sellerstation

Information Security and Data Privacy Policy

Seller Station, a product of Hype Media · contato@sellerstation.com.br · Version 1.0 · Effective 26 September 2026 · Owner: Founder / Technical Lead · Reviewed at least annually

1. Purpose and scope

This policy defines how Seller Station protects the information it processes on behalf of marketplace sellers who use the Seller Station dashboard (https://sellerstation.com.br). It applies to all systems, personnel and contractors involved in building and operating the service, and to all data obtained through marketplace APIs (Amazon, Mercado Livre, Shopee, TikTok Shop and others), whether in production, backups or development environments.

2. Data we process and data we do not collect

3. Data isolation (multi-tenancy)

Every dashboard user belongs to exactly one organization. Marketplace accounts, tokens, orders and inventory are stored with the organization identifier and every query is scoped to the organization of the authenticated session. No organization can read, list or infer data from another organization. Platform administrators may access a customer organization only through an audited "act as" session, shown to the administrator with a persistent banner, and only for support purposes.

4. Encryption

5. Access control

6. Network and infrastructure security

7. Logging, monitoring and auditing

Application logs record authentication events, API synchronization runs, marketplace webhook deliveries and errors, without tokens or passwords. Process supervision (pm2) restarts the service on failure and keeps logs for review. Administrator "act as" sessions are explicitly flagged in the session token.

8. Backups and business continuity

A consistent snapshot of the database is taken automatically every day, compressed, stored with owner-only permissions and retained for 30 days. Restoration is tested when the backup procedure changes. The service can be redeployed from source and configuration within hours on a new host.

9. Vulnerability and change management

10. Incident response

A security incident is any confirmed or suspected unauthorized access, disclosure, alteration or loss of customer data. On detection we (1) contain the incident (revoke tokens, rotate keys, isolate the host), (2) assess scope and affected organizations, (3) notify affected customers and the relevant marketplace partner program without undue delay and within 72 hours of confirmation, (4) remediate root cause and (5) document the incident and lessons learned.

11. Data retention and deletion

12. Third parties and data location

ProviderRoleLocation
Hostinger International Ltd.Virtual private server, DNSData center in Brazil (São Paulo region)
Let's EncryptTLS certificatesUnited States
Marketplace APIs (Amazon, Mercado Livre, Shopee, TikTok Shop)Data sources authorized by the sellerProvider regions

Customer data is not sold, shared with advertisers or used for any purpose other than delivering the dashboard to the organization that owns it. Marketplace data is never used to redirect transactions outside the marketplace.

13. People

Everyone with production access is bound by confidentiality obligations, receives this policy on onboarding and reviews it annually. Access is removed on the same day a person leaves the project.

14. Compliance

Seller Station follows the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and the partner program rules of each marketplace it integrates with, including their data protection policies. Contact: contato@sellerstation.com.br.