This page is maintained by SabarraaPay to answer common security and privacy questions about the platform. It describes the controls currently in place and is provided for transparency — it is not an independent certification or audit.
Authentication & Access
Accounts are invite-only and created by the platform owner — there are no anonymous or self-service sign-ups.
Every user signs in with their own credentials, and sessions are managed by our authentication provider.
Roles (Admin, Merchant, Agent, Employee) determine what each user can see and do, enforced on the server.
Row-Level Data Protection
Database access is governed by row-level security so users can only read and modify records that belong to them.
Financial records such as transactions are restricted to the owning agent, merchant, or an administrator.
Anonymous (signed-out) visitors cannot read or write protected application data.
Payments & Sensitive Data
Payment processing is handled through our payment gateway integrations; merchant credentials and signing keys are kept server-side and never exposed to the browser.
Withdrawals require administrator approval before funds leave the system.
One-time verification tokens are short-lived and are not readable by other users.
Storage
Uploaded files such as chat attachments and QR codes are stored in private buckets.
Only authenticated owners can modify their own stored files.
Platform & Hosting
SabarraaPay runs on managed cloud infrastructure providing database, authentication, storage, and serverless backend services.
Data is transmitted over encrypted connections (HTTPS) between your device and our services.
Shared Responsibility
We maintain application access controls and platform configuration described on this page.
Account holders are responsible for keeping their sign-in credentials confidential and for the activity within their accounts.
Reporting a security concern
If you believe you have found a security or privacy issue, please contact our team so we can investigate promptly.