Last updated | 17-07-2024

Privacy Policy

The privacy and protection of your personal data are two of the most important aspects for us. To this end, and in compliance with the General Data Protection Regulation, SELLROCKET provides in detail in this document all the procedures for collecting, storing and processing your personal information. Our privacy policy is intended not only for our customers (merchants), but also for their customers, affiliates and visitors to our site, so make sure you read this document carefully and in detail. Your acceptance presupposes knowledge of all the clauses and authorisation to collect and process data.
If you have any questions about these policies, please contact SELLROCKET at [email protected]. .

What is personal data?

Personal data is any information about a natural person which, directly or indirectly, can unequivocally identify them, such as their name, tax identification number, photograph, location data, among other elements of their identity.

Who are the personal data subjects?

The holders of personal data are the users or customers to whom the data belongs and who use SELLROCKET's services directly (customers) or indirectly (users). Users are all people who use SELLROCKET's services but who are not the owners of the service (e.g. employees of a company that has an online shop with SELLROCKET). The customer pays for the service and is the owner of the service, while the employee does not have access to the services).

What personal data do we collect and for what purpose?

In order to provide you with a better experience with our services, SELLROCKET collects some of your data, such as when you visit our website, create an account with us, register as an affiliate, make a support request, etc. We may also collect some data from third parties, service providers who provide us with information about your location, IP address, among others. You can choose to refuse to provide some of your personal data, but you may not be able to use our services if you do not provide us with the minimum required data.

As a customer, we collect the personal data listed below, depending on the specifications of the service:

Name and surname: we request this data to identify the customer, improve their experience, ensure greater proximity in future contacts, for billing purposes (where applicable) and to register the ownership of domains in the customer's name through us. This data constitutes a contractual and legal obligation. For contractual purposes, these fields must be filled in, without which it will not be possible to finalise the creation of an account and take advantage of the services. Legally, this information is required for domain registration purposes.
Category: identification data

Company:company name, if applicable. We require this information for invoicing purposes. This information constitutes a legal obligation (if any).

Email: we request this information to establish future contacts, for the purpose of resolving support requests, sending order and payment confirmations, proforma invoices, receipt invoices, service suspension notices, among other operational and informative emails. Marketing emails are only sent with the user's consent. Email constitutes a contractual obligation and is the preferred means of contact with the customer, without which we will not be able to provide a service.
Category: tracking data.

Password: we request this information for authentication purposes in the customer area. This information is automatically encrypted, i.e. placed in an incomprehensible format, making it impossible to read by any other person or entity, including SELLROCKET. The password is a contractual obligation required for access to registration and for creating and accessing an account.
Category: authentication data.

NIF: the tax identification number is requested for billing purposes and for registering the ownership of ".pt" domains in the client's name through us. This information is not compulsory and it is up to the customer to fill it in if they wish to include it on the invoice. If you decide to do so, you must provide a valid NIF to be able to finalise the creation of the account/order.
Category: identification data.

Address: this information is requested for billing purposes only and constitutes a contractual obligation without which it will not be possible to finalise the creation of an account and finalise the order.
Category: localisation data.

Telephone and mobile: we request this data to identify the customer, improve their experience, ensure greater proximity in future contacts, send operational and informative messages such as suspension and payment notices. Contact details are a contractual obligation and, although they are not the preferred means of establishing contact with the customer, they are necessary in order to establish more urgent contacts and send important notices when there is no reach by email. It is mandatory when creating a SELLROCKET account and finalising an order.
Category: tracking data.

Payment details: we collect payment data when made by credit card, namely the last four digits of the credit card number (the rest are encrypted), the expiry date and the type of card used. The remaining digits of the credit card number, although filled in by the customer, are automatically encrypted, i.e. placed in an incomprehensible format, making it impossible for any person or organisation, including SELLROCKET, to read them. This data is an obligation when payment is made by credit card. If the customer does not wish to provide these details, they can choose another payment method.
Category: financial data.

Domain: We collect this information in order to install the online shop and to issue the SSL certificate. This is a mandatory contractual requirement without which we cannot provide a service.
Category: tracking data.

Location data and devices: this data is contractual. We may collect some of this data when you access our website or backoffice, in particular:
a. access to the pages you visit, the products you search for and the actions you take on those pages.
b. your location (country and city), operating system and browser through which you access it.
This data is necessarily collected to enable chat support.
c. how long you have been online, how many visits you have made with the IP in question and the content of previous chats.
d. IP address, when you send us a support request by email. This data is mandatory for us to be able to provide you with a service.
Category: tracking and localisation data.

