Back to Home

Privacy & Data Protection

Last updated: September 23, 2026

Sellervate Privacy Notice

We are committed to protecting and respecting your privacy. This notice sets out how we look after personal data and tells you about your privacy rights and how the law protects you.

Sellervate handles personal data in two different capacities, and this notice is split accordingly. Part A covers visitors to our website, prospects and our own client account contacts. For that data we decide the purposes ourselves, so we are the controller. Part B covers the end-customer data we handle on behalf of client brands, where the client is the controller and we are the processor.

Part A: When we are the controller

This part applies to visitors to www.sellervate.com, to prospective customers, and to the people who hold or administer a Sellervate account on behalf of a client. In these situations we decide why and how personal data is processed, so we are the controller.

1. Introduction

"We", "us" and "our" refer to Sellervate and its affiliates. Sellervate is operated by SELLERVATE LLC, a company incorporated in the United States with its registered offices at 7901 4th St N, Suite 300, St. Petersburg, FL 33702, USA.

This part of the notice applies when you visit our website: www.sellervate.com and if you use the services we offer through our website. It also applies if we otherwise identify you as a potential customer or if you supply services to us. These are all situations where we are acting as a data controller with respect to your personal data, that is when we determine why and how your personal data is processed.

Sometimes we handle personal data about the end customers of a client brand, for example when we answer their messages, process their returns or analyse their reviews on that brand's behalf. We are not the controller of that data. The client brand is, and we act as its processor. That processing is described in Part B.

Contact us at privacy@sellervate.com with any questions in relation to this notice or your privacy rights.

Any changes we make to our privacy notice in the future will be posted on this page. Please check back frequently to see any updates or changes.

Our website may from time to time contain links to and from the websites of other businesses. If you follow a link to any of these websites, please note that these websites have their own privacy notices and that we do not accept any responsibility or liability for their privacy obligations. Please check their privacy notices before you submit any personal data to these websites.

2. The types of data that we collect and how we collect it

Personal information, or personal data, means any information about an individual from which that person can be identified. We may collect, use, store and transfer different kinds of personal data about you which we collect from various sources as described below:

Amazon Seller Data

  • Seller Central account access tokens (used only for your own account access)
  • Order and customer service data (for your own account only)
  • Product listings and inventory data (for your own account only)
  • Customer reviews and feedback (for your own account only)
  • Returns and refunds data (for your own account only)

Note: All Amazon seller data is processed only for your individual account. We do not aggregate, combine, or share data between different seller accounts.

Identity Data

Includes first name, last name and email address. We collect this data directly from you when you set up an account with us to use our services.

Contact Data

Includes name, email address, work details, address and telephone numbers. We collect this data from you when you request information about our products and services or create an account to use our services.

Publication Data

Includes details you choose to publish via our website to others including your Identity Data and Contact Data when you provide testimonials on our website.

Transaction Data

Includes details of our products and services you have purchased and payments made via our website. All payments are made through our payment processor.

Technical Data

Includes IP address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our website.

Usage Data

Includes information about how you use our website, products and services. On our website this is measured in aggregate by Plausible Analytics and Vercel Analytics, neither of which uses cookies or tracks you across other websites. See section 9 for details.

Marketing and Communications Data

Includes your preferences in receiving marketing communications from us. We collect this information when you sign up for our newsletters, request a demo, or create a user account.

Profile Data

Data that contributes to building a behavioral profile of you which is built up from a combination of information, for example:

  • Your name, username
  • Purchases or orders made by you
  • Your online behavior and browsing patterns
  • The electronic devices you use
  • Your interests, preferences, demographics, location data
  • Any feedback and survey responses

Data Usage and Privacy

We process your data solely for the purpose of providing our services to you. We do not:

  • We do not aggregate or combine data from multiple seller accounts
  • We do not share your Amazon seller data with other sellers or third parties
  • We do not use your data for any purpose other than providing our services to you
  • We do not create market insights or analytics from combined seller data

All data processing is done in compliance with Amazon's Terms of Service and data handling requirements.

Special Categories of Personal Data

We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offenses.

3. How we use your personal data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • Where you have given your consent to the processing of your personal data for a particular purpose.
  • Where it is necessary for the performance of a contract with you or to take steps to enter into a contract with you.
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal or regulatory obligation.

