Skip to content
Legal

Privacy Policy

Last updated
July 19, 2026
Version
1.0
Effective
July 19, 2026

1. Who is responsible for your data

This explains how ByteSell LLC, a New Mexico, USA company, handles personal data on bytesell.io. For Seller accounts and visitors to bytesell.io itself, we are the data controller. You can reach us about privacy at privacy@bytesell.io.

Our mailing address is ByteSell LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States. You can reach us about privacy by email at privacy@bytesell.io.

2. Controller and processor roles

There are two different data relationships here, and our role changes between them:

  • For account and platform data (your Seller account, billing, using bytesell.io), we are the controller.
  • For storefront data (what a Seller collects through their store, hosted with us or embedded on their own site: analytics about Buyers and visitors, plus buyer accounts, sign-ins, and subscriptions where the store uses ByteSell authentication or billing tooling), the Seller is the controller and we are the processor, handling it on their behalf to run the tooling.

If you are a Buyer or visitor and want to exercise rights over data from a Seller's store, contact that Seller. We will help them respond.

3. Data we collect

  • Account data - your name, email, and login details.
  • Usage and analytics - how the Platform and stores get used: pages, events, device and browser, and rough location from IP.
  • IP address - for security, fraud prevention, and running the service.
  • Wallet addresses - the public crypto addresses you connect to get paid.
  • Buyer account data - where a store uses ByteSell authentication or subscriptions, the sign-in and subscription details Buyers create with that store, processed on the Seller's behalf.
  • Session cookies - strictly-necessary cookies that keep you signed in (see Cookies and tracking).
  • Support messages - whatever you send us.

We never see or store card numbers. Stripe and PayPal handle payment details directly, under their own privacy policies.

4. How we use data and our legal bases

Where GDPR or UK GDPR applies, here is what we do and why:

  • Run the Platform - create and manage your account, operate stores, deliver the tools. Basis: performing our contract with you.
  • Keep it safe and improve it - fraud prevention, security, debugging, and product analytics. Basis: our legitimate interest in a safe, working, improving product.
  • Talk to you - service messages, plus product updates if you opt in. Basis: contract, legitimate interest, or consent.
  • Follow the law - tax, regulatory, and valid legal requests. Basis: legal obligation.

5. Sub-processors and sharing

A short list of providers processes data for us, under contract:

  • Amazon Web Services - hosting and transactional email (Amazon SES).
  • Cloudflare - CDN, security, and edge hosting.
  • ClickHouse - analytics storage and queries.
  • Stripe - card and payment processing on the Seller's own account.
  • PayPal - payment processing on the Seller's own account.

We do not sell your data. We may share it when the law or valid legal process requires it (see the Abuse & DMCA page), or as part of a merger or sale, still under this policy.

6. International transfers

We are based in the US, and our providers may process data in the US and elsewhere. When we move personal data out of the EEA or UK, we use appropriate safeguards, mainly the EU Standard Contractual Clauses and the UK Addendum / International Data Transfer Agreement, plus extra measures where needed.

7. Data retention

We keep personal data only as long as we need it: while your account is active, and for a reasonable period after to meet legal, tax, and security obligations or to sort out disputes. Analytics data is kept for a limited time. After that, we delete or anonymize it.

8. Your rights

EU / UK (GDPR)

If you are in the EU or UK, you can access, correct, delete, restrict, and port your data, object to processing based on legitimate interest, and withdraw consent where we relied on it. You can also complain to your local data protection authority (the ICO in the UK).

California (CCPA / CPRA)

If you are in California, you can ask what we collect and why, ask us to delete or correct it, and opt out of any "sale" or "sharing" of personal information. We do not sell your personal information, and we will not treat you differently for exercising these rights.

To use any of these, email privacy@bytesell.io. We will verify your request and respond within the timeframes the law sets.

9. Cookies and tracking

ByteSell is cookieless apart from strictly-necessary session and auth cookies, the ones that keep you signed in and the Platform working. You cannot turn those off without breaking the service. EU ePrivacy rules and the UK PECR exempt strictly-necessary cookies from consent, which is why there is no cookie banner.

No tracking, advertising, profiling, or third-party cookies, and no third-party trackers. Our product analytics is cookieless and does not build advertising profiles.

10. Security

We protect personal data with measures matched to the risk: encryption in transit, access controls, and hardened infrastructure. Nothing is perfectly secure, so we cannot promise absolute safety, but we work at it and we will notify you and regulators of breaches when the law requires.

11. Children

ByteSell is for people 18 and over. We do not knowingly collect data from children. If you think a child has sent us data, email privacy@bytesell.io and we will delete it.

12. Changes to this Policy

We will update this policy from time to time. We will change the date and version at the top, and for material changes we will give extra notice where it makes sense.

13. Contact

For any privacy question or to exercise your rights, email privacy@bytesell.io.