Privacy Policy
Last updated: July 21, 2026
Sellcast ("Sellcast", "we", "us") provides inventory planning and demand forecasting software for online sellers. This policy explains what data we process when you use Sellcast and connect your sales channels, how we use it, and how we protect it. It applies to app.sellcast.ai and the Sellcast service.
Data we collect
Account data. When you create an account we store your name, email address, and a securely hashed password. We record basic activity for security and support.
Connected-channel data. When you connect a sales channel (such as Amazon or Shopify) via that channel's official authorization flow, Sellcast reads the data needed to plan inventory: your product catalog and variants, inventory levels and locations, and order records at an aggregate level (quantities, order totals, and dates).
What we deliberately do NOT collect. Sellcast does not request or store buyer personal information such as customer names, email addresses, shipping addresses, or phone numbers. Our forecasting uses order quantities and values, not who the buyer is.
Access credentials. To keep your channels in sync we store the access and refresh tokens issued by each channel. These are encrypted at rest (see Security below) and are never shown to you or any third party.
How we use data
We use your data solely to provide the Sellcast service: to build demand forecasts, generate reorder and transfer recommendations, detect overstock and dead stock, and show you inventory coverage across your channels. We do not sell your data, and we do not use it for advertising.
How we protect data
- Channel access and refresh tokens are encrypted at rest using AES-256-GCM, with a key held only in the server environment.
- Account passwords are hashed with bcrypt and never stored in plaintext.
- All traffic is served over HTTPS/TLS.
- Data is isolated per account: every query is scoped to your organization, so one customer cannot access another's data.
- Sessions use signed, httpOnly, secure cookies and can be revoked.
- Our infrastructure runs on managed cloud services with private networking between application, database, and internal services.
Sharing and sub-processors
We do not sell or rent your data. We share it only with the service providers that operate Sellcast on our behalf, each under its own security and privacy commitments:
- Railway — cloud hosting and managed database and cache (United States), where the application and your data run.
- Resend — email delivery, used only when you enable email notifications; it receives recipient addresses and message content.
- Google (Gemini API) — powers Sellcast's optional in-app AI assistant. When you use the assistant, the records relevant to your question are sent to generate a response. This never includes buyer personal information (we store none), and the assistant is off unless you use it.
Where we process your data
Sellcast processes and stores data in the United States. If you access Sellcast from outside the United States, your data is transferred to and processed in the United States.
Payments
Sellcast does not collect or store your payment card details. When you subscribe to a paid plan, your payment is handled by our payment processor, which processes your card information directly under its own security standards.
Retention and deletion
We retain your data for as long as your account is active. When you disconnect a channel, we revoke and delete the stored credentials for that channel. When you close your account or request deletion, we delete your account data and connected-channel data. You can request export or deletion at any time using the contact below.
Your rights
You may request access to, correction of, or deletion of your data, and you may withdraw a channel connection at any time from Settings. Contact us to exercise these rights.
Contact
Questions about this policy or your data: support@sellcast.ai.