Privacy policy
This policy explains what personal data we process in connection with the sellaro.eu / sellaro.pl website and the Sellaro service, why, for how long, and what your rights are. We keep it in plain language, with nothing hidden in footnotes.
1. Data controller
The controller is Web Systems Krzysztof Balicki, ul. Bursztynowa 4, 95-020 Janówka, Poland, VAT ID (NIP) PL7292462454 (“we”, “Sellaro”).
For anything related to personal data, write to hello@sellaro.eu or send a letter to the address above. We have not appointed a data protection officer, as we are not required to.
2. What data, why, and on what legal basis
2.1. Visiting the website
The server records standard technical data in its logs: IP address, date and time, the page requested, the response code and browser information (user agent). We use it only to run and secure the service, for example to detect abuse and fix errors. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR). Logs are deleted automatically, currently after about 30 days.
Fonts are served from our own server, so your browser does not connect to third-party providers. The website uses no advertising pixels and no profiling. Visit statistics and cookies are covered in section 2.6.
2.2. Contact, demo requests and early access
When you email us, we process the data you choose to give us: usually your name, email address, company name and the content of your message. We use it to reply, book a demo or set up an early access account. Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR) and, otherwise, our legitimate interest in handling correspondence (Art. 6(1)(f) GDPR). We keep correspondence for as long as the matter requires and, where it relates to a contract, until any claims become time-barred.
2.3. Sellaro panel account
For panel users we process the email address, name (if provided), a password hash, team role, the customer account the user belongs to and basic login information. This data is necessary to provide the service (Art. 6(1)(b) GDPR). We keep it for the duration of the contract and afterwards until any claims become time-barred.
When you sign up yourself, you give us the company name, VAT number (or Polish NIP), your name, email address and password. We also record when you accepted the terms and this policy and when you were last active in the panel. We check the VAT number in a public register, the EU VIES system or the Polish Ministry of Finance VAT register (the so-called white list), to confirm that the account is created by a business, and we store the company name returned by the register. Legal basis: the contract (Art. 6(1)(b) GDPR) and our legitimate interest in preventing fake accounts (Art. 6(1)(f) GDPR). The sign-up form limits attempts per IP address. We may delete a free account that has not been used for 90 days, after warning you by email.
The panel stores a login token and your preferences, such as the colour theme, in your browser's local storage. This is strictly necessary for the panel to work and is not used for tracking.
2.4. Your store's customer data
Once you connect a store (e.g. PrestaShop, Sylius, WooCommerce), Sellaro receives order data, including your buyers' names, delivery addresses, email addresses and phone numbers. You, as the merchant, are the controller of that data; we process it only on your behalf and on your instructions, as a processor (Art. 28 GDPR). The data processing terms are set out in the Terms of service. Each Sellaro customer's data is kept in a separate database schema, isolated from other customers.
2.5. Billing, payments and the partner programme
If you use a paid plan or the partner programme, we process the company details needed to issue invoices and settle commissions (name, address, VAT ID, contact details). Legal basis: the contract (Art. 6(1)(b) GDPR) and our tax and accounting obligations (Art. 6(1)(c) GDPR). Accounting records are kept for the period required by law, usually 5 years from the end of the tax year.
Card payments are handled for us by Stripe. When you click “Upgrade to Pro” or “Upgrade to Business”, you are taken to a Stripe payment page and enter your card details and billing address there. We never see or store your card number - Stripe only gives us a customer and subscription identifier, the payment status, the amount, the currency, the billing address given at checkout and, for cards, the last four digits. Stripe also processes this data as a controller in its own right, to carry out the payment, prevent fraud and meet its own legal obligations; see the Stripe privacy policy.
VAT invoices are issued and emailed through Fakturownia. It receives the buyer details shown on the invoice: company name, address, VAT ID, email address, and the invoice line and amount.
2.6. Visit statistics (Google Analytics) and cookies
We want to know how many people visit the site and which articles get read, so we use Google Analytics 4, deployed through Google Tag Manager. It stores cookies and an identifier in your browser so that several page views can be counted as one visit. We collect page views, the traffic source, an approximate location (from a shortened IP address), the device type and the browser. We do not link this to your panel account and we do not use it for advertising.
Legal basis: your consent (Art. 6(1)(a) GDPR and Art. 173 of the Polish Telecommunications Act). Until you give it, we load no Google script, store no cookies and send no request to Google at all. You can withdraw consent at any time through the “Privacy settings” link in the footer; withdrawal applies going forward. Data in Google Analytics is kept for 14 months.
Whatever you answer, your browser remembers one technical detail: your answer to this question (in the browser's local storage), so that we do not ask again on every page.
3. Who we share data with
- Hetzner Online GmbH (Germany): provider of the servers Sellaro runs on, including the mail server.
- Google Ireland Limited (Ireland): Google Analytics and Google Tag Manager, only after you have given consent, limited to website visit data.
- Stripe Payments Europe, Limited (Ireland) and other Stripe group companies: card payments and subscriptions, limited to the billing data described in section 2.5.
- Fakturownia sp. z o.o. (Warsaw, Poland): the system used to issue and send invoices, limited to the buyer details on the invoice.
- Our accounting office: billing data only.
- The European Commission (VIES) or the Polish Ministry of Finance (VAT register): only the VAT number or NIP, at sign-up, to check it.
- Telecom operators: only if you use SMS notifications, limited to the phone number and message content.
- Public authorities: only where required by law.
We do not sell data or share it for marketing purposes.
Transfers outside the European Economic Area. The Sellaro servers, our mail server and the invoicing system all run in the European Union. Google may transfer website visit data to Google LLC in the United States, under the standard contractual clauses and the adequacy decision for the EU-US Data Privacy Framework; this only happens if you agree to statistics. Payments are the one exception: Stripe may transfer billing data to its group companies outside the EEA, including Stripe, Inc. in the United States. Those transfers rely on the standard contractual clauses approved by the European Commission and on the adequacy decision for the EU-US Data Privacy Framework. Your store's buyer data is not transferred outside the EEA.
4. Your rights
You have the right to access your data, to have it rectified, erased or restricted, to data portability, and to object to processing based on our legitimate interest. Just email hello@sellaro.eu. We reply without undue delay and within one month at the latest.
If you believe we process your data unlawfully, you can lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes UODO, ul. Stawki 2, 00-193 Warsaw), or with the authority in your country of residence.
If you are a buyer in a store that uses Sellaro, please contact that store first about your data, as it is the controller. We will help it handle your request.
5. Voluntary data and automated decisions
Providing data is voluntary, but without an email address we cannot reply to you or create an account, and without company and payment details we cannot start a paid plan. We do not make decisions about you based solely on automated processing and we do not profile you. Stripe runs its own automated fraud checks, which may decline a card payment; if that happens, write to us and we will look into it with you.
6. Security
Connections to the website and the panel are encrypted (HTTPS). Passwords are stored only as hashes and API keys as SHA-256 hashes. Data in the panel is accessible to the people on the customer's account according to their roles and, beyond them, only to our administrators when needed to run or support the service.
7. Changes to this policy
We may update this policy when the service or the law changes. The current version is always available at this address, and we will notify panel users by email about material changes.