Privacy
Privacy and data handling
How Siddex Tech collects, uses, stores and disposes of the data our software processes on behalf of the businesses that use it.
Last updated 24 September 2026
Who this covers
Siddex Tech builds and operates order management, CRM, e-commerce and HR software. When one of our platforms is used to run a business, we process data on that business’s behalf and under their instruction. We do not sell, rent or trade personal data, and we do not use it for advertising or profiling.
What we collect
- Order and customer data from the marketplaces and storefronts our customers sell on: buyer name, delivery address, contact details, order lines, prices, fees and settlement records.
- Business records: product catalogues, stock levels, suppliers, purchase and invoice data.
- Account data for the staff who use our software: name, email, role and authentication details.
- Enquiries you send us through this website.
Why we process it
Solely to operate the service our customer has asked for: picking, packing, dispatching and invoicing orders, keeping stock and prices correct across sales channels, reconciling marketplace payouts, and meeting tax obligations. We do not process this data for any purpose of our own.
How it is protected
- Encrypted in transit over TLS, on every service we operate.
- Databases are not reachable from the internet; applications sit behind a reverse proxy and servers are reached only by key-based SSH.
- Marketplace and payment credentials are encrypted with AES-GCM, with the key held outside the database it protects. Credentials are never displayed back to a user.
- Access follows job duty through a permission model enforced on the server, so staff see only what their role requires. Access is withdrawn when someone changes role or leaves.
- Passwords are hashed, must be at least 12 characters with mixed case, a digit and a symbol, and two-factor authentication is available on every account.
- An audit log records which account performed which action.
Who else sees it
Only the parties needed to run the service: the marketplaces the data came from, and any order management or listing vendor a customer has authorised on their own seller account. No other party receives it. When such a relationship ends, the authorisation is revoked and access removed.
How long we keep it
Records required for tax and statutory purposes are kept for as long as the law requires. Personal data held beyond that purpose is removed on a defined schedule. Marketplace credentials are deleted when an account is disconnected.
Your rights
If you believe we hold personal data about you and want to know what it is, have it corrected, or have it removed where no legal obligation requires us to keep it, write to us and we will respond. Where we process data on behalf of a business, we will direct your request to them and support them in answering it.
Security concerns
If you believe you have found a vulnerability or a data exposure in any Siddex Tech service, please tell us at info@siddextech.com. We investigate every report, and we notify affected customers and platforms within the timeframes their agreements require.
Contact
Siddex Tech
info@siddextech.com