← Back to Admin
Legal

Privacy Policy

Effective Date: June 18, 2026  ·  Saha Sales Inc.  ·  Last updated: June 18, 2026

Saha Sales Inc., a California corporation doing business as Saha Lighting Solutions ("Company," "we," "us," or "our"), operates the Lighting Studio platform ("Service"). This Privacy Policy explains what information we collect, how we use it, how we protect it, and your rights regarding it.

This Policy applies to: (1) Client administrators who use the admin panel, and (2) end users (your customers) who access the public-facing lighting layout tools hosted through the Service. The Service is a B2B platform not directed to children. We do not knowingly collect personal data from children under 13 (or, where the EU GDPR applies, under the applicable age of digital consent, which is 16 unless lowered by the relevant EEA member state). If we learn that we have inadvertently collected such data, we will delete it promptly.

1. Information We Collect

CategoryWhat We CollectWho It Applies To
Account Data Email address, hashed password, role, account creation date Client admin users
Client Content IES photometric files, logos, branding images, category names uploaded by the Client Client admins
Billing Metadata Billing email, Stripe customer/subscription identifiers, selected plan, subscription status, renewal/cancellation dates, and terms acceptance metadata Client administrators and billing contacts
Usage Analytics Fixture selections, tool type used, session ID (random, non-persistent), page URL, referrer URL, job name (if entered), timestamp - collected only if the Client enables tracking for their account End users of public tools
Technical / Log Data IP addresses, browser type, request timestamps, error logs - collected automatically by server infrastructure All visitors
Audit Log Data Admin action records (e.g., tenant created, file uploaded, user reset) - associated with admin account, not end users Client admins

We do not collect names, physical addresses, phone numbers, or payment card numbers from end users of the public tools. Payment information is collected and processed by Stripe and is never stored on our servers.

2. How We Use Information

We do not sell your data to third parties. We do not use Client Data or end-user data for advertising.

3. Legal Basis for Processing (EEA/UK)

For Clients and individuals located in the European Economic Area or the United Kingdom, we rely on the following legal bases under Article 6(1) of the GDPR (and the UK GDPR) for the processing described in the How We Use Information section:

4. Cookies and Tracking

We use only essential, functional cookies necessary to operate the Service. No analytics, advertising, or third-party tracking cookies are set by this platform.

Cookie Name / TypePurposeDuration
Session cookie Maintains authenticated admin sessions (httpOnly, Secure, SameSite=Strict) Session (expires on browser close or logout)
CSRF token Protects state-mutating requests from cross-site request forgery Session

The public-facing tools do not set persistent tracking cookies. If usage analytics are enabled by a Client, a random, non-persistent session identifier is generated in browser memory for the duration of the session only — it is not stored in a cookie and does not follow the user across sessions or sites.

5. Third-Party Services and Sub-Processors

We engage the following sub-processors to operate the Service. Each sub-processor is contractually required to handle data only as directed by us and in compliance with applicable data protection law.

Sub-ProcessorPurposeData SharedPrivacy Policy
Stripe Payment processing, subscription billing, and billing portal Billing email, payment details, customer/subscription identifiers, selected plan, and subscription status stripe.com/privacy
Resend Transactional email delivery (password resets, account setup, billing notices) Email address, reset/setup URLs, and account/billing message content resend.com/privacy
Railway Cloud application hosting and managed infrastructure All application data, including database records and uploaded files, resides on Railway-managed servers railway.app/legal/privacy
Cloudflare R2 / AWS S3 Object storage for uploaded files (IES files, logos, branding assets) and backup archives Uploaded file content and backup archives; no end-user PII beyond file metadata cloudflare.com/privacypolicy / aws.amazon.com/privacy
Sentry Application error monitoring and diagnostics Error stack traces, request metadata, and environment context; personally identifiable data is scrubbed before transmission where possible sentry.io/privacy

We do not integrate with advertising networks, social media platforms, or data brokers.