Purposes for which we will use your personal information

Purpose/ActivityLawful basis for processing
To register you as a user of our services (whether for a trial or paid subscription) and create your user accountPerformance of a contract with you
To provide the functionality of our services that you have requested via our web platformPerformance of a contract with you
To administer and support the services you have requested including to send service notifications, manage payments and exercise our legal rights
  • Performance of a contract with you
  • Necessary for our legitimate interests (efficient running of our business, recovery of amounts due)
To manage our relationship with you (changes to terms, updates, feedback, surveys)
  • Performance of a contract with you
  • Necessary to comply with legal obligations
  • Necessary for our legitimate interests (keeping records updated, managing our services)
To administer, protect and manage our business and website
  • Necessary for our legitimate interests (running our business, provision of administration and IT services)
  • Necessary to comply with legal obligations
To follow up sales leads and make sales
  • Your consent (if required)
  • Necessary for our legitimate interests (to grow our business)
To send you marketing communications
  • Your consent (if required)
  • Necessary for our legitimate interests (to market our products and services)
To use data analytics to improve our website, products/services, marketing, and user experiencesNecessary for our legitimate interests (to improve our products and services, develop our business)

Children

Our services are not directed to individuals under the age of 13 and you may only create an account to use our services if you are 18 or over.

Marketing and Opting out

You will receive our marketing communications if you have specifically consented to receive them.

If you have already purchased our products and services and/or signed up for a trial, we may send you information about our similar products or services under soft opt-in consent.

You may also receive our marketing communications in your business capacity if you have requested information from us or if we have identified you as someone who may be interested in our products/services.

You can unsubscribe from our marketing messages at any time by following the opt-out links on any marketing message sent to you or by emailing privacy@sellervate.com at any time.

4. Providing your personal data to others

Payments via our website

All payments through our website are made using our payment processor. You will be directed to the payment service to enter your card and other billing details.

In processing payment transactions, the Payment Processor acts as a data processor to us but in carrying out fraud monitoring, prevention and detection services, it acts as controller and may monitor insights and patterns of payment transactions and other online signals to reduce the risk of fraud, money laundering and other harmful activity.

On completion of payment, our Payment Processor will provide us with limited payment details (your name, billing address, billing email, card type, expiry date and the last four digits of your payment card number) so that we can manage payment transactions and your account. Full payment details are held securely by the Payment Processor.

Others with whom we may share personal data

We share limited personal data with our affiliates only to the extent required to provide our services and for internal administration purposes.

We share your personal data with selected third parties, including:

  • Third party service providers who we use to help manage our business.
  • Third party apps that you use to sell, support and fulfill your orders but only if you have chosen to integrate any such apps with our services.
  • Insurers and/or professional advisers insofar as reasonably necessary for the purposes of obtaining or maintaining insurance coverage, managing risks, obtaining professional advice, or the establishment, exercise or defense of legal claims.
  • Taxation authorities, regulators, law enforcement agencies and other authorities if required by such authorities or by due process of law.
  • Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets.

5. International transfers of your personal data

Sellervate is operated from the United States and your personal data is processed there. Our hosting, database, file storage and email infrastructure run in the Amazon Web Services US East (Northern Virginia) region, and our web applications are hosted in the United States.

If you are located in the United Kingdom or the European Economic Area (EEA), this means your personal data is transferred outside those jurisdictions. We make those transfers under the following instruments:

  • For transfers from the EEA: the European Commission's Standard Contractual Clauses (Decision 2021/914), module as applicable.
  • For transfers from the United Kingdom: the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses.

Please email privacy@sellervate.com if you would like details of the appropriate safeguards we have in place for transfers of data outside of the UK or EEA.

6. Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. These include:

Hosted on SOC 2 Type II certified infrastructure (Amazon Web Services). Sellervate does not itself currently hold a SOC 2 Type II report.
AWS infrastructure with encryption at rest and in transit
Least-privilege access with periodic access reviews
Access controls and audit logging
Automated data backup and recovery
Multi-factor authentication
Role-based access control
Incident response procedures

In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

7. Retaining and deleting personal data

We will retain your personal data for as long as necessary to provide you with our services and for so long as you do not wish to unsubscribe from our marketing communications or from receiving targeted advertising. We will also retain your personal data as necessary to fulfill our contractual obligations and to comply with our legal obligations, resolve disputes, and enforce our agreements.

