Privacy Policy
Last updated: January 2026. What we collect, why we collect it, and what rights you have over your data.
1. Introduction
SAASAF.AI ("we," "us," or "the Platform") respects your privacy and is committed to protecting the personal data you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, register as a vendor or reseller, or otherwise interact with the Platform. By using SAASAF.AI, you consent to the practices described in this policy.
2. Information We Collect
We collect the following categories of personal data:
- Account information: name, email address, company, role, billing address, and payment details when you register or make a purchase.
- Application data: details you provide when applying as a vendor or reseller, including audience size, niche, channel URLs, and revenue ranges.
- Usage data: pages visited, links clicked, time on page, browser type, operating system, IP address, and device identifiers.
- Tracking and attribution data: referral sources, click identifiers, conversion events, and commission events necessary to operate the reseller engine.
- Communications: emails, support tickets, and form submissions you send us.
- Cookies and similar technologies: as described in Section 6 below.
3. How We Use Your Information
We use the data we collect to:
- Operate, maintain, and improve the Platform.
- Process vendor and reseller applications and approve or decline accounts.
- Track referrals, attribute commissions, and process payouts.
- Provide customer support and respond to your inquiries.
- Send transactional emails (account, payment, payout, security notifications).
- Send marketing communications, where you have opted in or where permitted by law.
- Detect, prevent, and respond to fraud, abuse, security threats, and policy violations.
- Comply with legal obligations, enforce our Terms, and protect our rights.
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction that requires a legal basis for processing, we rely on one or more of: (a) performance of a contract with you, (b) compliance with a legal obligation, (c) our legitimate interests in operating and growing the Platform, and (d) your consent where required (for example, for marketing emails or non-essential cookies).
5. Third-Party Services
We share data with the following categories of service providers, only to the extent necessary for them to perform services on our behalf:
- Hosting and infrastructure: Netlify (site hosting), AWS (data storage and compute).
- Payments: Stripe (vendor billing, reseller payouts via Stripe Connect).
- Analytics: Google Analytics (anonymized usage data).
- Email and communications: Postmark or similar transactional email providers.
- Customer support: CRM and helpdesk tools used by our team.
- Fraud detection: third-party fraud and abuse detection systems.
We do not sell your personal data. We do not share your data with advertising networks for cross-site retargeting beyond what is necessary for the Platform to function. Each third-party service has its own privacy policy that governs their use of your data.
6. Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Strictly necessary cookies: session management, authentication, and security.
- Functional cookies: remembering preferences and settings.
- Analytics cookies: aggregated, mostly anonymized usage measurement.
- Attribution cookies: tracking referrals from resellers to vendor products for commission attribution.
You can control cookies via your browser settings. Disabling cookies may impact Platform functionality, including reseller attribution.
7. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to correct inaccurate or incomplete data.
- Deletion: ask us to delete your data, subject to legal and contractual retention requirements.
- Portability: request your data in a machine-readable format.
- Objection / restriction: object to or restrict certain processing activities.
- Withdraw consent: where processing relies on consent, you may withdraw it at any time.
- Do Not Sell / Do Not Share (CCPA): California residents may request that we do not sell or share their personal data. We do not sell personal data, but you may submit a request through our contact form regardless.
- Lodge a complaint: you may file a complaint with your local data protection authority.
To exercise any of these rights, email info@saasaf.ai or use the contact form with the topic "Privacy."
8. Data Retention
We retain personal data only as long as necessary to provide the Platform, comply with legal obligations, resolve disputes, and enforce our agreements. Account data is retained for the life of your account plus a reasonable archival period (typically 7 years for financial records). After that, data is deleted or anonymized.
9. Security
We use industry-standard technical and organizational measures to protect personal data, including TLS encryption in transit, encrypted databases at rest, access controls, audit logging, and regular security reviews. No system is perfectly secure. If a data breach affects your personal data, we will notify you and the appropriate regulators in accordance with applicable law.
10. International Transfers
SAASAF.AI is headquartered in the United States. If you access the Platform from outside the United States, your data will be transferred to and processed in the United States and other jurisdictions where our service providers operate. Where required, we use Standard Contractual Clauses or other approved transfer mechanisms.
11. Children's Privacy
The Platform is not directed at children under 18 and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to active account holders by email. The "Last updated" date at the top reflects the most recent revision.
13. Contact
Questions about this Privacy Policy or your data? Email our privacy team at info@saasaf.ai or send a message via the contact form with the topic "Privacy."