Content of conversations: we collect and store conversations exchanged via chat and email. This data is a contractual obligation and its collection is linked to the provision of chat support.
Category: communication data, identification data, tracking data, localisation data.

Email content: we store the content of all emails exchanged for future technical support enquiries. This is a prerequisite for providing you with a service.
Category: communication data, identification data, tracking data, localisation data.

Information on our clients' customers (Merchants): we will be able to access all the customer information of our clients (merchants) since the entire database is hosted on our servers. This includes all emails exchanged between merchants and customers when using our institutional email service (extension the same as the domain). We need to collect this content in order to send it to the recipient of your email and store it for future queries in the email database. If you do not wish to host your emails with SELLROCKET, you can associate an external email address. This data is a contractual obligation, given that all shops are hosted on our servers and we do not provide the online shop service on external hosting.
Category: communication data, identification data, tracking data, location data, financial data.

Other personal details:we may have access to other more specific data when, at the customer's request and consent, we need to collect it in order to provide a certain type of service.

If you are a visitor to our site or have submitted a request for information, we collect it:
a. access to the pages you visit, the products you search for and/or buy and the actions you take on those pages.
b. your IP address, your location (country and city), the device, operating system and browser through which you access. This data is necessarily collected to enable chat support.
c. how long you have been online, how many visits you have made with the IP in question, content of previous conversations.
- We may collect data such as name, telephone number and email address, filled in by the user when submitting the enquiry or contact request
- in telephone enquiries, we collect contact details.
- other data that the user transmits of their own free will

What data do we obtain from third parties?

In order to provide you with a good service and improve it, we may collect some data from third parties, such as:

Chat software: when you access the backoffice, visit our website or enter your customer area, SELLROCKET accesses personal data such as your operating system, browser, the pages you visit, your location (city and country, although this data is imprecise) and email address if you provide it.

Content management software: when you access your customer area, SELLROCKET accesses personal data such as the customer data registered in your account, the IP address and the time at which the access was registered. When you send a support request via our website, even if you are not our customer, SELLROCKET accesses your name, email address, telephone number (optional), comments, VAT number (if applicable) and IP address via the form you fill in when submitting the request. When you search for a domain on our site, SELLROCKET has access to the IP address that performed the search. This data is collected for billing purposes and to improve our services.

Telecommunications software (call centre): when you contact SELLROCKET via the Call Centre number, SELLROCKET collects the telephone number, the date and time of the call, and its duration. This data is collected to enable contacts to be made within the scope of the contracted services.

TIN validation system (AT): Through the AT validation system, SELLROCKET has access to the holder's full name and tax office in order to validate the NIF for invoicing purposes.

Intra-Community TIN validation system (VIES): through the European validation system, SELLROCKET can access data such as name and address (data varies according to country of residence) in order to validate the TIN for invoicing purposes.

Google Analytics: when you access our website and/or customer area, personal information such as IP address, location (city and country), browser, pages you visited, length of time on the page and the word you searched for on Google to access our page are recorded. This data is used to analyse the behaviour and preferences of our website users.

Facebook Pixel: when you access our website via Facebook advertising we access personal information such as IP address, location (city and country), browser, pages you have visited, length of time on the page and interests on Facebook. This data is collected in order to analyse the behaviour of users on the site who come from Facebook.

For any further clarification regarding the above-mentioned entities, please contact SELLROCKET at [email protected] , who can provide clarification within the following 30 days.

What data do we provide to third parties and for what purpose?

SELLROCKET maintains partnerships with other organisations as a way of improving its own services. These organisations may provide your personal data or part of it, depending on the type of service associated with it, as detailed below:

Invoicing software: for the purposes of issuing invoices, other tax documents and managing customer accounts, SELLROCKET shares the customer's name (when the customer requests it on the invoice), VAT number (when the customer requests it on the invoice), address and email address with the billing software.

Registrars (domain registrars and managers): for the purposes of registering or transferring domains, SELLROCKET, as the intermediary for such registration/transfer and at the customer's request, may have to provide personal data such as name, email address, telephone number and VAT number.

Datacentre (hosting server): all the information from site enquiries, emails, backoffice, shop databases and all the associated content is stored on the server for hosting purposes.

Datacentre (backup server): all the information referred to in the previous point is stored on the backup server for the purpose of recovering lost data, for a period defined in the section "How long do we store your personal data?".

Email distribution and monitoring service: all information relating to emails and their contents between SELLROCKET and the customer or user is made available to the organisation managing this service.

