Our commitment in plain English
- We process business operational data, not personal consumer data.
- We never sell your data to third parties.
- You can request deletion of your data at any time.
- We are GDPR-aware and apply privacy by design across our platform.
1. Who We Are
SellerDesk (“we”, “us”, “our”) is a business-to-business software-as-a-service platform that provides warehouse management, order management, and fulfilment operations tooling to merchants, brands, and logistics operators.
For the purposes of applicable data protection law, SellerDesk is the data controllerof the business and account information you provide to us during sign-up, onboarding, and ongoing use of the platform. Where we process data strictly on your instructions (for example, your customers’ order records stored within SellerDesk), we act as a data processor on your behalf.
For questions about this policy or our data practices, contact us at privacy@sellerdesk.app.
2. Data We Collect
We collect and process the following categories of information:
Account & Organisation Data
Company name, registered address, VAT/GST number, business type, subscription plan, and the name and work email address of authorised users within your organisation.
Operational Data
Purchase orders, goods-received notes, shipment records, packing instructions, stock levels, warehouse locations, supplier and carrier details, and related operational transactions you create or import within the platform. This data belongs to your business.
Billing & Payment Data
Subscription tier, billing cycle, invoice history, and payment method tokens. Full card numbers are never stored by SellerDesk; payments are processed by our certified payment provider.
Usage & Technical Data
Browser type, IP address, device identifiers, pages visited, feature interactions, timestamps, and error logs collected to operate, secure, and improve the service.
Communications Data
Emails, support tickets, and other messages you send to us, retained to resolve queries and improve our support quality.
3. How We Use Your Data
We use the data we collect to:
- Provide, operate, and maintain the SellerDesk platform and all features within your subscription.
- Process subscription payments, issue invoices, and manage your account.
- Send transactional communications — account confirmations, billing receipts, critical service alerts.
- Provide customer support and investigate technical issues.
- Analyse aggregated, anonymised usage patterns to improve product features and reliability.
- Detect, investigate, and prevent fraudulent, abusive, or illegal activity.
- Comply with legal obligations, including tax record-keeping and regulatory requirements.
- Send product updates and marketing communications — you may opt out at any time.
Our legal bases for processing under the UK GDPR and EU GDPR are: contract performance (delivering the service you subscribed to), legitimate interests (platform security and improvement), legal obligation (tax and compliance), and consent (marketing communications).
4. Third-Party Services & Sub-processors
We engage trusted sub-processors to deliver the platform. All sub-processors are bound by data processing agreements and are required to maintain appropriate technical and organisational safeguards.
- Cloud infrastructure — our platform is hosted on SOC 2-certified cloud infrastructure in data centres located in the EU and/or India.
- Payment processing — billing is handled by a PCI-DSS Level 1 certified provider. SellerDesk does not store raw card data.
- Email delivery — transactional and product emails are delivered via a third-party email service provider.
- Error monitoring — anonymised crash reports and logs may be sent to error-tracking services to improve stability.
- Analytics — privacy-preserving, aggregated usage analytics only. No individual user profiling for advertising.
We do not sell, rent, or share your data with third parties for their own marketing purposes.
5. Data Retention
We retain your data for as long as your subscription is active and for a defined period thereafter:
- Active account data is retained for the duration of your subscription.
- Operational records (orders, GRNs, shipments) are retained for 7 years from the date of creation to satisfy tax and audit obligations, unless you request earlier deletion and no legal hold applies.
- Billing records are retained for 7 years in line with financial record-keeping requirements.
- Support communications are retained for up to 3 years.
- Technical logs are purged within 90 days.
On account closure you may submit a data deletion request. We will delete or anonymise personal data within 30 days, subject to any applicable legal retention obligations.
6. Your Rights
Rights available under GDPR and UK GDPR
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — request deletion of your data where no legal basis for retention applies.
- Portability — receive your data in a machine-readable format.
- Restriction — ask us to pause processing while a dispute is resolved.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — opt out of marketing at any time without affecting other processing.
To exercise any of these rights, email privacy@sellerdesk.app. We will respond within 30 days. If you believe we have not handled your data correctly, you have the right to lodge a complaint with your national data protection authority.
7. Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls limiting employee access to data on a need-to-know basis.
- Regular security assessments and penetration testing.
- Incident response procedures and breach notification processes.
No system is perfectly secure. In the event of a personal data breach that poses a risk to your rights, we will notify affected organisations and the relevant supervisory authority within 72 hours of becoming aware, as required by applicable law.
8. International Data Transfers
SellerDesk primarily stores and processes data within India and the European Economic Area. Where we or our sub-processors transfer data outside these regions, we ensure appropriate safeguards are in place — including Standard Contractual Clauses approved by the European Commission, or equivalent mechanisms recognised under applicable data protection law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or by displaying a prominent notice in the platform at least 14 days before the changes take effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of SellerDesk after changes become effective constitutes acceptance of the updated policy.
10. Contact Us
For privacy enquiries, data subject requests, or to reach our Data Protection contact:
SellerDesk — Privacy Team