Our specific retention periods are:

Active account data: Duration of service usage
Archived data: 12 months after account closure
Audit logs: 7 years per compliance requirements
Analytics data: Anonymized after 24 months

Where we no longer need to process your personal data for the purposes set out in this privacy notice, we will delete your personal data from our systems unless we need to retain a limited amount of information to make sure that we act in accordance with your wishes.

Where permissible, we will also delete your personal data on your request. Information on how to make a deletion request can be found in Section 8, Your rights.

Please email privacy@sellervate.com if you would like details of our retention periods for different kinds of personal data.

8. Your rights

You have certain legal rights with respect to your personal information depending on your location and applicable laws. You may exercise your rights at any time by contacting us at privacy@sellervate.com.

Your rights if you are resident in the UK or the EEA

RightDescription
Right of accessYou have the right to access any personal data we hold about you: we will provide a copy of your personal data that we hold together with details of the purposes of the processing, the types of personal data we hold and the people to whom your personal data has been disclosed.
Right to rectificationYou have the right to have inaccurate or incomplete personal data corrected or to restrict the processing of personal data whilst the accuracy is checked.
Right to erasureYou have the right to ask to have personal data we hold about you erased. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing, where we may have processed your information unlawfully or where we are required to erase your personal data to comply with law.
Right to data portabilityIn certain circumstances, you have the right to have data we hold about you transferred to yourself or another data controller. Note, this right only applies to information that is processed by automated means which you initially provided consent for us to use or where we used the information to perform a contract with you.
Right to objectYou have the right to:
  • Ask us not to process your personal data for direct marketing purposes
  • Object, on grounds relating to your particular situation, to the processing of your personal data (including profiling) where we are relying on a legitimate interest
Right to withdraw consentYou have the right to withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent.
Right to complainYou have the right to lodge a complaint with the relevant data protection supervisory authority if you are unhappy with the way we are handling your personal data.

Your rights if you are a resident of California

How We Collect, Use, and Disclose your Personal Information

The types of data that we collect and how we collect it section describes the personal information we may have collected over the last 12 months, including the categories of sources of that information. We collect this information for the purposes described in the How we use your personal data section. We share this information as described in the Providing your personal data to others section.

Your CCPA Rights and Choices

As a California consumer and subject to certain limitations under the CCPA, you have choices regarding our use and disclosure of your personal information:

Exercising the right to know

You may request, up to twice in a 12-month period, information about the personal information we have collected about you during the past 12 months, including the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected the personal information, the business or commercial purpose for which we collected the personal information, the categories of third parties with whom we shared the personal information, and the categories of personal information about you that we disclosed for a business purpose, and the categories of third parties to whom we disclosed that information for a business purpose.

Exercising the right to delete

You may request that we delete the personal information we have collected from you, subject to certain limitations under applicable law.

Exercising the right to opt-out from a sale

You may request to opt out of any "sale" of your personal information that may take place.

Non-discrimination

The CCPA provides that you may not be discriminated against for exercising these rights.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

Time limit to respond

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

9. Cookies and analytics

This website sets no cookies at all.

We use no advertising cookies, no cross-site tracking, no social media pixels and no third-party marketing tags. Because we set nothing beyond what is strictly necessary and our analytics are cookieless, we do not show a consent banner. If that ever changes, we will ask for your consent before setting any non-essential cookie and update this notice.

How we measure website traffic

We measure traffic to www.sellervate.com using Plausible Analytics and Vercel Analytics. Neither sets a cookie or stores anything on your device.

To count returning visits within a day without storing an identifier, both take two details your browser sends with every request, your IP address and your user agent string, and combine them with a salt that rotates daily to produce a one-way hash. That hash stands in for "a visitor" for the rest of the day. It cannot be reversed to recover your IP address, it changes the next day, and it is not shared across other websites, so it cannot be used to follow you around the web or to build a profile of you.

What we actually see is aggregate: page views, referring sites, country, and device or browser type. We do not receive your IP address in these reports.

Cookies in the Sellervate application

The signed-in application at app.sellervate.com sets strictly necessary cookies only. These keep you signed in between pages and carry short-lived state during the invitation and sign-up flow. They are required for the application to work and cannot be switched off. No analytics or marketing cookies are set there.

You can block or delete cookies in your browser settings. Blocking the strictly necessary cookies will prevent you from signing in.

