Privacy Policy

Last updated: 12 August 2026

This policy explains what data Seyaq collects, how we use it, and your rights. We aim to align with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data

1. Who controls your data

Seyaq operates from Sharjah, United Arab Emirates - and your contract for the Service is with Seyaq personally and legally.

In case any sales tax, VAT or equivalent is due in your own country, our payment provider acts as merchant of record and shows it at checkout.

Legal notices and questions: legal@seyaq.ai

Privacy requests: privacy@seyaq.ai

2. Data we collect

Account data: your name, email, business name and locale. Store data: catalog content, prices, availability, store domain and the OAuth/access tokens you authorize (stored encrypted). Usage data: logs of API and MCP tool calls (with arguments redacted) and audit results.

3. How we use it

To provide the Service — sync your catalog, publish machine-readable assets, run audits — and to secure, monitor, and improve it. We send transactional emails (verification, plan activation, billing notices) related to your account.

4. Payment data

We never receive or store card details. Payments are processed by Paddle as merchant of record; checkout for your shoppers happens on your own store.

5. Sharing and sub-processors

We share data only with service providers that help us run Seyaq — hosting, Paddle for payments, our email provider (Resend), the AI provider used to generate audits (Anthropic), and Google for analytics as described in the next section — under appropriate safeguards. We do not sell personal data.

The machine-readable assets you enable are, by design, public so AI assistants can read them; do not include private data in your catalog fields.

6. Where your data is processed

Seyaq runs on cloud infrastructure that may be located outside the United Arab Emirates, and the sub-processors above may process data in other countries. Where personal data leaves the UAE we rely on the safeguards permitted by the applicable data protection law, including the providers’ own contractual commitments.

7. Cookies and analytics

We use Google Tag Manager and Google Analytics to understand how Seyaq is used — for example which pages are visited, which features are used, and where signups come from. Analytics cookies are set only after you choose “Accept” in the cookie banner. Until you choose, and if you decline, no analytics cookies are stored on your device.

Analytics data is limited to usage events and technical context (pages, actions, device and browser type, and the approximate location Google derives). We configure analytics so that it does not receive your name, email address, store name or store URL. Confirmed billing events (for example a completed subscription payment) are reported to Google Analytics from our servers with a transaction reference and amount — never card details.

You can change or withdraw your choice at any time by clearing this site’s data in your browser; the consent banner will appear again on your next visit. Google processes analytics data on our behalf as a service provider.

8. Security

Store tokens are encrypted at rest. Access is scoped per store (tenant isolation). We apply reasonable technical and organizational measures, though no system is perfectly secure.

9. Retention

We keep account and store data while your account is active and for a reasonable period afterwards as needed for legal, accounting and security purposes, then delete or anonymize it.

10. Your rights

Subject to applicable law, you may access, correct, export or delete your personal data, and object to or restrict certain processing. Contact us to exercise these rights.

11. Contact

Privacy questions or requests: privacy@seyaq.ai