We maintain the current list of sub-processors in this Policy. Before we engage a new sub-processor that will process Client or end-user personal data, we will give active Clients at least 30 days' advance notice — by email to the address on file and/or by updating this list with a dated change note — except where a shorter period is reasonably required to address an urgent security, legal, or service-continuity need. If a Client reasonably objects to a new sub-processor on data-protection grounds within that notice period, we will work with the Client in good faith to address the objection; if we are unable to do so, the Client may terminate the affected Service as its sole and exclusive remedy. Where a Client has executed our Data Processing Agreement, the sub-processor change and objection terms of that DPA govern and prevail over this paragraph to the extent of any conflict.

6. Embedded End Users and Acceptance Records

When an individual uses Lighting Studio through a lighting manufacturer, lighting representative agency, or other Host Customer, we may collect information needed to operate the tool and document agreement to the End-User Terms. This may include an acceptance ID, the Host Customer, embedding domain, Terms and disclaimer versions, date and time, session or anonymous-user identifier, IP address, browser and device information, user agent, and an immutable record or hash of the acceptance language and action.

We use this information to provide the Service, maintain security, prevent abuse, document contract formation, respond to disputes, comply with law, and enforce our agreements. We may disclose limited acceptance evidence to the applicable Host Customer, service providers, professional advisers, or government authorities where reasonably necessary for those purposes.

We retain End-User and Client acceptance records for up to five years after acceptance, and longer where reasonably necessary for an active dispute, legal hold, fraud prevention, or legal obligation. These legal and contract records are not included in the ordinary deletion of project content after account cancellation.

We may use cookies, local storage, or similar technology to remember that a particular browser accepted the current End-User Terms and to avoid asking for acceptance before every calculation. The Host Customer may separately use cookies, analytics, or other technology under its own privacy policy.

The Host Customer may independently determine the purposes and means of its own website, marketing, product, cookie, and analytics data. Questions about the Host Customer's independent practices should be directed to the Host Customer.

The acceptance log is part of our data inventory and is included in access and deletion workflows on the same basis as our other records, subject to the lawful retention exception described above: because these records document contract formation and are kept for fraud prevention, dispute response, and legal compliance, we retain them for up to five years (including the raw IP address recorded at the time of acceptance) and may decline a deletion request to the extent the law permits us to retain them for those purposes. We will still honor verified access requests and will delete or de-identify the records once the applicable retention period or legal basis no longer applies.

7. International Data Transfers

We are based in the United States, and our sub-processors store and process data in the United States. As a result, when you use the Service, your personal data is transferred to, and processed in, the United States and potentially other countries that may not provide the same level of data protection as your home jurisdiction.

Where we transfer personal data of individuals located in the European Economic Area (EEA), the United Kingdom, or Switzerland to a country that has not received an adequacy decision from the relevant authority, we rely on appropriate safeguards to protect that data, including the European Commission's Standard Contractual Clauses (Decision 2021/914/EU) and, for transfers subject to UK law, the UK International Data Transfer Addendum issued by the UK Information Commissioner's Office. These safeguards are incorporated into our agreements with the affected sub-processors and, where applicable, into the Data Processing Agreement we make available to Clients (see the Data Processing Agreement section).

You may request a copy of the relevant transfer safeguards by contacting us at support@sahalighting.com.

8. Data Storage and Security

All data is stored on servers hosted by Railway (see above). We implement reasonable technical and organizational security measures including:

No security measure is 100% foolproof. In the event of a data breach that affects Client account data, we will notify affected Clients within 72 hours of becoming aware of the breach, as required by applicable law.

9. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy or as required by applicable law.

