Privacy Policy
How Shop Pilot handles account, shop, listing, order, and service information.
Information we collect
- Account and license information: your account email, internal service identifiers, consent records, one-way access-key hash, key status and expiry, license/trial policy and usage records, browser authorization records, Bridge pairing records, security events, and support correspondence. The raw access key is not recoverable from the stored hash. Bridge v6 derives a stable machine signal locally and sends only a one-way identifier; Shop Pilot does not receive the underlying Windows registry value or other raw hardware source.
- Shop and Etsy connection information: profile labels and settings, Etsy user/shop identifiers, OAuth access and refresh tokens, permissions, connection timestamps, listing sections, and shop metadata. We never ask for or store your Etsy password.
- Listings and product files: seller-provided and generated titles, descriptions, tags, prices, attributes, designs, product images, mockups, digital files, listing identifiers/status, and workflow history.
- Orders, analytics, and fulfilment: when enabled, paid receipt/order identifiers, totals, currencies, timestamps, SKUs and variations. Fulfilment can also process buyer name, email, delivery address, country, and delivery status solely to complete the seller-requested order workflow.
- Optional integration data: credentials and settings you choose to save for AI, image/mockup, proxy, fulfilment, research, bridge, or other connected providers. This can include API keys, access tokens, proxy credentials, session cookies, and provider login credentials.
- Technical information: IP address in security logs, privacy-reduced network prefixes attached to device authorizations, browser/request metadata, Bridge version, diagnostic errors, rate-limit events, job logs, and information needed to detect abuse or interference.
Etsy OAuth permissions
The official workflow requests listings_r, listings_w, listings_d, shops_r, shops_w, transactions_r, transactions_w, and address_r. These allow Shop Pilot to read listing/shop context, create and update drafts, upload seller-authorized images and files, publish or delete only after a seller action, copy shipping profiles, return policies, processing profiles and sections between your own connected shops when you ask it to, display order/revenue analytics, and support seller-requested fulfilment including adding a tracking number to your own order once the print partner ships it. Shop Pilot does not process Etsy buyer payments or ask for Etsy passwords.
See the plain-language permissions explanation before connecting.
How we use information
- Authenticate accounts, validate license keys, enforce plan/trial limits, connect the selected shop, and provide the functions you initiate.
- Prepare files and previews; create or update Etsy drafts; upload authorized assets; publish, delete, analyze, or fulfil only following the relevant seller action.
- Run optional AI, mockup, research, proxy, bridge, and fulfilment integrations that you configure.
- Prevent duplicate or cross-shop actions, maintain seller-visible activity, secure the service, detect tampering or abuse, investigate incidents, and answer support requests.
- Comply with law and platform requirements and enforce our Terms of Service.
Essential service messages and promotional email
Account-security, password-reset, Etsy connection, proxy failure, subscription, billing, invoice, major service-change, and legally required messages are essential service communications. They do not depend on promotional-email consent.
Product updates, offers, and promotional messages use a separate optional preference that is off by default at signup. You may change that preference in Account Information or use an unsubscribe link. We respect recorded withdrawals and suppressed addresses and do not treat acceptance of the Terms or Privacy Policy as marketing consent.
AI and optional provider processing
If you enable an AI-assisted feature, prompts, listing inputs, and files you deliberately submit may be sent to the model or processing provider configured for your account. Shop Pilot does not use Etsy API content for model training and does not authorize providers to use it for advertising. You must review generated output and make any disclosures required by Etsy or law.
Depending on the features you choose, information may be processed by Etsy; the hosting and storage provider; your configured proxy provider; Anthropic or another configured AI provider; Hugging Face or another configured file/model provider; your configured mockup provider; your configured fulfilment provider; Pinterest or another research source; and the Shop Pilot desktop bridge. Each integration receives information needed for the action you request. Your use of those services is also governed by their own terms and privacy practices.
Storage, security, and retention
Hosted traffic is transmitted over HTTPS. Account data is separated by user; access keys and device identifiers are stored as one-way hashes; device network context is reduced to an IPv4 /24 or IPv6 /64 prefix; OAuth state is short-lived and single-use; and secrets are excluded from normal user-facing logs and exports. OAuth tokens, provider credentials, and seller files are stored on access-controlled systems, but Shop Pilot does not claim end-to-end encryption or guarantee that all files are encrypted at rest.
- OAuth tokens and provider sessions: until you disconnect, delete the account, revoke access at the provider, or the credential expires.
- Browser and Bridge authorizations: until they expire, an administrator resets or revokes them, the access key is revoked or permanently deleted, or the account is deleted.
- Seller settings, listing/order workflow files, and generated assets: while the account is active, then removed from the live service when account deletion completes; backup expiry may take up to 30 days.
- Security, license-usage, and activity records: normally up to 90 days after they are no longer operationally needed, unless retained to investigate abuse, enforce rights, resolve a dispute, or meet a legal obligation.
- Support, payment, tax, and other legally required business records: for the period required by applicable law.
Disclosure and legal requests
We may disclose information to the providers described above, to professional advisers and authorities when legally required, or when reasonably necessary to protect users, the service, or our rights. We do not disclose Etsy information to data brokers or advertising networks.
Your choices and rights
From Account Information you can review account and consent details and change permitted preferences. Existing data-export, Etsy-disconnect, and deletion controls remain available in the main Shop Pilot application where applicable. You may also request access, correction, portability, restriction, or deletion through [email protected] Discord: vilna2 metinatajs1. Disconnecting removes stored Etsy OAuth tokens and stops new Etsy API calls; it does not delete listings or records already held by Etsy. You can separately revoke Shop Pilot in Etsy's connected-app settings.
International users, children, and changes
Information may be processed where our providers operate, subject to applicable safeguards. The service is for adult business users and is not directed to children. Material changes will be dated and, where required, presented for renewed acceptance before continued use.