1. Controller#
ProductTickler B.V., trading as Sellgrip, Meerwijkselaan 5, 6571 CM Berg en Dal, Netherlands
Data protection: privacy@sellgrip.com
General enquiries: info@sellgrip.com
Further details are in the imprint.
We have not appointed a data protection officer, as we are not required to do so. Please send questions about data protection to privacy@sellgrip.com.
2. Scope#
This policy applies to our website (sellgrip.com) and to the Sellgrip application. It describes which personal data we process, for what purposes and on what legal basis.
We are the controller for the website, the customer account and billing.
For the data from our customers' Kaufland seller accounts, including data about their buyers, the customer is the controller. We process this data only on the customer's behalf. This is governed by the Data Processing Agreement (DPA). Buyers with questions about their data should contact the seller they bought from.
3. Hosting and delivery#
The website and the application run on the Cloudflare Workers platform of Cloudflare, Inc., USA. We store the data at Cloudflare with the European Union as the storage location: customer accounts and data from the Kaufland seller account in Durable Objects, the website data (such as the waiting list) in the D1 database and the backups in R2 storage. Cloudflare also handles name resolution (DNS) and delivery.
Each time a page is requested, Cloudflare processes technically necessary data: IP address, date and time, the URL requested, the status code and the browser's user agent. Cloudflare receives each request in a data centre of its global network, usually the one closest to you. This is used to deliver the content, operate securely and defend against attacks.
Cloudflare processes the data on our behalf. The legal basis is our legitimate interest in secure and fast operation (Art. 6(1)(f) GDPR). For the transfer to Cloudflare in the USA, see section 13.
4. Website#
Fonts and calculators#
We deliver fonts and images ourselves; no fonts are loaded from Google or other providers. The free calculators on the website run in your browser; what you enter is not sent to us. With your consent, Google Analytics only learns that a calculator was used (see below).
Google Analytics, only with your consent#
If you give your consent in the cookie banner, we use Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, on the website. Without your consent, Google Analytics is not loaded, sets no cookies and receives no data. If your browser sends the Global Privacy Control signal, we treat this as a refusal unless you give your consent yourself.
Google Analytics records how visitors use the website: pages viewed, time and duration of the visit, referring page, device, browser and approximate location. We also send a few events of our own: a click on a link to the demo or to registration (with the chosen plan and the place on the page), the first entry in a free calculator (only which calculator, not what you entered), the successful submission of the contact form (without its content) and a search on the website (with the search term). Each event includes the language of the page. We do not send your name, email address or the content of forms. Google Analytics sets cookies for this purpose (section 11). Google signals and ad personalisation are switched off. We use the analysis to improve the website and to see which pages lead to registrations. Google processes the data on our behalf.
The legal basis is your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG). You can withdraw your consent at any time via the "Cookie settings" link at the bottom of every page. Google Analytics is then switched off and we delete its cookies in your browser. Withdrawal takes effect for the future.
Google may transfer data to Google LLC in the USA (section 13). Google Analytics retains the data for 14 months.
Measuring sign-ups and purchases#
The Sellgrip application itself loads no analytics tools and sets no analytics cookies. It does, however, report three steps to Google Analytics if you consented on the website beforehand. For this, Sellgrip takes the identifier from the _ga cookie (client ID) when you register and, if present, the session identifier from the _ga_ cookie with an appended identifier. We store both with your account. Without your consent on the website, we take nothing and report nothing.
With this identifier, our server sends the following once per account: the registration (sign_up, with its source, such as a campaign or the demo, see section 5; additionally demo_signup if you came via the demo), the start of a trial (trial_start, with plan and billing interval) and the first paid invoice (purchase, with the amount excluding VAT, currency, plan, billing interval and Stripe's invoice number). We do not send your name, email address, company or our account ID. The data goes to Google Analytics' collection endpoint for the European Union. Use for personalised advertising is refused for these reports. We send nothing for demo and test accounts. The purpose is to see which pages and campaigns lead to accounts and subscriptions.
