Legal

Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your personal information.

Last updated: December 9, 2025

We collect information you provide directly to us, including:

  • Account Information: Name, email address, company name, and password when you register
  • Contact Data: Information about your customers and contacts that you add to the CRM
  • Communication Data: Call recordings, emails synced from your email provider, and meeting notes
  • Usage Data: Information about how you use our service, including actions taken and features used
  • Payment Information: Billing details processed securely through our payment provider

We automatically collect certain technical information:

  • IP address and browser type
  • Device information and operating system
  • Access times and pages viewed
  • Referring URL

We use your information to:

  • Provide our Services: Operate, maintain, and improve SellerCockpit's features
  • Process Transactions: Handle billing and send related information
  • Send Communications: Respond to inquiries and send service updates
  • Improve Experience: Analyze usage patterns to enhance our platform
  • Ensure Security: Detect and prevent fraud and unauthorized access
  • Legal Compliance: Meet our legal obligations and enforce our terms

AI Processing: We use AI services (Gemini) to transcribe calls and generate summaries. This data is processed securely and not used to train AI models.

We share your data only with:

  • Service Providers: Companies that help us operate (hosting, payment processing, email delivery)
  • Integrations You Enable: Third-party services you connect (Google Calendar, Gmail, Twilio)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

We never sell your data to third parties for marketing purposes.

Our Key Service Providers:

  • Supabase: Database and authentication (EU region)
  • Twilio: VoIP calling services
  • Google: Calendar and email integration
  • Stripe: Payment processing

We use cookies and similar technologies to:

  • Keep you signed in to your account
  • Remember your preferences and settings
  • Understand how you use our service
  • Improve our platform based on usage patterns

Types of Cookies We Use:

  • Essential Cookies: Required for the service to function (authentication, security)
  • Preference Cookies: Remember your settings (theme, language)
  • Analytics Cookies: Help us understand usage patterns (anonymized)

You can control cookies through your browser settings. Disabling essential cookies may affect functionality.

We retain your data for as long as your account is active or as needed to provide services:

  • Account Data: Retained while your account is active, deleted within 30 days of account closure
  • Call Recordings: Retained according to your plan settings, with options for automatic deletion
  • Activity Logs: Retained for 2 years for security and audit purposes
  • Backup Data: Retained for up to 90 days after deletion for disaster recovery

You can request earlier deletion of your data at any time (see Your Rights section).

Under GDPR and other privacy laws, you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct any inaccurate or incomplete data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Portability: Receive your data in a structured, machine-readable format
  • Restriction: Request that we limit how we use your data
  • Objection: Object to certain types of processing
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise these rights, visit our GDPR Compliance page or contact our Data Protection Officer.

We implement industry-standard security measures to protect your data:

  • Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access Controls: Role-based access with multi-factor authentication
  • Infrastructure: Hosted on SOC 2 compliant infrastructure in the EU
  • Monitoring: 24/7 security monitoring and anomaly detection
  • Audits: Regular security assessments and penetration testing

For more details, see our Security page.

SellerCockpit is based in the European Union. Your data is primarily stored and processed within the EU.

When we transfer data outside the EU (e.g., to service providers), we ensure appropriate safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with all third-party providers
  • Adequacy decisions where applicable

SellerCockpit is not intended for use by children under 16 years of age. We do not knowingly collect personal information from children.

If we learn that we have collected personal information from a child under 16, we will promptly delete that information. If you believe we may have information from or about a child, please contact us.

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new policy on this page with an updated "Last Updated" date
  • Sending an email notification to your registered email address
  • Displaying a prominent notice within the application

We encourage you to review this policy periodically. Your continued use of SellerCockpit after changes constitutes acceptance of the updated policy.

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: privacy@sellercockpit.com

Data Protection Officer: dpo@sellercockpit.com

Address: SellerCockpit, EU

For GDPR-specific requests, please use our GDPR request form.