Consent service for cookies and online tracking: the cookie consent history on the SELLROCKET website is accompanied by data on the user who accepted/refused them, such as IP address, country and browser.

Certificate issuer: when SELLROCKET contacts the user via the Call Centre number, SELLROCKET provides the telephone number. This data is shared to enable contacts to be made within the scope of the contracted services.

Telecommunications service (call centre): To issue an SSL certificate, you need to provide your shop's domain to the issuing organisation.

Customer service software (online chat): when you contact SELLROCKET via chat, your information is automatically filled in with the data you have filled in in your customer area, such as name, telephone number, address, email address, conversations exchanged, etc.

When do we collect your personal data?

Personal data is collected when you subscribe to our services, submit a support request, make or request a telephone call, search for a domain on our website, sign up as our affiliate or visit our website.

Who is responsible for processing your personal data?

The person responsible for processing your personal data is the organisation that provides you with the service and, as such, decides what data is collected, how it is processed and for what purpose. SELLROCKET is only responsible for its services, and partner organisations, even in this capacity, will be responsible for processing your data when it is the customer themselves who provides them with your data.

What are the rights of the data subject?

The data subject has the right to access, rectify, restrict, delete or request the portability of their data. Through the customer area, the user can access and rectify data such as name, email, telephone number, VAT number, company, address and credit card details. For more detailed access to location information, IP addresses, order history, pages visited, among other location and tracking data, purpose of data processing, etc., the user can request a report by sending an email to [email protected] . This report on access to personal data can be replied to within 30 days. Users should contact SELLROCKET via the same email address whenever they are unable to change or access one or more pieces of personal data.

Right of Access: the customer has the right to obtain information about which personal data is processed by SELLROCKET, the purposes for which it is processed, how long it is kept, etc. The customer also has the right to obtain all formalised information, such as invoices, terms and conditions, the history of conversations and other written agreements. The customer can request access to all this information and it can be provided within a maximum of 30 days.

Right of Rectification: the customer has the right to change their personal details at any time. SELLROCKET allows the customer to change any and all personal data contained in their customer file in the "Account" section. in the "Account" section.

Right to restriction of processing/limitation of processing: the customer has the right to limit access to their personal data when the purpose for which they agreed to provide it no longer applies. The user must bear in mind that limiting access to a certain type of data may also result in a limitation of the service provided. This request to limit data must be made in writing to [email protected] and a response can be given within a maximum of 30 days.

Right to Portability: the customer has the right to request the portability of their personal data, in a structured, commonly used and machine-readable format, to another management organisation that will become the new data controller. This request can be answered within a maximum of 30 days.

Right to be Forgotten: the customer has the right to request the deletion of their personal data, as long as this does not override a legal or judicial obligation to keep it for longer. This request should be sent by email to [email protected] and can be answered within a maximum of 30 days. Upon requesting the deletion of personal data, all the aforementioned data will be deleted, with the exception of data implicit in documents with fiscal relevance, such as invoices or others that serve as support for their issuance, which must be kept for the period stipulated by law.

Right to lodge a complaint with a supervisory body.

How we manage outgoing advertising emails

At the time of subscribing to the services, SELLROCKET gives the user the option of choosing whether they wish to receive promotional emails and messages by ticking a box which is intended solely to accept the receipt of advertising messages. SELLROCKET only sends advertising messages and emails with the express consent of the user, who can withdraw their consent at any time in their customer area at https://sellrocket.io/account ("Account" section).

What are cookies and how do we use them?

Cookies are small text files that are stored on the user's computer when they visit a website and are designed to track their behaviour, tastes and interests, making their browsing experience more personalised and dynamic. The user can refuse to accept their use, as well as delete cookies that have already been created via a browser option. SELLROCKET uses cookies when you access the website at https://sellrocket.io. Cookies are not active in the customer area.

We use cookies:
Necessary:Some cookies are important to facilitate navigation on the site and access to pages and functionalities. Without these cookies you may not be able to view pages correctly.
Statistical: these cookies are intended to analyse how users use the site and monitor its performance. This allows us to provide a better user experience.
Marketing: These cookies are available for various types of targeted digital marketing. They store content manager data, which allows advertising services to target audience groups according to variables such as location, interests, behaviour on our website, etc.

Refusal to accept cookies may result in the blocking of some functionalities on our website.

To deactivate cookies in your browser(s), and taking into account the variety of browsers available, consult the help of the respective browser to deactivate them.

Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences

Chrome: https://support.google.com/chrome/answer/95647?hl=pt

Internet Explorer: http://windows.microsoft.com/pt-pt/internet-explorer/delete-manage-cookies#ie=ie-10

Security of your personal data

User security is one of SELLROCKET's concerns. To this end, we maintain security procedures to protect user data from malicious and unauthorised access, use and/or disclosure, such as:

Firewall: this security measure blocks undue and abusive access. We can block IPs that access several times in a matter of seconds or that force entry several times in a row without success.

Firewall: this security measure blocks undue and abusive access. We can block IPs that access several times in a matter of seconds or that force entry several times in a row without success.

Anti-virus

Intrusion detection system

SSL certificate: the certificate guarantees the encryption of credit card payment data (credit card number (except last 4 digits) and CVV - Security Code), and access passwords. Data encryption is based on an algorithm that makes it impossible for any person or organisation, including SELLROCKET, to read the data.

Backup: backups of users' databases, email accounts and online shops are stored on a server separate from the hosting server, thus guaranteeing the possibility of recovery.

Log of users and actions: SELLROCKET maintains an active policy for controlling access to information by user and recording their actions.

Passwords and access to the customer area: SELLROCKET allows the customer to create sub-accounts for other users and assign them different passwords and types of access, thus limiting unauthorised access to personal data.

If the user believes that the measures used by SELLROCKET do not comply with the provisions of its privacy policies, the user can contact SELLROCKET via email support at [email protected]. If your complaint is not resolved, you can contact the online consumer dispute resolution centre at https://ec.europa.eu/consumers/odr.

Each and every page on the Internet can be penetrated, so we do not guarantee the security of your data at 100%.

Where is your personal data stored?

Personal data may be stored in different locations depending on the type of service.
Customer support (chat, knowledge base): USA
Customer management (support tickets, customer area): Switzerland
Telecommunications (call centre): United Kingdom
Metrics: worldwide
Cookies: Ireland, Netherlands
Billing: United Kingdom
Backup servers: United Kingdom
Servers: Portugal, Germany, Switzerland
Email distribution and monitoring: EU
SSL certificates: USA

If you would like more information, please email us at [email protected].

How long do we store your personal data?

SELLROCKET stores your personal data for as long as it maintains a contractual relationship with you and/or for the time strictly necessary to enable the provision of services, for the fulfilment of tax obligations, dispute resolution, among others inherent to the initial contract. The storage period for the different types of obligations may vary as detailed below:

Emails (from the client to their clients): as long as the customer uses the email accounts on the SELLROCKET server, the content of the emails is stored indefinitely, always depending on manual deletion action by the customer. The email will be permanently removed:
- when the customer deletes it from the deleted items box. The final deletion period can be extended by a further 3 days, during which time the email remains stored on the backup server.
- 60 days after the due date of the last unpaid proforma invoice when there has been no manifest request by the customer to cancel the service. To this period is added 3 days, the time the data remains on the backup server
- 3 days after account cancellation, when requested to delete by the customer (storage period on the backup server)
- 3 days after account cancellation, when SELLROCKET cancels the service on its own initiative, and after notifying the customer (storage period on the backup server)

Emails (between SELLROCKET and the customer): as long as the user is our client, the content of the emails is stored indefinitely. The email will be removed permanently:
- 60 days after the due date of the last unpaid proforma invoice when there has been no manifest request by the customer to cancel the service. To this period is added 3 days, the time the data remains on the backup server
- 3 days after account cancellation, when requested by the customer (storage period on the backup server)
- 3 days after account cancellation, when SELLROCKET cancels the service on its own initiative, and after notifying the customer (storage period on the backup server)

IP history: is kept for the duration of the customer's stay and disposed of:
- 60 days after the due date of the last unpaid proforma invoice when there has been no manifest request by the customer to cancel the service. To this period is added 3 days, the time the data remains on the backup server
- 3 days after account cancellation, when requested by the customer (storage period on the backup server)
- 3 days after account cancellation, when SELLROCKET cancels the service on its own initiative, and after notifying the customer (storage period on the backup server).

Cookies: are automatically removed after 30 days, at which point your profile, records and preferences are no longer tracked. Tracking resumes as soon as you re-enter our site. You can also remove cookies manually via your browser(s) (see "What are cookies and how do we use them?").

Online shops: the contents of the online shops and their databases are deleted 30 days after the due date of the last unpaid proforma invoice or after the date of the cancellation request by the customer, whichever is the earlier.

Invoices: invoices are kept for the period required by law.

Google Analytics metrics: the data collected is kept for a period of 50 months.

Personal data relevant for legal purposes may have to be stored for the time stipulated by law.

  • Selling
  • Inspire
  • Learning