Privacy Policy
Table of contents
1. Data controller
BLOOM & NOURISH LTD
Suite 5, 5th Floor, City Reach · 5 Greenwich View Place · London E14 9NN, United Kingdom
Companies House No. 14862714
Email: hello@sellereu.com
For all privacy enquiries, requests under GDPR or UK Data Protection Act 2018, contact: hello@sellereu.com
2. What data we collect
When you visit our website
- IP address (anonymized after 7 days)
- Browser type and version, operating system
- Country (derived from IP for language preference)
- Referring URL, pages visited, timestamps
- Cookies (see § 6)
When you submit a form, sign up, or buy a service
- Name, email address, company, VAT ID (if provided)
- Brand, Amazon storefront URL, ASINs (only when you submit them)
- Free-text descriptions of your problem or goal
- Payment data is processed by PayPal (we never see your full card details)
- Service usage history within the client portal
When you connect your Amazon Seller Central
- Read-only SP-API consent token (Amazon issues; we never see your password)
- Listing data, order data, advertising metrics, account-health signals — only for the marketplaces you authorize
- Files you upload to your client portal
When you use the Marktpilot Chrome extension
- Visible page content from amazon.de while you have the extension active (read-only)
- Your subscription status (Free / Pro / Team)
- Aggregated usage events (which modules opened, how long)
3. Why we process your data
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide our services | Account, contact, Seller Central | Art. 6(1)(b) GDPR (contract) |
| Process payments | Email, billing details | Art. 6(1)(b) GDPR (contract) |
| Send service-related emails | Email, name | Art. 6(1)(b) GDPR (contract) |
| Send marketing emails | Email, name | Art. 6(1)(a) GDPR (consent) |
| Improve the website (analytics) | Anonymized IP, page views | Art. 6(1)(f) GDPR (legitimate interest) |
| Defend against legal claims | Engagement data | Art. 6(1)(f) GDPR |
4. Legal basis
- Contract performance (Art. 6(1)(b)) — to deliver services you requested
- Legitimate interest (Art. 6(1)(f)) — analytics, fraud prevention, security
- Legal obligation (Art. 6(1)(c)) — accounting records, tax obligations
- Consent (Art. 6(1)(a)) — marketing emails, optional cookies
5. Sub-processors & recipients
We use carefully selected sub-processors. Each is bound by a Data Processing Agreement under Art. 28 GDPR.
| Provider | Purpose | Location |
|---|---|---|
| Hostinger International Ltd. | Website hosting | EU (Lithuania) / UK |
| Supabase Inc. | Database, auth, file storage (when client portal launches) | EU (Frankfurt) |
| PayPal (Europe) S.à r.l. | Payment processing | EU (Luxembourg) |
| Web3Forms / Formspree | Lead form processing | EU / USA (DPF) |
| Cal.com Inc. | Booking calendar | USA (DPF) |
| Google LLC (Chrome Web Store) | Marktpilot extension distribution | USA (DPF) |
| Anthropic PBC | AI advisor (only opted-in queries) | USA (DPF) |
6. Cookies & tracking
| Type | Purpose | Consent needed? |
|---|---|---|
| Strictly necessary | Login session, language preference, CSRF protection | No (Art. 6(1)(f)) |
| Analytics | Cloudflare Web Analytics or similar (anonymized) — page views, performance | Yes |
| Marketing | None at this time | — |
7. Retention periods
- Anonymized analytics: 14 months
- Account data while active: for the duration of your contract
- Account data after cancellation: deleted within 30 days, except invoices
- Invoices and accounting records: 6 years (UK) / 10 years (DE) per applicable tax law
- Marketing consent: until withdrawn
- Marktpilot extension data: aggregated only, no per-user retention beyond subscription period
8. Your rights under GDPR
- Access the data we hold about you (Art. 15)
- Correct inaccurate data (Art. 16)
- Delete your data ("right to be forgotten", Art. 17)
- Restrict processing (Art. 18)
- Port your data to another provider (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time (Art. 7(3))
- Lodge a complaint with a supervisory authority (Art. 77)
To exercise any right, email hello@sellereu.com. We respond within 30 days.
9. International data transfers
Bloom & Nourish LTD is established in the United Kingdom. The UK has been recognized as providing an adequate level of data protection by the European Commission under the UK Adequacy Decision (28 June 2021), so transfers between the EU and the UK are permitted without additional safeguards.
Where data is transferred outside the EU/EEA/UK to other sub-processors (e.g. Anthropic, Google, Cal.com), we rely on:
- EU-US Data Privacy Framework (DPF) certification, or
- EU Standard Contractual Clauses (SCCs)
10. Contact & complaints
For privacy questions: hello@sellereu.com
You have the right to lodge a complaint with a supervisory authority. EU customers may contact their national authority. Customers in Germany may contact their state's Data Protection Authority. UK customers may contact the Information Commissioner's Office (ICO):
Wycliffe House · Water Lane · Wilmslow, Cheshire SK9 5AF, United Kingdom
ico.org.uk · Helpline 0303 123 1113
Last updated: November 2026 · Material changes are notified by email to active customers.