← Back to site

Privacy Policy

Last updated: 16 September 2026

This Privacy Policy explains how EPAIFA GENERAL TRADING L.L.C ("we", "us"), operator of SakerCRM, collects, uses, stores, shares, and protects information when you use our website and CRM. We are based in Dubai, United Arab Emirates. By using the Service, you agree to the processing described here.

1. Information we collect

We collect:

  • Account information you provide (name, phone, email, company, job title, country).
  • Business data you create or import in the CRM (leads, customers, quotes, follow-up notes, attachments, visit records).
  • Device and log data (IP address, browser, operating system, access time, operation logs).
  • Information from cookies and similar technologies (see section 11).
  • Data from platforms you choose to connect, including Google Gmail, Meta, TikTok, and WhatsApp, as described below.

2. How we use information

We use information to: provide and operate SakerCRM; authenticate users and keep the service secure; capture and assign ad leads; support follow-up, visits, quotes, and reporting; send service notices; provide support; comply with law. We do not sell your data. We do not use Google user data for advertising.

3. Your leads and data belong to you

Customer and lead records you put into SakerCRM are your data. We process them on your behalf as a service provider, only to operate the service and follow your instructions. You can export or request deletion at any time using the contact details below.

4. Sharing and sub-processors

We do not sell personal information. We share it only: with your consent; with sub-processors needed to run the service; when required by law; or to protect legal rights. Current sub-processors include Alibaba Cloud (hosting in Dubai, UAE), Google LLC (Gmail API and optional system email), Meta Platforms, ByteDance / TikTok, OpenAI / DeepSeek for optional AI features, DeepL for optional inbox translation, and Deepgram / AssemblyAI / Alibaba Cloud Model Studio for transcribing voice recordings your team uploads. Gmail message content is never sent to AI services. Inbox message text is sent to our AI or translation provider only where your workspace has enabled the AI follow-up summary or the translate action — see section 6.

5. Google Gmail API (mailbox sync and sending)

If you, as a salesperson using SakerCRM, choose to connect your Gmail account in your personal settings, we access that Gmail account to (a) bring your correspondence with CRM customers and leads onto their cards, and (b) let you send or reply from the CRM using your own Gmail identity. Connecting is optional, started by you, and can be disconnected at any time.

Scopes requested. Two scopes only:

  • https://www.googleapis.com/auth/gmail.readonly (restricted) — read messages in order to match and display customer correspondence.
  • https://www.googleapis.com/auth/gmail.send (sensitive) — send or reply from the CRM using your connected Gmail address as From.

We do not request modify, delete, or full-mailbox control (gmail.modify, gmail.compose, or https://mail.google.com/).

What we read — and what we do not. We work in two stages. First we retrieve message headers only (From, To, Cc, subject, timestamp) and match those addresses against customers and leads already stored in your own tenant. Only if there is a match do we retrieve the body and attachments. For messages that do not match any customer or lead — including personal mail, vendor mail, and newsletters — we do not retrieve the full body or attachments, do not store them, and do not display them. Google’s header response includes a short snippet that cannot be turned off; that snippet is held in memory for the address check, not read for content, then discarded and never stored. For matched messages only, we store: subject, body, sender and recipient addresses, timestamp, and attachments.

How we use Gmail data. Read data is used solely to display correspondence on the matched customer or lead card. Send is used solely so you can email those customers or leads from SakerCRM as yourself. Mail is sent only from your connected Gmail, and only to customers or leads you own. Managers may view the timeline; they cannot send on your behalf. There is no bulk send and no mailbox export.

Limited Use. SakerCRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We do not use Gmail data for advertising, retargeting, or credit decisions, and we do not sell or transfer it to data brokers, information resellers, or any other third party except as allowed by that policy.
  • Saker personnel do not read your Gmail data, except (a) where you have given affirmative agreement to view specific messages, (b) where it is necessary for security (for example investigating a bug or abuse), (c) where it is necessary to comply with law, or (d) where data has been aggregated and anonymised for internal operations.
  • We do not submit Gmail message content or attachments to any AI or large-language-model service, including the AI features described elsewhere in this Policy.

Who inside your company can see it. Matched correspondence is shown on the customer card to the owner of that record and that person’s manager, under the same permission model as other CRM customer data. Connecting your mailbox is your agreement to this. If you do not want your manager to see that correspondence, do not connect Gmail. Data is never visible to another tenant.

