WhowSellCRM
FeaturesHow it worksPricingFAQAboutContact
FeaturesHow it worksPricingFAQAboutContact
Sign inStart free
Privacy

Privacy Policy

Last updated: August 2026

This Privacy Policy explains how WhowSell LLC processes personal data within the crm.whowsell.com service. By ticking the approval box during registration or by continuing with Google, you are deemed to have read and accepted this policy.

Data Controller

The controller of the personal data described in this policy is WhowSell LLC, 1209 Mountain Road Pl NE #7495, Albuquerque, NM 87110, United States. You can reach us at support@whowsell.com for any question about this policy or about your personal data.

This policy applies to the crm.whowsell.com service and to the browser extension that works together with it. It covers both the account you create and the business data you enter into the panel.

A single WhowSell account is also valid across our other applications such as Radar, AI and Server. Your identity credentials are held on shared infrastructure so that one sign-in works everywhere, while the application data of each product is kept separate from the others.

Personal Data We Process

We process only the data required to operate the service. Identity and contact data: first name, last name, email address and phone number; if you choose to sign in with Google, your name and email address are received from your Google account. Billing and brand data: the billing name or company name you enter, contact email address, phone, address, country and city, together with the logo you upload if you hold an Enterprise plan and use your own domain. Application data: store records, order lines (order number, ASIN, date, quantity, revenue, cost, profit, status, marketplace), expense items, notes and file attachments.

Subscription and transaction data: your selected plan, subscription status, invoice records and payment method information. Your card number, expiry date and security code are not stored on WhowSell servers; card transactions take place on the PCI-DSS compliant infrastructure of Stripe, and only the last four digits and the card brand are passed to us. Your tax identification number is collected solely on the Stripe side. End buyer data: the buyer name and delivery address you enter into the panel, used for order automation.

Technical data: IP address, session and sign-in records, browser and device information, interface language and theme preference. Device identifier: during registration a hash is derived irreversibly from browser and device characteristics in order to prevent abuse and duplicate accounts, and is compared against a list of blocked devices; this value cannot be traced back to your identity and is never used for advertising or profiling. Support and communication data: support tickets, messages and attachments. Atlas AI data: the messages you write to the assistant, the images you upload and your conversation history.

Why We Process Your Data

We process your identity, contact and billing data to create your account, verify you at sign-in and deliver the core CRM features: store records, order tracking, expense entry and profit reporting. Technical data such as interface language and theme preference is used to keep the panel in the form you chose.

Subscription and transaction data is processed to activate your plan, collect payments through Stripe, issue invoices and keep the accounting records required of us. Support and communication data is processed to answer your requests and to send transactional emails such as address verification, password reset and notifications.

Technical data, sign-in records and the device identifier are processed to keep accounts secure, to detect unauthorised access and to prevent abuse and duplicate registration. Atlas AI data is processed solely to produce the answers you request from the assistant.

Legal Bases

Creating your account, running your subscription and delivering the service rest on the performance of a contract, under Article 5/2-c of the Turkish Personal Data Protection Law (KVKK) and Article 6(1)(b) of the GDPR. Retaining invoice, payment and accounting records rests on compliance with a legal obligation, under Article 5/2-ç of the KVKK and Article 6(1)(c) of the GDPR.

Security measures, sign-in and access logs, the device identifier used against abuse and duplicate accounts, and work to improve the service rest on our legitimate interests, under Article 5/2-f of the KVKK and Article 6(1)(f) of the GDPR. We keep these processing activities limited to what is necessary and balance them against your rights and freedoms.

Where a processing activity does not fall under any of the bases above, we ask for your explicit consent under Article 5/1 of the KVKK and Article 6(1)(a) of the GDPR. You may withdraw consent at any time, and withdrawal does not affect the lawfulness of processing carried out before it.

Parties We Share Data With

We work with a limited number of service providers to run the service. Our database, authentication and file storage provider operates from servers located in Frankfurt, Germany, inside the European Union. The application itself is hosted by our hosting provider in the Washington D.C. region of the United States. A separate provider delivers our transactional emails.

Stripe, Inc. handles card payments and subscriptions and collects tax identification numbers on its own side. The language model behind the Atlas AI assistant is supplied by an external model provider, which processes the messages sent to the assistant together with the related account data. Google is involved only in authentication, and only if you choose to sign in with Google.

Your data is never sold, rented or transferred to third parties for marketing purposes, under any circumstances. We use no analytics or advertising cookies and carry no third-party tracking pixels. Beyond the providers listed here, we disclose data only to competent public authorities where a lawful request requires it.

International Transfers

Because our database sits in the European Union and our application server sits in the United States, your data is transferred abroad as part of normal operation. The same applies to the payment, email and artificial intelligence providers listed above, which operate from their own regions.

These transfers are limited by contractual safeguards. Our providers act as data processors, may process data only on our instructions and for the purposes set out in this policy, and are bound by their own confidentiality and security commitments.

