Legal
Privacy policy
What we hold, why we hold it, and what you can ask us to do with it.
Last updated: 16 September 2026
Who this covers
This policy covers two different things, and it is worth keeping them apart. The first is this website, which anybody can read. The second is the Sanad application, which a business signs into and uses to keep its books.
On the website you are a visitor. In the application you are either our customer or somebody our customer has given an account to — and in that case the business is responsible for its own records, and we hold them on its behalf.
The website
This page sets no cookies, runs no analytics, and embeds nothing from anybody else. The typefaces are served from our own domain rather than from a font service, so reading this page tells no third party that you were here.
The only thing stored in your browser is which language you chose, kept so the page opens in that language next time. It never leaves your device and we cannot read it.
The contact form does not send anything to us. It opens your own mail application with the message written out, and you decide whether to send it. If you do, we receive the email, and we keep it for as long as the conversation is useful.
The application: what we hold
When a business subscribes, we hold two kinds of information.
- Account information — the business name, the contact details of the people who sign in, their usernames, and a cryptographic hash of each password. We never hold a password itself.
- Business records — whatever the business enters: its customers and suppliers, invoices, payments, stock, employees and payroll. This is the business’s own data. We hold it so the software can work, and for no other purpose.
- Technical records — server logs of requests, and an audit trail inside each business’s own database showing who changed which record and when. The audit trail exists because accounting requires it.
Why we hold it
To run the service the business has asked us to run, to keep it secure, to bill for it, and to answer questions when something goes wrong. We do not profile anybody, we do not build advertising audiences, and we do not sell or rent anything to anybody. There is no arrangement under which we could.
Where it lives, and who else can see it
Each business has its own database rather than a row in a shared one. Backups are per business, restores are per business, and one customer’s data is not in the same table as another’s.
The only third party with access to the servers is the hosting provider, which supplies the machines and the storage and does not use what is on them.
We do not disclose customer data to anybody else unless the customer asks us to, or unless a court with jurisdiction over us orders it — and if that happens we will tell the customer, unless we are lawfully prevented from doing so.
How long we keep it
For as long as the subscription runs. Every business database is dumped nightly and copied off the server; daily copies are kept for a month and monthly copies for a year.
When a subscription ends, the business can take a full export of its own database. After that we delete the live database and let the backups age out on the schedule above.
Accounting records inside the application are append-only by design. A mistake is corrected by a reversal that stands beside the original rather than by deleting the original. That is a requirement of double-entry bookkeeping, not a choice we made about your privacy, and it means individual entries cannot be erased on request while the books are live.
Security
Traffic is encrypted in transit. Passwords are hashed with a memory-hard algorithm. Access inside the application is governed by roles, down to individual permissions, and every write is attributed to a named user — the database refuses a write that has nobody behind it.
No system is beyond reach. If we ever have reason to believe customer data has been exposed, we will say so, to the affected customers, without waiting to be asked.
What you can ask for
You can ask us what we hold about you, ask for a copy of it, ask us to correct it, or ask us to delete it. If you are a user of a business’s account rather than our direct customer, we will pass the request to that business, because the records are theirs.
Write to the address at the end of this page. We answer within thirty days, and usually much sooner.
Changes
If this policy changes in a way that matters, we will date the new version and tell subscribing customers by email. We will not make a quiet change and leave you to find it.