Data policy

This policy explains how the SaleFisher platform handles the data our customers bring into it — their product catalogues, orders, and the personal details of the buyers who place those orders. The short version: it's our customers' data, not ours. We process it on their instructions, we keep personal data only for a limited period, and the retention controls sit in their hands, not ours.

We are a processor, not a controller

For the data inside the SaleFisher platform, our customer — the business selling through SaleFisher — is the data controller. They decide what data enters the platform, what it's used for, and how long it's kept. SaleFisher is the data processor: we store and process that data solely to provide the service, on the customer's instructions, under the agreement between us.

In practice that means:

  • We use customer data only to run the platform — never for our own marketing, profiling or resale.
  • We don't decide what happens to a buyer's details; our customer does, through their own settings.
  • Requests from buyers about their personal data (access, correction, deletion) are handled by the business they bought from — the controller — and the platform gives that business the tools to comply.

The one place we act as a controller is this marketing website's contact form, which is covered separately by our privacy policy.

What data the platform holds

  • Business data — product catalogues, stock levels, prices, listings, invoices and reports. This is commercial data, kept for as long as the customer uses the service.
  • Buyer personal data — names, delivery addresses and contact details that arrive with marketplace orders, held only as long as fulfilling the order requires.
  • Account data — our customers' own sign-in details and settings.

How long personal data is kept

Buyer personal data is retained for 30 days after an order completes (the default — see below), and is then automatically and permanently redacted by a scheduled job that runs every night. Redaction removes the personal fields — names, addresses, contact details — while the order itself survives with its references, items, quantities and totals, so the business keeps a complete commercial and tax record without holding anyone's personal details longer than fulfilment needs.

This mirrors what marketplace data protection policies (Amazon's and eBay's among them) require of us and of our customers: personal data held only as long as its purpose lasts, never indefinitely.

Customers control their own retention

The retention period is not fixed by us. Each customer sets their own data storage requirements from the Data settings in their admin panel — shortening or lengthening the retention window to match their own policies and legal obligations. As controller, they are fully in charge of their data needs; the platform enforces whatever they choose, automatically, every night.

Where data lives and how it's protected

Customer data is stored in Microsoft Azure and kept strictly separated per customer account. Marketplace credentials are held encrypted. Access is limited to what operating the service requires, and every retention run is recorded in the customer's own activity log — so "is the policy actually running?" is a question the customer can answer from their own screen.

When a customer leaves

If a customer closes their account, their data is deleted from the platform in line with the agreement between us. We don't keep copies for our own purposes.

Questions

For anything in this policy — including data processing terms for your own compliance paperwork — contact us through the contact form.