Policy
Privacy Policy
1. Our role
For Etsy Member information accessed through the Etsy API, LocalShopOps acts as a service provider to the applicable authorizing Etsy seller. We process that information only to provide the seller-requested service under the applicable agreements and permissions.
Each Etsy shop connection requires a separate OAuth authorization from an account authorized to manage that shop. Data is isolated by LocalShopOps organization and shop.
2. Information we process
Seller account and support information
Account identifiers, contact details, permission settings, and support communications supplied by the seller.
Etsy authorization information
After a separately approved OAuth flow, LocalShopOps may process authorization status, exact granted scopes, references needed to bind the connection, token lifecycle metadata, and protected access and refresh tokens. We do not collect Etsy passwords.
For the proposed production service, the authorization response is intended to reach a dynamic HTTPS callback on the central U.S. service. State and PKCE validation, token exchange, connection binding and protected encrypted token storage are intended to take place in protected server-side components. The actual endpoint, storage configuration, and backup and logging boundaries must be reviewed and verified before production use. A separately approved development handshake is not evidence of persistent production token custody.
Authorization codes and state values may appear transiently in a redirect request but must not enter ordinary logs, analytics, screenshots, exports, or user-visible content. PKCE verifiers, tokens, credentials, and shared secrets must not be exposed to browser scripts or ordinary logs.
Shop and listing information
Shop information, listing identifiers, titles, descriptions, variations, SKUs, images and related listing data needed for seller-authorized listing and operational workflows.
Authorized-shop receipt and transaction information
The proposed first Commercial release is intended to process receipts and transactions belonging to the
authorized Etsy shop for shop order review, but only after the necessary permission and the applicable read Gate
have been separately approved and completed. This is not currently verified against Etsy and does not include
access to buyer_email.
LocalShopOps is intended to process only the minimum recipient, address, destination, and delivery fields reasonably needed for authorized-shop order review and fulfillment, with access restricted by organization, shop, and fulfillment role. Unavailable fields will be shown as unavailable and will not be inferred. These fields are intended to be deleted or de-identified no later than 30 days after terminal order state, subject to a documented legal, dispute, security, or compliance hold.
Order-level personalization is intended to be limited to order review, making, and expressly assigned production work and follows the same maximum 30-day post-terminal rule. A temporary Production-file copy may contain only approved minimum personalization; after successful download it is intended to enter deletion immediately, while an undownloaded copy is intended to expire within 24 hours. The temporary-file lifecycle is separate from order-level storage and Listing personalization configuration. These time limits are LocalShopOps policies, not Etsy deadlines, and automated enforcement remains subject to implementation verification.
Operational and security records
Job status, import and export history, confirmation records, audit events, error reports, and security logs.
3. How we use information
- connect the seller's authorized Etsy shop;
- after the applicable approvals, synchronize and display authorized-shop receipts, transactions, and listing data;
- prepare seller-confirmed listing and complete-inventory workflows and, once enabled and verified, execute them within the supported write boundaries;
- create operational reports and seller-controlled Production-file downloads;
- maintain seller and shop permissions, data isolation, and auditability;
- protect LocalShopOps and Etsy users against errors, abuse, and unauthorized access; and
- provide support and comply with applicable legal obligations.
4. Seller and shop isolation
LocalShopOps separates OAuth credentials, shop data, orders, listings, permissions, jobs, exports, and audit records by LocalShopOps organization and Etsy shop. Each Etsy shop connection requires a separate OAuth authorization from an account authorized to manage that shop.
5. How we do not use Etsy data
We do not sell or exchange Etsy data. We do not share one seller's data with another seller, use it for third-party advertising, or use it to train AI or machine-learning models. We do not use Etsy API data for cross-seller benchmarking, marketplace analytics, or competitive analysis. We do not scrape Etsy webpages.
6. Sharing and service providers
Infrastructure and technical providers
LocalShopOps may use infrastructure or technical service providers only when reasonably necessary to host, secure, maintain, or support the service and only under appropriate contractual and security restrictions.
