Privacy Policy
At SEPIVEL LTD ("SEPIVEL", "we", "us", or "our"), we respect your privacy and are committed to protecting the personal data of our merchants, storefront visitors, and platform users.
1. Data Controller and Scope
SEPIVEL LTD acts as the data controller for personal data collected through the SEPIVEL platform, website, and related administrative services. When providing hosted storefront software to our merchants, we may also process customer order information on behalf of merchants as a data processor.
2. Categories of Personal Data We Collect
We collect and process personal data necessary to provide our e-commerce platform services:
- Identity and Account Data: Full name, company or business name, tax identification number (for commercial invoices and regulatory compliance).
- Contact Information: Email address, business telephone number, billing address, and shipping/fulfillment address.
- Commercial & Catalog Data: Marketplace store URLs, catalog sync metadata, pricing settings, inventory counts, and order transaction records.
- Technical & Usage Data: IP address, browser type and version, device characteristics, operating system, and session telemetry required for security and fraud prevention.
3. Purposes and Legal Bases of Processing
Your personal data is collected and processed for the following lawful business purposes:
- Provisioning, operating, and maintaining your independent online storefront;
- Executing automated catalog, inventory, and order synchronization;
- Facilitating secure online payments via licensed, PCI-DSS Level 1 compliant payment gateways;
- Delivering merchant customer support, technical onboarding, and service communications;
- Complying with applicable statutory accounting, taxation, and consumer protection regulations;
- Protecting against security vulnerabilities, malicious activity, and unauthorized account access.
4. Data Sharing and Third-Party Sub-processors
We do not sell, rent, or trade your personal data to third parties for advertising or marketing purposes. Data is shared strictly on a need-to-know basis with vetted infrastructure providers and sub-processors:
- Payment Service Providers: PCI-DSS certified payment processors (e.g., licensed virtual POS providers and Stripe) to execute payment transactions securely.
- Cloud Infrastructure: High-reliability cloud hosting, edge compute, and database infrastructure (Vercel, Supabase, Cloudflare R2).
- Legal and Regulatory Authorities: Government authorities or law enforcement only when legally compelled under mandatory statutory provisions.
5. Data Security Measures
We employ state-of-the-art organizational and technical measures to safeguard your personal data:
- End-to-end 256-bit TLS 1.3 cryptographic encryption for all data in transit;
- Row-Level Security (RLS) and strict multi-tenant database isolation;
- Role-Based Access Control (RBAC) and mandatory two-factor authentication for administrators;
- Zero storage of sensitive payment card numbers (PAN) or card verification codes (CVV).
6. Data Subject Rights (GDPR & International Standards)
Subject to applicable local data protection legislation, you are entitled to exercise the following rights regarding your personal data:
- The right to request access to and a copy of your personal data;
- The right to request rectification of inaccurate or incomplete records;
- The right to request erasure ("right to be forgotten") of your personal data;
- The right to restrict or object to the processing of your data;
- The right to data portability in a structured, machine-readable format.
To exercise any of these rights, please submit your request in writing to support@sepivel.com. We review and respond to verified requests within thirty (30) days.
7. Updates to This Policy
We may update this Privacy Policy periodically to reflect enhancements to our platform features or changes in regulatory requirements. Material revisions will be notified via email or through the merchant dashboard.