Skip to content
Sell Through
Legal

Privacy policy

The short version: we collect what you type into the enquiry form so we can reply to it, our host keeps standard server logs, and that is the lot. No cookies, no advertising trackers, nothing sold to anyone.

Last updated

Who we are

Sell Through is a retail media agency operating in the United States. This policy covers sellthrough.co and the enquiry form on it. It does not cover the retailer or advertising platforms we operate on behalf of clients — those are governed by each platform’s own terms and by our agreement with the client.

What we collect

Two things, and nothing else.

What you send us

If you fill in the enquiry form, we receive what you typed: your name, work email, company, and optionally your website, an annual revenue range, which channels you sell on, and your message. All of it is optional except name, email, company and message — and you decide what goes in the message.

What your browser sends automatically

Our host records standard server logs for every request: IP address, user agent, the page requested, and a timestamp. We use these to keep the site up and to stop abuse of the enquiry form. We also see an aggregated count of page views and load-speed measurements.

An automated check on the enquiry form

When you submit the form, a background check runs to tell a person apart from a script. It reads technical signals from your browser — how the page was interacted with, and characteristics of the browser itself — and returns a single verdict: human or bot. There is no puzzle to solve and nothing for you to click. The signals are used for that verdict only. They are not stored by us, not linked to your enquiry, and not used to identify or profile you.

What we don't do

  • No cookies. This site sets none — not for analytics, not for preferences, not for anything. That is why you were not asked to dismiss a banner.
  • No cross-site tracking and no advertising pixels. There is no Meta pixel, no Google Ads tag, no LinkedIn Insight tag, no third-party script of any kind.
  • No profile building. Our analytics count page views in aggregate. They do not assign you an identifier or follow you between visits.
  • We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act, and we never have.

Why we collect it

  • To reply to you. That is the only reason we ask for contact details.
  • To keep the site working and free of abuse. Server logs let us rate-limit the enquiry form and block automated submissions.
  • To see which pages are read. Aggregate page views tell us what to write more of.

We do not add you to a marketing list because you sent an enquiry. If we ever start a newsletter you will have to ask for it.

Who processes it

Three vendors, each doing one job:

  • Vercel — hosts the site, serves every page, keeps server logs and provides the aggregate page-view and page-speed measurements.
  • Resend — delivers your enquiry to our inbox as an email. It handles the message in transit.
  • Vercel BotID — runs the automated human-or-bot check described above. It sees the technical signals, not the contents of your message.
  • Our email provider — stores the enquiry once it arrives, the same way any email you send us would be stored.

Nobody else receives it. We do not pass enquiries to partners, data brokers or advertising networks.

How long we keep it

Enquiries stay in our email for as long as the conversation or the prospect of working together is live, and are deleted when you ask us to. Server logs are held by our host on its own short retention schedule and are not copied anywhere by us. Aggregate analytics contain nothing that identifies you, so there is nothing in them to delete.

Your rights

Wherever you are, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Email us and we will action it — we do not require a form or a process.

If you are in California, the CCPA and CPRA give you rights to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We will not treat you differently for exercising any of these rights.

If you are in the EU or UK, our basis for handling your enquiry is our legitimate interest in responding to someone who contacted us about our services, and for server logs it is our legitimate interest in keeping the site secure. You can object to either, and you can complain to your local supervisory authority.

How it is protected

The site is served over HTTPS only, with a content security policy, strict transport security and a set of hardening headers on every response. The enquiry form is rate-limited and screened for automated submissions. We hold no database and no accounts, so there is no store of personal data on this site to breach.

Children

This is a business-to-business site and is not directed at anyone under 16. We do not knowingly collect information from children. If you believe a child has sent us something, tell us and we will delete it.

Changes to this policy

If we change what we collect or who processes it, we will update this page and move the date at the top. There is no archive of previous versions, so if the specifics matter to you, keep a copy.

Getting in touch about your data

Email us and say what you want done. A request to see, correct or delete what we hold does not need to be formal — one line is enough.

Email us