Security and storage. OAuth access and refresh tokens are encrypted at rest and used only server-side to call the Gmail API. Message content and attachments are stored in the Alibaba Cloud Dubai (UAE) Region and isolated per tenant. Message bodies are not written to application logs. Data in transit uses HTTPS/TLS.

Disconnecting. You can disconnect in SakerCRM personal settings, or revoke access at myaccount.google.com/permissions. We then stop syncing and sending, and delete stored OAuth tokens. Correspondence already synced stays in the tenant’s customer records (it belongs to the customer relationship). To delete that as well, use the request path below.

Data deletion requests. Email contact@sakercrm.com with the subject Gmail data deletion request, from the connected Gmail address or your tenant administrator account. We confirm within 5 business days and complete deletion within 30 days, unless retention is required by law or for security incident response.

6. Advertising and messaging platforms (Meta, TikTok, WhatsApp)

If you connect TikTok Ads, Meta ads, Facebook Page / Instagram messaging, or WhatsApp, we process only the data those platforms return under the permissions you grant — for example advertiser IDs, campaign metrics, lead-form submissions, and messages sent to a connected business account — so your team can follow up inside SakerCRM. We do not use that data for our own advertising. You must have a lawful basis to contact your leads. You can disconnect each channel in the CRM or in the platform’s own settings.

TikTok direct messages (Business Messaging API) — not yet live. We have applied to TikTok for access to the Business Messaging API and have not yet been granted it. Once granted, and once a workspace connects its own TikTok Business Account, we will receive direct messages sent to that account so the team can reply from the SakerCRM inbox. We will only ever reply to a user who messaged the business first, within TikTok’s permitted reply window: SakerCRM offers no bulk send, no broadcast and no marketing outreach over TikTok messaging. Message bodies are encrypted at rest; a conversation is linked to a CRM record only when a staff member confirms it, and only from a phone number or email the user typed into the chat — never from TikTok identity. Until access is granted we neither receive nor store any TikTok direct-message data. Full detail is in the in-product policy at app.sakercrm.com/privacy.html (section 5.4).

Optional AI and translation processing of inbox messages. Two optional features send the text of a conversation to a sub-processor. AI follow-up summary: where your workspace enables it, the text of recent messages is sent to our LLM provider to draft a follow-up note — only text is sent, never attachments, images, audio or documents. Inbox translation: where a translation provider is configured, and only when a user presses translate on a specific message or draft, that one message or draft is sent. This applies to WhatsApp, Facebook, Instagram and (once live) TikTok alike. We do not use message content to train any AI model.

To request deletion of Meta Marketing API, TikTok Marketing API, Meta messaging, or TikTok messaging data we hold, email contact@sakercrm.com with subject Meta data deletion request, TikTok data deletion request, Meta messaging data deletion request, or TikTok messaging data deletion request, and enough detail to locate the account or conversation.

7. Security

We use HTTPS/TLS in transit; role-based access control; tenant isolation by tenant ID; encryption of OAuth tokens at rest; and audit logs of critical actions. No system is perfectly secure. If a personal-data incident occurs, we will notify you as required by law.

8. Where data is stored and international transfers

Primary storage is the Alibaba Cloud Dubai (UAE) Region. Some sub-processors (including Google, OpenAI, and DeepSeek) operate servers in other countries. Your information may therefore be processed outside your country. If you do not agree to such transfers, some features may be unavailable.

9. Retention

We keep data while your account is active. After account deletion we keep it for 15 days for possible recovery, then delete or anonymise it, unless a longer period is required by law (for example certain logs).

10. Your rights

Subject to applicable law (including the UAE PDPL, and where applicable the EU GDPR or PRC PIPL), you may request access, correction, deletion, export, restriction, withdrawal of consent, or account closure. Contact contact@sakercrm.com. We respond within the time limits required by law, and in any event within 15 business days of receipt.

11. Cookies, children, and changes

We use essential cookies to run the site and, if you accept, analytics cookies (including Google Tag Manager / Google Analytics on this website) to understand traffic. You can decline analytics cookies or control them in your browser. The service is for businesses and is not directed to children under 18. We may update this policy and will post the new date above. Material changes will be notified more prominently.

12. Contact us

EPAIFA GENERAL TRADING L.L.C — 504, Al Khor Building, Baniyas Road, Deira, Dubai, UAE. Email: contact@sakercrm.com · WhatsApp/Phone: +971 58 581 4667. We have not appointed a dedicated DPO. You may also contact the UAE Data Office or your local data protection authority.