What data we process, how long we keep it, how we delete it and how we respond when you connect your store or marketplace.
Annex to the SendingBay Data Privacy and Security Policy · Last updated: 23 September 2026 · Version 3.0
This annex applies to the services through which a merchant connects its online store or its marketplace account to SendingBay to manage its shipments. It covers all connected platforms equally, both those we integrate today and those we add in the future; the list of integrations available at any given time is published on the product website. Anything not covered in this annex is governed by the general policy.
SendingBay accesses each platform's data as an authorised developer, within the permissions granted by the customer and the rules of the platform's developer programme. We comply with the requirements of each of those programmes, including their restrictions on the use of the data the platform makes available to connected applications, also where those restrictions extend to aggregated or anonymised data. Each platform is responsible, within its own scope, for the data of its sellers and buyers that it processes itself; the merchant is responsible for the buyer data it entrusts to us to carry out the shipment.
We request from each platform only the permissions the service needs.
The aggregated and anonymised information referred to in section 4 of the general policy is derived, in this service line, only to the extent permitted by each platform's developer programme, and never from buyer data.
Buyer data is not kept beyond the shipment creation operation. Shipment references are kept while the connection to the platform is active and are deleted within a maximum of 30 days from disconnection, or earlier if the customer or the platform so requests. Access credentials are deleted on disconnection. On the written request of a customer or a platform, we confirm deletion in writing.
The relationship with a platform ends when the seller revokes authorisation, uninstalls the application or removes the integration from the SendingBay panel. We revoke and delete access credentials without delay, stop reading and updating orders, and delete shipment references within the period in section 3. We also honour each platform's own mechanisms: uninstall or revocation notices, data and deletion requests that the platform passes on to connected applications, and deletion requests from the platform itself.
If the customer cancels its account or terminates the contract, the account remains recoverable for 30 days; once that period has elapsed, the access credentials for all its platforms and the shipment references are deleted. At the customer's request, deletion is immediate.
In addition to the general channel (privacidad@sendingbay.com), we handle access, rectification and erasure requests received through each platform's own mechanism, within the timelines set by its developer programme. Where the request concerns buyer data, for which the merchant is the controller, we forward it and help the merchant respond.
The third parties involved are the sales platform to which the merchant connects its account and the carrier network it chooses for each shipment. Each is independently responsible for the data it receives to perform its function.
In the event of an incident affecting a platform's data or credentials, we notify the platform through the security channel it designates, and the affected merchants, within 24 hours of detection and, in any case, within the timelines set by its developer programme.
SENDINGBAY S.L.