Privacy Policy

Last updated: May 9, 2026

Who we are

Sellersperch is a multi-channel listing-management service operated at sellersperch.com. This policy explains what data we collect, how we store it, and how to delete it.

What we collect

  • Account info: name, email, hashed password (or OAuth identity if you sign in via Google) — used to authenticate you and contact you about your account.
  • Connected marketplace credentials: when you link an eBay, Amazon, Shopify, or similar account, we store the refresh token issued by that marketplace. Tokens are encrypted at rest with libsodium crypto_secretbox_easy using a per-deployment master key. We never see or store your marketplace password.
  • Listing and order data: products, prices, inventory, orders, messages, and templates you create or import. This is your business data; we store it so the service can function.
  • Operational data: server logs, error reports, and rate-limit telemetry, retained for up to 90 days for debugging and abuse prevention.

What we do not do

  • We do not sell your data.
  • We do not use your listing or order data to train machine-learning models that benefit other customers.
  • We do not share marketplace tokens or credentials with third parties outside the marketplace they belong to.

How we share data

We share data only with:

  • The marketplaces you connect (eBay, Amazon, Shopify, etc.) — to list, update, and fulfill on your behalf.
  • Sub-processors strictly necessary to run the service: our hosting provider (Vercel), database (Neon), object storage (Cloudflare R2), queue (Upstash Redis), and email provider. Each is bound by contractual data-processing terms.
  • Law enforcement, when legally compelled.

How long we keep it

Account and listing data are retained as long as your account is active. When you delete your account, we delete or anonymize your data within 30 days, except where retention is legally required (e.g. tax records).

eBay Marketplace Account Deletion

When eBay sends us a Marketplace Account Deletion notification for a user, we delete or anonymize all data tied to that eBay user (refresh tokens, listing cache, order history) across every Sellersperch tenant that had connected that eBay account, within 30 days of receiving the notification.

Your rights

You can request export or deletion of your data by emailing support@sellersperch.com. If you are in the EU/UK, you have rights under GDPR/UK-GDPR including access, correction, portability, and erasure.

Security

We encrypt data in transit (TLS 1.2+) and encrypt marketplace refresh tokens at rest. Production access is restricted to authorized personnel using SSO and MFA.

Changes

When we change this policy materially, we will notify users by email at least 14 days before the change takes effect.

Contact

Email support@sellersperch.com for any privacy questions or to exercise your rights.