Skip to content

Legal

Privacy Policy

How Sellit collects, uses, and protects your personal data — and the rights you have over it.

Last updated: 26 September 2026

Who we are

Sellit (sellit.ge) is operated by SHPS SAINAPS STUDIO (tax ID 406555829), registered in Tbilisi, Georgia. For data about your Sellit account and your use of the platform, SHPS SAINAPS STUDIO is the data controller. You can reach us at contact@sellit.ge.

Each shop on Sellit is run by an independent seller. When you buy from a shop, that seller is a separate controller of your order data and is responsible for fulfilling and supporting your order under their own policies and Georgian law.

What we collect

Account details you give us (name, email, phone, password — stored hashed); delivery and contact addresses; orders and their status; messages you send to support; and, with your consent, anonymous usage analytics. We do not collect card numbers — see Payments below.

Why we use it (legal bases)

To run your account and process orders — performance of a contract with you.

Analytics and any marketing — your consent, which you can withdraw at any time.

Accounting, tax, and responding to lawful requests — compliance with a legal obligation.

Keeping the platform secure and preventing fraud and abuse — our legitimate interests.

Payments and sellers

Card payments are processed directly by the seller's payment provider (such as Bank of Georgia or TBC). Your full card details go to the bank, not to Sellit — we never see or store them. We receive only the payment result (paid / failed) and the order reference.

To complete an order, we share the data the seller needs to fulfill it (your order, delivery details, and contact) with that seller and, where used, the delivery provider (such as QuickShipper). Sellers' own credentials are stored encrypted and are never exposed in the interface.

Who we share data with

Only as needed: the seller you order from; payment providers (BOG/TBC); delivery providers; Microsoft Azure (API, database, and secure infrastructure hosting); Vercel (website hosting and request routing); and Amazon Web Services (the AI assistant, through Amazon Bedrock in the EU). These providers process data on our behalf. We do not sell your personal data.

Storage and security

Authentication is handled with secure, server-side cookies. Sensitive credentials are encrypted and the master key is held in a dedicated key-management service, never in the app. We keep personal data for as long as your account is active and as required by accounting and tax law, then delete or anonymise it.

Product analytics and session recordings

For the seller dashboard and sign-up flow, we use PostHog (PostHog Inc., US Cloud) to understand where sellers get stuck and to spot crashes quickly. PostHog acts as our data processor under a data processing agreement; the data it holds is pseudonymous (an account ID, never your phone, email or name) and all form inputs are masked before any session recording leaves your browser.

Analytics and session recordings are switched ON by default; you can turn either off at any time in cookie preferences (the banner, or “Cookie policy” in the footer), and we respect that choice immediately. Analytics events are anonymous usage events tied to your account id — never your phone number, email, or name. Session recordings help us see where the interface is confusing; anything you type is always masked before it leaves your browser, and recordings never run on sign-in, password, or payment-detail pages.

Two things are collected regardless of your cookie choice, on the basis of our legitimate interest in keeping the platform working and secure: a first-party error report when something crashes (the page, a generic message, never your data) and which channel first brought you to Sellit (e.g. a search engine or a social network, derived from the page you arrived from — never a cookie placed on your device).

We keep usage events for up to 12 months and session recordings for up to 30 days, then they are deleted.

Facebook and Instagram (Meta) data

If you are a seller and connect your Facebook Page or Instagram Business account, Sellit accesses that data solely to operate your own shop and your own message inbox — on your behalf and in line with the Meta Platform Terms and Developer Policies. We never use it to build advertising profiles, and we never share it with other sellers.

For a connected account we store: your Facebook Page ID and Instagram Business Account ID; the Page access token that lets us receive and send your messages (stored AES-256 envelope-encrypted, with the master key held in AWS KMS and never in the app or in logs); and, delivered to us by Meta webhooks, the content of the messages your customers send you together with the sender's basic information (their Meta-scoped ID and name). This is used only to show and answer those conversations inside your Sellit inbox.

Disconnecting (dashboard → Settings → Integrations → Disconnect) removes the encrypted Meta connection and access tokens, deletes the imported Meta business profile, and stops further imports and webhook data. Existing Messenger/Instagram conversation history and products already added to the shop remain as the seller's business records, so related orders keep their context. To delete Meta-derived conversation history or request full account deletion, follow the instructions on our Data Deletion page.

Sellit Ecommerce mobile app

The Sellit Ecommerce app for iPhone and Android is a companion for existing Sellit sellers. It uses the same account and data as the seller dashboard: your name, phone and email to sign you in, and your shop's orders, products and customer details so you can manage them. Your sign-in is kept in the device's secure storage.

The app uses the camera and your photos only when you tap to add a product photo or your shop logo, and it uploads only the image you choose. It shows no ads, does not track you across other apps or websites, and does not use the advertising identifier.

You can sign in to the app with Apple or Google if that account connects to your Sellit account, or shares its email address. From Apple or Google we receive only an account identifier, your email address, and, the first time with Apple, your name if you choose to share it. With Apple, the email can be a private relay address from “Hide My Email”; emails sent to it go through Apple's private relay service. We never receive your Apple or Google password. To let you end the connection, we keep an encrypted Apple sign-in token, protected like our other secrets; we revoke it at Apple when you request account deletion, and you can also disconnect Sellit in your Apple ID or Google account settings.

You can request deletion of your account inside the app (Profile → Delete account) or by following our Data Deletion page.

AI assistant

Sellit's AI assistant runs on Claude, an AI model by Anthropic, which we use through Amazon Web Services (Amazon Bedrock) in the EU. Amazon Web Services processes this data on our behalf.

When you use the assistant we send it your messages, any photos or files you attach, and the shop data it looks up to answer you, such as products and orders. This data is used only to answer you and is not used to train AI models. We keep your conversations with your account so you can open them again.

In the mobile app nothing is sent to the AI provider until you agree on the consent screen. You can withdraw that consent at any time: open the assistant's sidebar → AI data sharing → Stop sharing with AI.

Your rights

Under the Law of Georgia on Personal Data Protection you can ask us to: access your data; correct it; delete it; restrict or object to processing; receive a copy in a portable format; and withdraw consent at any time. To exercise these, email contact@sellit.ge — we respond within the timeframe the law requires.

If you believe we've mishandled your data, you may lodge a complaint with the Personal Data Protection Service of Georgia (personaldata.ge).

Your choices

Update your profile, saved addresses, and security settings from your account page. Manage cookies any time via “Cookie settings” in the footer.

Changes

We may update this policy as the platform or the law changes. We'll revise the “last updated” date above and, for significant changes, tell you in the app.

We use cookies to keep you signed in, remember your cart, and — unless you turn it off — measure how the site is used. Cookie policy