Privacy Policy
Last updated: [DATE — fill in on actual publish]
This Privacy Policy explains how [Company Legal Name] ("we," "us," or "our") collects, uses, and protects information when you use xlister.pro (the "Service").
1. Information We Collect
Account information you provide directly:
- Email address and password (password is stored as a salted hash — see Security — we never store or have access to your plaintext password).
- Any information you submit via the Contact Us form (name, email, message).
eBay account information (once you connect an eBay seller account):
- OAuth access/refresh tokens issued by eBay, used solely to act on your behalf via eBay's APIs.
- Your eBay listing, pricing, inventory, and order data, to the extent needed to provide the Service's listing management, repricing, order sync, and analytics features.
- Buyer information contained in order data (e.g., shipping address, order contents) to the extent eBay provides it to sellers for fulfillment purposes — this data is used only to support your own order fulfillment and reporting, never for our own marketing or resold to third parties.
Automatically collected information:
- Basic technical/log data (IP address, browser/device information, timestamps) for security, rate-limiting, and abuse-prevention purposes.
- [Placeholder — specify if/when analytics cookies, session-replay tools, or similar are added; none are implemented as of this writing.]
2. How We Use Information
We use the information we collect to:
- Create and manage your account, and authenticate you (email verification, password reset, session management).
- Connect to and act on your eBay seller account(s) per the features you configure (listing management, repricing rules, order sync, analytics).
- Send transactional email (email verification, password reset, and, once you connect an eBay account, notifications related to that connection) via our email provider (Amazon SES).
- Respond to support requests submitted via the Contact Us form.
- Detect, prevent, and respond to fraud, abuse, or security incidents (e.g., rate-limiting login attempts).
- Improve and maintain the Service.
We do not sell your personal information or your eBay/buyer data to third parties.
3. How We Share Information
We share information only as necessary to operate the Service:
- eBay — via eBay's official APIs, to perform the actions you configure (this is inherent to how the Service works, not optional third-party sharing).
- Infrastructure/service providers — our hosting provider (AWS, for the backend and database), Amazon SES (for transactional email), and our frontend hosting provider (Vercel). These providers process data on our behalf and are bound by their own data-processing terms.
- Legal requirements — if required by law, court order, or to protect the rights, property, or safety of xlister.pro, our users, or the public.
We do not share buyer information from your eBay orders for any purpose beyond supporting your own use of the Service.
4. Data Retention
We retain account information for as long as your account is active. If you disconnect an eBay seller account, we [placeholder — specify retention period for historical listing/order/analytics data tied to that account, e.g. retained for N days then deleted, or retained until account deletion]. If you delete your account, we will delete or anonymize your personal information within [placeholder — e.g. 30 days], except where retention is required by law or for legitimate business records (e.g., financial/audit records).
5. How We Protect Your Information
- Passwords are never stored in plaintext — they are hashed using Django's password-hashing framework.
- eBay OAuth tokens and other credentials are stored securely and are never exposed in application logs or API responses.
- Data in transit is encrypted via TLS/HTTPS.
- Access to production systems and data is restricted to authorized personnel only.
No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we follow industry-standard practices and review our security posture on an ongoing basis.
6. Your Rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us via the Contact Us page. We will respond within the timeframe required by applicable law.
[Placeholder — if the Service has or will have users in the EU/UK, add GDPR-specific language (legal basis for processing, data protection officer contact if required, right to lodge a complaint with a supervisory authority). If it will have California users, add CCPA/CPRA-specific language (right to know, delete, opt out of sale/sharing — note we state above we don't sell data, but CCPA's definition of "sale/share" can be broader than a plain-English reading).]
7. Children's Privacy
The Service is not directed at individuals under 18, and we do not knowingly collect personal information from children.
8. International Data Transfers
[Placeholder — specify if data is processed/stored in a different country than where your users are located, and what safeguards apply (e.g., AWS region, standard contractual clauses if relevant).]
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy with a new "Last updated" date. Material changes will be communicated via email or a notice on the Service where appropriate.
10. Contact
Questions about this Privacy Policy, or requests to access/delete your data, can be sent via the Contact Us page.