Data TypeRetention Period
Admin account data (email, hashed password, role)Retained while the subscription is active. After cancellation, account data is retained for approximately 30 days to allow data export, then generally deleted or de-identified, unless a longer period is required by law or another retention basis described in this Policy applies.
Client content and project data (IES files, logos, branding assets, saved layouts and calculations)Retained while the subscription is active. After cancellation, project content is generally deleted or de-identified within approximately 30 days, subject to backup cycles, fraud prevention, legal holds, contract records, and legally required retention; you may export it before then. This ordinary deletion does not extend to acceptance and other legal/contract records, which are retained as described in their own rows below.
Billing metadataRetained for a minimum of 7 years from the transaction date for tax, accounting, dispute, and legal compliance purposes, as required by applicable financial regulations.
End-User and Client acceptance records (acceptance ID, Host Customer, embedding domain, Terms/disclaimer versions, timestamp, session or anonymous-user identifier, IP address, browser/device information, user agent, and an immutable record or hash of the acceptance)Retained for up to 5 years after acceptance, and longer where reasonably necessary for an active dispute, legal hold, fraud prevention, or legal obligation. The IP address captured at acceptance is retained for the same period. These legal and contract records are not deleted in the ordinary ~30-day deletion of project content after cancellation.
Usage analytics eventsRolling window configurable by Client (7–365 days); events older than the configured window are pruned automatically. Default retention is 90 days.
Audit logs2 years from creation, then deleted automatically.
Server / infrastructure logsUp to 30 days, as managed by Railway infrastructure. We do not retain separate application-level access logs beyond 30 days.
Backup archivesLocal on-server backups are kept to the admin-configured retention count (default: last 3) and older copies are pruned automatically. Offsite backup copies (Cloudflare R2 / AWS S3) are automatically deleted 30 days after creation by a storage lifecycle policy, so no backup — and no data it contains — is retained offsite beyond 30 days.
Password reset tokens60 minutes from generation, then expired and deleted regardless of use.

10. End-User Data and Client Responsibility

When a Client enables usage analytics, their end users' fixture interactions are tracked and stored. Clients are responsible for:

The Company acts as a data processor with respect to end-user analytics data. The Client is the data controller. Clients in the EU or processing EU resident data should contact us to execute a Data Processing Agreement (DPA).

11. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

To exercise these rights, contact us at the address in the Contact section below. We will respond within the time required by applicable law. For requests under the EU/UK GDPR, we will respond within one month, which we may extend by up to two further months for complex or numerous requests, with notice to you of any extension. For requests under the CCPA/CPRA, we will respond within 45 days, which we may extend by an additional 45 days where permitted, with notice to you. Where no specific statutory deadline applies, we will respond within 30 days.

12. California Residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with specific rights regarding your personal information.

We do not sell personal information. We do not sell or share personal information with third parties for cross-context behavioral advertising purposes.

California residents have the right to:

To exercise these rights, contact us at support@sahalighting.com. We will verify your identity before processing your request and respond within 45 days as required by law, which we may extend by an additional 45 days where permitted, with notice to you.

Notice at Collection. This Policy serves as our notice at collection under Cal. Civ. Code §1798.100(a). The categories of personal information we collect are described in the Information We Collect section, the purposes for which we use each category are described in the How We Use Information section, and the period for which we retain each category (or the criteria used to determine that period) is described in the Data Retention section. We use personal information only for the purposes disclosed in this Policy and do not use it for materially different, unrelated, or incompatible purposes without providing notice. We do not collect or process "sensitive personal information" as that term is defined by the CPRA (Cal. Civ. Code §1798.140(ae)) — we do not collect government identifiers, precise geolocation, account log-in combined with credentials, contents of private communications, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, biometric data used to uniquely identify you, or data concerning health, sex life, or sexual orientation — and therefore do not use or disclose any sensitive personal information for any purpose. We do not sell personal information for monetary or other valuable consideration, and we do not share personal information for cross-context behavioral advertising, as those terms are defined by the CPRA; we have not sold or shared personal information in the preceding twelve (12) months and do not disclose it to third parties for any purpose other than the business and service purposes described in the How We Use Information and Third-Party Services and Sub-Processors sections.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify active Clients via the email address on file at least 30 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

14. Data Processing Agreement (DPA)

Enterprise and EU-based Clients who require a Data Processing Agreement for GDPR compliance may download our standard DPA template. The DPA covers Controller/Processor obligations, security measures, sub-processor disclosure, Standard Contractual Clauses for international transfers, breach notification, and data deletion upon termination.

Download DPA Template →

Contact Us

For privacy-related questions, requests, or to execute a DPA, contact:

Saha Sales Inc. (d/b/a Saha Lighting Solutions)
1823 N Solano Ave
Ontario, California 91764, USA
Email: support@sahalighting.com

Data Protection Contact. For privacy, GDPR, or UK GDPR matters, contact us at support@sahalighting.com. If you are in the EEA or the UK, you have the right to lodge a complaint with your local data protection supervisory authority.