Privacy Policy
Last updated: July 26, 2026
1. Who We Are
The SellDrop platform ("Service") is operated by SellDrop LLP, a limited liability partnership registered in England and Wales with registration number OC461138, whose registered office is at 128 City Road, London, EC1V 2NX, United Kingdom. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, SellDrop LLP is the controller of the personal information described in this policy, except where the Merchant Stores section below says otherwise. We are registered with the Information Commissioner's Office (registration reference ZC198639).
You can contact us about anything in this policy at privacy@selldrop.io.
2. Information We Collect
We collect information you provide directly to us, and information generated by your use of the Service:
- Account Information: Name, email address, and password when you create an account.
- Merchant Information: Business name, payment details, and payout information necessary to process transactions. Identity verification for payments is carried out by our payment processor, Stripe, under its own terms.
- Identity Verification: Merchants in certain countries are required to verify their identity before selling. Verification is performed by Stripe Identity, which captures a government-issued photo ID and a selfie. We never receive or store these images, and they are permanently deleted from Stripe once the check completes; we retain only the outcome of the check (verified status, date, and the document's issuing country).
- Business Location: When you use the merchant dashboard, we may infer your business country from your device's IP address (using standard geo-IP request headers) to determine which verification, tax, and compliance requirements apply to you. We record that the value was inferred rather than declared, and it is superseded by the country you verify with our payment processor (Stripe). We rely on our legitimate interests in onboarding integrity, fraud prevention, and meeting tax and compliance obligations for this processing; you have the right to object, and if the detected country is wrong you can have it corrected at any time by contacting support@selldrop.io.
- Tax Details: Where platform tax-reporting rules apply to your business location (currently the United Kingdom and Australia), we collect the seller information those rules require, such as legal name, date of birth, address, and tax identifiers (for example a National Insurance number, UTR, or ABN). These are stored securely, never shown publicly, and used only to meet our legal reporting obligations.
- Transaction Data: Purchase history, order details, and payment information processed through the platform.
- Content: Files, product listings, images, and other material you upload to the Service.
- Usage Data: Information about how you interact with the Service, including IP address, browser type, device information, and pages visited.
- Communications: Information you provide when contacting support or communicating through the platform.
3. How We Use Your Information and Our Lawful Bases
UK data protection law requires us to have a lawful basis for each way we use your personal information. We rely on the following:
- Performance of a contract: To provide, maintain, and operate the Service, register and administer your account, process transactions and deliver purchases, and send related information such as confirmations, invoices, and receipts.
- Legitimate interests: To secure and improve the Service; to detect, investigate, and prevent fraud, abuse, and other illegal activity; to understand how the Service is used; to enforce our Terms of Service; and to establish, exercise, or defend legal claims. Where UK law recognises crime prevention and the safeguarding of vulnerable individuals as recognised legitimate interests, we also rely on that basis for our fraud prevention and content safety work.
- Legal obligation: To keep tax and accounting records, comply with financial sanctions screening, respond to valid legal process, and make reports to authorities where the law requires it.
- Consent: For marketing communications and for any non-essential cookies that require consent. You can withdraw consent at any time.
Some of our fraud prevention and content safety systems operate automatically. Where an automated decision would have a legal or similarly significant effect on you, you can contact us to request human review, except where immediate automated action is necessary to remove illegal material or prevent fraud.
4. Content Safety
We use automated tools, including hash-matching technology provided by third-party infrastructure providers, to scan uploaded content for known child sexual abuse material and other illegal content. Confirmed or suspected illegal material is removed and may be reported to relevant authorities and organisations (including law enforcement and child protection bodies) together with associated account information.
5. Information Sharing
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers: With third-party vendors who process personal information on our behalf to operate the platform, such as hosting, database, storage, email delivery, and analytics providers. Our current sub-processors are listed in our Data Processing Addendum.
- Payment Processing: With Stripe and other payment providers to process payments and payouts. Payment providers act under their own privacy policies for the payment data they collect.
- Legal Requirements: When required by law, regulation, or legal process, or to protect the rights, property, or safety of SellDrop, our users, or others, including the content safety reporting described above.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
- With Your Consent: When you have given us explicit permission to share your information.
6. International Data Transfers
Some of our service providers process personal information outside the United Kingdom, including in the United States and the European Economic Area. Where we transfer personal information outside the UK, we rely on UK adequacy regulations where they apply, and otherwise on appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. You can contact us for more information about the safeguards that apply to a particular transfer.
7. Data Retention
We keep personal information only for as long as we need it for the purposes described in this policy. As a guide:
- Account and profile information is kept while your account is active, and removed or anonymised within 90 days of account closure, except where we need to keep it longer as described below.
- Transaction, invoicing, and tax records are kept for six years from the end of the financial year they relate to, as required by UK tax and accounting law.
- Support communications are kept for up to two years after the matter is closed.
- Server and security logs are kept for up to twelve months.
