Privacy policy

Last updated August 11, 2026

Who we are

Sablora ("we") is an invoicing service for small businesses, operated at sablora.com. Questions about this policy or your data: support@sablora.com.

What we collect

Account data — your email address and sign-in credentials (your password is stored only as a salted argon2id hash; we cannot read it back), plus the business profile you fill in: business name, address, tax ID, logo.

Data you enter — your customers (names, email addresses, billing addresses) and the invoices you create for them. You control this data; we store and process it only to provide the service.

Billing data — paid plans are processed by Stripe. We store your plan and a Stripe customer reference, never card numbers.

Security and usage data — sign-in events (IP address, browser user agent) used for account-security notices, monthly document counts used to enforce plan limits, and support-chat messages you send us.

Email we send on your behalf

When you send an invoice or receipt, Sablora emails it to the customer address you entered, on your behalf. Every such email identifies the sender, carries a working unsubscribe link and one-click unsubscribe headers, and replies go to your business email, not to us.

We record delivery failures: an address that hard-bounces, marks a message as spam, or unsubscribes is suppressed immediately and automatically — we refuse to email it again until you correct it.

Read receipts — on paid plans, and only while the workspace leaves the setting switched on, invoice emails include a small tracking image hosted by our email provider. When a recipient's mail app loads it we record that the invoice was opened, along with the time, the recipient's IP address and their browser user agent. It is used solely to show the sender whether their invoice has been opened. Free plans send no such image at all, and a workspace can turn this off under Settings → Business profile. Many mail apps block or preload remote images, so an open is an imperfect signal in both directions.

Processors we rely on

Amazon Web Services (email delivery via SES, infrastructure), Stripe (payments), Google (advertising measurement, and only with your consent — see Cookies below; and bot protection — see below), Microsoft (Clarity, which measures how our public pages are used, and only with your consent — see Cookies below). Each processes data only as needed to provide their function.

Bot protection

The sign-up, password-reset and resend-confirmation forms are protected by Google reCAPTCHA, which scores how likely a submission is to come from a person rather than a script. To do that it observes how the page is used and sets its own cookies. Unlike the advertising cookies below, this is not optional and is not covered by the consent banner: it is a security measure that protects these forms from being used to send mail to addresses that never asked for it. It runs on those three forms only — never in the signed-in app. Google's privacy policy and terms apply.

Cookies

Cookies the app needs — a session cookie and a CSRF-protection cookie. These are set whenever you use Sablora; without them you cannot stay signed in or submit a form safely.

Advertising cookies — on our public pages (the home page, pricing, our policy pages and the sign-in and sign-up forms) we ask whether you consent to Google Ads measurement cookies, which tell us whether an advert led to a sign-up. Nothing is loaded and no request reaches Google until you press Accept; if you decline, or ignore the banner, or block scripts, no advertising cookie is set and no data leaves this site. Your answer is remembered in your browser, and you can change it by clearing this site's storage.

Analytics cookies — on the same public pages, and behind the same banner, we use Microsoft Clarity to see how those pages are used: how far people scroll, what they click, and where they get stuck. To do that it records the page as you see it, which it stores as an anonymised replay, and it sets its own cookies. Everything you type is masked before it leaves your browser — email addresses and passwords are never captured — and Clarity runs on the public pages only. It is never loaded in the signed-in app or on the links we email to your customers, so no invoice, customer record or payment page is ever recorded. Nothing loads and no request reaches Microsoft until you press Accept.

Measuring a sign-up — if you accepted the banner above and you then create an account, we report that one sign-up to Google Ads on the first page you open after signing in. That report includes a one-way cryptographic hash of your email address — never the address itself — which lets Google match the sign-up to the advert you clicked. It happens once per account and never again. Decline the banner and none of this happens.

Apart from that single report, the signed-in app carries no advertising or analytics tracking and is never recorded, and neither are the links we email to your customers — your invoices, your customers and your payment pages are never reported to anyone.

Retention and deletion

Your data is kept while your account is active. Deleting your organization removes its customers, invoices and profile. To request access, export or deletion, email support@sablora.com.