1. Who We Are
Saintara is operated by a sole trader based in the United Kingdom ("we", "us", "our"). Our postal address is Office 2069, 60 Tottenham Court Road, Fitzrovia, London W1T 2EW, United Kingdom. You can contact us about privacy at [email protected].
We play two roles, depending on the data:
- Controller — for the data about you as our customer: your account, billing, and use of our website and client portal. We decide how and why this data is used.
- Processor — for the content of your website that is sent to us for translation, and for data about your website's visitors that reaches us as a result. We handle this on your behalf and on your instructions, to provide the Service. You remain responsible for that content and for telling your visitors about it.
The Service is intended for people aged 18 or over, acting for themselves or their organisation. It is not offered to people in the European Union, and we do not knowingly accept registrations from there.
2. What Data We Collect
We collect only what is necessary to provide the Service:
- Account data — your email address, your password (stored only as a secure hash, never in readable form), your organisation name, and the website domains you add
- Billing data — your subscription plan, billing period, and a Stripe customer and subscription reference. Stripe collects your card details and billing address; we never see or store your full card number
- Provider API key — for Bring-Your-Own-Key plans, your translation provider's API key, stored encrypted and used only to send your translation requests to that provider. It is never written to our logs
- Website content sent for translation — the text on your web pages that our snippet sends to us, and the translations we return. This text may include personal data if your pages contain it (for example names, reviews or contact details). We cache it to avoid translating the same text twice (see section 7)
- Translation overrides — any replacement translations set for your website
- Consent records — which version of our Terms and this Policy you accepted, and when
- Usage data — how many words or characters you translate each billing period, used to apply your plan's limits
- Technical data — IP addresses and request details (time, path, and your website's domain) in our server logs, used for security and debugging. When you register, we also check the country your connection comes from, to apply our eligibility rules in section 1
When a visitor to your website uses our translation feature, their browser connects to our service, so we also receive their IP address and the page text sent for translation. We use this only to provide the Service to you, to prevent abuse, and to keep it secure. Our logs do not record page text as readable text, only its length and a short fingerprint.
3. Legal Basis for Processing
Where we are the controller, we rely on the following legal bases under the UK GDPR:
- Contract (Art. 6(1)(b)) — your account data, billing data, provider key and usage data, to provide the Service you signed up for
- Legitimate interests (Art. 6(1)(f)) — server logs and rate limiting for security and fraud prevention; the registration country check, to apply our eligibility rules; and keeping records of which Terms you accepted, so we can show what was agreed
- Legal obligation (Art. 6(1)(c)) — keeping billing records for as long as UK tax law requires
Where we act as a processor for your website content, you decide the legal basis for that processing.
4. How We Use Your Data
- To authenticate you and maintain your session
- To process translation requests on your behalf (using your provider key for Bring-Your-Own-Key plans, or our own provider accounts for Managed plans)
- To measure your usage against your plan's limits and warn you when you are close to them
- To manage your subscription and take payments through Stripe
- To send transactional emails (verification, password reset, trial, usage, billing, and changes to our Terms)
- To check eligibility at registration, and to investigate security incidents or abuse
We do not use your data for advertising or profiling, we do not sell it, and we do not make decisions about you by automated means that have legal or similarly significant effects.
5. Third Parties and International Transfers
We share data with the following service providers only as necessary to provide the Service. Each processes it under its own data protection terms:
- Translation providers — DeepL, OpenAI, Amazon Translate or Google Translate, whichever applies to your plan and settings. Your website text is sent to the provider to be translated. On Bring-Your-Own-Key plans, the provider processes it under your account with them and their terms with you.
- Stripe — payments. Handles your card details, billing address and subscription billing. We receive only a customer and subscription reference and payment status.
- Resend — delivers our account, security and billing emails to you.
- Cloudflare — protects and routes all traffic to our website and service, so it processes IP addresses and request data.
- Hetzner — hosts our servers and databases, located in Germany.
International transfers. Some of these providers (including Stripe, Resend, Cloudflare, Amazon, Google and OpenAI) are based in, or may process data in, the United States or other countries outside the UK. Where personal data is transferred outside the UK, we rely on the provider's safeguards recognised under UK law, such as the UK International Data Transfer Addendum or the UK–US data bridge where the provider is certified. Germany, where our servers are hosted, is recognised by the UK as providing adequate protection. You can ask us for more information about these safeguards.
6. Cookies and Local Storage
We use only cookies and browser storage that are strictly necessary for the Service or that remember a choice you made. We do not use analytics, advertising or tracking cookies.
- sb_client_token (cookie) — keeps you signed in to the client portal. HttpOnly, secure, expires after 7 days.
- sb_token (cookie) — keeps our own staff signed in to the admin panel. HttpOnly, secure, expires after 7 days.
- Local storage in your browser — remembers that you dismissed our cookie notice or a notice about updated Terms, and your light or dark theme choice in the portal.
- On your website — our snippet stores the language your visitor chose, and your page's original language, in their browser's local storage, so the choice carries across pages.
Under the Privacy and Electronic Communications Regulations (PECR), storage that is strictly necessary to provide a service the user asks for does not need consent. Web fonts are self-hosted, so no data about your visit is sent to a font provider.
7. Data Retention
- Account data — kept for the life of your account, and deleted within 30 days of you closing it
- Consent records — deleted together with your account
- Translation cache — deleted when you delete your account, and otherwise removed automatically after 90 days without being requested. If shared caching has been enabled for your account, translations of common text may be stored in a cache shared across customers. Those entries are not linked to your account, so they cannot be deleted with it, and are removed after 90 days without being requested by any customer
- Server logs — kept for up to 30 days
- Billing records — kept for as long as UK tax law requires (currently at least five years after the relevant tax return deadline)
Stripe keeps its own records of your payments under its own retention policy.
8. Your Rights
Under the UK GDPR you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your account and personal data
- Portability — receive your data in a structured, machine-readable format
- Restriction — ask us to limit how we use your data
- Objection — object to processing based on our legitimate interests
To exercise any of these rights, contact us at [email protected]. We will respond within one month. If you are a visitor to one of our customers' websites, please contact that website first, as they control that data; we will help them respond.
You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
9. Data Security
We take appropriate technical and organisational measures to protect your data, including encrypting provider API keys at rest (AES-256-GCM), enforcing HTTPS, storing passwords only as secure hashes, rate limiting, and keeping readable page text out of our logs. No method of transmission over the internet is completely secure, so we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will tell you about material changes by email or in the portal at least 14 days before they take effect, and may ask you to confirm them when you next sign in. Continued use of the Service after changes take effect constitutes acceptance. Previous versions are linked at the top of this page.
11. Contact
For privacy questions or to exercise your rights: [email protected], or write to us at Office 2069, 60 Tottenham Court Road, Fitzrovia, London W1T 2EW, United Kingdom.
We are registered with the Information Commissioner's Office as a data controller. If you would like our ICO registration number, or any other information about us that is not published here, contact us at [email protected] and we will provide it.