- Identity verification images (photo ID and selfie) are never stored by us and are permanently deleted from our verification provider once the check completes. Seller tax details are kept for as long as platform tax-reporting rules require.
- Records connected to fraud, abuse, or illegal content investigations are kept for as long as needed for the investigation, any report to authorities, and any legal proceedings.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. This includes encryption of data in transit and at rest, access controls, and regular security assessments. However, no method of transmission over the Internet or electronic storage is 100% secure. If a personal data breach occurs that is likely to result in a risk to you, we will notify the Information Commissioner's Office and, where required, affected individuals in accordance with UK GDPR.
9. Your Rights
Under UK data protection law, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your personal information.
- Object to or restrict the processing of your data, including processing based on legitimate interests.
- Request portability of your data in a machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Not be subject to solely automated decisions with legal or similarly significant effects, subject to the exceptions in UK GDPR.
To exercise any of these rights, contact us at privacy@selldrop.io. We will respond within one month, and we may ask you to verify your identity first. These rights are not absolute and are subject to the exemptions in UK data protection law.
10. Complaints
If you are unhappy with how we have handled your personal information, please raise it with us first at privacy@selldrop.io. We will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
11. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the right to know what personal information we collect, to request deletion or correction, to opt out of the sale or sharing of personal information, and to non-discrimination for exercising these rights. The categories of personal information we collect are described in the Information We Collect section above. We do not sell or share your personal information as those terms are defined in the CCPA. To exercise these rights, contact us at privacy@selldrop.io.
12. Merchant Stores: Controller and Processor Roles
SellDrop is a multi-tenant platform. For personal information that buyers provide to an individual merchant's store, the merchant is the controller and SellDrop acts as a processor on that merchant's behalf under our Data Processing Addendum. Requests from a store's buyers regarding their personal data should be directed to the relevant merchant; if you contact us instead, we will pass your request on where we can. SellDrop LLP is the controller for the personal information of the merchants and account holders who use the SellDrop platform directly, and for platform-level operational data such as security logs and fraud signals.
13. License Keys
Our License Keys feature lets a merchant issue software licenses to their own end users and validate those licenses through our API. When a merchant enables this feature, the licensed software transmits a hardware identifier, an IP address, including the country it resolves to, and an application version to SellDrop each time it validates a license key. We process this information on the merchant's behalf as a processor under our Data Processing Addendum; the merchant is the controller for this data and is responsible for disclosing this collection in their own privacy policy and for having a lawful basis for it under the UK GDPR and any other law that applies to them. We retain license validation events for 90 days, after which they are deleted. Two further populations of this data persist longer, because they are needed for the feature to keep working rather than for a historical log: the hardware identifier currently bound to a license key is stored for the life of that key, so it can be shown to the merchant in their dashboard and cleared through a reset; and any hardware identifier or IP address a merchant chooses to block is stored until the merchant removes that block.
14. Law Enforcement and Legal Requests
We may disclose personal information in response to valid legal process from law enforcement and other public authorities. We handle such requests as described in our Information Requests guidelines.
15. Cookies and Tracking
We do not use advertising or cross-site tracking cookies. The cookies and browser storage we use are:
- Strictly necessary (no consent required): sign-in session cookies (
selldrop-session,selldrop-customer-session, Supabasesb-*auth cookies), a trusted-device token after two-factor sign-in (selldrop-td, 30 days), a non-identifying signed-in hint (selldrop-auth-hint), Cloudflare Turnstile bot-protection on security-sensitive forms, and Stripe's fraud-prevention cookies (__stripe_mid,__stripe_sid) on payment and billing pages only. - Preferences: your chosen dashboard language (
locale, 1 year, set when you pick a language), theme (dashboard-theme), and similar interface settings you select. - Analytics (with your consent): on our own site and merchant dashboard (never on merchant storefronts) we use Google Analytics (
_gacookies) and Vercel Speed Insights to understand how SellDrop is used and how it performs. In the EEA, UK, and Switzerland these load only after you choose "Allow analytics" in our cookie banner; elsewhere they run unless you opt out. We honor the Global Privacy Control browser signal as a refusal, and you can change your choice at any time: . - First-party store analytics: on merchant storefronts we set a referral-attribution cookie (
sd_attr, 30 days) and browser-storage identifiers (sd_vid, rotated after 13 months, and a per-session id) so the store owner can see visit counts, referral sources, and sales funnels for their own store. This is first-party audience measurement only: it does not track you across other sites, is not used for advertising, and is never sold or shared. In the UK we rely on the statistical-purposes exception in PECR (as amended by the Data (Use and Access) Act 2025) for this, with the information here and a free opt-out: we honor the Global Privacy Control browser signal, which disables these analytics entirely.
You can also control or delete cookies through your browser settings, though disabling essential cookies may prevent parts of the Service from working.
16. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date, and, where a change materially affects how we use your personal information, by notifying you through the dashboard or by email.
18. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact SellDrop LLP (registered office: 128 City Road, London, EC1V 2NX, United Kingdom) at privacy@selldrop.io.
