Privacy notice
This notice explains which personal data is processed when Resellize (resellize.com) is used, on what legal basis, how long the data is kept and what rights exist. It fulfils the information duties under Art. 13 and Art. 14 of the General Data Protection Regulation (GDPR).
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Mathias Jehle Schubertweg 9/1 8141 Premstätten Austria Email: support@resellize.com
An informal message to that email address is enough for any data protection enquiry.
2. Data protection officer
No data protection officer has been appointed. In the provider's assessment the conditions of Art. 37(1) GDPR are not met, since neither regular and systematic monitoring of data subjects on a large scale nor large-scale processing of special categories of data is a core activity.
3. The provider's two roles
The provider processes personal data in two different roles:
As controller for all data needed to operate the customer account, to bill for the service and to run the website. Those processing activities are the subject of this notice.
As processor for personal data of third parties that users bring into the tool in the course of their own sales activity, in particular messages from buyers. For that data the user concerned is the controller. The basis for it is the data processing agreement under Art. 28 GDPR, available at https://resellize.com/legal/dpa. It is concluded by accepting the general terms and conditions at registration.
4. The processing activities in detail
4.1 Registration and customer account
Data processed: email address, password in the form of a cryptographic hash, time of registration, plan chosen.
Purpose: setting up, authenticating and administering the customer account.
Legal basis: Art. 6(1)(b) GDPR (performance of the service contract).
Retention: for the duration of the contractual relationship. After the account is deleted the data is removed without delay, unless a statutory retention obligation prevents this.
4.2 Item data and item photographs
Data processed: uploaded photographs of listed items, together with title, brand, size, condition, purchase and sale price, shipping cost, storage location and free-text notes.
Purpose: delivery of the main contractual service, that is, the creation of listing texts, price suggestions and inventory management.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until the individual item is deleted by the user, and at the latest until the account is deleted. Photographs are removed from object storage at the same time.
Note: these fields contain personal data only insofar as the user enters such data themselves. Users are advised not to put personal details into note fields.
4.3 Purchase lots and bookkeeping entries
Data processed: purchase lots, expenses, proceeds recorded by the user and the analyses derived from them.
Purpose: providing the bookkeeping function as part of the contractual service.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until deleted by the user, and at the latest until the account is deleted. Compliance with the user's own tax retention obligations, for example under § 132 of the Austrian Federal Fiscal Code, is a matter for the user; the data can be exported at any time through the account settings.
4.4 Usage log of the AI features
Data processed: per call, the timestamp, the type of action, the language model used, the number of tokens processed, the cost incurred and a reference to the item concerned.
Purpose: enforcing the monthly allowance, billing additional consumption, transparency towards the user, and detecting abusive use.
Legal basis: Art. 6(1)(b) GDPR for allowance enforcement and billing; additionally Art. 6(1)(f) GDPR for abuse detection. The legitimate interest lies in operating the service in a technically and economically stable way.
Retention: 24 months from the call. Where individual entries feed into billing records, the retention period under point 4.5 applies.
4.5 Payment processing and subscription management
Data processed: Stripe customer ID, subscription ID, price ID, subscription status and the invoice data. Card details are entered and processed solely at Stripe; they are never stored on the provider's servers.
Purpose: processing payment, managing the subscription, issuing invoices.
Legal basis: Art. 6(1)(b) GDPR for the processing; Art. 6(1)(c) GDPR in conjunction with the retention obligations under tax and commercial law for the invoicing records.
Retention: invoicing and accounting records are kept for seven years from the end of the calendar year for which the entry was made, in accordance with § 132(1) of the Austrian Federal Fiscal Code. They are held separately from the other account data and survive the deletion of an account.
4.6 System emails
Data processed: email address, time of dispatch, delivery status.
Purpose: sending registration confirmations, password reset messages and other system messages necessary for the contract.
Legal basis: Art. 6(1)(b) GDPR.
Retention: 30 days at the email service provider.
No newsletter or other promotional email is sent.
4.7 Server logs at the hosting provider
Data processed: IP address, time of access, address requested, volume of data transferred, status code, referring page and browser details.
Purpose: delivering the website, detecting and repelling attacks, diagnosing faults, ensuring operational security.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the secure and undisturbed operation of the website.
