Policy

Privacy Policy

Version 1.0 — not yet effective for Etsy-connected use. The Effective Date will be the first valid acceptance date after all prerequisites close.

This Privacy Policy explains how Grace & Crafted Inc. (“LocalShopOps,” “we,” “us,” or “our”) processes information when Etsy sellers and authorized LocalShopOps account users use LocalShopOps.

1. Our role

For Etsy Member information accessed through the Etsy API, LocalShopOps acts as a service provider to the applicable authorizing Etsy seller. We process that information only to provide the seller-requested service under the applicable agreements and permissions.

Each Etsy shop connection requires a separate OAuth authorization from an account authorized to manage that shop. Data is isolated by LocalShopOps organization and shop.

2. Information we process

Seller account and support information

Account identifiers, contact details, permission settings, and support communications supplied by the seller.

Etsy authorization information

After a separately approved OAuth flow, LocalShopOps may process authorization status, exact granted scopes, references needed to bind the connection, token lifecycle metadata, and protected access and refresh tokens. We do not collect Etsy passwords.

For the proposed production service, the authorization response is intended to reach a dynamic HTTPS callback on the central U.S. service. State and PKCE validation, token exchange, connection binding and protected encrypted token storage are intended to take place in protected server-side components. The actual endpoint, storage configuration, and backup and logging boundaries must be reviewed and verified before production use. A separately approved development handshake is not evidence of persistent production token custody.

Authorization codes and state values may appear transiently in a redirect request but must not enter ordinary logs, analytics, screenshots, exports, or user-visible content. PKCE verifiers, tokens, credentials, and shared secrets must not be exposed to browser scripts or ordinary logs.

Shop and listing information

Shop information, listing identifiers, titles, descriptions, variations, SKUs, images and related listing data needed for seller-authorized listing and operational workflows.

Authorized-shop receipt and transaction information

The proposed first Commercial release is intended to process receipts and transactions belonging to the authorized Etsy shop for shop order review, but only after the necessary permission and the applicable read Gate have been separately approved and completed. This is not currently verified against Etsy and does not include access to buyer_email.

LocalShopOps is intended to process only the minimum recipient, address, destination, and delivery fields reasonably needed for authorized-shop order review and fulfillment, with access restricted by organization, shop, and fulfillment role. Unavailable fields will be shown as unavailable and will not be inferred. These fields are intended to be deleted or de-identified no later than 30 days after terminal order state, subject to a documented legal, dispute, security, or compliance hold.

Order-level personalization is intended to be limited to order review, making, and expressly assigned production work and follows the same maximum 30-day post-terminal rule. A temporary Production-file copy may contain only approved minimum personalization; after successful download it is intended to enter deletion immediately, while an undownloaded copy is intended to expire within 24 hours. The temporary-file lifecycle is separate from order-level storage and Listing personalization configuration. These time limits are LocalShopOps policies, not Etsy deadlines, and automated enforcement remains subject to implementation verification.

Operational and security records

Job status, import and export history, confirmation records, audit events, error reports, and security logs.

3. How we use information

4. Seller and shop isolation

LocalShopOps separates OAuth credentials, shop data, orders, listings, permissions, jobs, exports, and audit records by LocalShopOps organization and Etsy shop. Each Etsy shop connection requires a separate OAuth authorization from an account authorized to manage that shop.

5. How we do not use Etsy data

We do not sell or exchange Etsy data. We do not share one seller's data with another seller, use it for third-party advertising, or use it to train AI or machine-learning models. We do not use Etsy API data for cross-seller benchmarking, marketplace analytics, or competitive analysis. We do not scrape Etsy webpages.

6. Sharing and service providers

Infrastructure and technical providers

LocalShopOps may use infrastructure or technical service providers only when reasonably necessary to host, secure, maintain, or support the service and only under appropriate contractual and security restrictions.

The initial production service is planned to operate centrally on applicant-controlled infrastructure in the United States, with authorized users accessing it through a browser. The actual host, stable service address, protected storage, and processing locations must be documented and verified before production processing is enabled. Cloud backup is a planned requirement, not an enabled or verified service in this candidate. Any provider, processing region, data categories, encryption, access controls, retention and deletion arrangements for cloud backup or remote logging must be reviewed before use. No production cloud or backup provider is selected or approved by this Policy.

A future cloud migration is a separate decision. Before a third-party provider processes Etsy Member data, Grace & Crafted Inc. must recheck the then-current Etsy API Terms, the provider's contractual role and restrictions, applicable privacy law, security controls, processing location, and this Policy.

Seller-controlled operational downloads

An authorized LocalShopOps account user may generate and download a shop-specific Production file containing approved order-item, SKU, Variation, quantity, production fields and, when expressly authorized, the minimum personalization needed for the assigned task. Production files exclude recipient, address, destination, delivery, and buyer-email fields. LocalShopOps does not automatically transmit Etsy Member data or downloaded files to suppliers, carriers, fulfillment providers, other sellers, or unrelated third parties.

Nothing in this policy authorizes redistribution of Etsy API access, credentials, or Etsy Member data in a manner prohibited by Etsy's API Terms.

We may also disclose information when required by law or to protect users, the service, or legal rights.

7. Etsy data freshness, security, and retention

LocalShopOps is designed to apply organization/shop isolation, authorization checks, protected credential handling, PKCE, a LocalShopOps-mandated short-lived and single-use state value, CSRF protection, secret redaction, explicit confirmations, and fail-closed handling. These measures remain subject to the applicable production and verification Gates.

Etsy data is retained only as long as reasonably necessary to provide the seller-requested service, maintain proportionate security and transaction integrity, or meet a documented legal obligation. Recipient/address and order-level personalization follow the intended maximum 30-day post-terminal rule above; temporary Production-file copies follow immediate-after-download or maximum 24-hour undownloaded cleanup. Documented holds are limited to affected records and purposes. Other data remains purpose-limited.

Disconnecting a shop is intended to block new Etsy calls for that connection and begin credential and working-data cleanup. After a verified closure or deletion request, Etsy operational data that is no longer reasonably necessary is deleted or de-identified, subject to limited documented exceptions. Real automatic cleanup and file-backed execution remain subject to verification; no unsupported backup-expiry schedule is published.

8. Seller choices and controls

Sellers may:

Instructions are available on the Data Deletion page.

9. Security incidents

If a Developer Account, Etsy API keystring, shared secret, or other Etsy API credential is compromised or suspected to be compromised, Grace & Crafted Inc. will immediately notify Etsy at security@etsy.com.

If Etsy Member data accessed through the Etsy API is compromised or suspected to be compromised, Grace & Crafted Inc. will notify Etsy at dpo@etsy.com and the affected Etsy seller promptly, and no later than 24 hours after discovery. We will also notify relevant authorities when required by applicable law.

10. International processing

The initial central service is planned for the United States. Access by authorized users from other countries may involve transmitting information to that central service. The actual processing locations, any third-party involvement, and applicable legal requirements and safeguards must be documented and reviewed before production use. A later cloud migration or change in processing location remains a separate decision and must be reflected in the Policy and renewed acceptance where required.

11. Policy updates

We may update this policy when LocalShopOps features, legal obligations, or data practices change. Material changes will be communicated through the application, website, or seller contact information as appropriate. Material changes to permissions, Etsy-data purposes, sharing, retention, fees, or responsibility allocation require separate renewed affirmative acceptance of the current Terms and Privacy Policy before continued Etsy-connected use.

12. Contact

Privacy and data requests: gracecrafted2025@outlook.com