Privacy Policy

    Your privacy is important to us. This policy explains how we collect, use, and protect your information in compliance with GDPR, CCPA, and ePrivacy regulations.

    Last updated: March 15, 2026

    Encrypted

    All transfers are transmitted over TLS. Files encrypted at rest (AES-256).

    No Scanning

    We never scan, read, or analyze the contents of your files.

    Auto-Delete

    Files and metadata are deleted after expiration. No long-term retention.

    1. Information We Collect

    Account Information: Email address, name (optional), and password hash when you create an account. We use your email to authenticate you and send transfer notifications.

    Transfer Data: File names, sizes, recipient emails, transfer titles, expiry dates, and download counts. We do NOT access or scan file contents.

    Usage Data: IP addresses (anonymized after 30 days), browser type, and interaction data to improve our service and detect abuse.

    Payment Information: Processed securely by Stripe, Inc. We receive only a token reference. We never store or access credit card numbers, CVV codes, or bank details.

    Cookies & Technical Data: Session identifiers, preference cookies, and optional analytics data. See our Cookie Policy for the full list.

    2. How We Use Your Information

    • To provide, maintain, and improve our file transfer service
    • To send transfer notifications and download alerts to recipients
    • To process payments and manage subscriptions via Stripe
    • To send transactional emails (receipts, expiry warnings) via Resend
    • To detect and prevent fraud, abuse, and security incidents
    • To comply with legal obligations under French and EU law
    • To generate anonymized analytics to improve the product (with your consent)

    We do NOT sell, rent, or trade your personal information to any third party for marketing purposes.

    3. Data Retention

    Data TypeRetention PeriodReason
    Transfer filesUntil expiry date (3 to 365 days)Service delivery
    Transfer metadata90 days after expirySecurity audit trail
    Account dataUntil account deletionService continuity
    Payment records10 yearsLegal / tax obligation (France)
    IP addressesAnonymized after 30 daysAbuse prevention
    Cookie consent log12 monthsGDPR / ePrivacy compliance
    Deletion audit log2 yearsRGPD traceability (Art. 5)

    4. Your Rights under GDPR (EU)

    As a data subject under the GDPR (Regulation 2016/679), you have the following rights. To exercise any of them, contact contact@sandrafiles.io.

    Right to Access (Art. 15)

    Request a copy of all personal data we hold about you.

    Right to Erasure (Art. 17)

    Request deletion of your personal data ('right to be forgotten').

    Right to Rectification (Art. 16)

    Correct inaccurate or incomplete personal data.

    Right to Data Portability (Art. 20)

    Receive your personal data in a structured, machine-readable format (JSON/CSV) to transfer to another service.

    Right to Object (Art. 21)

    Object to processing of your personal data for direct marketing or based on our legitimate interests.

    Right to Restrict Processing (Art. 18)

    Request that we limit how we use your data while a dispute is resolved.

    Right to Withdraw Consent

    Withdraw consent for analytics or marketing cookies at any time without affecting prior lawful processing.

    You also have the right to lodge a complaint with your national Data Protection Authority. In France: CNIL (cnil.fr).

    5. California Privacy Rights (CCPA / CPRA)

    California residents have the right to:

    • Know what personal information is collected and how it is used
    • Know whether personal information is sold or disclosed, and to whom
    • Opt out of the sale or sharing of personal information
    • Access, correct, or delete your personal information
    • Limit the use of sensitive personal information
    • Not be discriminated against for exercising your privacy rights

    We do NOT sell or share your personal information with third parties for commercial purposes.

    To submit a CCPA request, email contact@sandrafiles.io with subject line "CCPA Request". We will respond within 45 days.

    6. Data Processors & Sub-processors

    We rely on the following trusted sub-processors to operate Sandra. Each has a Data Processing Agreement (DPA) in place with us.

    ProcessorPurposeLocationTransfer Mechanism
    Supabase (EU infrastructure, Ireland)Database, file storage, authenticationEU (Ireland)EU-hosted · no transfer needed
    Stripe, Inc.Payment processing, subscription managementUSSCCs (EU Commission Decision 2021/914)
    ResendTransactional email deliveryUSSCCs (EU Commission Decision 2021/914)

    All transfers to processors outside the European Economic Area (EEA) are protected by Standard Contractual Clauses (SCCs) as approved by the European Commission (Decision 2021/914), ensuring an adequate level of data protection equivalent to EU standards.

    7. International Data Transfers

    Our primary infrastructure is located in the European Union (Ireland). Where personal data is transferred to countries outside the EEA (for example, to Stripe or Resend in the United States), we ensure that such transfers are protected by:

    • Standard Contractual Clauses (SCCs) approved by the European Commission
    • Adequacy decisions where applicable
    • Supplementary technical and organisational measures as required

    8. Data Breach Notification

    In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will:

    • Notify the CNIL (French supervisory authority) within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33
    • Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34)
    • Document all breaches in our internal breach register regardless of whether notification is required

    To report a security vulnerability, please email contact@sandrafiles.io or see our security disclosure policy.

    9. Cookies & Tracking

    We use cookies and similar technologies. You can manage your preferences at any time via the cookie banner or by visiting our full Cookie Policy.

    • Essential: Required for authentication and security (cannot be disabled)
    • Analytics: We use Plausible Analytics, a privacy-first, cookie-free tool hosted in the EU. No personal data collected, no consent required.

    Your consent choices are logged with a timestamp and can be withdrawn at any time.

    10. Children's Privacy

    Sandra is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us at contact@sandrafiles.io and we will promptly delete it.

    11. Changes to This Policy

    We may update this Privacy Policy from time to time. Material changes will be communicated by email or via an in-app notification at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the most recent revision.

    12. Contact & Data Controller

    Data Controller

    Sandra SAS

    Paris 75016, France

    Privacy inquiries

    contact@sandrafiles.io

    Supervisory authority

    CNIL · cnil.fr