Privacy Policy
Draft — last updated 7 July 2026
1. Who we are
Masilar (operated by [LEGAL ENTITY NAME], registered at [ADDRESS], RC/NIF [RC-NIF]) provides business-management software for vehicle-protection shops and film distributors, available at app.masilar.com. Contact: app@masilar.com.
This policy explains what personal data we process, why, and the rights you have under Algerian Law No. 18-07 on the protection of personal data and, where applicable, the EU General Data Protection Regulation (GDPR).
2. Two roles: controller and processor
For the account data of shop owners and staff who register with Masilar, we act as data controller.
For the data your shop stores about its own customers (names, phone numbers, vehicles, photos, invoices), your shop is the controller and Masilar is a processor acting on your instructions. Each shop's data is isolated from every other shop by database-level row security.
3. Data we collect as controller
Account data: email address, password (hashed by our authentication provider), display name, organization name, preferred language.
Billing data: your subscription plan, payment records, and — for card payments — a customer reference at our payment processor Stripe. We never store card numbers.
Technical data: server logs and error reports. Error reports are scrubbed of cookies, request bodies, emails and phone numbers before storage; session replay is disabled.
4. Data we process on your shop's behalf
Customer records your staff create: names, phone numbers, email addresses, free-text notes, vehicles and their history.
Photos: vehicle and inspection photos are stored in private buckets and served through short-lived signed links.
Documents: quotes, invoices, warranty certificates and — where you use electronic signatures — the signature record, which includes the signer's IP address and browser identifier retained as legal evidence of the signature.
Messages: where you enable notifications, customer phone numbers and message content pass through our SMS/WhatsApp provider (Twilio) and email provider (Resend).
5. Cookies and local storage
The public marketing site sets no analytics cookies and uses no trackers.
The application sets strictly-necessary authentication cookies (your login session) and stores interface preferences (theme, language) locally on your device.
Product analytics inside the application, where enabled, are limited to pseudonymous identifiers (user ID, organization ID) — never names, emails, phone numbers or prices.
6. Processors and sub-processors
We use the following providers to run the service: Supabase (database, authentication and file storage — hosted in [DATA REGION]), Vercel (application hosting), Stripe (card payments), Sentry (error monitoring, PII-scrubbed), PostHog (in-app product analytics, hosted in the United States), Twilio (SMS/WhatsApp), Resend (email), Yalidine and ZRexpress (delivery, where the wholesale module is enabled), Anthropic (AI assistant, beta features only), and Inngest (background jobs).
Where data leaves Algeria or the EU, we rely on the safeguards offered by these providers and on your instructions as controller of your shop's data.
7. Retention and deletion
Your shop's data remains available for the life of your account, including through non-payment locks — we do not delete data for non-payment.
You can delete customer records from within the product (deletion is blocked only where financial records reference them, to preserve accounting integrity).
Some records are append-only by design and cannot be silently deleted: the platform audit log and electronic-signature records. Where erasure is requested for these, we anonymize the personal elements instead of deleting rows, preserving the integrity of the chain.
Data-portability exports are available on request via app@masilar.com.
8. Your rights
Under Law 18-07 and, where applicable, the GDPR, you may request access, rectification, erasure (subject to §7), portability, and restriction of processing. Write to app@masilar.com. We respond within 30 days.
Shop customers should address requests to the shop that holds their data (the controller); we assist shops in fulfilling them.
9. Security
Isolation is enforced at the database layer with row-level security on every tenant table. Sensitive platform actions are written to a hash-chained, append-only audit log. Third-party courier credentials are encrypted at rest (AES-256-GCM). Access to production is restricted and logged.
No system is perfectly secure; we commit to notifying affected users of any breach without undue delay, in line with applicable law.
10. Changes and contact
We will announce material changes to this policy in the application and on this page. Continued use after the effective date constitutes acceptance.
Questions: app@masilar.com, or by post at [ADDRESS].