Retention: the hosting provider keeps runtime logs for one day. The network and domain provider stores security events for 24 hours; longer retention of access logs is not enabled. These logs are not exported to third parties.
4.8 Contact by email
Data processed: email address, the content of the message and any further details given voluntarily.
Purpose: dealing with the enquiry.
Legal basis: Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR in answering enquiries.
Retention: three years from the last correspondence, in line with the general limitation period.
4.9 Referral programme
Data processed: the referral code generated per account, the record of which account was referred through which code, and a count of rewarded referrals and the bonus generations credited.
Purpose: running the referral programme — a discount for the referred buyer and a bonus for the referrer.
Legal basis: Art. 6(1)(b) GDPR. Processing only takes place where a user uses the programme, by sharing their code or entering someone else's.
Retention: for the duration of the contractual relationship, at the latest until the account is deleted. The referral code itself is additionally held at Stripe as a promotion code (see point 4.5).
5. Publicly retrievable item photographs
Uploaded item photographs are delivered via the address cdn.resellize.com. That delivery takes place without any sign-in. Anyone who knows the full address of an image can retrieve that image permanently and without a user account.
The address contains a randomly generated user identifier 122 bits long. It is therefore practically impossible to guess. The images are not listed in any directory and are not made discoverable by search engines. Access therefore requires knowledge of the specific address.
The images sit in a publicly readable object store and are delivered from there, both inside the tool and when the user goes on to use them for a selling platform. No access check takes place. The protection therefore rests solely on the address being unknown.
Legal basis: Art. 6(1)(b) GDPR, since storing, processing and displaying the photographs is the main service the user has ordered.
Users are advised not to upload photographs in which people, addresses, documents or other personal content are identifiable. When an item or the account is deleted, the image is removed from storage and can no longer be retrieved.
6. Recipients and processors
Data processing agreements under Art. 28 GDPR are in place with all of the service providers listed below, insofar as they process personal data on the provider's behalf.
Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA Hosting and delivery of the application. In doing so it processes server logs including IP addresses, and all data that passes through the application.
Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 Database and administration of user accounts. Storage region: eu-central-1 (Frankfurt am Main, Germany).
Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA Storage of item photographs in R2 object storage, Eastern Europe region (EEUR), together with domain management, DNS and delivery of content over that provider's network.
Anthropic PBC, 548 Market St., PMB 90375, San Francisco, CA 94104, USA Image analysis and text generation. Uploaded item photographs, item data and description texts are transmitted to this service provider insofar as this is necessary for the feature requested. Under that provider's commercial terms of use, content submitted through its programming interface is not used to train models. That is an assurance given by the service provider, not an assurance of the provider of Resellize.
Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA Delivery of system emails. Technical delivery is handled by Amazon Simple Email Service in the eu-west-1 region (Ireland).
Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA, together with Stripe Payments Europe, Ltd., Dublin, Ireland Payment processing and subscription management. Stripe processes payment data as its own controller under its own privacy terms.
GitHub, Inc., 88 Colin P Kelly Jr St., San Francisco, CA 94107, USA Nightly encrypted backup of the entire database including customer data. Backups are retained for 90 days. A deletion in the live system takes effect on existing backups only when those backups expire.
Express clarifications
No data is transmitted to selling platforms. The tool only prepares texts and photographs; posting is done by the user. The website merely carries links to those platforms.
Typefaces are embedded when the pages are built and are served from the provider's own server. No requests are made to Google or other font providers at runtime.
No analytics tools, advertising networks, audience measurement or profiling services are used.
7. Transfers to third countries
Some of the service providers named are established in the United States of America or in Singapore, or process data there. A transfer to a third country within the meaning of Chapter V GDPR therefore takes place. There is no European Commission adequacy decision for Singapore; transfers there are based on the standard contractual clauses. The data of that service is, however, stored in the eu-central-1 region (Frankfurt am Main) and does not leave the European Union in normal operation.
Where the recipient concerned is certified under the EU-U.S. Data Privacy Framework, the transfer is based on the European Commission's adequacy decision of 10 July 2023 pursuant to Art. 45 GDPR.
