Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information in compliance with GDPR, CCPA, and ePrivacy regulations.
Last updated: March 15, 2026
Encrypted
All transfers are transmitted over TLS. Files encrypted at rest (AES-256).
No Scanning
We never scan, read, or analyze the contents of your files.
Auto-Delete
Files and metadata are deleted after expiration. No long-term retention.
1. Information We Collect
Account Information: Email address, name (optional), and password hash when you create an account. We use your email to authenticate you and send transfer notifications.
Transfer Data: File names, sizes, recipient emails, transfer titles, expiry dates, and download counts. We do NOT access or scan file contents.
Usage Data: IP addresses (anonymized after 30 days), browser type, and interaction data to improve our service and detect abuse.
Payment Information: Processed securely by Stripe, Inc. We receive only a token reference. We never store or access credit card numbers, CVV codes, or bank details.
Cookies & Technical Data: Session identifiers, preference cookies, and optional analytics data. See our Cookie Policy for the full list.
2. How We Use Your Information
- To provide, maintain, and improve our file transfer service
- To send transfer notifications and download alerts to recipients
- To process payments and manage subscriptions via Stripe
- To send transactional emails (receipts, expiry warnings) via Resend
- To detect and prevent fraud, abuse, and security incidents
- To comply with legal obligations under French and EU law
- To generate anonymized analytics to improve the product (with your consent)
We do NOT sell, rent, or trade your personal information to any third party for marketing purposes.
3. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Transfer files | Until expiry date (3 to 365 days) | Service delivery |
| Transfer metadata | 90 days after expiry | Security audit trail |
| Account data | Until account deletion | Service continuity |
| Payment records | 10 years | Legal / tax obligation (France) |
| IP addresses | Anonymized after 30 days | Abuse prevention |
| Cookie consent log | 12 months | GDPR / ePrivacy compliance |
| Deletion audit log | 2 years | RGPD traceability (Art. 5) |
4. Your Rights under GDPR (EU)
As a data subject under the GDPR (Regulation 2016/679), you have the following rights. To exercise any of them, contact contact@sandrafiles.io.
Right to Access (Art. 15)
Request a copy of all personal data we hold about you.
Right to Erasure (Art. 17)
Request deletion of your personal data ('right to be forgotten').
Right to Rectification (Art. 16)
Correct inaccurate or incomplete personal data.
Right to Data Portability (Art. 20)
Receive your personal data in a structured, machine-readable format (JSON/CSV) to transfer to another service.
Right to Object (Art. 21)
Object to processing of your personal data for direct marketing or based on our legitimate interests.
Right to Restrict Processing (Art. 18)
Request that we limit how we use your data while a dispute is resolved.
Right to Withdraw Consent
Withdraw consent for analytics or marketing cookies at any time without affecting prior lawful processing.
You also have the right to lodge a complaint with your national Data Protection Authority. In France: CNIL (cnil.fr).
5. California Privacy Rights (CCPA / CPRA)
California residents have the right to:
- Know what personal information is collected and how it is used
- Know whether personal information is sold or disclosed, and to whom
- Opt out of the sale or sharing of personal information
- Access, correct, or delete your personal information
- Limit the use of sensitive personal information
- Not be discriminated against for exercising your privacy rights
We do NOT sell or share your personal information with third parties for commercial purposes.
To submit a CCPA request, email contact@sandrafiles.io with subject line "CCPA Request". We will respond within 45 days.
6. Data Processors & Sub-processors
We rely on the following trusted sub-processors to operate Sandra. Each has a Data Processing Agreement (DPA) in place with us.
| Processor | Purpose | Location | Transfer Mechanism |
|---|---|---|---|
| Supabase (EU infrastructure, Ireland) | Database, file storage, authentication | EU (Ireland) | EU-hosted · no transfer needed |
| Stripe, Inc. | Payment processing, subscription management | US | SCCs (EU Commission Decision 2021/914) |
| Resend | Transactional email delivery | US | SCCs (EU Commission Decision 2021/914) |
All transfers to processors outside the European Economic Area (EEA) are protected by Standard Contractual Clauses (SCCs) as approved by the European Commission (Decision 2021/914), ensuring an adequate level of data protection equivalent to EU standards.
7. International Data Transfers
Our primary infrastructure is located in the European Union (Ireland). Where personal data is transferred to countries outside the EEA (for example, to Stripe or Resend in the United States), we ensure that such transfers are protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Supplementary technical and organisational measures as required
8. Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will:
- Notify the CNIL (French supervisory authority) within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33
- Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34)
- Document all breaches in our internal breach register regardless of whether notification is required
To report a security vulnerability, please email contact@sandrafiles.io or see our security disclosure policy.
9. Cookies & Tracking
We use cookies and similar technologies. You can manage your preferences at any time via the cookie banner or by visiting our full Cookie Policy.
- Essential: Required for authentication and security (cannot be disabled)
- Analytics: We use Plausible Analytics, a privacy-first, cookie-free tool hosted in the EU. No personal data collected, no consent required.
Your consent choices are logged with a timestamp and can be withdrawn at any time.
10. Children's Privacy
Sandra is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us at contact@sandrafiles.io and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or via an in-app notification at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the most recent revision.
12. Contact & Data Controller
Data Controller
Sandra SAS
Paris 75016, France
Privacy inquiries
contact@sandrafiles.ioSupervisory authority
CNIL · cnil.fr