Skip to content

Security

Concrete measures instead of badges.

This is what we actually do: where your data is stored, how we protect it, who processes it on our behalf and how you get it back.

Last updated: September 28, 2026

Where your data is stored

For every service we choose the EU region wherever the provider offers one. For providers based in the US, standard contractual clauses and the EU-US Data Privacy Framework apply in addition.

  • Vercel Inc.

    Purpose
    Application hosting, server functions, scheduled jobs, cookieless web statistics
    Location
    Frankfurt (fra1), no fallback region outside the EU
    Transfer
    US company: standard contractual clauses and EU-US Data Privacy Framework
  • Supabase Inc.

    Purpose
    Database, file storage for documents, background jobs
    Location
    Frankfurt (eu-central-1)
    Transfer
    US company: standard contractual clauses and EU-US Data Privacy Framework
  • Stripe Payments Europe Ltd. / Stripe, Inc.

    Purpose
    Payment processing, subscriptions, invoices, VAT calculation
    Location
    Primarily EU
    Transfer
    US company: standard contractual clauses and EU-US Data Privacy Framework
  • Amazon Web Services EMEA SARL / Amazon.com, Inc.

    Purpose
    Sending system emails such as sign-in codes, reminders and export notifications
    Location
    Frankfurt (eu-central-1), dedicated AWS account
    Transfer
    US company: standard contractual clauses and EU-US Data Privacy Framework
  • Functional Software, Inc. (Sentry)

    Purpose
    Error and stability monitoring
    Location
    EU region (Frankfurt)
    Transfer
    US company: standard contractual clauses and EU-US Data Privacy Framework
  • Vercel AI Gateway → Amazon Web Services (Bedrock)

    Purpose
    AI suggestions for product classification – you confirm every suggestion, can be switched off per shop
    Location
    Frankfurt (AWS Bedrock, eu-central-1), no storage beyond the request
    Transfer
    US company: standard contractual clauses and EU-US Data Privacy Framework

Encryption

  • In transit

    All connections use HTTPS with HSTS. Unencrypted requests are redirected.

  • At rest

    Database and file storage are encrypted at rest by our hosting provider.

  • Etsy access keys

    Additionally encrypted inside the application with AES-256-GCM. The key lives outside the database and can be rotated.

Tenant isolation

  • Row-level security

    Every table with customer data is bound to your tenant via Postgres row-level security. Without a matching tenant, the database returns no rows.

  • Separate database roles

    Sign-in and business data use separate roles without bypass rights. Access happens server-side only – there is no public database API.

  • Tested on every change

    Automated tests try to read other tenants’ data on every change – and have to fail.

Etsy access: read-only

  • Two read permissions

    SellReady only requests shops_r and listings_r – no write access, no access to orders, email addresses or postal addresses.

  • No buyer data

    Because SellReady does not read orders, your customers’ names and addresses never reach us in the first place.

  • Disconnect any time

    If you disconnect, we delete access keys and imported Etsy data immediately. Your own details, such as manufacturers and documents, stay.

Account & sign-in

  • Sign in without password pressure

    Magic link, one-time code, passkey or password – your choice.

  • Two-factor sign-in

    Optional for your account, mandatory for every account with admin rights at SellReady.

  • Lean sessions

    We store neither IP address nor browser identifier with sessions.

This website

  • No tracking cookies

    Only technically necessary cookies, for example for sign-in and your language choice. That is why there is no cookie banner.

  • No third parties in your browser

    Fonts are served from our own server, there are no embedded videos or chat widgets. To pay, we redirect you to Stripe’s own page.

  • Reach without profiles

    For visitor numbers we use cookieless statistics without any cross-site identifier.

Export & deletion

  • Export everything

    A ZIP with JSON, CSV and all document files, created in the background. The download link is valid for 72 hours.

  • Delete your account

    Right in your settings. You have 14 days to change your mind, then we delete for good.

  • What has to stay

    We must keep invoices for 7 years. Until then they are locked and used for that purpose only.

Retention

Every data category has a fixed period and is deleted or locked automatically.

Retention
DataPeriod
Server logs (with IP address)30 days
Imported raw Etsy dataUntil disconnect, then immediately
Export files72 hours
In-app notifications180 days
Deleted accounts14 days to reconsider, then final
Invoices7 years, locked

Agreements & lists

Found a vulnerability?

Write to us confidentially at hallo@sellready.eu. We get back to you as quickly as we can.

This page describes our technical setup. It is not a certification and does not replace the data processing agreement.