changes with it. For anything that materially affects how your data is handled, we email account holders before it takes effect. Continuing to use Sailo after that means the new version applies.
Section 17. Contact
Privacy requests and questions about this policy go to the address below. For anything else, see the Terms of Service or the Refund Policy.
privacy@sailo.storeKhaleel Musleh
920 Masson Ave
San Bruno, California 94066
United States