GDPR
Our roles, our lawful bases, and how to complain — to us, or to the regulator.
Last updated 31 August 2026
Our roles
For your account data we are the controller. For your buyers’ personal data you are the controller and we are the processor, acting on your instructions. The processing agreement between us forms part of our Terms of Service.
Lawful bases
| What we process | Lawful basis |
|---|---|
| Your account data, to provide the service | Performance of a contract with you |
| Your billing records | Legal obligation (tax and accounting) |
| Your buyers’ personal data | We act as your processor on your instructions. You determine the lawful basis as controller. |
| Security, fraud prevention and technical logs | Legitimate interests — keeping the service running and secure |
Data minimisation and retention
We do not keep buyer personal data indefinitely, and we do not hide behind “as long as necessary”. Buyer identity is stripped from stored emails within 30 days, the remaining email body within 90 days, and the duplicate HTML copy of each email is never stored at all. Extracted business records — order numbers, costs, titles, profit — are kept as the seller’s business record.
Because our database keeps daily backups covering roughly the last week, stripped data can persist in a backup for up to a further seven days before rolling off. That is why we say “removed within 30 days” rather than “deleted immediately”. The reasoning behind both periods is set out in full in the Privacy Policy.
Erasure when an eBay user closes their account
eBay notifies registered applications when a user closes their account. We act on those notices automatically: we check whether that person appears as a buyer anywhere on SellerControl and erase their identifying details across every affected seller workspace at once, while leaving the seller’s own sale, cost and profit records intact.
International transfers
Our database and authentication are hosted in the EU (London) by Supabase, and our application functions run in the EU region on Vercel.
Inbound email is processed by Postmark in the United States. That transfer is covered by Postmark’s data processing agreement, which incorporates the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. Stripe processes payment data globally under its own transfer safeguards.
Your rights
You have the right to access, correct, delete, restrict and port your data, and to object to processing. Email support@fynvro.com and we will respond within one month.
If you are a buyer whose data reached us through a seller, that seller is the controller. Contact them first; if you come to us, we will pass your request on and help them answer it.
How to complain to us
Since 19 June 2026, UK organisations must offer a clear route to complain about data protection directly to them. Ours is:
- Email support@fynvro.com with “Data protection complaint” in the subject, or write to us at 318 Barking Road, London, England, E13 8HL.
- We will acknowledge your complaint within 30 days of receiving it.
- We will investigate it, and tell you the outcome and what we have done about it.
Complaining to the regulator
You can complain to the Information Commissioner’s Office at any time, whether or not you come to us first, at ico.org.uk or on 0303 123 1113.
We are registered with the ICO. Our registration number is ZC208078. Registration is a legal requirement, not an endorsement by the ICO.
Contact
Data protection questions go to support@fynvro.com. We are FYNVRO LTD, a company registered in England and Wales (company number 17287290), registered office 318 Barking Road, London, England, E13 8HL.
