Version 2026-09-06 · Last updated: 2026-09-06
This policy explains which personal data poSell processes, why, and what rights you have. Data controller: Linkia Solutions LLC (30 N Gould St Ste R, Sheridan, WY 82801, USA — [email protected]).
| Data | Why |
|---|---|
| Shop name, subdomain | Creating and identifying your account |
| Email address | Verification, service notices, support |
| Password (stored irreversibly) | Authentication |
| IP address and activity logs | Security, abuse detection, legal retention |
| Terms acceptance: time, IP, version | Proof of consent |
| Payment records (amount, date, method) | Subscription management and accounting |
We never hold your card details. poSell does not store or even see credit card numbers at any point.
The products you sell, your customers and your sales records belong to you. For that data the Provider acts as a processor: it is accessed only to operate the service, back it up, and support you when you ask. When you collect your own customers' data, the obligations towards them (notice, consent) are yours.
Our servers are located in Germany (Hetzner Online GmbH) and traffic is routed through Cloudflare. Your data is therefore processed on infrastructure in the European Union and/or the United States. By signing up you consent to this transfer.
| Party | Purpose | What is shared |
|---|---|---|
| Hetzner (Germany) | Server hosting | All service data |
| Cloudflare | Network security, performance, bot protection on the sign-up form (Turnstile) | IP, request headers |
| Email provider | Verification email | Email address |
Beyond these, your data is not shared with or sold to anyone, and is never used for advertising. If a legal obligation arises (a court order, for instance), disclosure is limited strictly to what is requested.
Only strictly necessary cookies are used: the session cookie that keeps you signed in, and the form-security (CSRF) cookie. No advertising or profiling cookies.
You may ask whether your personal data is being processed, request a copy, ask for correction or deletion, learn which parties it has been transferred to abroad, and claim compensation for damage. Businesses in Turkey hold these rights under KVKK Article 11; comparable rights apply under GDPR in the EU. Send requests to [email protected]; we respond within 30 days.
All traffic is encrypted with TLS. Every tenant's data is held in a separate database. Passwords are stored irreversibly and database credentials are encrypted. In the event of a breach, affected users and the competent authority are notified within the period required by law.
When this policy changes the version number is updated, and material changes are announced by email.