The legal basis is the consent you gave on the website (Art. 6(1)(a) GDPR; for reading the cookies, § 25(1) TDDDG). Withdrawing via "Cookie settings" deletes the cookies in your browser, but does not reach the identifier stored with your account. You therefore withdraw this measurement by emailing privacy@sellgrip.com. We then delete the stored identifier and send no further reports to Google. The identifier is deleted at the latest when you delete your account. Google retains the data for 14 months, as above; for the transfer to the USA, see section 13.
Contact form and email#
If you contact us via the contact form or by email, we process your details in order to reply to you. In the contact form, these are your name, email address, topic and message, and optionally your company.
The form does not store your message in a database but sends it by email via Brevo (section 12) to the relevant mailbox (info, support or privacy). So that you do not have to type everything again after an error, your browser keeps what you entered in its session storage (sessionStorage) when you submit the form. It does not leave your browser. It is deleted as soon as the message has been sent, and at the latest when you close the tab.
To prevent spam, the form uses a hidden field, a minimum time for filling it in and a limit of five messages per hour. For this limit, we store a hash of your IP address with a counter in the website database, not the address itself. After one hour the entry is no longer used, and it is then deleted. No third-party services such as reCAPTCHA are used.
The legal basis is steps prior to entering into a contract or the performance of a contract (Art. 6(1)(b) GDPR), otherwise our legitimate interest in replying to you and in keeping the form free from abuse (Art. 6(1)(f) GDPR).
Waiting list#
On the Dutch page “Van bol naar Kaufland” you can join the waiting list for Sellgrip. For this we process your name and email address, optionally your company and your shop name on bol, as well as the approximate number of your products, the date and where you came from (for example, whether you followed a link from ProductTickler). Purpose: to let you know as soon as you can create an account, and to help you move to Kaufland.
The entries are stored in the website database at Cloudflare in the European Union (D1, section 3). We send the confirmation to you and the notification to us via Brevo (section 12). The same anti-spam measures apply as for the contact form.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by ticking the box in the form. You can withdraw it at any time by emailing info@sellgrip.com; we then delete the entry. Withdrawal applies to the future. We keep the entry until six months after Sellgrip launches, or for less time if you withdraw earlier.
5. Customer account#
When you register, we store your first and last name, your email address and your password. We store the password only as a hash (scrypt); we cannot read it. We also store that you confirmed you are acting as a business, and which version of the Terms and Conditions, the DPA and the Privacy Policy you accepted and when. You confirm your email address via a link.
We then ask about your business: company name, country of establishment, address (only required for a paid plan) and, optionally, your VAT identification number. We need this information for your invoices and to apply the correct VAT. You can also tell us, optionally, how many products you offer on Kaufland and in how many Kaufland countries you sell. We use this to recommend a plan and for nothing else.
If you reach registration via a link with campaign details (for example from a newsletter, a social media post or the demo), we store this source with your account. Your browser remembers it until the end of the session for this purpose (section 11). We use it to see how customers find their way to Sellgrip. The legal basis is our legitimate interest in this (Art. 6(1)(f) GDPR).
VAT identification number check#
If you provide a VAT identification number, we check it in the European Commission's VAT Information Exchange System (VIES). To do so, we send the number to the European Commission and the tax authority of the member state concerned. We receive back whether the number is valid and, where the member state provides this, the registered name and address. We use these to pre-fill any fields you have not yet completed. We store the result of the check with the date. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and our obligation to verify the customer's number for invoices without VAT (reverse charge) (Art. 6(1)(c) GDPR).
If you invite further users, we store their email address, role and password hash. We log invitations, role changes and the removal of users with the time and the person who made the change.
The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). For invited users and the log, it is our legitimate interest in managing the account securely (Art. 6(1)(f) GDPR). We process the optional information for the plan recommendation on the basis of our legitimate interest in recommending a suitable plan to you (Art. 6(1)(f) GDPR).
6. Kaufland credentials#
To connect Sellgrip to your Kaufland seller account, you enter your API keys. We store them encrypted with AES-256-GCM and do not display them again after they have been entered. We delete them as soon as you disconnect or delete your account. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
7. Data from the Kaufland seller account#
We process this data on behalf of the customer (section 2). The details are set out in the DPA. In short:
- Sellgrip retrieves orders, returns, tickets, products and offers, transactions and payouts.
