Security
Concrete measures instead of badges.
This is what we actually do: where your data is stored, how we protect it, who processes it on our behalf and how you get it back.
Last updated: September 28, 2026
Where your data is stored
For every service we choose the EU region wherever the provider offers one. For providers based in the US, standard contractual clauses and the EU-US Data Privacy Framework apply in addition.
Vercel Inc.
- Purpose
- Application hosting, server functions, scheduled jobs, cookieless web statistics
- Location
- Frankfurt (fra1), no fallback region outside the EU
- Transfer
- US company: standard contractual clauses and EU-US Data Privacy Framework
Supabase Inc.
- Purpose
- Database, file storage for documents, background jobs
- Location
- Frankfurt (eu-central-1)
- Transfer
- US company: standard contractual clauses and EU-US Data Privacy Framework
Stripe Payments Europe Ltd. / Stripe, Inc.
- Purpose
- Payment processing, subscriptions, invoices, VAT calculation
- Location
- Primarily EU
- Transfer
- US company: standard contractual clauses and EU-US Data Privacy Framework
Amazon Web Services EMEA SARL / Amazon.com, Inc.
- Purpose
- Sending system emails such as sign-in codes, reminders and export notifications
- Location
- Frankfurt (eu-central-1), dedicated AWS account
- Transfer
- US company: standard contractual clauses and EU-US Data Privacy Framework
Functional Software, Inc. (Sentry)
- Purpose
- Error and stability monitoring
- Location
- EU region (Frankfurt)
- Transfer
- US company: standard contractual clauses and EU-US Data Privacy Framework
Vercel AI Gateway → Amazon Web Services (Bedrock)
- Purpose
- AI suggestions for product classification – you confirm every suggestion, can be switched off per shop
- Location
- Frankfurt (AWS Bedrock, eu-central-1), no storage beyond the request
- Transfer
- US company: standard contractual clauses and EU-US Data Privacy Framework
| Provider | Purpose | Location | Transfer |
|---|---|---|---|
| Vercel Inc. | Application hosting, server functions, scheduled jobs, cookieless web statistics | Frankfurt (fra1), no fallback region outside the EU | US company: standard contractual clauses and EU-US Data Privacy Framework |
| Supabase Inc. | Database, file storage for documents, background jobs | Frankfurt (eu-central-1) | US company: standard contractual clauses and EU-US Data Privacy Framework |
| Stripe Payments Europe Ltd. / Stripe, Inc. | Payment processing, subscriptions, invoices, VAT calculation | Primarily EU | US company: standard contractual clauses and EU-US Data Privacy Framework |
| Amazon Web Services EMEA SARL / Amazon.com, Inc. | Sending system emails such as sign-in codes, reminders and export notifications | Frankfurt (eu-central-1), dedicated AWS account | US company: standard contractual clauses and EU-US Data Privacy Framework |
| Functional Software, Inc. (Sentry) | Error and stability monitoring | EU region (Frankfurt) | US company: standard contractual clauses and EU-US Data Privacy Framework |
| Vercel AI Gateway → Amazon Web Services (Bedrock) | AI suggestions for product classification – you confirm every suggestion, can be switched off per shop | Frankfurt (AWS Bedrock, eu-central-1), no storage beyond the request | US company: standard contractual clauses and EU-US Data Privacy Framework |
Encryption
In transit
All connections use HTTPS with HSTS. Unencrypted requests are redirected.
At rest
Database and file storage are encrypted at rest by our hosting provider.
Etsy access keys
Additionally encrypted inside the application with AES-256-GCM. The key lives outside the database and can be rotated.
Tenant isolation
Row-level security
Every table with customer data is bound to your tenant via Postgres row-level security. Without a matching tenant, the database returns no rows.
Separate database roles
Sign-in and business data use separate roles without bypass rights. Access happens server-side only – there is no public database API.
Tested on every change
Automated tests try to read other tenants’ data on every change – and have to fail.
Etsy access: read-only
Two read permissions
SellReady only requests shops_r and listings_r – no write access, no access to orders, email addresses or postal addresses.
No buyer data
Because SellReady does not read orders, your customers’ names and addresses never reach us in the first place.
Disconnect any time
If you disconnect, we delete access keys and imported Etsy data immediately. Your own details, such as manufacturers and documents, stay.
Account & sign-in
Sign in without password pressure
Magic link, one-time code, passkey or password – your choice.
Two-factor sign-in
Optional for your account, mandatory for every account with admin rights at SellReady.
Lean sessions
We store neither IP address nor browser identifier with sessions.
This website
No tracking cookies
Only technically necessary cookies, for example for sign-in and your language choice. That is why there is no cookie banner.
No third parties in your browser
Fonts are served from our own server, there are no embedded videos or chat widgets. To pay, we redirect you to Stripe’s own page.
Reach without profiles
For visitor numbers we use cookieless statistics without any cross-site identifier.
Export & deletion
Export everything
A ZIP with JSON, CSV and all document files, created in the background. The download link is valid for 72 hours.
Delete your account
Right in your settings. You have 14 days to change your mind, then we delete for good.
What has to stay
We must keep invoices for 7 years. Until then they are locked and used for that purpose only.
Retention
Every data category has a fixed period and is deleted or locked automatically.
| Data | Period |
|---|---|
| Server logs (with IP address) | 30 days |
| Imported raw Etsy data | Until disconnect, then immediately |
| Export files | 72 hours |
| In-app notifications | 180 days |
| Deleted accounts | 14 days to reconsider, then final |
| Invoices | 7 years, locked |
Agreements & lists
Found a vulnerability?
Write to us confidentially at hallo@sellready.eu. We get back to you as quickly as we can.
This page describes our technical setup. It is not a certification and does not replace the data processing agreement.