How a buyer gets their documents
There is no share link in Saudaflow. No expiring URL, no read-once mode, no watermark, no one-time code on a document. If you read otherwise on this page before, that was wrong and it has been removed. What exists is Buyer Connect: your buyer signs in to your portal with the phone number on their booking and downloads their own paperwork.
- Where this is
- You: Settings → Buyer Connect. Your buyer: https://app.saudaflow.in/buyer/<your workspace>, the address that page prints for you to copy.
- What you need
- The settings permission to switch the portal on. Nothing on the document itself changes — there is no per-document sharing control.
Read these two before you send a buyer anywhere.
Buyer Connect is complete and working, and both of these are true today. They decide whether the steps further down actually reach your buyer, so they are here rather than in a footnote.
1. The portal is off until your organisation turns it on
It is opt-in, per workspace, and off by default. A builder who has never opened the Buyer Connect screen has no configuration at all, and no configuration means closed — a buyer following your link gets a “not available” page. One person with the settings permission turns it on once.
The switch works in both directions immediately: turn it off and anyone already signed in is signed out on their next request, rather than lingering until their session expires.
2. The sign-in code is not being delivered yet
Sign-in is by one-time passcode to the phone number on the booking. The code is generated, hashed and rate-limited exactly as it will be in production — but the SMS is not going out. Our sender ID and templates are in DLT registration with TRAI, which is a two-to-three-week telecom process, not a code change.
So today: switch the portal on for rehearsal, walk your team through it, and settle what your buyers will see. Do not print the portal link on a possession letter yet — a buyer who follows it cannot finish signing in. We would rather you hear that from us than from them.
Setting it up.
-
Open Settings → Buyer Connect and switch the portal on
Press Save changes once, whichever way you set it — that is what turns “never configured” into a decision. The same screen carries the switches for what buyers may see: the cost sheet, construction updates, the estimated value, a site-visit request. Anything sensitive is off until you turn it on.
-
Copy your buyers’ address
The page prints your portal address and a Copy link button. It looks like https://app.saudaflow.in/buyer/greenfield-estates — one address for your whole workspace, not one per buyer and not one per document. There is nothing secret in it: it is the front door, and the sign-in behind it is what decides who gets in.
-
Make sure the number on the booking is the buyer’s own
Sign-in matches the mobile number on the contact record — primary or alternate — and only for a contact that has at least one booking. A number that is not on a booking simply never receives a code, and it is told nothing else, so nobody can use the sign-in screen to find out who your customers are.
If a family member handles the paperwork, put their number on the contact as the alternate. If a number is wrong, fix it on the contact before you invite anyone.
-
Your buyer signs in
They open the address, type their mobile number, and receive a one-time code — valid 10 minutes by default, with five attempts and up to five codes an hour. Once verified, the session lasts 30 days by default and resolves to exactly one buyer. Both timings are yours to change in the same settings screen.
No password, no invitation e-mail, no account to create. And, until DLT registration completes, no code actually arrives — see the two conditions above.
What lands on their screen.
The buyer’s documents tab lists every document row on their booking — the paperwork first, then the identity documents — each with its title, its status and when it last changed.
- Download appears only where there is a file. A document sitting at Pending shows its status and nothing to press. The button appears the moment a version with real bytes behind it exists — the row is not enough on its own.
- They see the status you set. Drafted, Under review, Signed, Registered — in the same words your team uses, which is the point: nobody has to phone and ask where the agreement has got to.
- They never see your working record. The internal note, the legal compliance note and the e-sign metadata are not in the payload at all. That is the staff’s record of the buyer, not a document about them.
- They cannot upload. A buyer cannot send you their PAN card through the portal. They can raise a query or a request, and someone on your team uploads what they send by whatever route you already use.
- Nothing is cached on the way. A downloaded document is served no-store, private — never a shared cache, never a CDN edge.