- Sellgrip does not import buyers' names, addresses, email addresses or telephone numbers when retrieving orders. An allowlist lets through only the fields Sellgrip needs, such as order number, item, amounts, status and timestamps.
- If the seller issues an invoice through Sellgrip, Sellgrip retrieves the buyer's name and billing address from Kaufland for that single order. After that, these details appear only in the invoice (PDF) that Sellgrip keeps for the seller.
- Sellgrip displays ticket messages by retrieving them from Kaufland. Sellgrip does not store the text of the messages, only the topic, status and timestamps.
We do not use buyer data for our own purposes.
8. Use of the application#
Usage statistics#
To improve Sellgrip, we store which areas are used: account ID, name of the area, type of action (such as viewing or exporting), date and time. We do not store IP addresses, browser, referring page, search terms or entered values for this, and no additional cookie is set. The legal basis is our legitimate interest in developing Sellgrip further (Art. 6(1)(f) GDPR).
Action log#
We log actions a user triggers towards Kaufland (such as confirming shipment, refunding or replying to a ticket) with the user, type of action, time and result. We do not store the text of messages. The log allows the customer to trace what was done. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in security (Art. 6(1)(f) GDPR).
Logs and abuse prevention#
The messages the application logs itself contain no credentials, no password reset links and no buyer data. To limit login attempts, registrations, password resets and the opening of the demo, we count attempts per IP address, per email address or per account for a short time window. For this we store only a hash of that value with a counter, not the value itself. The legal basis is our legitimate interest in security and operation (Art. 6(1)(f) GDPR).
Feedback#
Via "Give feedback" in Sellgrip you can send us a rating and a short text. Only the page you are on and your language are sent with it. We store the feedback with your account and send a copy, with your email address, the account name and the plan, by email to our support mailbox (via Brevo). We use it to improve Sellgrip and, where needed, to reply to you. The legal basis is our legitimate interest in developing Sellgrip further (Art. 6(1)(f) GDPR).
9. Payments#
Paid plans and the trial are processed by the payment service provider Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. You enter your payment details directly with Stripe. Card details never reach our servers.
We send Stripe your email address and the business details from section 5: company name, address and, if provided, your VAT identification number. You can add to or change these details on the checkout page. From Stripe we receive the customer ID, the plan, the billing period, the subscription status and the invoices. Stripe calculates the VAT and issues the invoices.
Stripe is an independent controller for processing the payment, fraud prevention and its own legal obligations.
The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and our legal obligation to retain invoices (Art. 6(1)(c) GDPR). For more information, see Stripe's privacy policy.
10. Emails#
We send you and your users emails that are necessary for the service:
- a link to confirm your email address, when you register and when you change the address
- a welcome email after registration with the first steps
- no more than two reminders to connect Kaufland if you postponed this when registering: one day later and three days after that, never after two weeks
- a link to reset your password (valid for one hour, can be used only once) and a notice when your password has been changed
- an invitation for a new user
- a notice when the account's email address has been changed
- a reminder three days before the trial ends
- notices about your subscription: a failed payment and the end of the subscription
- a summary of your open cases, weekly on the Free plan and daily from Pro upwards, only when there is something to do.
You can unsubscribe from the summary in the settings; you will then also stop receiving reminders to connect Kaufland.
The emails contain plain text and a designed version of it (HTML). The logo is included in the email itself; nothing is loaded when you open it. There are no tracking pixels and no click tracking. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
11. Cookies#
Website#
Strictly necessary, without consent (§ 25(2) no. 2 TDDDG):
- sellgrip_consent: stores your choice in the cookie banner so that we do not ask you again on every visit. Expires after 12 months.
- sellgrip_lang_choice: stores the language you picked in the language switcher. While it is set, the home page no longer redirects to another language automatically. Without this cookie we pick the language of the home page once, from your browser's language setting or, if that does not match, from the country Cloudflare derives from your IP address. Neither is stored. Expires after 12 months.
- sg_internal: set only when the website is opened with ?sg_internal=1 added to the address. Only we do this, on our own devices, so that our visits are not counted in Google Analytics. It contains no identifier. Expires after 400 days.