Atlas AI and Artificial Intelligence Processing

Atlas AI is the assistant built into the panel. The messages you write, the images you upload and your conversation history are transmitted to the model provider so that a response can be produced, and are stored in your account so that you can return to earlier conversations.

The model provider does not use data received through its API to train its general-purpose models. WhowSell likewise does not train any model with your data and does not use your content for any purpose other than answering you.

Because the assistant is a general-purpose tool, we recommend that you avoid sharing information with it that is not needed for the task at hand, such as credentials or personal data belonging to other people.

End Buyer Data and Our Respective Roles

The buyer name and delivery address that you enter into the panel, or that reach the panel through the browser extension, are personal data belonging to your own customers. For that data you act as the data controller and WhowSell acts as the data processor.

We process this data only on your instruction and only to deliver the features you use, such as order records and order automation. We do not use it for our own purposes, do not enrich it and do not share it with anyone outside the providers listed in this policy.

Establishing a lawful basis for collecting the data of your buyers, and informing them, remain your responsibility as the controller. When you delete a record, or when your account is deleted, the related buyer data is removed with it.

Browser Extension

The WhowSell browser extension reads order information on your Amazon seller pages and transfers it to your CRM panel. It runs only on Amazon domains, does not access any other website and never reads your Amazon password or login credentials.

The extension keeps your session token and preferences such as language selection in the local storage of your browser; it sets no cookies and contains no tracking script or advertising pixel. The session is verified on every request and refreshed periodically for security.

The data brought over by the extension is written into the same account as the rest of your panel data, and is subject to the same retention, security and deletion rules described in this policy.

Retention Periods

We retain your account and application data for as long as your account remains active. Invoice and payment records are retained for the minimum period required by tax legislation, even after the account is closed.

Message attachments are deleted automatically fourteen days after they are uploaded. When a subscription ends, your data is retained for at least thirty days so that you can export it.

Sign-in records and the IP address they carry are kept for twelve months and then deleted; they exist so that unauthorised access can be detected and abuse prevented. If you turn on two-step verification and choose to trust a device, that record (a coarse browser and device summary, the address the trust was granted from and the country) is kept for the 30 days it is valid and for a further 30 days after it is removed, as an audit trail; you can view and remove your trusted devices at any time under Settings, Security. Where the same device is seen on more than one account, a finding is opened for review by our administrators; findings are kept for twelve months. Neither the browser and device summary nor the IP address is used for advertising or profiling.

Data whose retention period has expired is deleted, destroyed or anonymised. Anonymised records can no longer be linked to you and may be kept for statistical purposes only.

Data Security

Messaging content is treated separately and more strictly. The messages, files and images users exchange one-to-one or in groups are encrypted in transit and at rest and are shown only to the parties to that conversation. WhowSell does not read, monitor, scan or moderate this content, and it cannot be displayed on any administration screen: the restriction is enforced by database-level access policies rather than by hiding elements in the interface. Administrators authorised for group moderation can see only the existence of a group, its member count, its member list and membership changes — never message text, files or file names. Files sent in messages remain accessible for thirty (30) days from the moment they are sent; after that the file can no longer be opened, whatever its type. We disclose messaging content only where a competent authority makes a duly issued and binding request under applicable law, limited to the scope of that request.

All traffic between your browser and our servers is encrypted with TLS. On the database side we use row level security, so that each record is readable only by the account that owns it and by the friends to whom the owner has granted viewer or editor access to the relevant store; that access ends the moment the owner withdraws it.

Access and sign-in activity is logged, and the API keys of our providers are held only on the server side and never exposed to the browser. HSTS and content security policy headers are enforced at the application layer.

No system can be guaranteed to be completely secure. If a breach occurs that is likely to create a risk to your rights, we will notify you and the competent authorities within the periods required by law.

Your Rights, Account Deletion and Contact

You have the right to access your personal data, to have it corrected or erased, to have processing restricted, to receive your data in a portable format, to object to processing and to withdraw a consent you previously gave. Most of these can be exercised directly from the panel; for the rest, writing to us is enough. One exception is stated openly: when you remove a saved card, it stops appearing in the panel, but if an open (unpaid) invoice exists at that moment, the payment token of the card is kept solely to collect that invoice and solely until it is closed. The token is retained for at most ninety (90) days and is then deleted entirely at the payment service provider; where no open invoice exists, a removed card is never charged again.

To delete your account, send a request from your registered email address to support@whowsell.com. Deletion requests are taken into process within thirty days, apart from records we are legally required to keep, such as invoices.

For any question about this policy you can reach WhowSell LLC at support@whowsell.com or at 1209 Mountain Road Pl NE #7495, Albuquerque, NM 87110, United States. You also have the right to lodge a complaint with the data protection authority in your country.

WhowSellCRM

Every store you run, in one panel.

Store and profit management for marketplace sellers.

WhowSell LLC

Product

FeaturesHow it worksPricingFAQ

Company

WhowSell CloudAboutContact

Legal

Terms of ServicePrivacy PolicyCookie PolicyRefund PolicyData Protection
© 2026 WhowSell. All rights reserved.support@whowsell.com