Privacy Policy
How we collect, use, and protect your personal information.
Last updated: 6 July 2026
1. Introduction
At reseller.best ("we," "our," or "us"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our website and services. This policy applies to all information collected on our website reseller.best and any related services, sales, marketing, or events. Under GDPR, you have extensive rights over your personal data, which are detailed in this policy.
Data controller information
Data Controller: reseller.best. Address: Keurenplein 41 Box C6494, 1069CD Amsterdam, Netherlands. KVK number: 98080490. VAT ID: NL005308257B06. Privacy Contact: [email protected]. Support Contact: [email protected]. We are not required to appoint a Data Protection Officer under GDPR Article 37. This Privacy Policy complies with the EU General Data Protection Regulation (GDPR).
2. Information we collect
Personal Information: We collect information you provide directly to us, including your email address (required for order confirmation and product delivery), payment information (processed securely through Stripe and not stored on our servers), and order history (records of your purchases for support purposes). Technical Information: We automatically collect certain information when you visit our website, including your IP address (for security and fraud prevention), browser information (type, version, and settings), device information (operating system and screen resolution), and usage data (pages visited and time spent on site).
3. Legal basis for processing (GDPR)
Under GDPR Article 6, we process your personal data based on the following legal bases. Contract Performance (Art. 6(1)(b)): Processing necessary to fulfill our contract with you, including order processing, product delivery, and customer support. Legal Obligation (Art. 6(1)(c)): Processing required for tax records, invoicing, and regulatory compliance. Legitimate Interest (Art. 6(1)(f)): Fraud prevention, security monitoring, and service improvement, balanced against your privacy rights.
4. How we use your information
We use the information we collect for the following purposes: order processing (to process payments and deliver digital products), customer support (to respond to inquiries and provide assistance), fraud prevention (to detect and prevent fraudulent transactions), legal compliance (to comply with applicable laws and regulations), and service improvement (to analyze usage and improve our website).
5. Information sharing and disclosure
We do not sell, trade, or rent your personal information to third parties. We share your information only with the following data processors, strictly for the purposes described: Stripe, Inc. (United States) - payment processing; receives your email address, payment card details, IP address, and order data. Transfer safeguard: EU-US Data Privacy Framework. Resend, Inc. (United States) - transactional email delivery; receives your email address and email content (license keys, verification codes, support replies). Transfer safeguard: Standard Contractual Clauses (SCCs). Cloudflare, Inc. (United States) - CDN, DNS, and CAPTCHA (Turnstile) services; processes HTTP traffic data including IP addresses, browser information, and interaction data for bot detection. Transfer safeguard: EU-US Data Privacy Framework. Discord, Inc. (United States) - optional sale notification webhooks for sellers; receives only product names, sale amounts, and stock counts. No personal customer data is transmitted. We may also share information when required by law or to protect our rights, and in case of merger, acquisition, or asset sale.
6. Data security
We implement appropriate security measures to protect your personal information. All data transmission is encrypted using SSL/TLS. Payments are processed through PCI-compliant Stripe. Access to personal data is limited on a need-to-know basis. Security patches and updates are applied promptly. Note: No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Data retention
We retain your personal information only for as long as necessary for the purposes for which it was collected. Order records (including the email address, billing country, consent records, and the IP address and browser data captured as part of an order for fraud prevention and dispute evidence) are retained for 7 years to comply with Dutch tax and accounting obligations. Standalone technical and security logs that are not part of an order record - such as login-attempt logs, license-access logs, and referral-click logs, which may contain IP address and browser information - are retained for up to 180 days and then automatically deleted; this window covers the payment-card chargeback and dispute period. One-time verification codes are deleted once used or expired. When a retention period ends, the data is permanently deleted from our systems.
8. Your GDPR rights
Under GDPR, you have the following rights regarding your personal data. Right of Access (Art. 15): Request copies of your personal data and information about processing. Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data. Right to Erasure (Art. 17): Request deletion of your data, subject to legal obligations. Right to Restrict Processing (Art. 18): Request limitation of processing under certain circumstances. Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format. Right to Object (Art. 21): Object to processing based on legitimate interests. Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. To exercise your rights, contact us at [email protected] with "GDPR Request" in the subject line. We will respond within 1 month. Identity verification may be required. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
9. Cookies and tracking technologies
We use only strictly necessary and functional cookies required for our website to operate. We do not use Google Analytics, Facebook Pixel, advertising cookies, or any tracking technologies. The cookies we use are: Session cookie (next-auth.session-token) - used for admin authentication; strictly necessary; expires when the browser session ends. Seller session cookie (seller-session) - used for seller portal authentication; strictly necessary; expires when the browser session ends. Referral cookie - stores referral attribution when you arrive via a referral link; functional; used to attribute referral commissions to the correct partner. Cloudflare cookies - set by Cloudflare for CDN and bot protection purposes; strictly necessary for security. Because all cookies used on our website are strictly necessary or functional, no prior consent is required under the Dutch Telecommunicatiewet (Art. 11.7a). We do not place any tracking, advertising, or analytics cookies.
10. International data transfers
Your information is processed by third-party service providers located in the United States. We ensure these transfers are lawful under GDPR Chapter V through the following safeguards: Stripe and Cloudflare participate in the EU-US Data Privacy Framework, as recognized by the European Commission's adequacy decision. Resend operates under Standard Contractual Clauses (SCCs) approved by the European Commission. Your personal data is stored in our self-hosted database on servers located in the European Economic Area.
11. Children's privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a child under 18, please contact us immediately and we will promptly delete such information.
12. Policy updates
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. For significant changes, we will provide additional notice via email or prominent website notification.
13. Contact us
If you have any questions about this Privacy Policy or our data practices, please contact us. Business & Privacy: [email protected]. General Support: [email protected]. Response time: within 24 hours. For GDPR-related requests, please specify "GDPR Request" in your email subject line and contact [email protected].