Legal
Privacy Policy
Effective version: 2026-07-20
1. Who provides this application
SellerFlow Central is independently provided by AK Frames (the “Application Developer”). The application provides seller-authorised catalogue, listing, inventory, image, sales-reporting and notification services to approved users and their Workspace members.
The term 'Etsy' is a trademark of Etsy, Inc. This Application uses Etsy's API, but is not endorsed or certified by Etsy.
2. Our role when handling Etsy data
When a seller authorises a shop, the Application Developer processes Etsy data as a service provider to that seller. We use the data only to provide the approved application functions, maintain security, provide support, comply with law and protect the application.
3. Information we collect and process
- Application account data: name, email address, password hash, account and Workspace membership, roles, permissions and account-security information.
- Legal acceptance records: accepted Terms and Privacy versions, timestamps, IP address and limited user-agent information.
- OAuth connection data: Etsy user and shop identifiers, approved scopes, token expiry and refresh information, and access and refresh tokens stored using application-level encryption.
- Catalogue data: shop profile details, listings, titles, descriptions, tags, images, inventory, variations, prices, quantities, categories and other fields required for authorised catalogue-management features.
- Order and sales data: receipts, orders, transaction identifiers, listing and item details, quantities, prices, discounts, taxes, shipping amounts, payment or ledger information, order status and timestamps returned by Etsy for the connected seller's shop.
- Limited buyer information: where Etsy returns buyer or delivery details with an authorised order endpoint, those details are processed only when needed for the seller's order records, support or reporting. They are not used for advertising or unrelated marketing.
- Operational and security data: synchronisation status, queued-operation results, safe API metadata, audit events, sanitised error details, IP address and user-agent information.
- User-provided files: CSV imports, exports and image uploads used to perform requested catalogue operations.
4. Information we do not collect or use
We do not ask for or store Etsy account passwords or buyers' full payment-card details. Etsy authentication occurs on Etsy through OAuth. We do not sell Etsy data, use it for third-party advertising, market to Etsy buyers, or use seller-authorised Etsy content to train artificial-intelligence or machine-learning models.
5. How we use information
- Authenticate users and enforce Account, Workspace and feature permissions.
- Connect seller-authorised shops through Etsy OAuth.
- Synchronise, display and manage shop, listing, image, pricing and inventory information.
- Read authorised orders and transactions to calculate revenue, order totals, quantities sold, top-selling listings and sales trends.
- Perform user-requested single-item, bulk, import, export and automation operations.
- Maintain data freshness, operational history, security monitoring and troubleshooting.
- Send transactional emails to registered application users for verification, password resets, requested reports, security notices and synchronisation alerts.
- Provide support, comply with applicable law and respond to security incidents.
6. Sales reports and data minimisation
Sales reports are generated for the authorised seller and assigned Workspace users. We aim to use aggregated values where possible and do not expose buyer details in dashboards when those details are unnecessary for the report. Reports are operational information and are not a substitute for accounting, tax or legal advice.
7. Transactional email
We send service messages only to registered application users or support contacts. Messages may include account verification, password resets, requested reports, security notices and synchronisation alerts. We do not use Etsy buyer email addresses for Catalogue Pilot marketing and do not send promotional messages to buyers through Etsy data.
8. Sharing and service providers
We may use hosting, email-delivery, storage, monitoring and security providers only as reasonably necessary to operate the application. They may process data under appropriate confidentiality and data-protection obligations. We may disclose information when required by law, to protect rights and security, or to Etsy where required under Etsy's API terms or an investigation.
9. Security
We use access controls, Workspace isolation, encrypted OAuth-token storage, password hashing, HTTPS, CSRF protection, rate limiting, restricted administration and sanitised logging. Raw OAuth tokens, passwords and authorisation headers are not displayed in public pages or routine logs.
10. Retention, disconnection and deletion
We retain seller-authorised data only while reasonably necessary to provide the service, preserve operational history, maintain security, resolve disputes or comply with legal obligations. Disconnecting a shop disables future Etsy API operations and removes or disables active credentials without deleting the Etsy shop itself.
Historical catalogue, order, report and audit records may remain preserved after disconnection so the seller retains an operational record. An authorised Account Owner may request account closure or deletion assistance through Support. Encrypted infrastructure backups may retain historical copies until normal backup rotation expires.
11. Your choices and controls
- Review and update application profile information.
- Export available catalogue or report information.
- Reconnect a shop to approve newly requested Etsy permissions.
- Disconnect a shop to stop future Etsy API operations.
- Request access, correction, retention or deletion assistance through Support.
- Decline a material Terms or Privacy update by discontinuing use of the application.
12. Cookies and sessions
We use necessary cookies and session technologies for secure login, CSRF protection, authentication, preferences and application integrity. We do not use Etsy data for third-party behavioural advertising.
13. Children
The application is intended for authorised business users and is not directed to children.
14. Changes to this policy
We may update this Privacy Policy when application features, legal requirements or Etsy API obligations change. Material changes may require renewed in-application acceptance.
15. Contact
Privacy and support enquiries: admin@prelogex.com
Application Developer: AK Frames