> Canonical page: https://www.sellready.eu/en/security

# Security & privacy

> Where your data is stored, how SellReady protects it and how you export or delete it – concrete measures instead of badges.

## Concrete measures instead of badges.

This is what we actually do: where your data is stored, how we protect it, who processes it on our behalf and how you get it back.

## Encryption

### In transit

All connections use HTTPS with HSTS. Unencrypted requests are redirected.

### At rest

Database and file storage are encrypted at rest by our hosting provider.

### Etsy access keys

Additionally encrypted inside the application with AES-256-GCM. The key lives outside the database and can be rotated.

## Tenant isolation

### Row-level security

Every table with customer data is bound to your tenant via Postgres row-level security. Without a matching tenant, the database returns no rows.

### Separate database roles

Sign-in and business data use separate roles without bypass rights. Access happens server-side only – there is no public database API.

### Tested on every change

Automated tests try to read other tenants’ data on every change – and have to fail.

## Etsy access: read-only

### Two read permissions

SellReady only requests shops_r and listings_r – no write access, no access to orders, email addresses or postal addresses.

### No buyer data

Because SellReady does not read orders, your customers’ names and addresses never reach us in the first place.

### Disconnect any time

If you disconnect, we delete access keys and imported Etsy data immediately. Your own details, such as manufacturers and documents, stay.

## Account & sign-in

### Sign in without password pressure

Magic link, one-time code, passkey or password – your choice.

### Two-factor sign-in

Optional for your account, mandatory for every account with admin rights at SellReady.

### Lean sessions

We store neither IP address nor browser identifier with sessions.

## This website

### No tracking cookies

Only technically necessary cookies, for example for sign-in and your language choice. That is why there is no cookie banner.

### No third parties in your browser

Fonts are served from our own server, there are no embedded videos or chat widgets. To pay, we redirect you to Stripe’s own page.

### Reach without profiles

For visitor numbers we use cookieless statistics without any cross-site identifier.

## Export & deletion

### Export everything

A ZIP with JSON, CSV and all document files, created in the background. The download link is valid for 72 hours.

### Delete your account

Right in your settings. You have 14 days to change your mind, then we delete for good.

### What has to stay

We must keep invoices for 7 years. Until then they are locked and used for that purpose only.

## Retention

- Server logs (with IP address): 30 days
- Imported raw Etsy data: Until disconnect, then immediately
- Export files: 72 hours
- In-app notifications: 180 days
- Deleted accounts: 14 days to reconsider, then final
- Invoices: 7 years, locked
