Privacy Policy
Last updated: 4 September 2026
Who we are.
SafeSell is a self-service tool that helps you organise your product-safety information and generate GPSR document templates. It is provided by:
- SafeSell is a trading name of S Dunsmore, sole trader.
- Suite 732, 80A Ruskin Ave, Welling, DA16 3QQ, United Kingdom
- hello@safesell.co.uk
This policy explains what personal and business information we handle, why, and the rights you have. Where this policy says "we", "us" or "our", it means SafeSell.
Who we serve (UK only).
SafeSell is currently available to UK-established businesses and sole traders only. We do not offer accounts (free or paid) to customers whose business is established in the EU or EEA at launch. If you are not UK-established you should not create an account or provide us with personal data.
SafeSell has not appointed a representative under Article 27 of the EU GDPR. At launch, the service is offered only to UK-established businesses and sole traders and is not directed at customers established in the EU or EEA. We will review this position if the service's territorial scope or data-processing activities change.
A quick summary.
SafeSell is built to keep your data close to you. Your business and product information stays in your own browser. The only personal things we hold on our server are a small subscription record for paying customers and anonymous, cookieless analytics counts. We do not sell your data, and we do not use it for marketing unless you ask us to.
What data we process.
(a) Your business and product information (stored only in your browser). When you use SafeSell, the business profile and product details you enter (for example, your business name and address, product category, hazards, safety warnings, target markets, risk-assessment notes and the documents we generate for you) are stored in your own browser's local storage on your device. This information:
- is used on your device to build your saved products and generate documents;
- is not sent to our servers; and
- is not uploaded to us, even on the paid plans.
Because it lives in your browser, it can be lost if you clear your browser data, use a private/incognito window, or switch to another device. Please keep your own copies of anything important.
(b) Subscription record (stored on our server, paying customers only). When you subscribe to a paid plan, we store a small record on our server containing:
- the email address you provide at checkout;
- your Stripe customer ID;
- your plan (Starter or Pro);
- your billing cadence (monthly or annual); and
- your subscription status.
This record is what lets us recognise you as a paying customer, enforce your plan's limits, and manage renewals/cancellations. The free tier does not require you to provide contact or payment details. Your business and product information stays in your browser, although limited analytics events are sent to our server as described below.
How and why we use your data (lawful bases).
- To provide the service and manage your subscription and billing — this is necessary for the performance of our contract with you (for example, enforcing your plan's product limit and processing renewals).
- For security and fraud prevention — this is in our legitimate interests as a business (for example, preventing abuse or misuse of the service).
- For marketing (only with your consent) — we will only send you marketing if you have opted in, and you can withdraw your consent at any time. If you do not opt in, we will not contact you for marketing.
- To meet our legal obligations — for example, keeping the financial records the law requires us to keep.
Stripe (payment processing).
Payments are processed by our payment service provider Stripe, a third-party payment provider. When you pay:
- payments are handled through Stripe-hosted checkout using Onelink Managed Payments; Stripe and Onelink process payment information under their respective terms and privacy policies;
- your card details and other payment information are handled by Stripe on its own systems and never pass through or are stored by us — we do not see or hold your card number;
- we only receive confirmation from Stripe that the payment succeeded (which is how we know your subscription is active).
Payments are handled through Stripe-hosted checkout using Onelink Managed Payments. Stripe and Onelink process payment information under their respective terms and privacy policies. SafeSell does not receive or store your full card details. Where card or other payment-related data may be transferred outside the UK or EEA, they rely on appropriate safeguards, including Standard Contractual Clauses where applicable.
Where we store data.
Your subscription record is stored on our hosting provider's servers. When payment data is involved, Stripe may transfer data to the United States or other countries outside the UK and EEA; Stripe uses appropriate safeguards (such as Standard Contractual Clauses) for these transfers. We have taken reasonable steps to ensure that any providers we use protect your data to an adequate standard.
How long we keep data.
We keep your subscription record for as long as your subscription is active. After you cancel, we stop using it for billing and keep it only as long as needed to meet legal or accounting obligations (for example, tax records) or to resolve disputes, after which it is deleted. If you cancel within the cooling-off period and receive a refund, we delete your subscription record unless we are required by law to keep a record of the transaction.
Your rights.
You have the right to:
- access a copy of the personal data we hold about you;
- rectify inaccurate data;
- erase your data ("the right to be forgotten");
- restrict how we process your data in certain circumstances;
- data portability — receive your data in a structured, machine-readable form, where it applies;
- object to processing based on our legitimate interests; and
- withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email hello@safesell.co.uk. We will respond within one month. You may also opt out of any marketing at any time.
If you are not happy with how we handle your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, which is the UK regulator for a service of this kind.
Children.
SafeSell is not aimed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact hello@safesell.co.uk and we will delete it.
Cookies and analytics.
The SafeSell website sets no cookies and runs no advertising or third-party tracking. We use privacy-friendly, cookieless, first-party analytics: when you browse, your browser sends an anonymous event message to our own server (for example "homepage visited" or "checkout started"). To connect the steps of a visit into a funnel, your browser creates a randomly generated session identifier and keeps it in local storage — it is not a cookie. Analytics events do not include the business or product information you enter, your name, email address or payment details. They use a randomly generated session identifier stored in local storage and are used only to produce aggregate usage statistics. These records do not include your name, email address, business or product information, or payment details — we only use these events as aggregate counts (for example, how many people visit, start the free plan, or reach checkout). Access to the analytics dashboard is restricted to the SafeSell operator and authorised administrators. Analytics records are retained only for as long as reasonably necessary to understand product usage and improve the service, and are periodically reviewed and deleted when no longer needed. You can clear the anonymous session id and your app data at any time via your browser's local storage settings. If we ever add cookies or different analytics, we will update this policy and ask for your consent where required by law (such as the UK Privacy and Electronic Communications Regulations and the EU ePrivacy rules).
Changes to this policy.
We may update this policy from time to time. The "last updated" date at the top shows when it was last changed, and we will draw material changes to your attention. Continued use of the service after a change means you accept the updated policy.