- __cf_bm: set by Cloudflare when bot protection is active, to distinguish bots from people. Expires after 30 minutes.
Only with your consent (Google Analytics, section 4):
- _ga: distinguishes visitors from one another. Expires after up to 2 years.
- _ga_ followed by an identifier: stores the session state. Expires after up to 2 years.
When you register, the application reads these two cookies once if you have given your consent (section 4, "Measuring sign-ups and purchases").
The website also stores some information in your browser's storage (localStorage remains until you delete it; sessionStorage ends when you close the tab). This information is not sent to us, except for the campaign details when you register:
- sellgrip-theme (localStorage): light or dark design.
- sellgrip-route (localStorage): your answer to "Already selling on Kaufland?" on the home page.
- sellgrip-gm-check (localStorage): the ticked items of the checklist on the Kaufland Global Marketplace page.
- sellgrip-src and sellgrip-from-kaufland (sessionStorage): the campaign details of the link you came from (utm_source and utm_campaign) and whether you came from Kaufland. The details are added to the links to registration (section 5); if you came from Kaufland, the website shows matching notices.
- sellgrip-bar-… and sellgrip-langbar-closed (sessionStorage): that you closed a notice bar.
- sellgrip-contact-draft (sessionStorage): what you entered in the contact form (section 4).
- sg-ga-lead and sg-ga-tool-… (sessionStorage, only with consent): so that an event is sent to Google Analytics only once per session.
Sellgrip application#
In the application, we set only strictly necessary cookies:
- pf_session: keeps you logged in. Scripts cannot read it (HttpOnly), it is not sent with requests from other sites (SameSite=Lax) and it is transmitted only in encrypted form. The session is extended by 14 days each time you use it and ends no later than 90 days after login. It ends immediately when you log out or change your password. We store only a hash of the session key. For each session we also store the browser and operating system in rough form (such as "Chrome on Windows") and the network you logged in from (for IPv4 the first three blocks of the IP address, for IPv6 the first 48 bits), so that you can recognise your logins in the settings. If you open the public demo without an account, the same cookie holds a demo session; it lasts two hours from opening and is not extended.
- kp_locale: remembers your chosen language. Expires after one year.
- kp_intent: remembers the plan and billing interval you clicked on the website until you have registered. Expires after 30 days.
- kp_intro: remembers on which pages you have already seen the short introductory sentence. Expires after one year.
- kp_tour: remembers whether you started, finished or declined the Sellgrip tour. Expires after one year.
- kp_home: counts, up to nine, how often you have opened the overview, so that the tour is offered only from the second visit. Expires after one year.
- kp_start: remembers that you hid the "Getting started" list. Expires after one year.
- kp_begin: remembers whether you folded or closed "Start here". Expires after one year.
- kp_next: remembers that you closed the "Next step" notice. Expires after one year.
In your browser's storage, the application keeps: sellgrip-theme (light or dark design), kp_search_recent (the pages you opened most recently, at most five, for the search), sellgrip-begin-seen (which steps of "Start here" your browser has already shown) and, until you close the tab, a draft of your feedback. This information is not sent to us.
12. Recipients and processors#
- Cloudflare, Inc., USA: hosting of the website, application, databases and backups (Cloudflare Workers, Durable Objects, D1 and R2, storage location European Union), name resolution (DNS) and delivery; sees IP addresses and request data. Cloudflare also receives emails sent to our addresses (info@, support@, privacy@sellgrip.com) and forwards them (Cloudflare Email Routing). Processor.
- Sendinblue SAS (Brevo), 9-17 rue Salneuve, 75017 Paris, France: sending of the emails listed in section 10, of the messages from the contact form and of the waiting list emails (section 4), and of the copy of feedback to us (section 8). Data processed in the European Union. Processor.
- Google Ireland Limited, Ireland: Google Analytics on the website and measurement of sign-ups and purchases (section 4), only with consent. Processor.
- Stripe Payments Europe, Limited, Ireland: payments, VAT and invoices (section 9). Independent controller.
- European Commission and tax authorities of the member states: VAT identification number check in VIES (section 5). Independent controllers.
