Legal
Privacy Policy
Last updated 8 September 2026
Selitics is commerce software for merchants. This policy explains what we do with personal data when you use the Selitics Dashboard mobile app, the Selitics web dashboard, and the storefronts our merchants run on our platform.
1. Two different roles
We handle personal data in two distinct ways, and your rights differ depending on which one applies to you.
When you are a merchant
If you sign in to Selitics to run a store, we are the controller of your account data — we decide why and how it is processed, and this policy governs it.
When you are a shopper
If you bought something from a store built on Selitics, the merchant is the controller of your order. We are their processor: we store and serve that data on their instructions and do not use it for our own purposes. Direct requests about your order, your data, or its deletion to that merchant. We will support them in answering you.
2. What the mobile app collects
The Selitics Dashboard app is a tool for people who already run a store. It has no sign-up, no advertising, no analytics SDK, and no third-party trackers.
| Data | Why | Kept |
|---|---|---|
| Email address and password | To sign you in to the account you already hold. The password is sent once over an encrypted connection to verify you and is never stored on the device. | Your account email, until you close the account |
| Session token | Issued after sign-in so you are not asked for your password on every screen. Held in the device keychain, which is encrypted by the operating system. | Expires automatically; deleted when you sign out |
| Photos and camera | Only when you choose a picture for one of your own products. The app reads the single image you select and uploads it to your store. It never scans your library. | In your store, until you delete the image |
| Your store's business data | Orders, products, customers and sales are fetched from your account so the app can show them. The app displays this data; it does not create a second copy of it. | Cached in memory only, cleared on sign-out |
The app is scoped to the stores you own or have been given staff access to. It cannot read another merchant's data.
3. What we never do
- We do not sell personal data, and we never have.
- We do not track you across other companies' apps or websites, and we do not share data with data brokers or advertising networks.
- We do not use your store's data, or your customers' data, to train models or to build profiles for anyone else.
- We do not ask the app for your location, contacts, microphone, or health data.
4. Data we process as a merchant's processor
To run a storefront, our platform necessarily stores what a merchant's customers submit at checkout: name, email address, phone number, delivery address, order contents, and the payment status of the order. Card numbers are handled by the payment provider the merchant connects and never reach our servers.
5. Legal bases
- Performance of a contract — running the account and store you signed up for.
- Legitimate interests — keeping the service secure, preventing abuse, and fixing faults, balanced against your rights.
- Legal obligation — retaining records where tax or accounting law requires it.
- Consent — anything optional, which you can withdraw at any time.
6. Sharing
We share personal data only with the service providers that make the platform run — hosting, transactional email delivery, error monitoring, and the payment providers a merchant chooses. Each is bound by contract to process data only on our instructions. We also disclose data where the law compels us to, and will tell you when we are permitted to.
7. International transfers
Selitics serves merchants worldwide, so personal data may be processed outside the country where it was collected. Where we transfer data out of a region with transfer restrictions, we rely on the safeguards that region's law provides, such as standard contractual clauses.
8. Security
Traffic is encrypted in transit. Passwords are stored only as salted hashes and are never readable by us or recoverable. The app's session token lives in the platform keychain rather than in ordinary app storage, and expires on its own. Access to production systems is limited to the people who need it.
9. Retention
We keep merchant account data for as long as the account is open, and delete or anonymise it afterwards except where we must keep records to meet a legal obligation. Operational logs are kept for a short, fixed window and then purged automatically.
10. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, export it, object to or restrict processing, and withdraw consent. Merchants can exercise most of these directly in the dashboard.
To delete your merchant account and its data, email support@selitics.com from the address on the account. We will confirm and complete the deletion within 30 days.
You also have the right to complain to your local data protection authority.
11. Children
Selitics is a tool for running a business. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.
12. Changes
If we change this policy we will update the date at the top of this page, and tell merchants directly when the change is material.
13. Contact
Selitics FZ-LLC is the controller for merchant account data. Reach us at: