Privacy policy
Last updated 22 September 2026
What we collect, why we collect it, who else touches it and what you can make us do about it. If anything here is unclear, ask - a privacy policy nobody can follow is not doing its job.
Who we are
usellit is point of sale software operated by usellit Inc., registered at 2525 SW 109th Ave, Miami, FL 33165, United States. For personal data belonging to your staff and customers that we process on your behalf, you are the controller and we are the processor - see the data processing addendum.
What this website collects
Almost nothing, and that is a design decision rather than an accident. usellit.ai is static HTML and CSS. It runs no JavaScript at all, sets no cookies, and carries no analytics, advertising or tracking pixels. There is no consent banner because there is nothing to consent to.
Our host records standard server logs - IP address, user agent, the URL requested and a timestamp - which exist to keep the service running and to investigate abuse. They are not used to build a profile of you.
What the application collects
Signing in to app.usellit.ai is different. There we hold:
| Category | Examples | Why |
|---|---|---|
| Account | Name, work email, hashed password, role, company | To sign you in and decide what you may do |
| ERP connection | NetSuite account identifier, OAuth tokens | To sync on your behalf. Encrypted, see Security |
| Business records | Items, customers, transactions synced from your ERP | To run the point of sale. This is your data, not ours |
| Audit | Who changed what, and when | Accountability. You asked for it, and so will your auditor |
| POS terminals | Terminal name, which device holds it, clerk sign-ins, agreements to the app's terms | To run the counter and attribute every action to a named person |
| Operational | Error reports, request logs | To find and fix faults |
We do not receive cardholder data. Card payments are captured by the payment terminal and handled by the payment provider; card numbers never reach our servers, so we cannot lose or misuse them.
What the POS app keeps on the device
The usellit.pos app keeps a copy of your company's catalog on the device, so the counter stays fast and keeps working through short interruptions, along with the terminal's pairing credential (held in the device's secure storage), who is signed in, and any sale in progress. Unpairing the terminal from the console cuts the device off from the account.
Where a device has no hardware scanner, the camera is used only to read barcodes: frames are processed on the device, and no photograph or video is stored or transmitted. Clerk PINs are stored as hashes and cannot be read back - not by staff, and not by us.
Why we may process it
- To perform our contract with you - running the service you signed up for.
- Legitimate interests - keeping the service secure, preventing abuse, and fixing faults, balanced against your rights.
- Legal obligation - where we are required to retain or disclose records.
- Consent - only where we ask for it plainly, and you may withdraw it.
Who else can see it
Only the providers we need to run the service, listed with what each one does on the sub-processors page. We do not sell personal data, and we do not share it for advertising. We have never done either and the product has no mechanism to.
We may disclose data if legally compelled. Where we are permitted to tell you first, we will.
AI, and what leaves our systems
AI is an add-on called Spark, and the built-in help is free on every plan. Using either sends the part of your data that the question needs to our model provider so it can answer, and that is the only time your data goes to them. What is sent depends on what was asked: item names and descriptions for an item search or a catalog regrouping, a customer's name and their own purchase history for a customer brief, the figures already on your screen for a dashboard read, or the record of one sale or one import run when somebody asks why it behaved as it did.
Card numbers, expiry dates and card verification values never form part of it, and we do not send the last digits of a card. Our model provider is contractually bound not to train on what it receives, and is named on the sub-processors page. Every action is recorded in the console with what asked, from where, and when, so an account can see exactly what has been sent on its behalf.
Where it is processed
Our infrastructure runs in the United States. If you are in the UK or EEA, that is an international transfer, and we rely on the UK addendum and the EU Standard Contractual Clauses as the transfer mechanism. Those terms are in the DPA.
How long we keep it
- Account data - while your account is open. A lapsed trial or subscription goes read-only for 30 days and is then deleted; on any other closure we delete or anonymise within 90 days.
- Business records synced from your ERP - deleted with your tenant. Your ERP is untouched.
- Audit records - retained for the life of the account, because a log you can edit is not a log.
- Server logs - a rolling window, typically 30 days.
Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and complain to a regulator. If you are in the UK that regulator is the ICO; in the EEA it is your national authority.
Ask at support@usellit.ai and we will respond within 30 days. If your data reached us through a usellit customer - because you shopped somewhere that uses us - ask them first; they control it and we act on their instruction.
We will never charge you for exercising a right, and never treat you differently for having done so.
Security
Covered properly on the security page, including what we have not done yet.
Children
usellit is business software. It is not directed at children and we do not knowingly collect their data.
Changes
If we change this materially we will say so on this page and, for changes that affect you, by email before they take effect. The date at the top always reflects the current version.
Contact
support@usellit.ai, or the postal address above. More routes on the contact page.