The initial production service is planned to operate centrally on applicant-controlled infrastructure in the United States, with authorized users accessing it through a browser. The actual host, stable service address, protected storage, and processing locations must be documented and verified before production processing is enabled. Cloud backup is a planned requirement, not an enabled or verified service in this candidate. Any provider, processing region, data categories, encryption, access controls, retention and deletion arrangements for cloud backup or remote logging must be reviewed before use. No production cloud or backup provider is selected or approved by this Policy.
A future cloud migration is a separate decision. Before a third-party provider processes Etsy Member data, Grace & Crafted Inc. must recheck the then-current Etsy API Terms, the provider's contractual role and restrictions, applicable privacy law, security controls, processing location, and this Policy.
Seller-controlled operational downloads
An authorized LocalShopOps account user may generate and download a shop-specific Production file containing approved order-item, SKU, Variation, quantity, production fields and, when expressly authorized, the minimum personalization needed for the assigned task. Production files exclude recipient, address, destination, delivery, and buyer-email fields. LocalShopOps does not automatically transmit Etsy Member data or downloaded files to suppliers, carriers, fulfillment providers, other sellers, or unrelated third parties.
Nothing in this policy authorizes redistribution of Etsy API access, credentials, or Etsy Member data in a manner prohibited by Etsy's API Terms.
We may also disclose information when required by law or to protect users, the service, or legal rights.
7. Etsy data freshness, security, and retention
LocalShopOps is designed to apply organization/shop isolation, authorization checks, protected credential handling, PKCE, a LocalShopOps-mandated short-lived and single-use state value, CSRF protection, secret redaction, explicit confirmations, and fail-closed handling. These measures remain subject to the applicable production and verification Gates.
Etsy data is retained only as long as reasonably necessary to provide the seller-requested service, maintain proportionate security and transaction integrity, or meet a documented legal obligation. Recipient/address and order-level personalization follow the intended maximum 30-day post-terminal rule above; temporary Production-file copies follow immediate-after-download or maximum 24-hour undownloaded cleanup. Documented holds are limited to affected records and purposes. Other data remains purpose-limited.
Disconnecting a shop is intended to block new Etsy calls for that connection and begin credential and working-data cleanup. After a verified closure or deletion request, Etsy operational data that is no longer reasonably necessary is deleted or de-identified, subject to limited documented exceptions. Real automatic cleanup and file-backed execution remain subject to verification; no unsupported backup-expiry schedule is published.
8. Seller choices and controls
Sellers may:
- decline OAuth authorization;
- review requested permissions before authorizing LocalShopOps;
- revoke LocalShopOps from Etsy's Connected Apps page;
- request access to or correction of their LocalShopOps account information; and
- request deletion of their account, OAuth credentials, and associated shop data, subject to limited legal or security retention requirements.
Instructions are available on the Data Deletion page.
9. Security incidents
If a Developer Account, Etsy API keystring, shared secret, or other Etsy API credential is compromised or suspected to be compromised, Grace & Crafted Inc. will immediately notify Etsy at security@etsy.com.
If Etsy Member data accessed through the Etsy API is compromised or suspected to be compromised, Grace & Crafted Inc. will notify Etsy at dpo@etsy.com and the affected Etsy seller promptly, and no later than 24 hours after discovery. We will also notify relevant authorities when required by applicable law.
10. International processing
The initial central service is planned for the United States. Access by authorized users from other countries may involve transmitting information to that central service. The actual processing locations, any third-party involvement, and applicable legal requirements and safeguards must be documented and reviewed before production use. A later cloud migration or change in processing location remains a separate decision and must be reflected in the Policy and renewed acceptance where required.
11. Policy updates
We may update this policy when LocalShopOps features, legal obligations, or data practices change. Material changes will be communicated through the application, website, or seller contact information as appropriate. Material changes to permissions, Etsy-data purposes, sharing, retention, fees, or responsibility allocation require separate renewed affirmative acceptance of the current Terms and Privacy Policy before continued Etsy-connected use.
12. Contact
Privacy and data requests: gracecrafted2025@outlook.com