Privacy Policy

Last updated: 10 August 2026

Powix FZE ("Powix", "we", "our", "us") is committed to protecting your personal data. This Privacy Policy has two parts: Part A for merchants who install the Powix app for Salla (and, through them, their customers), and Part B for visitors to this website. It explains what data we collect, how we use it, and your rights under applicable law, including the EU General Data Protection Regulation (GDPR) and Saudi Arabia's Personal Data Protection Law (PDPL, 2023).

Part A — The Powix App for Salla Merchants

This part applies if you are a merchant using the Powix app, installed through the Salla App Store, or a customer of such a merchant.

Powix is a merchant revenue protection platform for stores on the Salla e-commerce platform. It comprises two modules:

  • COD Guard — automated confirmation of cash-on-delivery (COD) orders before fulfilment, with revenue-protection reporting shown in the store's currency. Confirmation messages are delivered to the end customer over WhatsApp, live today, through the official WhatsApp Business Platform. A customer confirmation scoring feature is planned as a future addition; the sections below describe how it will process data once introduced, so merchants and their customers know in advance.
  • Cart Recovery — automated email reminders for abandoned carts, live today. WhatsApp cart recovery messaging is planned as a future addition.

In providing the service, we process personal data belonging to the merchant's customers ("end customers") — the people who place orders or add items to a cart on the merchant's store.

For end customers' data, Powix acts as a service provider processing data on the merchant's behalf, not as the data controller. The merchant's own privacy policy, and their relationship with their customers, governs that data primarily; we process it only to deliver the modules the merchant has enabled.

What we collect — From the merchant's Salla store, via Salla's official OAuth authorisation and strictly limited to the scopes the merchant grants:

  • Store details: name, contact email, domain, currency.
  • Order event data: order reference, order status, and payment status, as reported by Salla's order events — used to stop any recovery messaging once an order is placed or paid. For COD orders, where the merchant has enabled COD Guard, we also process the order details needed to run the confirmation service: order total, currency, payment method, and the customer contact details attached to the order (name, email, phone number).
  • Abandoned cart data (Cart Recovery): cart contents (product name, price), cart total, checkout link, and the customer contact details attached to the cart — only when Salla reports them as part of the cart data.

Operational data we generate:

  • A log of every event our systems receive from Salla and our messaging providers, kept for diagnosability. Access tokens and refresh tokens are never stored in this log.
  • Scheduling and delivery status of confirmation and recovery messages (sent, failed, cancelled).
  • COD Guard confirmation outcomes (confirmed, no response, declined).
  • Unsubscribe requests, recorded per store so we stop emailing that address on the merchant's behalf.

We do not collect payment card details, passwords, or browsing behaviour beyond what Salla's order and cart events already include.

Minimal permissions by design — We request only the Salla authorisation scopes required for the modules the merchant actually uses, and we do not read or retain store data beyond what those modules need. This is a deliberate design principle of the product.

Why we process it — Solely to run the merchant revenue protection service: confirming COD orders with the merchant's customers before fulfilment, scheduling and sending cart recovery reminders, computing the metrics and reporting shown to the merchant, and letting the merchant manage their account.

Payment status — a protective use only — We process each order's payment status for one purpose: making sure we never send a recovery or confirmation message to a customer whose order is already paid. This is a firm product rule, not an optional setting.

Customer confirmation scoring (planned feature — not yet available) — A future version of COD Guard will calculate a confirmation score indicating how likely a COD order is to be successfully confirmed and delivered. The score will be based solely on that customer's order history with the merchant's own store (for example, previously confirmed, cancelled, or refused COD orders). It will be presented to the merchant as decision support: Powix will not automatically cancel, refuse, or block any order or customer, and the merchant will always make the final decision. Scores will never be shared between different merchants' stores, never combined across stores, and never used for any purpose other than helping that merchant assess their own COD orders. An end customer will be able to contest a decision based on the score, or request more information about it, through the merchant or via support@powix.io. Today, no scoring is computed, and Powix does not read or write anything on the merchant's orders via Salla's API beyond the order events described above — our order permissions are read-only, and COD Guard never cancels or modifies any order in Salla: the decision always stays with the merchant.

Who else sees this data (subprocessors)

  • Supabase (database, hosted on AWS, us-east-1 region) — stores all the data above.
  • Vercel — hosts and runs the application.
  • Brevo — delivers confirmation and recovery emails on the merchant's behalf.
  • 360dialog / Meta (WhatsApp Business Platform) — delivers COD order confirmation messages over WhatsApp on the merchant's behalf. The data processed is the end customer's phone number and the content of the confirmation message (which includes the order reference and total). WhatsApp cart recovery messages will be delivered through the same subprocessor if and when that planned feature is enabled.
  • Stripe — processes the merchant's subscription billing. Stripe never receives end customers' order or cart data.
  • Anthropic (Claude) — powers the in-dashboard AI support assistant; processes the merchant's support-chat messages to generate replies. Never receives end customers' order or cart data.

