This Privacy Policy explains what personal information we collect, how we use it, and the choices you have. It applies to the Silaar website (https://silaar.com) and our B2B API Gateway services (the “Services”). It is written to satisfy the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA, and other applicable U.S. state privacy laws.
1. Overview
Silaar operates a business-to-business (B2B) API gateway that lets authorized business customers programmatically access third-party e-commerce data through a single, unified interface. Because our direct customers are businesses rather than consumers, the personal data we process is limited to what is necessary to operate the account, provision and secure the Services, and comply with our legal obligations.
This Policy does not apply to data that our customers process through the Services on their own behalf. Where Silaar processes personal data on behalf of a customer, that processing is governed by our Data Processing Agreement (DPA).
2. Data Controller
Silaar LLC is the controller of the personal data described in this Policy.
- Entity: Silaar LLC
- Form: Limited Liability Company (LLC)
- Jurisdiction: State of Wyoming, United States of America
- Address: Silaar LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States
- Privacy contact: privacy@silaar.com
For GDPR purposes, our representative for data-protection matters can be reached at the privacy contact above. We do not currently have a formal Article 27 EU representative; EU data subjects may contact us directly and we will respond without undue delay.
3. Data We Collect
3.1 Data you provide directly
- Account data: full name, business email address, company name, and a password (stored as a salted hash).
- Verification data: email verification codes and, for paid plans, identity/KYB details required by our payment processor (e.g., billing name, billing address, country).
- Support & sales communications: the content of messages you send us, plus any attachments.
- API keys & configuration: the names, labels, and usage metadata for keys you create. API key secrets are hashed and shown only once at creation time.
3.2 Data collected automatically
- Usage & telemetry: request volume, error rates, rate-limit events, and performance metrics, used to operate and improve the Services.
- Technical data: IP address, browser type, operating system, referring URL, and approximate location (derived from IP).
- Cookies & similar technologies: authentication and preference cookies. See Section 10 and our Cookie Policy.
3.3 Data we do not collect
We do not knowingly collect or process Special Categories of personal data under GDPR Article 9 (e.g., health, racial or ethnic origin, religious beliefs, biometric or genetic data), and you must not submit such data through the Services.
4. Purposes & Legal Basis (GDPR Art. 6)
| Purpose | Legal basis | Lawful reference |
|---|---|---|
| Providing and maintaining your account and the Services | Performance of a contract | Art. 6(1)(b) |
| Billing, invoicing, fraud prevention, payment processing | Contract & legal obligation | Art. 6(1)(b) & (c) |
| Communicating about your account, security, and service updates | Contract & legitimate interests | Art. 6(1)(b) & (f) |
| Security, abuse and rate-limit enforcement, threat detection | Legitimate interests | Art. 6(1)(f) |
| Product analytics and service improvement | Consent / legitimate interests | Art. 6(1)(a) & (f) |
| Compliance with tax, AML, sanctions (OFAC), and record-keeping laws | Legal obligation | Art. 6(1)(c) |
5. Data Retention
We keep personal data only as long as necessary for the purposes set out above and to meet legal, accounting, or reporting requirements:
- Account data: kept while your account is active and for up to 90 days after deletion, after which it is erased or fully anonymized.
- Billing & tax records: retained for 7 years as required by U.S. federal tax and record-keeping rules.
- Usage logs & security telemetry: aggregated or anonymized after 90–180 days; raw security logs may be kept longer to detect and investigate abuse.
- Support communications: retained for up to 2 years after the last interaction.
6. Data Sharing & Recipients
We do not sell personal data. We share data only as described below:
- Service providers (processors): cloud hosting, email delivery, analytics, error monitoring, and customer support tools — each bound by written data-protection terms.
- Payment processor: our payment processor receives billing data necessary to process transactions. Card data is handled entirely by the processor under their PCI-DSS certified environment; Silaar never stores full card numbers.
- Legal & regulatory: where required by law, court order, or to protect our rights, customers, or the public from fraud, abuse, or security threats.
- Corporate transactions: in connection with a merger, acquisition, or asset sale, subject to confidentiality safeguards.
7. International Data Transfers
Silaar is a U.S. company and may process data in the United States and in other countries where our service providers operate. For transfers out of the European Economic Area, United Kingdom, or Switzerland, we rely on an appropriate safeguard such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, or another recognized transfer mechanism.
8. Security
We implement industry-standard technical and organizational measures, including TLS encryption in transit, hashed credentials at rest, least-privilege access controls, audit logging, and regular reviews. However, no method of transmission or storage is fully secure, and we cannot guarantee absolute security.
In the event of a personal-data breach affecting your rights, we will notify the relevant supervisory authority and, where required, affected individuals without undue delay and in accordance with applicable law.
9. Your Rights
Depending on where you live, you may have the following rights. To exercise any right, email privacy@silaar.com. We will verify your identity before responding, typically within 30 days.
- GDPR (EEA/UK residents): access, rectification, erasure (“right to be forgotten”), restriction, data portability, objection, and rights related to automated decision-making. You may lodge a complaint with your local data protection authority.
- CCPA/CPRA (California residents): the right to know, delete, correct, and opt out of the “sale” or “sharing” of personal information, and the right not to receive discriminatory treatment. Silaar does not sell personal information as defined by California law.
- Other U.S. states: rights similar to the above may apply under Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other state laws.
We do not make automated decisions producing legal or similarly significant effects based solely on automated processing.
10. Cookies & Tracking Technologies
We use cookies and similar technologies for authentication, security, and basic analytics. We do not use cookies for cross-site advertising or selling data. For details and opt-out choices, see our Cookie Policy.
11. Children’s Privacy
The Services are intended for business use and are not directed to individuals under 16 (under 13 in the U.S. under COPPA, and under 16 in the EEA under the age threshold in GDPR Art. 8). We do not knowingly collect data from children. If you believe we have, please contact us and we will promptly delete it.
12. Changes to This Policy
We may update this Policy from time to time. We will post the updated version here with a revised “Last updated” date and, for material changes, provide notice through the Services or by email. Your continued use of the Services after a change constitutes acceptance of the revised Policy.
13. Contacting Us
Questions about this Privacy Policy or your data can be sent to privacy@silaar.com or by mail to the address in Section 2.
Questions about this document?
We’re happy to clarify any part of this policy. For legal or privacy inquiries, contact our team:
- Email: legal@silaar.com (legal) · privacy@silaar.com (privacy / DPA)
- Phone: +213 675 295 494
- Mail: Silaar LLC 30 N Gould St, Ste R Sheridan, WY 82801 United States
© 2026 Silaar LLC. All rights reserved.