Safiالعربية

Privacy policy

Last updated: 24 July 2026

Safi is a profit-analytics tool for merchants. This page states exactly what data we read, why, how long we keep it, and how you delete it.

What we read from your Salla store

When you install the app, Salla grants read-only scopes. Safi cannot create, change, or delete an order, and cannot alter any setting in your store.

  • Basic store information: name, currency, time zone.
  • Orders: amounts, payment method, status, line items, and any discount codes used. Order data includes the customer name, shipping address, and phone number as Salla sends them.
  • Products and variants: names, prices, and costs where recorded.
  • Shipments and settlements: to compute shipping cost, returns, and amounts collected.

What we read from your advertising accounts

If you connect an ad account (Meta, Snapchat, TikTok, Google), Safi reads campaign-level spend and performance reports only: amount spent, currency, date, and campaign name and id.

We do not publish ads, do not create or pause campaigns, do not access audience lists or customer data inside those platforms, and never upload anything to them. The access requested is read-only.

You can also enter spend manually or upload it as a CSV without connecting any account at all.

Why we read it

For one purpose: to compute your net profit and show it to you. Every figure on the dashboard is derived from this data.

We do not sell your data, do not share it with advertisers, do not use it to train models, and do not use it for anything other than showing you your own store analytics.

Where it is stored

On servers in Frankfurt, Germany (EU). Access tokens for your store and ad accounts are encrypted at rest with AES-256-GCM and are never written to logs.

All traffic to the application is encrypted with HTTPS.

How long we keep it, and how you delete it

While the app is installed, we keep your data so your historical analytics stay available.

When you uninstall the app from your store, syncing stops immediately, you have thirty days to export your data, and it is then permanently deleted with a proof-of-deletion record. You do not have to ask — this is the default.

To delete sooner, or to request a copy of your data, write to hello@safi.corearch.dev. We respond within thirty days at the latest.

Your rights

Under Saudi Arabia's Personal Data Protection Law you have the right to access your data, correct it, request its deletion, and receive it in a portable format.

For any of these: hello@safi.corearch.dev

Changes to this policy

If what we read or how we use it changes, we update this page and change the last-updated date above it before the change takes effect.