Sign in Create account

Security

How we protect your data

SellerHelp holds order, inventory, pricing and settlement data from your marketplace accounts. This page describes the controls that protect it. Report a suspected security issue to security@sellerhelp.pl.

Hosting and encryption

Where your data lives

All customer data is stored and processed on infrastructure located in the European Union. Data at rest is encrypted with AES-256; data in transit uses TLS 1.2 or higher, and plaintext protocols are disabled.

Each customer’s data is held in a logically isolated tenant. We never combine one customer’s marketplace data with another’s.

Marketplace authorisation credentials — including Login with Amazon client credentials and per-seller refresh tokens — are held in a managed secrets vault with envelope encryption, separate from application data. They are never written to source control, application logs or developer workstations. Encryption keys are managed in a key management service and rotated at least annually.

Access

Who can reach production

  • Every person has a unique named account. Shared logins are prohibited.
  • Multi-factor authentication is mandatory for all administrative and production access.
  • Passwords require at least 12 characters with mixed character classes; accounts lock after 10 failed attempts.
  • Access is granted by role on a least-privilege basis and requires documented approval.
  • All human and service access is reviewed quarterly.
  • Access for departing personnel is revoked within 24 hours of termination.

Production runs in a segmented private network. Databases have no public endpoints and are reachable only from application subnets. Administrative access requires VPN with multi-factor authentication, and public web traffic passes through a web application firewall with rate limiting.

Development, staging and production environments are separated. Production marketplace data is never copied into non-production environments; testing uses synthetic or anonymised data.

Monitoring

Logging and detection

Application, infrastructure and access logs are collected centrally and retained for at least 12 months. Each record carries a timestamp, actor identity, source address, the operation performed and the affected resource. Personally identifiable information is never written to logs, and logs are write-protected against modification by the systems that generate them.

Alerts fire on authentication failures, privilege changes, configuration changes and anomalous API usage. Aggregated security findings are reviewed at least every two weeks.

Vulnerabilities

Finding and fixing problems

We scan infrastructure, container images and application dependencies at least every 30 days, and dependency scanning runs on every build in our CI pipeline. Critical findings are remediated within 7 days and high-risk findings within 30 days, tracked to closure. An independent penetration test is commissioned annually.

Changes reach production only through peer-reviewed, approved pull requests with an automated test suite and a documented rollback path.

Incidents

What happens if something goes wrong

We maintain a written incident response plan approved by the management board and reviewed every six months. A named Incident Management Point of Contact is responsible for triage, containment, eradication, recovery and post-incident review, with a documented escalation path.

If we confirm an incident affecting data obtained from a marketplace platform, we notify that platform within 24 hours of detection through the channel it designates. Affected customers are notified without undue delay, and the Polish supervisory authority within 72 hours where the GDPR requires it.

To report a suspected vulnerability or incident, write to security@sellerhelp.pl. We acknowledge reports within one working day. We will not pursue legal action against researchers who report findings in good faith, do not access or modify data beyond what is needed to demonstrate the issue, and give us reasonable time to remediate before disclosure.

Retention

How long we keep data

Personally identifiable information from orders
Deleted no later than 30 days after the order is delivered, unless invoicing or tax law requires a restricted-access archive
Order, inventory, pricing and financial data without PII
Maximum 18 months
Marketplace authorisation tokens
Destroyed within 24 hours of revocation or account closure
Security and access logs
12 to 24 months
Backups
35 days rolling, encrypted, replicated within the EU

Deletion is permanent and follows NIST SP 800-88 media sanitisation guidance, and propagates to backups on their next rotation cycle. You can request deletion of your data at any time by writing to biuro@sellerhelp.pl; we confirm in writing within 30 days. Full detail is in our privacy policy.

Subprocessors

Third parties with access to data

Every vendor and subprocessor with any access to customer data is risk-assessed before access is granted and at least annually thereafter, and is bound by a written contract and a GDPR data processing agreement with obligations no weaker than our own. We do not share customer or marketplace data with advertising networks, data brokers or third-party analytics providers.

Cloud infrastructure
[nazwa dostawcy, region UE]
Payment processing
PayPro S.A. (Przelewy24), Poznań, Poland
Transactional e-mail
[nazwa dostawcy]
Monitoring and logging
[nazwa dostawcy]

We notify customers before adding a subprocessor with access to their data.

Contact

Reaching the right person

Security and incident reports
security@sellerhelp.pl
Data protection enquiries
biuro@sellerhelp.pl
Customer support
support@sellerhelp.pl
Postal address
SPEEDPARCEL sp. z o.o.
ul. Firlejowska 2A/16
20-306 Lublin, Poland
SellerHelp AI Mentor

Pytaj normalnie: „czy macie GT?”, „jak połączyć Base → Nexo?”, „jak wygenerować ofertę Allegro?”. Mentor poda kroki i link do modułu.

Zadaj pytanie albo wybierz gotowy temat. Po odpowiedzi możesz pytać dalej bez zamykania czatu.
Otwórz pełny AI Mentor