Skip to content

Privacy Policy

Last updated 3 September 2026

Draft pending legal review. The facts below describe how SellerTower actually handles data today. The wording has not been reviewed by a lawyer and must be before launch.

SellerTower is business software for retailers. This policy covers two different groups of people, and the difference matters throughout: merchants, who sign up and run their shop on SellerTower, and their customers, whose details a merchant records in the course of selling to them.

What we collect from merchants

  • Account details: name, email address, and a password we store only as a hash.
  • Business details: trading name, country, and the stores, staff, catalogue and stock you create.
  • Billing details: your plan, billing country and currency, and the invoices raised against them. Card numbers never reach us — payments run through Stripe, and we hold only the customer reference Stripe gives us.
  • Operational records: an activity log of actions taken in your account (who did what, to which record, when), and standard server logs.

What merchants record about their own customers

A merchant may store a customer's name, email address, phone number, delivery address, order history and — where the merchant asks for one — an uploaded proof of payment.

For that data the merchant is the controller and SellerTower is the processor. We hold it on the merchant's behalf and act on their instructions. A customer wanting their details corrected or removed should contact the shop they bought from; if they contact us, we pass the request to that merchant.

Why we hold it

  • To run the service you have asked us to run.
  • To take payment for it, and to tell you when a payment fails.
  • To keep the service secure and to investigate abuse.
  • To meet legal and tax obligations.

We do not sell personal data, and we do not use it to train models.

Who else processes it

  • Stripe — payments and subscriptions. Stripe receives your billing details directly.
  • MongoDB Atlas — the databases holding your business records.
  • Cloudflare — content delivery, DNS, and the object storage holding uploaded images and files.
  • DigitalOcean — the servers the application runs on.
  • Zoho Mail — transactional email (verification, password reset, invitations, billing notices).

How long we keep it

History windows depend on your plan and are shown on your billing page. When a window passes, the records beyond it stop being readable in the app and are removed on a schedule.

When you delete your account we remove your business records from both of our databases, cancel your subscription, delete your customer record at Stripe, and delete the files you uploaded from object storage. Some records are kept where the law requires it — tax and invoicing records in particular.

Where it is held

Your data is stored in the region your account was provisioned in. Our sub-processors above operate globally, so data may be processed outside your country in the course of delivering the service.

Security

Traffic is encrypted in transit. Passwords are hashed, never stored or logged in readable form, and email addresses are masked in our logs. Access to your account is controlled by roles and permissions you set. No system is perfect; if we discover a breach affecting your data, we will tell you.

Your choices

You can access, correct, export or delete most of your data from inside the app. For anything you cannot reach yourself, write to [email protected] and we will answer within 30 days. Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to your data-protection authority.

Children

SellerTower is for businesses. It is not intended for anyone under 16.

Changes

If we change this policy materially we will say so in the app before the change takes effect. The date at the top always reflects the current version.

Contact

Seller Tower, Akurana, Central Province, Sri Lanka
[email protected]


Questions about this document? Write to [email protected].

Back to SellerTower