Privacy Policy
Last updated: September 11, 2026
1. Who we are
Sijilak is a CRM and order management platform for e-commerce brands. This policy explains what data we collect, why, and how we protect it.
Contact: hello@sijilak.com
2. Data we collect
Account data: name, email address, and password (stored encrypted) for each user a brand creates.
Business data entered or synced by brands: customers, orders, products, stock, expenses, conversations, and support tickets. This data belongs to the brand.
Technical logs: basic request logs needed to keep the service secure and reliable.
3. How we use data
We use data solely to provide the service: managing orders, inventory, conversations, and reports for each brand.
We never sell data, never use it for advertising, and never share it with third parties except the processors listed below.
4. Service providers (processors)
Supabase — database and authentication. Railway — application hosting.
Meta APIs (Messenger, Instagram) — only when a brand connects its own Facebook Page and Instagram account, to receive and reply to its customers' messages inside Sijilak's inbox. We read the list of Pages the brand manages so it can pick one, the Page's name, and the public profile name and picture of a customer who messages it. We do not read Page insights, posts, comments, ads, or the brand's followers.
Google Analytics API — only when a brand connects its own Google Analytics property. We access read-only reporting metrics (such as sessions, page views, traffic sources, and aggregate device and location data) solely to display the brand's website statistics inside the system. We never modify the brand's Analytics account.
Google Gemini API — only when a brand's agent presses "Suggest reply" on a conversation, or uses the assistant or the order-text extractor. The text of that conversation and the customer's name are sent to Gemini to draft a reply the agent then reviews before sending. This is never used to train or improve any model.
Shipping carriers the brand connects itself (Bosta, ShipBlu, Aramex, Mylerz, OTO, DHL Express, FedEx) — only when the brand creates a shipment. The recipient's name, phone number and address are sent to the carrier the brand chose, so the order can be delivered.
5. Google user data — Limited Use
Sijilak's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Analytics data is only displayed to the brand that connected it, is never used for advertising, and is never sold or transferred to any other party.
We never use Google user data to train, fine-tune, or improve any artificial intelligence or machine-learning models.
A brand can disconnect its Google Analytics at any time from inside Sijilak, or revoke Sijilak's access directly from its Google Account permissions page (myaccount.google.com/permissions).
6. Data ownership, retention and deletion
Each brand fully owns its business data. Data is isolated per brand at the database level.
We retain a brand's data only for as long as its account is active. When a brand deletes specific data, closes its account, or requests deletion, that data is permanently removed from our systems within 30 days — except limited records we are legally required to keep.
A brand can request a full export or permanent deletion of its data at any time by contacting hello@sijilak.com.
To remove specifically what we hold from Meta — your Page token, the messages synced from Messenger and Instagram, and our webhook subscription on your Page — the steps are at sijilak.com/data-deletion.
7. Security
All traffic is encrypted (HTTPS). Passwords are hashed. Every brand's data is isolated with row-level security so no brand can ever read another brand's data.
8. Changes to this policy
We will post any changes on this page and update the date above. Material changes will be announced inside the system.