The consequence worth knowing before you add a document
There is no per-document “hide from buyer” switch. Everything on the booking is on their wall by title and status, including a custom row you added for internal reasons. A file only becomes downloadable when you upload a version — but the title is visible from the moment the row exists.
So: if it should not be seen, it does not belong on the booking. Put it where your internal notes live.
A link that leaks is still a link that works.
Expiring share links are the obvious feature and we do not have one. What is here instead is, for a document that carries a buyer’s PAN and their agreement value, the stronger arrangement — and it is worth knowing why, because it is what you would tell a buyer who asks.
- The document id in the URL is proved, not trusted. The query that fetches a document already contains this session’s organisation and this session’s contact, joined through the booking. A document belonging to another buyer, to another builder, or to nobody at all produces the same not-found. There is no id to guess your way into.
- Access is a session, not a secret in a message. A forwarded WhatsApp link cannot hand your buyer’s paperwork to a stranger, because the link is not the credential — their phone is.
- Withdrawal is immediate. Turning the portal off ends every live session on its next request. There is no expiring window to wait out.
- Codes cannot be brute-forced or farmed. Five attempts per code, five codes an hour per number, and the sign-in screen answers identically for a number it knows and one it does not.
Five things this page used to promise.
None of them exists in the product. Listed by name so nobody plans around one.
-
No expiring share link
There is no route that mints a URL for a document, and no expiry field to put on one. Not 15 minutes, not any duration.
-
No read-once mode
Nothing burns after first view, because there is no link to burn.
-
No watermarking
Saudaflow does not stamp a buyer’s name, phone number or a view timestamp onto a document. The file your buyer downloads is the file you uploaded.
-
No one-time code on a document
The passcode gates sign-in to the portal. Once a buyer is in, their own documents are simply theirs — there is no second challenge per file.
-
No e-mail or WhatsApp delivery of a document
Saudaflow does not send the file anywhere. If you need to e-mail an allotment letter today, download it and send it the way you do now.
-
No buyer upload
Your buyer cannot return a signed page or their KYC through the portal. They ask; your team uploads.
Asked by post-sales teams.
How do I send one document to one buyer right now?
Download it from the versions drawer and send it the way you already do — e-mail, WhatsApp, printed and couriered. Saudaflow does not have a send action and does not have a share link, so nothing here replaces that step today.
What Buyer Connect changes is the ongoing ask: once a buyer can sign in, they stop phoning to request the allotment letter for the third time, because it is on their screen with its status beside it.
Can I stop one document from reaching the buyer?
Not per document — there is no visibility switch on a document row. Every document on the booking appears on their wall by title and status, and becomes downloadable when a version exists.
The controls you do have are the portal itself, which is on or off for the whole workspace, and the section switches in Settings for the cost sheet, construction updates and the estimated value. If a piece of paperwork must not be seen by the buyer, keep it off the booking.
My buyer says the sign-in code never arrived.
Today that is expected, everywhere, for everyone: our DLT registration with TRAI is still in progress, so no sign-in SMS is being delivered. It is not your buyer’s handset and not their number.
When it is live, the ordinary causes are a number that is not on any booking, five codes already requested in the last hour, or a code older than ten minutes. The screen says which without ever revealing whether the number belongs to a customer.
Two buyers own the flat jointly. Do both get access?
A session resolves to one contact, and a booking has one contact on it. Both the primary and the alternate number on that contact can sign in, which covers the common case of a spouse or a son handling the paperwork. A genuinely separate second contact with their own booking-level access is not something the portal does today.
Related pages.
- Buyer Connect, in fullEverything the portal shows a buyer, how it is branded, and where it is honestly not ready.
- How booking documents workWhat creates the wall, the two status machines, and what protects a stored file.
- Upload a documentUploading a version is what makes a document downloadable for the buyer.
- Tracking an e-signatureThe six states, and what completing one moves.
Waiting on the sign-in SMS, or unsure whether your portal is on? Write to support@saudaflow.in — the desk is open 09:30–19:00 IST, every day.