How it works For Businesses Cities Pricing Get Started
Legal

Privacy Policy

Last updated: March 2026
GDPR Compliant
Portugal / EU Law
01

Who We Are

Sakaloz ("we", "our", or "us") operates the Sakaloz mobile application and the website at sakaloz.com. We are a student discount platform based in Portugal that connects verified students with local businesses offering exclusive discounts.

For the purposes of the General Data Protection Regulation (GDPR) and Portuguese data protection law (Lei n.º 58/2019), Sakaloz acts as the Data Controller for the personal data you provide when using our services.

Contact: For any privacy-related questions or requests, you can reach us at sakaloz.hello@gmail.com or at our general address: sakaloz.hello@gmail.com.

02

Data We Collect

We only collect data that is necessary to provide you with our services. Below is a summary of what we collect and why.

Account & Identity Data

Data Purpose Required
Full name Display in profile and QR code Yes
Email address Account login and communications Yes
Phone number Optional profile field No
Password (hashed) Account security — never stored in plain text Yes

Student Verification Data

Data Purpose Required
Student ID photo Verify student status — reviewed by our team and then deleted Yes (for full access)
University name Displayed on profile No
Verification status Determine access level (verified / pending / rejected) System record

Payment Data

We use Stripe to process payments. We do not store your card number, CVV, or bank details on our servers. Stripe handles all payment data under their own privacy policy and PCI-DSS compliance. We only store your Stripe Customer ID and subscription status.

Usage & App Data

  • QR code redemption history (business name, timestamp, discount used)
  • Favorite businesses you have saved
  • App activity logs for bug fixing and security purposes (via Sentry)
  • Device type and operating system (collected by Sentry for crash reports)
03

How We Use Your Data

We use your personal data strictly for the following purposes:

  • Providing the service: creating and managing your account, generating QR codes, and processing discount redemptions.
  • Student verification: reviewing your student ID photo to confirm eligibility. Photos are deleted once verification is complete.
  • Subscription management: processing payments, managing renewals, and sending receipts via Stripe.
  • Customer support: responding to your questions and resolving issues.
  • Security and fraud prevention: monitoring for abuse, account lockouts, and suspicious activity.
  • Service improvement: using anonymised crash reports and usage data to fix bugs and improve the app.
  • Legal compliance: retaining records as required by Portuguese and EU law.

We do not sell your data. We do not use your personal data for advertising, profiling, or any purpose other than those listed above. We do not share your data with third parties for their own marketing purposes.

05

Sharing Your Data

We share your personal data only where necessary, and only with trusted service providers who process it on our behalf under strict data processing agreements:

Provider Purpose Location
Stripe Payment processing and subscription management USA / EU (SCCs)
Railway Database hosting and backend infrastructure USA / EU (SCCs)
Cloudinary Storage of profile and business images USA / EU (SCCs)
Sentry Error tracking and crash reporting USA (SCCs)
Vercel Website hosting USA / EU (SCCs)

Where providers are located outside the EU/EEA, we ensure appropriate safeguards are in place through Standard Contractual Clauses (SCCs) as required by GDPR Article 46.

We may also disclose personal data if required to do so by law, court order, or regulatory authority.

06

Data Retention

We keep your personal data only for as long as necessary to provide our services or comply with legal obligations:

  • Student ID photos — deleted within 14 days of verification decision (approved or rejected).
  • Account data — retained while your account is active. Deleted within 30 days of account deletion request.
  • Payment records — retained for 7 years to comply with Portuguese tax and accounting law (Código do IRC).
  • Redemption history — retained for 2 years for service purposes, then anonymised.
  • Crash logs and error data — retained for 90 days by Sentry, then automatically deleted.
07

Your Rights

Under the GDPR, you have the following rights regarding your personal data. You can exercise any of these rights by contacting us at sakaloz.hello@gmail.com. We will respond within 30 days.

Right to Access
Request a copy of all personal data we hold about you.
Right to Rectification
Correct any inaccurate or incomplete data in your account.
Right to Erasure
Request deletion of your account and personal data ("right to be forgotten").
Right to Restriction
Ask us to stop processing your data in certain circumstances.
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests.

You also have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) at cnpd.pt if you believe your data has been processed unlawfully.

08

Cookies

Our website (sakaloz.com) uses minimal cookies. We do not use advertising or tracking cookies.

Cookie Type Purpose Duration
Session token Essential Keep you logged in Session
Language preference Functional Remember your language choice 1 year
Vercel analytics Analytics Anonymous page view counts — no personal data 90 days

The mobile app does not use cookies. Authentication is handled via secure JWT tokens stored locally on your device.

09

Security

We take the security of your data seriously. Our technical measures include:

  • All passwords are hashed using bcrypt — we never store plain-text passwords.
  • All data transmitted between the app and our servers is encrypted via HTTPS/TLS.
  • JWT tokens are short-lived and automatically refreshed.
  • Rate limiting and account lockout mechanisms to prevent brute-force attacks.
  • OWASP security headers implemented on all API responses.
  • Student ID photos are stored in a private, access-controlled Cloudinary environment.
  • Real-time error and security monitoring via Sentry.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the CNPD within 72 hours and inform affected users without undue delay, as required by GDPR Article 33–34.

10

Children

Sakaloz is intended for use by university students and is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal information, please contact us at sakaloz.hello@gmail.com and we will delete it promptly.

11

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services or legal requirements. When we make material changes, we will notify you by email and update the "Last updated" date at the top of this page.

Your continued use of Sakaloz after a policy update constitutes your acceptance of the revised policy. If you do not agree with the changes, you may delete your account at any time from within the app.

12

Contact Us

If you have any questions about this Privacy Policy, want to exercise your rights, or have a complaint about how we process your data, please contact us:

Sakaloz — Privacy
Email: sakaloz.hello@gmail.com
General: sakaloz.hello@gmail.com
Website: sakaloz.com

We aim to respond to all privacy requests within 30 days. If you are not satisfied with our response, you may escalate your complaint to the CNPD at cnpd.pt.