10. Contact Us

If you have any questions or complaints about this Privacy Notice, please send an email to:

privacy@sellervate.com

Or write to:

SELLERVATE LLC

7901 4th St N, Suite 300

St. Petersburg, FL 33702

United States

team@sellervate.com

Our use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Part B: When we are a processor for our clients

This part applies to the personal data of end customers of our client brands, which we handle on the client's behalf when we provide customer service, review management or analytics. It is written for the data protection and procurement teams of our clients.

11. Our role when we work for a client brand

When Sellervate provides customer service, review and feedback management, or analytics and reporting for a client brand, the client is the controller of the end-customer personal data involved and Sellervate is the processor.

We process that personal data only on the client's documented instructions, including with regard to transfers of personal data to a third country, unless we are required to do otherwise by law that applies to us. In that case we will inform the client of that legal requirement before processing, unless the law prohibits us from doing so.

We do not sell end-customer personal data, we do not use it to build or train our own models or products, and we do not combine or share data between different client accounts.

People who make our services available to the client's data are bound by confidentiality obligations in their employment or contractor agreements.

12. Categories of data and data subjects

Data subjects

  • End customers of our client brands who buy from, contact, review or return products to that brand.
  • Employees and agents of the client who use our platform.

Categories of personal data

  • Name and buyer contact details, including the marketplace-issued or forwarding email address.
  • Order details: order identifiers, products purchased, quantities, prices and order dates.
  • Delivery and shipping details, including delivery address elements and tracking information.
  • Message content exchanged between the end customer and the brand, and any attachments the end customer sends.
  • Review and feedback content, ratings and the associated marketplace profile name.
  • Return, refund, claim and warranty details, including the reason given for a return.

We do not ask end customers for special category data. Message and review content is free text written by the end customer, so it may occasionally contain information the end customer volunteers, such as a health-related reason for a return. We do not process that content for any purpose other than handling the enquiry and reporting to the client.

13. Purposes of the processing

We process end-customer personal data on our clients' instructions for the following purposes:

  • Receiving, routing and responding to customer enquiries on the client's behalf, across the marketplace and email channels the client has connected.
  • Processing and following up returns, refunds, replacements, claims and warranty requests.
  • Review and feedback management, including monitoring new reviews and responding where the marketplace allows it.
  • Producing analytics, insights and periodic reports for the client, including AI-assisted classification and summarisation of message, review and return content.
  • Operating, securing, monitoring and supporting the platform on which the above is delivered.

The duration of the processing is the term of our agreement with the client, followed by the deletion or return period described in section 17.

14. Subprocessors

We engage the subprocessors below to deliver the services. Each is bound by a written contract imposing data protection obligations no less protective than those we owe our clients, and we remain fully liable to the client for their performance.

SubprocessorUsed forProcessing location
Amazon Web Services, Inc.Cloud hosting and compute, file and attachment storage, message queuing, and inbound and outbound email deliveryUnited States (US East, Northern Virginia)
Supabase, Inc.Managed PostgreSQL database holding tickets, messages, orders, reviews and returns, and platform authenticationUnited States (hosted on AWS US East, Northern Virginia)
Vercel Inc.Hosting and delivery of our web applications, through which client users view and respond to customer dataUnited States
Anthropic, PBCAI classification, tagging and summarisation of message, review and return content for client analytics and reportingUnited States
OpenAI, L.L.C.AI summarisation and translation of customer messages and review contentUnited States
Stripe, Inc.Subscription billing and payment processing. Client account and billing contact data only. No end-customer data is sent to StripeUnited States
Amazon.com Services LLC (Selling Partner API and Seller Central)Source of the client's orders, buyer messages, reviews and returns, and the channel through which replies are delivered to the end customerThe Amazon regional endpoint for the client's marketplaces (North America, Europe or Far East)

We give clients notice of any intended addition or replacement of a subprocessor before that subprocessor starts processing their data, so that the client has a reasonable opportunity to object. To receive these notices, email legal@sellervate.com.

Our AI providers process content to return a result to us. They do not use client content to train their models, and they retain it only for the limited period needed to deliver and monitor the service.

15. International transfers of client data

Sellervate is established in the United States and processes client data there, in the Amazon Web Services US East (Northern Virginia) region. Every subprocessor listed in section 14 processes data in the United States, except Amazon's Selling Partner API, which serves each marketplace from its own regional endpoint.

Where a client is established in the United Kingdom or the EEA, or instructs us to process data originating there, the transfer to us is made under:

  • EEA transfers: the European Commission's Standard Contractual Clauses (Decision 2021/914), controller-to-processor module.
  • UK transfers: the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, at the client's election.

