Privacy Policy

Last updated: March 2026

1. What We Collect and Why

We collect only what is necessary to provide the service:

  • Account information — your email address and password, used to authenticate your account
  • Inventory data — item descriptions, photos, pricing, and notes that you enter, used to create and manage your listings
  • Platform credentials — OAuth tokens from Etsy, eBay, and other connected marketplaces, used solely to perform actions on your behalf
  • Usage data — standard server logs (IP address, browser type, page visits), used to operate the service and diagnose problems

We do not collect your data to sell it, share it with advertisers, or build profiles for purposes unrelated to this service. Every piece of data we collect exists to help the service work better for you.

2. How Your Data Is Used

Your data is used for three purposes only:

  • Operating the service — storing your inventory, processing your photos, pushing listings to platforms
  • Improving accuracy — when you use AI-generated listing info and modify the results, we log those corrections in a fully anonymized form (no account, no item ID, no personal information) to improve the accuracy of future suggestions. This data describes patterns — which fields AI gets right or wrong — nothing more.
  • Service communications — transactional emails such as processing failures or billing receipts. We do not send marketing email without explicit opt-in.

3. Data Storage and Security

Your data is stored in Supabase (PostgreSQL) hosted on AWS infrastructure. Your photos are stored in private Supabase Storage buckets that are inaccessible to other users. Platform OAuth tokens are stored encrypted and are never exposed on the client side or in logs.

All connections to the service are encrypted via HTTPS/TLS. Authentication is handled through secure, httpOnly session cookies. We do not store payment card numbers — billing is processed entirely by Stripe.

No system is 100% secure, and we will notify you promptly if a breach affects your account.

4. Data Retention

We retain your data for as long as your account is active and needed to provide the service. When you delete your account, your personal data, inventory records, and processed images are removed from our systems within 30 days, except where retention is required by law (for example, billing records required for tax purposes).

Anonymized AI correction data (which contains no personal information) may be retained indefinitely to improve service accuracy.

5. Third-Party Services We Use

Yes — we are required to disclose the third-party services that process your data as part of delivering this service. Each service has access only to the data necessary for its specific function:

  • Supabase — database and file storage (your inventory data and photos)
  • Vercel — application hosting (processes all web requests)
  • Stripe — subscription billing (we do not store payment card numbers)
  • Photoroom — automated photo background removal (your item photos are sent to their API for processing)
  • Anthropic (Claude API) — AI-powered item identification (the first photo of each item may be sent to Claude for analysis when you use the "Generate listing info" feature)
  • Resend — transactional email delivery (team invite emails)
  • Etsy, eBay, and other connected marketplaces — listing creation and management on your behalf

We do not share your data with any other third parties. We do not sell your data. We do not use your data for advertising.

6. Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us at support@listit.com or through the support option within your account.

If you are located in the EU or California, you have additional rights under GDPR and CCPA respectively, including the right to data portability and the right to know what data we hold about you. Contact us to exercise these rights.

7. Communication Preferences

We send transactional emails only (billing receipts, processing failures, team invitations). We do not send marketing email without your explicit opt-in. If you have opted in to marketing communications, you can unsubscribe at any time using the link at the bottom of any marketing email or by contacting us at support@listit.com.

8. Cookies

We use cookies to maintain your login session and remember your preferences (such as dark mode). We do not use third-party tracking or advertising cookies. Essential session cookies are required for the service to function.

9. Do-Not-Track

We do not track users across third-party websites and do not use advertising cookies. Because we do not engage in cross-site tracking, Do-Not-Track browser signals do not change how our service operates.

10. Age Requirement

This service is intended for users who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. If we become aware that a user under 18 has created an account, we will deactivate the account and delete the associated data promptly.

11. Changes to This Policy

We will notify you of material changes to this policy via email before they take effect. Continued use of the service after changes take effect constitutes acceptance of the updated policy.

12. Contact

Questions about this Privacy Policy or your data can be directed to support@listit.com or submitted through the support option within your account.