Back to home

Data Processing Agreement

Last updated : 31 August 2026

1. Purpose and roles

This agreement supplements the terms of use and the privacy policy. It governs Revendor’s processing of personal data concerning third parties — buyers, sellers and people who have contacted the Customer — to which the service gives access.

The Customer is the data controller. Revendor is the processor, within the meaning of article 28 GDPR. Revendor processes this data only on the Customer’s documented instructions and solely for the purposes described below, never for its own purposes.

For data concerning the Customer themselves — identity, connection, billing, service usage — Revendor remains the data controller: that data falls under the privacy policy, not under this agreement.

2. Description of the processing

  • Nature: collection from the selling marketplaces and from the Customer’s notification emails, storage, structuring, display in the dashboard, transmission to the recipients listed in article 6.
  • Purposes: managing the Customer’s sales and purchases, producing their invoices, tracking their shipments, running their messaging and support.
  • Duration: processing lasts as long as the Customer’s account exists. It ends when the account is closed.

3. Categories of data and data subjects

Data subjects: buyers, sellers and people who have contacted the Customer on the marketplaces where they operate.

Categories of data:

  • Marketplace identifiers: username, technical identifier, profile picture, country
  • Content of the relationship: messages exchanged, attachments, offers sent or received, reviews
  • Transaction data: item, price, date, status, carrier, tracking code
  • Shipping and invoicing data, where necessary: name, postal address, email address, collection point address

No third-party banking data is processed: payments are handled by the marketplaces, outside the service.

4. The Customer’s instructions

Revendor processes the data only on the Customer’s documented instructions. These terms, the configuration chosen by the Customer within the service, and the actions they trigger there constitute those instructions.

If Revendor considers that an instruction infringes the GDPR, it will inform the Customer without delay and may suspend its execution.

It is the Customer’s responsibility to have a legal basis for this processing and to inform the data subjects, in accordance with articles 13 and 14 GDPR.

5. Confidentiality and security

Revendor warrants that persons authorised to process the data are bound by a duty of confidentiality.

Revendor implements the following technical and organisational measures, within the meaning of article 32 GDPR:

  • Encryption of data in transit (TLS) and at rest with the database host
  • Segregation of data per account, enforced at the database level itself
  • Authenticated access, restricted to what is strictly necessary
  • Logging of administrative access
  • Regular backups provided by the database host
  • Automatic purging of raw marketplace data once processed

6. Sub-processors

The Customer authorises Revendor to use the following sub-processors, each bound by obligations equivalent to those of this agreement:

  • Supabase — database hosting (European Union)
  • Vercel — application hosting
  • Cloudflare — image storage and delivery
  • Resend — email delivery
  • Upstash — technical caching and rate limiting
  • Stripe — processing the Customer’s payments
  • PostHog — audience measurement, in the European Union, with the data subject’s consent only
  • DeepSeek — AI-assisted generation, only if the Customer enables these features
  • Google — reading notification emails, only if the Customer connects their inbox
  • Discord — notification delivery, only if the Customer enables it

Revendor will inform the Customer of any addition or replacement of a sub-processor at least 30 days in advance. The Customer may object on legitimate grounds; failing agreement, they may cancel their subscription at no cost.

7. Transfers outside the European Union

Processing takes place within the European Union, with two exceptions, both optional and disableable by the Customer: the AI features, operated by DeepSeek, and the inbox connection, operated by Google.

These transfers are governed by the European Commission’s standard contractual clauses. A Customer who wants no transfer outside the European Union can simply leave these two features disabled: the rest of the service works without them.

8. Assistance to the Customer

Revendor assists the Customer, as far as possible and taking into account the nature of the processing:

  • In responding to requests from data subjects exercising their rights — access, rectification, erasure, portability, objection, restriction
  • In ensuring the security of the processing and, where applicable, carrying out a data protection impact assessment
  • By notifying the Customer of any personal data breach affecting them, without undue delay and no later than 48 hours after becoming aware of it, with the information needed for their own notification to the supervisory authority

Any request under this article should be sent to [email protected].

9. Fate of the data at the end of the contract

When the Customer’s account is closed, Revendor deletes the data concerned, along with existing copies, unless a legal retention obligation applies. Erasure takes place at the end of a 30-day cancellation window, which the Customer may waive for immediate deletion.

Before closing, the Customer can retrieve all of that data from their account settings, in JSON format, without any intervention on our part.

10. Audit

Revendor makes available to the Customer the information needed to demonstrate compliance with the obligations of this agreement.

The Customer may request an audit once per twelve-month period, subject to reasonable notice, at the Customer’s expense and without disrupting the service or compromising the confidentiality of other customers’ data.

11. Duration and contact

This agreement applies for as long as the Customer holds a Revendor account, and survives its closure as regards the confidentiality and deletion obligations.

For any question about this agreement: [email protected]