SellerProAI legal
Cookie Policy
The cookies SellerProAI sets, what each is for, how long it lasts, and what happens if you block them.
- Version
- 2.3
- Effective
- 25 August 2026
- Last updated
- 25 August 2026
1. About this policy
This policy explains which cookies SellerProAI sets, what each is for, how long it lasts, and what happens if you block them. It covers the SellerProAI application, the public pages that support it, and the separate administration console.
It is operated by Hummingbird Enterprises, D27, Jaipur, Rajasthan, 302006, India. How personal data is handled more generally is described in the Privacy Policy.
2. What a cookie is
A cookie is a small piece of data a website asks your browser to store and send back on later requests. It is what allows a site to recognise that two requests came from the same signed-in person, because otherwise each request would arrive as if from a stranger.
3. The cookies we set
SellerProAI currently uses only cookies that are necessary for authentication, session management, and operation of the administration console. We do not currently deploy analytics, advertising, or other optional tracking cookies.
These are the cookies we set. All of them are first-party, set by our own API:
- accessToken — identifies your signed-in session on each request. Expires about 15 minutes after it is issued.
- refreshToken — obtains a new access cookie without making you sign in again. Lasts about 12 hours, or about 30 days if you select "Remember Me" when signing in.
- adminAccessToken — the equivalent of the first, for the separate administration console. About 15 minutes.
- adminRefreshToken — the equivalent of the second, for the administration console. Always about 12 hours; the "Remember Me" option does not extend an administration session.
The administration cookies are set only when someone signs in to the administration console. They are not set for ordinary seller accounts.
None of these cookies contains your name, email address or payment details. Each carries a signed session credential that only our servers can interpret.
4. Why each of them is necessary
We treat all four as strictly necessary, and it is worth saying why rather than simply asserting it.
Signing in consists of receiving these cookies. Without them the application cannot tell one request from another, which means no dashboard, no projects, no listing generation, no exports, no billing pages, no support history, and no administration console. They are not used to observe your behaviour, to build a profile, or for any purpose beyond keeping you signed in and separating your account from everyone else's.
There is no version of the signed-in service that works without them.
5. How long they last, and how they end
The durations above are maximums, not guarantees. A session can end sooner:
- Signing out ends it immediately.
- Completing a password reset ends every session on the account, on every device.
- A session reaches an absolute limit measured from when you signed in — 30 days for a seller account, 12 hours for an administration session — after which you sign in again regardless of activity.
- Expired session records are removed automatically from our systems.
6. How they are protected
Each cookie carries these attributes:
- HttpOnly — page scripts cannot read them, so a script injected into a page cannot steal your session.
- Secure in production — sent only over an encrypted connection. This attribute is not applied in local development, which runs over plain HTTP.
- SameSite=Lax — not sent when another website triggers a request to us, which is most of the defence against cross-site request forgery.
- Host-only — no wider cookie domain is set, so they reach our API and nothing else.
- Path — set at the site root, so they accompany the application's own requests.
We hold no security certification and make no claim of one. No system can be guaranteed perfectly secure.
7. Optional cookies and tracking
SellerProAI does not currently use analytics cookies, advertising cookies, marketing cookies, tracking pixels, web beacons, fingerprinting, or third-party tracking of any kind. We do not track you across other websites and we do not build a profile of you.
Because SellerProAI does not currently deploy optional cookie categories, the service does not currently present an optional-cookie consent banner.
If SellerProAI introduces optional cookies or similar tracking technologies, we will review the applicable legal requirements and update this policy and any required consent controls before deployment.
Legal review required. Whether, and in what form, consent is required for cookies is a matter of law rather than of this policy. The position above describes what the service currently does; it is not a legal opinion that a banner is never required. Counsel should confirm the position before any optional cookie is introduced.
8. Third-party services in the browser
One third-party component runs in your browser, and only in one place.
When you open the payment checkout, we load the payment provider's checkout script from their servers so that you can enter your card details with them rather than with us. That script is loaded on demand at the moment you start a payment — not when you browse the application, and not on our public pages.
That component operates under the payment provider's own terms and privacy policy, and any cookies or storage it uses are set by them on their own domain, not by us. We do not receive or read them. If you never open the payment checkout, it never loads.
No other third-party script runs in the application. The fonts the site uses are served from our own site rather than fetched from a font provider, so no request is made to a third party to render a page.
9. Other browser storage
SellerProAI does not use localStorage, sessionStorage, IndexedDB, the Cache API or service workers to store your information. Cookies are the only browser storage mechanism the application relies on.
10. Controlling and deleting cookies
Your browser lets you view, delete and block cookies, usually under privacy or site settings. Deleting ours will sign you out.
If you block them, you will be able to read our public pages — including this one and the rest of our policies — but you will not be able to sign in or use any part of the application that requires an account, because signing in is precisely what these cookies do.
11. How this relates to our other policies
The Privacy Policy describes what we do with the information associated with a session, including the IP address, browser user-agent and device label recorded when you sign in, how long it is kept and what rights you have.
This policy covers the cookies themselves. Where the two overlap, the Privacy Policy governs the handling of personal data.
12. Changes to this policy
We may update this policy — for example if we add a cookie, change a duration, or introduce a new browser-based technology. The version and effective date are shown at the top of this page.
If we introduce optional cookies, we will update this policy before they are deployed.
13. Contact
Questions about this policy, or about cookies and your personal data: contact@sellerproai.com.
Who we are
SellerProAI is operated by Hummingbird Enterprises, D27, Jaipur, Rajasthan, 302006, India.
For any question about this policy, your personal data, or a complaint, write to contact@sellerproai.com.