SellerProAI legal

Privacy Policy

What personal data SellerProAI collects, why, who it is shared with, how long we keep it, and the choices you have.

Version
2.3
Effective
25 August 2026
Last updated
25 August 2026

1. Scope, and who is responsible

This policy explains what personal data SellerProAI collects, why, who we share it with, how long we keep it and what choices you have. Hummingbird Enterprises, D27, Jaipur, Rajasthan, 302006, India is responsible for that data.

It is designed to address the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. It is not a claim of certification, nor of complete compliance with any law.

It covers the SellerProAI application and the public pages that support it. It does not cover other companies' websites or the marketplaces you sell on, which have their own policies.

2. Words used here

  • "Personal data" means information about an identifiable person.
  • "Product content" means the catalogue material you put into the Service — product information, uploaded templates, generated listing content, exports and drafts. It is usually about products rather than people, but see section 4.
  • "Processor" means a company that handles data on our instructions, such as our payment or email provider.
  • "Account" means your registered access to the Service.

3. What we collect

Only what the Service actually needs.

  • Account — your name, email address and a securely hashed password. A mobile number and business name if you choose to give them.
  • Billing — billing address and, if you provide one, your GSTIN, used to raise invoices.
  • Payments and subscriptions — payment, invoice, credit note, refund and subscription records. Card details are entered with our payment provider and never reach our servers.
  • Sessions — for each sign-in, the IP address, browser user-agent and a device label, used to keep you signed in and to detect abuse.
  • Tokens — short-lived email verification and password reset tokens, stored hashed.
  • Support — the content of tickets and contact messages you send, and any files you attach.
  • Your product content — projects, product information, uploaded templates, generated listings, exports and drafts.
  • Service records — notifications, quota and usage records, sign-in throttling records, and an administrative audit log.

4. Product content, and what you should not send us

Product content is normally information about products, not about people. But whether it contains personal data depends entirely on what you type into it — a field filled with a customer's name and address would contain personal data, and we cannot tell in advance that you have done so.

Please do not submit personal information that is not needed to prepare a listing.

In particular, do not upload or enter:

  • Passwords or authentication credentials of any kind, including your marketplace credentials — we never ask for them and the Service does not use them.
  • Payment card numbers or bank details — payment happens with our payment provider, never in a product field.
  • Government identity documents or identification numbers.
  • Customer lists, order data or contact databases.
  • Health information, or any other sensitive personal information about an individual.
  • Anyone else's personal data that you have no right to process.

5. What we do not collect

We do not use analytics or advertising trackers. We do not build marketing profiles. We do not track you across other websites. We do not collect location data beyond the IP address recorded with a session. We do not use social sign-in.

We do not sell personal data, and we do not share it for anyone else's marketing.

6. How we use it, and on what basis

Not everything rests on consent, and describing it that way would be misleading. The bases differ:

  • To provide the Service you asked for — creating and running your Account, verifying your email address, preparing and exporting listings, taking payment, issuing invoices and giving support. This processing is necessary to deliver what you signed up for.
  • To keep the Service secure and prevent abuse — session records, sign-in throttling, and the administrative audit log.
  • To meet legal obligations — for example invoicing and tax records.
  • With your consent, and only where we say so — optional product and marketing email. You may withdraw this at any time from your account settings, without affecting your Account.

7. AI-assisted listing generation

This happens only when you ask for it, at the generation step. It is not applied to your data in the background.

When you generate, the product information in your project — for example brand, material, attributes and variant values — is sent to our AI provider, OpenAI, which processes it in the United States.

Your name, email address, account identifier and payment details are not included in what is sent. The Service does not send passwords or authentication credentials to the AI provider.

We do not use your content to train AI models. We operate no model training of any kind.

Generated content can contain errors and must be reviewed before you use it. The AI Disclaimer covers this in full.

If you would rather your product information were not processed outside India by an AI provider, do not use the generation step; the rest of the Service does not depend on it.

Legal review required. What our AI PROVIDER does with data submitted through its API — its own retention period, and whether any of it is used for model improvement — is governed by that provider's terms, not by this policy. The statement above is about SellerProAI's own practice. Counsel should confirm the provider's current API data handling terms and, if appropriate, put a written data processing agreement in place.

8. Who we share it with

Four external providers, and no others. We do not sell personal data.

  • Razorpay (India) — payments, autopay mandates and payment webhooks. Receives what is needed to process a payment. Card details go to them directly and are never stored by us. Necessary because we do not process card payments ourselves.
  • Postmark (United States) — sends transactional email such as email confirmation, password reset and account notices. Receives the recipient address and the message content. Necessary to deliver account email reliably.
  • OpenAI (United States) — generates listing content from the product information you entered, as described in section 7. Necessary only for that feature.
  • Our own database and file storage, on infrastructure we control.

Legal review required. Whether written data processing agreements are in place with each provider, and what they say, has not been verified from the codebase — it is a contractual matter. Counsel should confirm and put any missing agreement in place.

9. Processing outside India

Two of our providers process data outside India, in the United States: Postmark, to send you account email, and OpenAI, to generate listing content when you ask for it. Razorpay operates in India, and our database and file storage are on infrastructure we control.

