Sijilak

Privacy Policy

Last updated: July 12, 2026

1. Who we are

Sijilak is a CRM and order management platform for e-commerce brands. This policy explains what data we collect, why, and how we protect it.

Contact: hello@sijilak.com

2. Data we collect

Account data: name, email address, and password (stored encrypted) for each user a brand creates.

Business data entered or synced by brands: customers, orders, products, stock, expenses, conversations, and support tickets. This data belongs to the brand.

Technical logs: basic request logs needed to keep the service secure and reliable.

3. How we use data

We use data solely to provide the service: managing orders, inventory, conversations, and reports for each brand.

We never sell data, never use it for advertising, and never share it with third parties except the processors listed below.

4. Service providers (processors)

Supabase — database and authentication. Railway — application hosting.

Meta APIs (WhatsApp, Instagram, Messenger) — only when a brand connects its own channels, to send/receive its customer messages and read its page insights.

Google Analytics API — only when a brand connects its own Google Analytics property. We access read-only reporting metrics (such as sessions, page views, traffic sources, and aggregate device and location data) solely to display the brand's website statistics inside the system. We never modify the brand's Analytics account.

5. Google user data — Limited Use

Sijilak's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google Analytics data is only displayed to the brand that connected it, is never used for advertising, and is never sold or transferred to any other party.

We never use Google user data to train, fine-tune, or improve any artificial intelligence or machine-learning models.

A brand can disconnect its Google Analytics at any time from inside Sijilak, or revoke Sijilak's access directly from its Google Account permissions page (myaccount.google.com/permissions).

6. Data ownership, retention and deletion

Each brand fully owns its business data. Data is isolated per brand at the database level.

We retain a brand's data only for as long as its account is active. When a brand deletes specific data, closes its account, or requests deletion, that data is permanently removed from our systems within 30 days — except limited records we are legally required to keep.

A brand can request a full export or permanent deletion of its data at any time by contacting hello@sijilak.com.

7. Security

All traffic is encrypted (HTTPS). Passwords are hashed. Every brand's data is isolated with row-level security so no brand can ever read another brand's data.

8. Changes to this policy

We will post any changes on this page and update the date above. Material changes will be announced inside the system.

Back to home