Where a recipient is not certified, the transfer is based on the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR, together with supplementary technical and organisational measures, in particular encryption in transit and encryption of particularly sensitive fields at rest.
The current certification status of each recipient can be checked in the public register of the US Department of Commerce at dataprivacyframework.gov.
Please note that, despite these safeguards, US authorities may under certain conditions gain access to data, and that legal protection against this does not in every case match the European standard.
Copies of the standard contractual clauses can be requested at the email address given above.
8. Cookies and similar technologies
Only the following three cookies are set:
Sign-in session (Supabase) – maintains the signed-in state. Without this cookie the account cannot be used. Validity: as specified by the authentication service; the session token is renewed continuously while the sign-in is active and is deleted on sign-out.
Language choice – stores the interface language chosen by the user. Validity: one year.
Colour scheme – stores the light or dark presentation chosen by the user. Validity: one year.
Why no consent banner appears
Under § 165(3) of the Austrian Telecommunications Act 2021, consent is not required for storing information on a device where the sole purpose is carrying out the transmission of a communication, or where the storage is strictly necessary to provide a service expressly requested by the user. The same result follows from Art. 5(3) of Directive 2002/58/EC.
The session cookie is technically indispensable for the sign-in function the user has requested. The cookies for language and colour scheme store only a setting the user has made themselves, contain no identifier by which a person could be recognised, and serve no further purpose.
Since no cookies are set for analytics, advertising or audience measurement beyond this, and no data is transmitted to third parties for such purposes, there is no consent requirement and therefore no occasion for a consent banner.
9. Automated decision-making
The tool creates listing texts and price suggestions automatically. These results are non-binding suggestions which the user reviews and then adopts or discards. There is no automated decision within the meaning of Art. 22 GDPR producing legal effects concerning a person or similarly significantly affecting them. No profiling to evaluate personal aspects takes place.
10. Whether providing data is required
Providing an email address and a password is necessary to set up an account. Without them no contract can be concluded and the service cannot be used. All further details, in particular item data, photographs and bookkeeping entries, are voluntary; without them the features concerned are unavailable.
11. Rights of the data subject
The following rights exist:
Access under Art. 15 GDPR to the data processed, the purposes, the recipients and the envisaged retention period.
Rectification of inaccurate or incomplete data under Art. 16 GDPR.
Erasure under Art. 17 GDPR, unless a retention obligation prevents it.
Restriction of processing under Art. 18 GDPR.
Data portability under Art. 20 GDPR in a structured, commonly used and machine-readable format.
Objection under Art. 21 GDPR to processing based on Art. 6(1)(f) GDPR, on grounds relating to the data subject's particular situation.
Withdrawal of consent under Art. 7(3) GDPR with effect for the future, where processing is based on consent.
Exercising two rights immediately in the account
Two of these rights can be exercised without a request and without waiting. The account settings offer:
Data export – a complete export of all data stored in the account as a JSON file. This allows the right of access under Art. 15 GDPR and the right to data portability under Art. 20 GDPR to be exercised directly.
Account deletion – permanent deletion of the account including all stored data and all uploaded photographs. This allows the right to erasure under Art. 17 GDPR to be exercised directly. Note that encrypted backups persist for up to 90 days and that invoicing records continue to be kept because of statutory retention obligations.
All rights can of course still be asserted by email to support@resellize.com.
12. Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, there is a right to lodge a complaint with a data protection supervisory authority, in particular in the member state of habitual residence, place of work or place of the alleged infringement.
The supervisory authority responsible for the provider is:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde) Barichgasse 40–42 1030 Vienna Austria Telephone: +43 1 52 152-0 Email: dsb@dsb.gv.at Website: www.dsb.gv.at
People habitually resident in Germany may also contact the data protection supervisory authority of their federal state.
13. Data security
Transmission between device and server is encrypted using TLS. Passwords are stored only as a hash. Database backups are stored encrypted. Access to production systems is restricted to the provider.
14. Changes to this notice
This notice is updated when the processing changes, for example through new features or a change of service provider. The version published on the website applies in each case.
15. Language
This is a translation provided for convenience. The German version prevails in the event of any discrepancy.
Version: 7 September 2026