SAFE Privacy Policy
- Last updated:
- August 3, 2026
- Data controller:
- SIDE Costa Rica B M M P Sociedad Anónima, cédula jurídica 3-101-542382, San José, Costa Rica.
This policy explains what information SAFE collects, how we use it, and what control you have over it.
1. Summary
- Gmail access is optional. You can use SAFE without connecting a Gmail account.
- SAFE only accesses Gmail if you enable the supplier invoice import feature and authorize the connection with Google.
- We use Gmail only to detect and import supplier invoice messages or attachments relevant to that feature.
- We only process messages carrying an XML or ZIP attachment relevant to that feature. We do not read your personal conversations.
- We do not sell your information and we do not use it for advertising.
- No one on our team reads your email.
- You can disconnect Gmail or revoke access from your Google account at any time.
2. Information we collect
2.1 Your SAFE account data
Name, contact email, the taxpayer's tax ID or business name, and the billing data you enter yourself.
2.2 Google user data
SAFE collects Google user data only if you choose to enable the optional Gmail invoice import feature. See the "Google user data" section below for the full detail.
2.3 Technical data
IP address, browser type, and access logs. This site does not use advertising or third-party tracking cookies.
3. Google user data
The Gmail connection is an optional feature used to import electronic invoices from suppliers that arrive in your inbox. You can use SAFE without connecting Gmail. SAFE only requests access when you choose to enable this feature and complete Google’s authorization flow. At that point, SAFE requests a single permission:
https://www.googleapis.com/auth/gmail.readonlyread-only access to your Gmail messages.
What we access with that permission
- Your Gmail address, to identify the connected account and display it on your settings screen.
- Identifiers and headers of the messages that match our search filter. The filter is enforced server-side and only returns messages carrying an .xml or .zip attachment within the date range you configured. We include the spam folder, because electronic invoices are frequently misclassified there.
- The contents of the .xml and .zip attachments that are electronic invoices under Costa Rican tax regulation. That file is the tax document we need to process.
What we do not access
- We do not read the body or text of your messages.
- We do not access messages that carry no XML or ZIP attachment.
- We do not use this permission to monitor your mailbox for general purposes.
- We do not download attachments that are not electronic invoices (for example, personal photos or documents).
- We do not access your contacts, calendar, Drive, photos, or any other Google service.
- We do not send, modify, archive, or delete any email. The permission is read-only and does not allow us to write to your mailbox.
No human reads your email
Processing is fully automated. No one on our team or at our providers reads your messages or attachments. The only exceptions are those allowed by the Google API Services User Data Policy: you expressly ask us to in order to resolve a support issue, it is necessary for security purposes (for example, investigating abuse), or the law requires it.
4. How we use the information
If you enable Gmail import, we use the data obtained from Gmail for one purpose only: turning your suppliers’ electronic invoices into purchase records inside your SAFE account, so you can review, accept, or reject them and use them in your tax filings.
We do not use your Google data for anything else. Specifically:
- We do not sell or rent it to anyone.
- We do not share it with advertising platforms, ad networks, or data brokers.
- We do not use it for targeted advertising or to build marketing profiles.
- We do not use it to train, fine-tune, or improve artificial intelligence or machine learning models, whether ours or a third party’s.
- We do not use it to assess your creditworthiness or for lending purposes.
5. Who we share information with
We do not sell or trade your information. We share it only with the following categories of recipients, and only to the extent needed to run the service:
| Recipient | What they receive | What for |
|---|---|---|
| Linode | Stores your invoices and account data. | Hosting the application and the database. |
| Amazon SES | Your contact email address. | Sending you system notifications. |
| Costa Rica's Ministry of Finance (Hacienda) | The electronic invoices you issue or look up. | Complying with Costa Rican tax regulation. |
There are no other transfers. We do not share your Google data with any other third party, except in two cases: (a) when you expressly ask or authorize us to, and (b) when required by law, a court order, or a competent authority, in which case we will notify you whenever the law allows it.
If SAFE were ever involved in a merger, acquisition, or asset sale, we will notify you before your data becomes subject to a different privacy policy, and give you the option to delete it.
6. How we protect your information
Encryption in transit
All communication between your browser, our servers, and Google's APIs uses TLS 1.2 or higher.
We never store your Google password
Authorization uses Google's OAuth 2.0 system: you authenticate directly with Google, and we only receive a revocable token.
Isolation between customers
Each company's data is stored in separate databases.
Immediate revocation
When you disconnect your account, we revoke the token with Google at that moment and delete it from our systems.
7. Retention and deletion
Google authorization tokens
Kept while the Gmail connection is active. When you disconnect your account, we revoke the token with Google immediately and delete it from our systems.
Billing documents
Invoices, credit notes, debit notes, and other receipts: kept for up to 5 years, as required by Costa Rican tax retention rules.
Technical logs
Kept for up to 90 days. They do not contain the content of your emails.
When you close your account
We delete your data within 10 days, except for what we are legally required to retain (see "Billing documents" above).
You can disconnect your Gmail account at any time from Settings → Email access inside SAFE, or revoke access directly from your Google account's permissions page.
See also our data deletion page for the step-by-step.
8. Compliance with Google's policy
SAFE's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. Your rights and controls
- Revoke Gmail access at any time.
- Request access to the data we hold about you.
- Correct inaccurate data.
- Request deletion of your data.
- Request a copy of your data in a readable format.
To exercise any of these rights, write to us at privacidad@sidecr.com. We respond within a maximum of 10 business days, under Costa Rica's Law No. 8968 on the Protection of Individuals with Regard to the Processing of Their Personal Data, and before PRODHAB (the national data protection authority).
10. Minors
SAFE is a tool for business and professional use. It is not directed at anyone under 18, and we do not knowingly collect information from minors.
11. Changes to this policy
If we change this policy, we will update the "Last updated" date above. If the change affects how we handle your Google data, we will notify you by email before it takes effect and, where applicable, ask you to authorize it again.
12. Contact
For questions about this policy or your data, write to us at: privacidad@sidecr.com