Privacy for the store app
Last updated: 26 September 2026
This notice covers the Sahifa app for online stores, starting with the Sahifa app on the Salla App Store. It makes invoices, packing slips, receipts and quotations for a store's orders. The general privacy notice covers the rest of sahifa.dev.
The short version
The app can only read orders and shipping details; it cannot change anything in your store. Order and customer details are fetched from Salla when you make a document, used to make it, and not stored. Everything runs on our server in Jeddah, Saudi Arabia. When you remove the app, its access to your store and your settings are deleted at once.
Who is responsible
For the order and customer details in your store, you, the merchant, are the controller, and Sahifa processes them on your behalf, only to make the documents you ask for. For your own store account with the app (settings, plan, usage), the responsible party is Yimello LLC, UAE Business Center, Al Messaned, United Arab Emirates, Trade License 243080201. Contact: support@sahifa.dev.
What the app can access
When you install the app, Salla grants it read-only access to:
- Orders: order number, date, status, items, prices, tax, discounts, totals, payment method, order notes, gift message, and the tax invoice number and QR code that Salla issued;
- Shipping: the customer's name, phone number and delivery address, the courier and the tracking number;
- Store details: store name, logo, VAT and commercial registration numbers, address and contact details, to print them on your documents.
The app asks for no write permission. It cannot create, change or delete orders, products, customers or settings in your store.
What is stored, and for how long
Order and customer details: not stored
They are fetched from Salla when you open the order list or make a document, held in the server's memory while the document is made, and returned to your browser as a PDF. They are not written to disk, logged or kept afterwards. The PDF is not kept on our server either.
Kept while the app is installed
- your store's ID on Salla and its name;
- the access keys Salla gives the app, encrypted (AES-256-GCM) with a key that exists only on our server;
- your settings: design, document language, colour, whether to show the logo and the order notes;
- your plan, and the number of documents made each month, to apply the plan's allowance.
Store details (name, logo, tax numbers, address) are held in the server's memory for up to 10 minutes, so that Salla is not asked for them for every document.
When you remove the app
Salla tells us at once, and the access keys, the store name and your settings are deleted. We keep only your store's ID, the dates of installation and removal, and the monthly document counts, because they are the record of what was billed. The encrypted backups that still contain the deleted data expire within 35 days.
Technical logs
For each request the server records the method, the path without any parameters, the status code, the time taken and, for app events, the event's name. For an unexpected error, only its type is recorded. Order details, customer details, access keys and IP addresses are not recorded. The log has a fixed maximum size and overwrites its oldest entries.
Where it is processed
The app runs on Oracle Cloud in the Jeddah region of Saudi Arabia. Order and customer details travel only between Salla and our server in Jeddah, and from there to your browser. The database and its encrypted backups are kept in the same region. The app page in your Salla dashboard loads its files only from our server, not from outside content networks. Details of every location are in the data residency statement.
Who else receives it
No one. Oracle Cloud Infrastructure hosts the server in Jeddah. Subscriptions to the app are billed by Salla, and Sahifa never sees your payment details. If you write to support, your email and our reply pass through our email provider, Rackhost, in Hungary (European Union). Order and customer details are never sent to email, to AI services or to any other party, and are never sold or used for advertising.
Security
All traffic uses HTTPS. Events from Salla are accepted only with a valid signature. The app page works only inside the Salla dashboard, and only after Salla confirms which store is signed in; each of its requests carries a short-lived session tied to that store, so one store can never see another store's orders. The server that makes documents cannot reach private or internal networks.
Your rights, and your customers' rights
You can ask what is held about your store, and ask for it to be corrected or deleted, by writing to support@sahifa.dev; you will have an answer within 30 days. Because the app does not store your customers' details, a customer's request about their data is answered from your store on Salla. Depending on where you are, you may also have rights under local law, such as the Personal Data Protection Law in Saudi Arabia.
Changes
If this notice changes, the date at the top changes with it. If a change affects what the app can access or keep, we will tell you in the app before it takes effect.