1. Who is responsible
Operator: Berkay Yalinkilic
Location: Türkiye
Privacy contact: berkayyalinkilic@outlook.com
For Etsy shop data processed to provide the service requested by a connected seller, the operator acts as a service provider to that seller under Etsy's API Terms. The seller remains responsible for its shop, products and listing content.
2. Information processed
Information received through Etsy OAuth and the Open API
- Etsy user and shop identifiers, shop name and connection status;
- listing identifiers, status, title, description, tags, materials and other supported listing fields;
- listing images selected or associated with a seller's listing;
- price, quantity, SKU and basic inventory information;
- relevant shipping and processing profile information; and
- OAuth access and refresh tokens used for authorized API requests.
The application does not receive the seller's Etsy password through OAuth and does not ask sellers for an Etsy developer API key or shared secret.
Information provided directly
Account name, email address, one-way password hash, product and listing information, image files, Terms acceptance records and support communications that a user chooses to submit. Plain-text account passwords are not stored.
Technical and security information
IP address, request time, browser or device information, authentication events, error information and limited security logs needed to operate and protect the application. Secrets and full private listing payloads will be excluded from routine logs.
3. Why information is used
- Connect the shop authorized by the seller;
- display the seller's own shop and listing information;
- create new drafts, upload selected images and apply draft inventory after the seller explicitly confirms;
- manage seller-provided images and basic inventory for a draft;
- retrieve shop configuration required for listing forms;
- secure and troubleshoot the application; and
- answer support and privacy requests.
Etsy member data will not be sold, used for advertising, unrelated profiling, browser scraping, content licensing or unrelated data-product development.
4. OAuth permissions
V1 requests listings_r, listings_w and shops_r. It does not request listings_d or shops_w. A purpose or permission change will require updated disclosure, any required Etsy approval and new user authorization.
5. Sharing
Information is shared with Etsy to perform the seller-confirmed operation. Railway provides the live application hosting and storage environment. Cloudflare may provide secondary web delivery and Google provides the monitored support email service. These providers process information only as needed to operate, secure and support the application under their applicable service terms. Etsy member data is not disclosed to advertising networks, data brokers or unrelated applications.
6. Storage, freshness and retention
| Information | Publication rule |
|---|---|
| OAuth tokens | Until disconnect, revocation, account deletion or expiry; then deleted from active storage. |
| Displayed Etsy listing content | Fetched live in V1. If caching is introduced, it will be refreshed or discarded within six hours when displayed. |
| Other displayed Etsy content | Fetched live in V1. If caching is introduced, it will be refreshed or discarded within 24 hours when displayed. |
| Application drafts, profiles and image files | Until the seller deletes them or requests deletion of the application workspace. |
| Member account and sessions | Account records are kept while the account is active. Sign-in sessions expire after seven days or are deleted at sign-out or account deletion. |
| Terms acceptance record | Kept while the account is active and as reasonably needed to demonstrate the accepted terms. |
| Support communications | Normally up to 12 months after the last message, unless a longer period is needed for security, legal or dispute handling. |
7. Security
The application uses encrypted transport, one-way password hashing with a unique salt, HttpOnly session cookies, server-side secret management, AES-GCM encrypted OAuth-token storage, owner-scoped database queries, access controls and restricted logs. OAuth tokens, Etsy passwords and API credentials are not exposed through the browser.
If Etsy member data is compromised or suspected to be compromised, the operator will notify Etsy and the affected seller without undue delay and no later than 24 hours after discovery, as required by Etsy's API Terms.
8. Seller controls
A seller can decline authorization, disconnect in the application, revoke through Etsy's connected-app controls, delete local drafts and images, delete the member account and associated application data, and request access or correction by emailing the privacy contact. Disconnecting deletes stored OAuth tokens and stops future API requests; it does not delete listings already submitted to Etsy.
9. International processing and legal details
The operator is located in Türkiye. Railway, Cloudflare and Google may process information through infrastructure in other countries. Where applicable, those providers use contractual and legal safeguards for international transfers. Users may request access, correction, deletion, restriction or objection where applicable under the law governing their information.
10. Changes and contact
Material changes to data use or the application's Etsy API purpose will be disclosed and handled under Etsy's current approval and authorization requirements. Questions or requests can be sent to berkayyalinkilic@outlook.com.