We enter into the same instruments with our own subprocessors where they apply, and we carry out a transfer risk assessment where one is required. These clauses are included in the Data Processing Agreement executed with the client (section 21).

16. Security measures

The technical and organisational measures we apply to client data are:

  • Role-based access control. Platform access is scoped by role and by organisation, so a user can only reach the data of the client they belong to.
  • Unique named accounts. Every person who accesses client data has their own account. Shared or generic logins are not used.
  • Multi-factor authentication on administrative access to our infrastructure and cloud accounts.
  • Encryption in transit. All traffic to our applications, APIs and databases runs over TLS.
  • Encryption at rest for our database, file and attachment storage and backups, using the encryption our cloud provider applies to those services.
  • Least privilege and periodic access reviews. Access is granted on a business need-to-know basis and reviewed periodically, with access removed when it is no longer needed.
  • Logging. Application and infrastructure activity is logged, and actions taken on a customer conversation are recorded against the user who took them.
  • Incident response. We maintain a documented procedure for detecting, triaging, containing and reporting security incidents.
  • Confidentiality obligations. Staff and contractors with access to client data are bound by written confidentiality obligations that survive the end of their engagement.
  • Onboarding and offboarding. Access is provisioned on a documented onboarding step and revoked as part of offboarding when someone leaves or changes role.
  • Backups. Databases are backed up automatically, with restore procedures maintained by our hosting providers.

Our infrastructure providers hold their own independent certifications, including SOC 2 Type II and ISO 27001 for Amazon Web Services. Sellervate does not itself currently hold a SOC 2 Type II report or an ISO 27001 certificate; the measures above are practices we operate, not certifications.

17. Retention and deletion of client data

We retain end-customer personal data for as long as the client's agreement with us is in force, because the client needs the history to answer enquiries, handle returns and compare reporting periods. Clients can ask us to delete specific records at any time.

On termination

At the client's choice, we return the client's data in a commonly used machine-readable format, or delete it, within 30 days of the end of the agreement. If the client makes no election within that period, we delete it.

Residual copies held in routine encrypted backups are expired on the normal backup cycle rather than individually erased, and remain protected by the same security measures until they expire. We may retain a limited amount of data where a law that applies to us requires it, for as long as that requirement lasts and for no other purpose.

18. Personal data breach

If we become aware of a personal data breach affecting personal data we process for a client, we will notify that client without undue delay after becoming aware of it.

Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, and the measures we have taken or propose to take. Where we cannot provide all of that at once, we provide it in phases as the investigation progresses.

We will assist the client with its own notifications to its supervisory authority and, where required, to affected individuals. We will not notify a client's supervisory authority or its customers on the client's behalf unless the client instructs us to.

19. Assisting our clients

Data subject requests

An end customer may contact us directly to exercise a data protection right, such as access, correction, erasure, restriction, portability or objection. We will not respond to the substance of that request ourselves. We forward it to the relevant client without undue delay, and acknowledge to the individual that we have passed it to the brand. We then assist the client in responding, including by locating, extracting, correcting or deleting the relevant records in our platform.

Impact assessments and regulator queries

Taking into account the nature of our processing and the information available to us, we provide reasonable assistance to clients with data protection impact assessments, prior consultations with a supervisory authority, and questions from a regulator relating to the data we process for them.

20. Audit and information rights

We make available to clients the information reasonably necessary to demonstrate compliance with our obligations as a processor, including responses to security questionnaires and documentation of the measures in section 16.

Clients may also audit us, or appoint an independent auditor to do so, subject to the following: audits are limited to once in any twelve month period, require 30 days' written notice, take place during business hours without unreasonable disruption, are carried out at the client's cost, and are subject to confidentiality obligations. The auditor must not be a competitor of Sellervate. An additional audit may be carried out where a supervisory authority requires it or following a confirmed personal data breach affecting the client's data.

21. Data Processing Agreement

This page is a public notice, not a contract. Article 28 of the UK and EU GDPR requires a written agreement between controller and processor.

A Data Processing Agreement (Article 28 UK/EU GDPR) is available on request. Contact legal@sellervate.com. We are also happy to review and execute a client's own standard DPA.

Whichever paper is used, it incorporates the standard contractual clauses referred to in section 15 and the subprocessor list in section 14.

© 2026 Sellervate. All rights reserved.