Privacy Policy
Applies to users in the EU/EEA, UK and Switzerland.
Controller
Felix Grams — Contact: sellmoworldwide@gmail.com
Purposes of Processing
- Provide the app and server functions
- User management, authentication, subscriptions/billing
- Diagnostics and security (pseudonymised logs)
- Cookieless usage analytics (aggregated)
Legal Bases
- Art. 6(1)(b) GDPR (contract / pre-contractual steps)
- Art. 6(1)(f) GDPR (legitimate interests: operation, security, abuse prevention)
- Art. 6(1)(a) GDPR (consent, where applicable)
Recipients / Categories
- Hosting/Serverless: Vercel Inc. — DPA
- Database/Backend: Supabase (EU region) — DPA, Security/Trust, TIA, Schedule (Sub‑processors)
- Payments: PayPal (independent controller) — Privacy (EEA), Data Protection Addendum. We transmit only transaction‑relevant details (e.g., billing/contact). Payment data is processed by PayPal.
- OAuth: Google/Apple (when used voluntarily)
Retention
We retain personal data only as long as necessary for the purposes or where statutory retention periods apply. Usage logs are pseudonymised and rotated in short cycles.
Data Subject Rights
Under GDPR you have rights of access, rectification, erasure, restriction, portability and objection (Art. 15–21). Contact: sellmoworldwide@gmail.com.
Cookies / Tracking
We do not set non‑essential cookies. Any local storage/session artifacts are strictly necessary to provide the service (authentication/session continuity). Analytics runs cookieless and without cross‑site tracking.
Data Hosting & Transfers
Compute runs in the EU region “fra1” (Frankfurt) at Vercel: see Vercel DPA. Data at rest (DB/storage) is hosted with Supabase in the EU: see Supabase DPA, TIA, Schedule (Sub‑processors), Security.
International Transfers
EU/EEA
Where third‑country transfers occur, we rely on the EU Standard Contractual Clauses (SCCs) and/or the EU‑US Data Privacy Framework (DPF) where the recipient is self‑certified.
UK
For UK transfers, we rely on the UK‑US Data Bridge (DPF extension) where applicable, or the UK Addendum/IDTA together with SCCs. A UK representative is not required for this service.
Switzerland
Under the Swiss FADP, we use SCCs with Swiss adaptations (“Swiss finish”) or the Swiss‑US DPF where applicable.
Last updated: 2025-08-29