Privacy Policy
What we hold, how long we keep it, and who else touches it.
Last updated 31 August 2026
Who we are
SellerControl is a product of FYNVRO LTD, a company registered in England and Wales (company number 17287290), registered office 318 Barking Road, London, England, E13 8HL. You can reach us at support@fynvro.com.
We are registered with the Information Commissioner’s Office (ICO). Our registration number is ZC208078. Registration is a legal requirement for organisations that process personal data. The ICO does not certify, approve or endorse any organisation, and we do not present it as such.
Two different relationships: your data, and your buyers’ data
This distinction matters, so we state it plainly.
| Data | Who decides what happens to it |
|---|---|
| Your account data — name, email, plan, billing | We are the controller. We decide how it is used, to provide and bill for the service. |
| Your buyers’ personal data — the people who buy from your eBay shop | You are the controller. We are the processor, acting only on your instructions. |
In other words, we do not decide what happens to your buyers’ personal data — you do, and we act on your instructions. The processing terms that govern this form part of our Terms of Service.
What we actually hold
Your account. Your name, email address, plan and subscription status. Passwords are stored in hashed form by our authentication provider. Card details are handled by Stripe — we never see or store your card number.
The emails you send us. SellerControl works by you forwarding your eBay and supplier order confirmations to a unique address. We store the text of those emails so we can read the order details out of them and match your supplier costs to the right sale.
We want to be exact about this, because understating it would make everything below meaningless: a forwarded eBay order confirmation normally contains your buyer’s full name, their complete delivery address including postcode, and sometimes a phone number. That whole email is stored until it is stripped on the schedule set out in the next section. The values we actually use to match a supplier order to a sale are minimal and held only in memory while matching runs — but the email itself is stored, and we would rather say so.
Your business records. The information we extract from those emails: order numbers, item titles, sale amounts, supplier costs, fees, postage, refunds, profit, stock levels and payouts.
Technical logs. The basic records needed to run, secure and debug the service.
Documents you upload. If you upload a supplier invoice or receipt, we store the file itself so you can open it again from the record it belongs to. These files are private — they are not publicly reachable and they are scoped to your workspace. They are held in our storage service, which is separate from the database, so they are not covered by the daily database backups described below.
How long we keep buyer data — the actual periods
Most privacy policies say “as long as necessary”. We can be specific, because these periods were chosen deliberately and are built into the product.
| When | What happens |
|---|---|
| Straight away | The duplicate HTML copy of every forwarded email is not stored at all. |
| Within 30 days | Buyer identity — name, delivery address, postcode and phone number — is stripped from the stored email. |
| Within 90 days | The remaining email body is stripped. |
| Kept | The extracted business data — order numbers, costs, item titles, profit — is kept as your business record for as long as your account is open. |
Why 30 days for buyer identity. Our supplier matcher reads the buyer’s identity from the stored eBay email at the moment it matches a supplier cost to a sale, which happens days after the sale itself. That matching process looks back 14 days. Thirty days doubles that window to allow for supplier emails that arrive late. After that, the identity serves no further purpose, so it goes.
Why 90 days for the rest of the email. Amounts, order numbers and item titles are what you need to deal with refunds and dispute cases, which typically run to around two months. Ninety days gives roughly a month of headroom on top.
An honest caveat about backups. Our database keeps daily backups covering roughly the last week. When personal data is stripped it is removed from the live database at that point, but a copy can survive in those backups for up to seven more days before rolling off. That is why we say data is removed within 30 days rather than claiming it disappears the instant it is stripped. We do not restore backups in order to retrieve stripped personal data.
When an eBay user closes their account
When someone closes their eBay account, eBay notifies every application registered with it. We receive those notices, check whether that person appears as a buyer in any seller’s orders on SellerControl, and erase their identifying details across every affected workspace at once.
The sale, the cost and the profit stay, because those are the seller’s own business records and, once the identifying details are gone, they no longer identify anyone.
Who else processes data
We use the following providers to run the service. Each processes data under contract and on our instructions only.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database and authentication | EU (London) |
| Vercel | Application hosting | Global edge network; functions run in the EU region |
| Stripe | Payments and subscription billing | Global |
| Postmark | Inbound email processing | United States |
We do not sell your data, or your buyers’ data, to anyone.
Data leaving the UK
Inbound email is processed by Postmark in the United States. That is a transfer outside the UK, and it is covered by Postmark’s data processing agreement, which incorporates the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. Our database and authentication sit in the EU (London), and our application functions run in the EU region. Stripe operates globally under its own transfer safeguards.
Security
Data is encrypted in transit. Access to production systems is restricted, and each seller’s workspace is separated from every other seller’s at the database level. We hold no security certifications and we do not claim any.
Your rights
You can ask us to show you, correct, delete, restrict or export your data, and object to how we use it. Email support@fynvro.com and we will respond within one month, which is the statutory timeframe.
If you close your account, we delete your data other than anything we are legally required to keep, such as billing records retained for tax purposes.
If you are a buyer rather than a seller and your details reached us because a seller uses SellerControl, that seller is the controller of your data. Contact them first — and if you contact us, we will help them respond.
Complaints
If you are unhappy with how we have handled your data, tell us first: email support@fynvro.com with “Data protection complaint” in the subject. We will acknowledge your complaint within 30 days, look into it, and tell you the outcome. Our full complaints route is set out on the GDPR page.
You can also complain to the Information Commissioner’s Office at any time, at ico.org.uk. You do not have to come to us first.
Changes
We will update this page when our practices change, and note the date at the top.
