Privacy Policy

Being finalized. This describes our current practices and will be updated before general release.

Your business data stays private

Your invoices and business records belong to your organization.

Sarebel does not share your invoices, suppliers, customers, prices, purchasing information, document contents, or other confidential business records with other stores or Sarebel customers in an identified or reasonably re-identifiable form.

Other Sarebel customers cannot search, view, access, compare, retrieve, or download your organization’s information.

Sarebel does not sell your Customer Content, use it for advertising, or use your documents to train general-purpose artificial-intelligence models for other customers.

Sarebel is a business tool for independent store owners: capture the invoices you get from your suppliers, have them read automatically, keep them in one place, and see when a supplier’s prices move. It is built for business operators (store owners, managers, and staff), not consumers. This policy explains what we collect, why, and the controls you have.

What we collect

Account data. Your name, email address, role, and the store account you belong to. Passwords are stored only as salted hashes.

Invoice records. The photos and PDFs of supplier invoices you capture, and the details we extract from them (supplier, date, amounts, line items). These are your business records, attributed to the store that uploaded them.

Security and diagnostics. Sign-in attempts and password changes are kept in a security log with IP and device context. Error reporting, when enabled, is configured not to send personally identifying values.

Payment details. Subscription checkout runs on Stripe’s hosted pages; Sarebel does not receive or store your card number.

What we do not do

  • No advertising, ad tracking, or sale of personal data.
  • No third-party analytics SDKs in the mobile app.
  • Your invoice records are never shared with other stores.

How data is shared

Data moves only as running the product requires. The service providers we rely on are: hosting and database hosting; AWS (for the AI that reads your invoices); Stripe (payments, when enabled); and an email provider (to send the monthly invoice email you can turn off in Notifications). AI features are assistive: they help read and summarize your invoices and are never the system of record.

Retention and deletion

You can delete individual invoices at any time. You can export a month’s invoices as a ZIP from the Invoices screen. If you close your account, contact us and we will remove your personal account details; invoice records you chose to keep remain yours to export or delete.

Security

We use hashed passwords, HTTPS-only signed sessions, login rate limiting, strict isolation so one store’s data is never visible to another, parameterized database access, and encrypted storage of secrets. To report a vulnerability, email support@sarebel.com.

Contact

Questions about this policy? Email support@sarebel.com.