Cross-border processing may be subject to applicable Indian law and to notifications or rules the Government may issue.

Legal review required. Cross-border transfer restrictions under the DPDP framework depend on notifications the Government may issue, and no specific transfer mechanism is claimed here. Confirm the current position before relying on this section.

10. Cookies

SellerProAI uses cookies only to keep you signed in: a short-lived access cookie and a longer refresh cookie, plus the equivalent pair for the separate administration console. They are HTTP-only, restricted to secure connections in production, and limited to our own site.

There are no analytics cookies and no advertising cookies, and the application does not use browser local or session storage to hold your information. That is why you are not shown a cookie consent banner — the cookies we set are strictly necessary to provide a service you asked for.

The Cookie Policy sets this out in full.

11. How we protect it

The measures actually in place include:

  • Passwords stored hashed, never in readable form.
  • Session cookies that page scripts cannot read, restricted to secure connections in production and to our own site.
  • Rate limiting on sign-in and other authentication endpoints.
  • Password reset links that can be used once and expire, with all sessions ended when a reset completes.
  • Authorisation checked on the server for every request, not in the browser.
  • Separation of each customer's content, so it is not shared between accounts.

12. How long we keep it

Where the system defines a period, it is:

  • Unfinished drafts are removed 72 hours after they were last worked on, and are treated as abandoned after 24 hours of inactivity.
  • Sessions are removed automatically when they expire.
  • Email verification and password reset tokens are removed automatically when they expire.
  • Unverified contact-form submissions are removed automatically.

Legal review required. No fixed period is currently defined for account records, projects, templates, generated files, exports, support tickets and attachments, notifications, or the audit log — and one is not invented here. Statutory minimum retention for invoices, tax records and financial documents must be confirmed with a tax and legal adviser and then stated explicitly in this section.

13. Closing your account, and deletion

There is no self-service account deletion button today. To close your Account or ask for your personal data to be deleted, write to contact@sellerproai.com and we will handle it.

We would rather say that plainly than imply a button exists.

When we act on a deletion request, some information can be removed and some cannot. Records we are required to keep — invoices, credit notes and other financial and tax records — are retained for as long as the law requires. We may also retain what is reasonably necessary for security, fraud prevention, and to establish or defend a legal claim.

Download anything you need — your exports and project files — before asking us to close the Account.

Legal review required. Deletion is handled manually today. If the volume of requests grows, or if a statutory response timeline is confirmed to apply, a documented internal procedure and possibly a self-service route should be built. Counsel should also confirm which records must be retained and for how long.

14. Your rights and choices

Subject to applicable law, you can:

  • Ask what personal data we hold about you and why.
  • See and correct your account details in the application, or ask us to correct anything else.
  • Ask us to delete your personal data, subject to section 13.
  • Withdraw consent for optional marketing email at any time, from your account settings.
  • Ask us who we have shared your personal data with.
  • Complain to us, and to the relevant authority if you are not satisfied.

Withdrawing consent applies to processing that rests on consent — which for SellerProAI means optional marketing email. It does not stop processing that is necessary to provide the Service you are using, or that the law requires us to carry out. To stop the first kind, close your Account.

15. Making a privacy request

Write to contact@sellerproai.com. To help us act on it quickly, include:

  • The email address your Account is registered with.
  • What you are asking for — access, correction, deletion, or something else.
  • Any detail that helps us find the right records, such as an invoice number or a project name.

We may need to verify that the request really comes from you before we disclose, change or delete anything — releasing someone's personal data to a stranger who asked for it would be its own kind of breach. We will ask only for what is reasonably necessary to do that.

We will respond as soon as we reasonably can.

Legal review required. No response deadline is stated because none has been verified as applicable. If the DPDP Rules prescribe one when the relevant provisions commence, it should be stated here explicitly and met.

16. If something goes wrong

If a personal data breach occurs, we will investigate it, contain and remediate it where we can, assess what notification obligations apply, and notify affected people and any authority where the law requires it.

Legal review required. Breach notification form, timing and recipients are specified by the DPDP Rules, 2025. A documented internal breach-response procedure — who decides, within what time, and to whom — should be written before those provisions come into force. None is claimed here.

17. Children

SellerProAI is a business tool intended for people aged 18 or over, and is not directed at children. We do not knowingly collect personal data from children.

If you believe a child has given us personal data, write to contact@sellerproai.com and we will look into it.

18. Changes to this policy

We may update this policy. The version and effective date are shown at the top of this page, and earlier acknowledgements are kept as a record rather than overwritten.

Where a change is material we will tell Account holders.

19. Contact and complaints

Write to contact@sellerproai.com with any question, request or complaint about your personal data. Tell us what you need and we will respond.

Legal review required. Whether a Grievance Officer or a Data Protection Officer must be formally appointed and published depends on the intermediary determination noted in the Terms and on whether the business is classified as a Significant Data Fiduciary. Neither has been determined, and no officer is named here. Both need legal advice.

Who we are

SellerProAI is operated by Hummingbird Enterprises, D27, Jaipur, Rajasthan, 302006, India.

For any question about this policy, your personal data, or a complaint, write to contact@sellerproai.com.