We do not sell data, and we do not share it with anyone beyond what is needed to run the service.

End customers' rights — End customers can stop receiving recovery and confirmation emails at any time via the one-click unsubscribe link included in every email — no account or login required. For any other request (access to their data, correction, or deletion), they — or the merchant, on their behalf — can contact support@powix.io and we will act on it.

How long we keep it — We keep cart, order-event, and messaging records for as long as the merchant's app installation is active, so recovery sequences and reporting keep working. If a merchant uninstalls the app, they can contact support@powix.io to request deletion of associated data.

Support assistant conversations — The Powix dashboard includes an AI support assistant that answers merchants' questions about the app. When a merchant uses it, we store the conversation — the merchant's messages and the assistant's replies — to provide support, improve our answers, and keep a record of what was discussed. These records are tied to the merchant's account only and do not contain end customers' personal data unless the merchant types it in. To generate answers, the merchant's messages are sent to our AI provider, Anthropic (listed under subprocessors above). We keep support conversation records for as long as the merchant's app installation is active; they are deleted automatically when the merchant uninstalls the app, and a merchant can request earlier deletion at any time via support@powix.io.

Part B — Our Website

The rest of this policy applies to visitors of this website (powix.io) — for example if you fill out a contact form, request a demo, or browse the site.

1. Data Controller — The data controller is Powix FZE, registered at Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates (License No. 4424795.01), represented by Yamani Djaouat. Contact: support@powix.io.

2. Data We CollectIdentity and Contact Data: full name, email address, phone/WhatsApp number, and company name provided during registration or contact forms. Business Data: e-commerce platform details (e.g., Salla store name), monthly revenue range, and business type. Usage and Analytics Data: pages visited, features used, session duration, device and browser type, IP address, and referral source. Communication Data: messages sent through our contact form or email correspondence. Billing Data: transaction identifiers and subscription status. We do not store full card numbers — all card data is handled by Stripe.

3. How We Use Your Data — To provide, maintain, and improve our merchant revenue protection services (COD Guard and Cart Recovery); to process subscription payments and send billing notifications; to respond to enquiries and provide customer support; to send service-related communications and product updates; to analyse usage patterns and improve platform performance and user experience; to comply with our legal obligations; and to send marketing communications where you have given consent (you may withdraw consent at any time).

4. Legal Bases for ProcessingContract: processing necessary to perform our contract with you. Legitimate Interests: improving our services, fraud prevention, and security. Consent: marketing communications and optional analytics. Legal Obligation: where required by applicable law.

5. Data Storage and Security — Your data is stored in Supabase (PostgreSQL), a managed cloud database service, hosted on AWS in the us-east-1 (United States) region. Supabase applies industry-standard encryption at rest and in transit. We implement appropriate technical and organisational security measures to protect your data against unauthorised access, loss, or destruction.

6. Payment Data — All payment transactions are processed by Stripe, Inc., which is PCI-DSS Level 1 compliant. Powix does not store, access, or process raw card numbers or full payment credentials. Stripe's privacy practices are governed by Stripe's Privacy Policy.

7. Third-Party Service Providers — We share data with trusted service providers only where strictly necessary to deliver our services: Stripe, Inc. — payment processing; Supabase, Inc. — database infrastructure and authentication; Vercel — application hosting; Brevo — transactional and marketing email delivery; Anthropic — AI support assistant (dashboard only). All third-party providers are bound by data processing agreements and applicable data protection law.

8. Your Rights — Access; rectification; erasure; portability; objection; restriction; withdrawal of consent. To exercise any right, contact us at support@powix.io. We will respond within 30 days.

9. Cookies — We use cookies and similar tracking technologies. For full details, please see our Cookie Policy.

10. Data Retention — Account and subscription data: retained for the duration of the subscription plus 5 years for legal and accounting purposes. Contact form enquiries: retained for 2 years. Analytics data: retained in aggregated form for up to 3 years. Billing records: retained for 7 years in accordance with UAE financial regulations.

11. Cross-Border Data Transfers — Your data may be transferred to and processed in countries outside your country of residence, including the UAE, USA, and EU. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms under Saudi Arabia's PDPL.

12. Children's Data — Our services are not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, contact us immediately at support@powix.io.

13. Changes to This Policy — We may update this Privacy Policy from time to time. Material changes will be communicated via email or platform notification. Continued use of our services following the update constitutes acceptance of the revised policy.

14. Contact and Data Requests — For all privacy-related enquiries and data subject requests: support@powix.io.