Privacy Policy
Last updated: 17 September 2026
This Privacy Policy explains how Sellup.io (the "Platform", "we", "us") handles personal data. It covers two different roles we play, and it is important to keep them apart.
1. Our two roles
- As a controller — for the personal data of store owners (our direct users): the account you create with us and how you use the Platform. This section of the policy governs that data.
- As a processor — for the personal data that you, a store owner, collect about your own customers (buyers) through your store. For that data you are the controller and your own store privacy policy applies. We only process it on your behalf and under your instructions, to run the Platform for you.
2. Data we collect as controller (store-owner accounts)
- Account details: email address and password (stored only as a secure hash).
- Login identifiers: if you sign in with Google or Discord, the identifier those services return; optional Discord membership/trial status.
- Security data: two-factor (2FA) settings, failed login counts, and lockout state.
- Usage and session data: device name, browser, IP address and approximate location, last login, and active sessions.
- Billing identifiers: if you buy Premium, your Stripe customer and subscription identifiers and your plan status. Card details are handled by Stripe and are never stored by us.
- Preferences you set in your dashboard.
3. Why we use it, and our legal basis
- To provide the Platform and your account — performance of our contract with you.
- Security, fraud prevention and abuse detection (including IP logging, rate limiting and audit logs) — our legitimate interests and legal obligations.
- Premium billing — performance of our contract with you.
- Service and, where you have opted in, product emails — legitimate interest or consent, which you can withdraw at any time.
- Legal compliance — where we must keep or disclose data to meet a legal obligation.
4. Service providers we share account data with
We use a small number of processors to run the Platform. They act on our instructions:
- Stripe — Premium subscription billing and payment processing for our own plans.
- SendGrid — sending transactional and account email.
- Cloudflare — content delivery, DNS and security/DDoS protection.
- Google and Discord — only if you choose to sign in with them, to authenticate you.
We do not sell your personal data.
5. Features you turn on that share data
Some features are optional and only send data to a third party when you enable them with your own credentials. When you do, you are directing that sharing:
- Your payment gateways — for example Stripe, Coinbase Commerce, NOWPayments, Square/Cash App and PayPal — process your customers' payments under your own accounts and their own privacy policies.
- Mailbox connection: if you connect an email inbox (IMAP) so the Platform can match incoming PayPal or Cash App payment receipts to orders, we access that mailbox only to read and match those receipts. Mailbox credentials are stored encrypted.
6. Customer (buyer) data we process for store owners
When you run a store, the Platform stores the data your store collects — such as customer accounts, orders, licences, download links, abandoned carts, email subscribers, and store analytics (including page views, referrers and IP addresses). For this data you are the controller. We process it solely to operate your store and only as you instruct. Buyers who want to exercise their rights or ask how their data is used should contact the store they purchased from; the Platform provides store owners with tools to handle access and erasure requests.
7. Cookies
- Essential cookies — we use a session cookie and a "remember me" cookie (up to 30 days) to keep you logged in and to protect the Platform. These are required for it to work.
- Store-configured tracking — individual store owners may add their own analytics or pixels (for example Google Analytics) to their storefronts. Those are controlled by the store owner, not by us.
8. How long we keep data
We keep account data for as long as your account is active. Security and webhook logs are rotated and cleaned automatically on a schedule. When you close your account we delete or anonymise your account data within a reasonable period, except where we must keep certain records to meet legal, tax or fraud-prevention obligations.
9. Your rights
Subject to applicable law (including the GDPR for users in the EU/EEA), you have the right to access, correct, delete, export, restrict or object to the processing of your personal data, and to withdraw consent where processing is based on consent. To exercise these rights, contact us through our Support page. You also have the right to complain to your local data protection authority.
10. International transfers
Some of our providers operate outside your country, including in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
11. Security
We use industry-standard measures to protect data, including TLS in transit, hashed passwords, encryption at rest for sensitive payment and mailbox credentials, and access controls. No method of transmission or storage is completely secure, but we work to protect your data.
12. Children
The Platform is not intended for children under 18 and we do not knowingly collect their personal data.
13. Changes and contact
We may update this policy from time to time; the date above shows the latest version. For any privacy question, contact us through our Support page.