- Kaufland: source of the seller data. Kaufland receives from Sellgrip only the actions a user triggers, for example a shipment confirmation, a ticket reply or an invoice.
- Public authorities: only where we are legally required to disclose data.
We have concluded contracts under Art. 28 GDPR with our processors.
We are planning a feature that translates buyer messages and suggests replies in the buyer's language. It is intended to use an external translation service (DeepL or Anthropic). This feature is not yet in use. Before it launches, we will update this policy and the DPA.
13. Transfers to third countries#
- Cloudflare, Inc. (USA): the stored data is kept in the European Union (section 3). For delivery, operation and support, however, Cloudflare may also process data in the USA and in other countries. The basis is the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR), under which Cloudflare, Inc. is certified, supplemented by the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR).
- Google LLC (USA): only if you have consented to Google Analytics, including for the measurement of sign-ups and purchases (section 4). The basis is the EU-US Data Privacy Framework (Art. 45 GDPR), under which Google LLC is certified, supplemented by the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR).
- Stripe, Inc. (USA): Stripe Payments Europe may transfer data to Stripe, Inc. The basis is the EU-US Data Privacy Framework (Art. 45 GDPR), under which Stripe, Inc. is certified, supplemented by the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR).
We transfer data to countries outside the European Economic Area only where listed here.
14. Retention periods#
- Account, users, business details, VIES check result, settings, action log: until you delete the account. Deleting the account in the settings removes all of its data immediately and in a single step. Only a deletion record with the account ID and date remains, so that the deletion still applies after a restore from backup.
- Kaufland credentials: until you disconnect or delete the account.
- Data from the Kaufland seller account: for as long as the contract is in force. Cancelling a paid plan deletes nothing; the account continues on the Free plan. If the contract ends in any other way, we delete the data after a transition period of 30 days. Automatic deletion of individual order data after a fixed period is not set up.
- Invoices the seller issues through Sellgrip: until the account is deleted.
- Feedback: until the account is deleted; the copy in the support mailbox as for messages to us.
- Usage statistics: 14 months, after which we delete the entries automatically.
- Google Analytics identifier stored with the account: until you withdraw the measurement or delete the account.
- Logs at Cloudflare: 7 days.
- Google Analytics: 14 months.
- Backups: we back up the application's databases every day, encrypted, in R2 in the European Union. Backups are deleted automatically after 30 days. Separately, Cloudflare can reset the databases to any point in the last 30 days; deleted data remains there for no longer than that. If a backup is restored, any deletions made since it was created are automatically repeated.
- Invoices and accounting records for your subscription: seven years, as required by Dutch tax law (Art. 52 Algemene wet inzake rijksbelastingen).
- Messages to us: until the enquiry has been dealt with; business correspondence for the statutory retention periods. Hashes for the contact form limit: in use for one hour, then deleted.
- Waiting list: until six months after Sellgrip launches, or until you withdraw your consent, if that is earlier.
15. Your rights#
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on our legitimate interest (Art. 21). You can withdraw your consent at any time with effect for the future (Art. 7(3)).
You can exercise two rights directly in Sellgrip: in the settings, you can download an export of your data in JSON format and delete your account with all its data. For anything else, write to privacy@sellgrip.com.
16. Right to lodge a complaint#
You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Our lead supervisory authority is the Autoriteit Persoonsgegevens in The Hague, Netherlands. You can also contact any other supervisory authority, in particular in the country where you live or work.
17. No automated decision-making#
We do not make decisions based solely on automated processing that produce legal effects concerning you (Art. 22 GDPR). Sellgrip calculates and makes suggestions; you decide and act.
18. Security#
The measures we use to protect the data include:
- transmission only in encrypted form (TLS with HSTS)
- Kaufland API keys encrypted with AES-256-GCM, passwords and session keys stored only as hashes
- strict separation of customers: each request applies only to the logged-in account
- roles that determine who may do what, enforced on the server
- limits on login attempts
- action log for all actions towards Kaufland and all changes to the team
- no third-party scripts in the application; protection against embedding in other sites
- daily encrypted backups in the European Union with tested recovery
19. Changes#
We update this policy when Sellgrip or the legal situation changes. The current version, with the date shown above, applies.