Privacy Policy
This Privacy Policy explains how SoldFetch collects, uses, shares, stores, and protects personal information when you use our websites, accounts, APIs, and related services.
Effective Date: August 14, 2026Last Updated: October 9, 2026
1. Introduction
Welcome to SoldFetch ("SoldFetch," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit our websites or use our accounts, dashboards, APIs, support, and related services (collectively, the "Service").
SoldFetch is the controller of personal information we collect directly for account administration, billing, security, product operations, analytics, and support. Customers determine the purpose of the queries and other data they submit through their workflows. Where a separate data processing agreement applies, the roles and instructions in that agreement control.
By using the Service, you acknowledge this Privacy Policy. If you have questions or want to exercise a privacy right, contact contact@soldfetch.com.
2. Information We Collect
2.1 Information You Provide Directly
Depending on how you use the Service, you may provide:
- Account and profile information — such as your name, email address, profile image, and authentication-provider identifiers.
- Organization information — organization names, team membership, roles, and invitations.
- API key information — a label, prefix, status, and other metadata used to administer a key. The complete key is displayed once and is not stored in recoverable form.
- Billing information — billing contact details, Stripe customer or subscription references, purchase amounts, and payment status. SoldFetch does not intentionally receive or store full payment-card numbers.
- API inputs — product identifiers, keywords, marketplace choices, filters, and other query parameters required to perform a request.
- Communications — information you include in support, feedback, sales, or other messages to us.
2.2 Information Collected Automatically
When you access or use the Service, we may collect:
- Device and browser information — browser type, operating system, language, and similar technical data.
- Network and security information — IP address, browser identifiers, authentication events, and abuse-prevention signals.
- Service usage information — endpoints called, request times, status codes, credits consumed, organization or user identifiers, error classifications, and request latency.
- Product analytics — interactions with the site or dashboard when the applicable analytics control permits collection.
We do not intentionally place API keys, authorization headers, upstream response bodies, billing details, authenticated search inputs, or free-form customer content into browser analytics events. Masked session replay, when enabled with consent, is configured to mask text and form inputs and to block sensitive dashboard areas.
2.3 Public Marketplace Data and Upstream Requests
The Service retrieves publicly available eBay marketplace information requested by customers, such as product, offer, seller, review, and search-result data. To fulfill a request, SoldFetch sends the upstream data provider the query parameters needed for that operation. We do not send your SoldFetch password, API key, or payment credentials to the upstream provider.
You are responsible for ensuring that your use of requested data complies with applicable law, platform terms, and the rights of others.
3. How We Use Information
We use personal information to:
- create and manage accounts, organizations, memberships, and sessions;
- authenticate users and issue, revoke, and administer API keys;
- process API requests and route them to appropriate upstream services;
- meter usage, apply rate limits, calculate credits, and administer subscriptions;
- process purchases and maintain billing and transaction records;
- send service messages, including sign-in, billing, usage, security, and support communications;
- detect abuse, prevent fraud, investigate errors, and protect the Service;
- understand performance and improve reliability and product design; and
- comply with law, enforce our agreements, and protect rights, safety, and property.
Browser analytics and session replay use consent controls. We may process limited, allowlisted server-side operational events without browser analytics consent where necessary to operate, secure, and troubleshoot the Service; these events do not include API payloads.
4. Legal Bases for Processing
Where UK or European data-protection law applies, we rely on one or more of the following legal bases:
| Legal basis | When we rely on it |
|---|---|
| Performance of a contract | Creating and administering your account, processing API requests, metering usage, delivering the Service, and providing support. |
| Legitimate interests | Operating, securing, troubleshooting, and improving the Service; preventing abuse and fraud; and communicating about related services, balanced against your rights. |
| Consent | Optional browser analytics, session replay, and any other processing for which consent is requested. You may withdraw consent at any time. |
| Legal obligation | Maintaining required financial records, responding to lawful requests, and meeting legal or regulatory duties. |
5. How We Share Information
We disclose information only as needed to operate the Service, follow your instructions, meet legal obligations, or complete a business transaction. Our principal categories of service providers include:
| Provider or category | Purpose | Information involved |
|---|---|---|
| Supabase | Authentication, database, and account infrastructure | Account, session, organization, membership, API-key metadata, and service records. |
| Stripe | Payment and subscription processing | Billing contact details, customer and subscription references, purchase amounts, and payment status. Stripe receives payment credentials directly. |
| Resend | Transactional email delivery | Recipient address, delivery metadata, and message content. |
| Google Analytics | Consent-based public-site traffic measurement | Pseudonymous browser identifiers, public page paths, referring site origin, and device/browser information. Query strings and private account/API routes are excluded; advertising features are disabled. |
| PostHog | Product analytics, reliability events, and consent-based masked session replay | Pseudonymous identifiers, normalized page paths, allowlisted events, and technical metadata. |
| Upstash Redis | Rate limiting and short-lived caching | Rate-limit keys or digests, counters, and cached operational data. |
| Cloudflare R2-compatible object storage | Temporary generated exports | Export files and object metadata. |
| Oxylabs | Upstream eBay marketplace data acquisition | The query parameters required to obtain the marketplace data you request. |
| Hosting, network, and security providers | Hosting the Service and maintaining availability and security | Request metadata, IP address, system logs, and related technical data. |
Service providers process information for contracted services and are subject to applicable confidentiality, data-protection, and security obligations.
We may also disclose information:
- to members and administrators of your organization according to their roles;
- when required by law, legal process, or a valid government request;
- to protect the rights, property, security, or safety of SoldFetch, our users, or others; or
- in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate safeguards.
SoldFetch does not sell personal information or share it for cross-context behavioral advertising.
6. Cookies and Similar Technologies
We use cookies and browser storage to authenticate users, remember choices, prevent abuse, and, with the applicable consent, understand product usage.
| Cookie or storage | Purpose | Typical duration |
|---|---|---|
| Supabase authentication cookies | Maintain and refresh an authenticated session. | Set according to the authentication session. |
soldfetch_browser_id |
Apply browser-level public-tool limits and help prevent abuse. | Up to 400 days. |
soldfetch_org_id |
Remember the organization selected for an authenticated session. | Up to one year. |
soldfetch_policy_consent |
Carry a secure, short-lived policy acknowledgement through an authentication flow. | Up to 10 minutes. |
soldfetch_analytics_consent in local storage |
Remember whether optional browser analytics are allowed. | Until changed or cleared. |
_ga and _ga_* cookies |
Support optional Google Analytics on public pages after consent. | Configured to expire after 60 days, renewed with activity. |
| PostHog browser storage | Support consent-based analytics and masked session replay. | According to the configured PostHog settings. |
You can control cookies and local storage through your browser and the consent choices made available by the Service. Blocking essential storage may prevent authentication or other core features from working. Declining optional browser analytics does not prevent use of the core Service.
For a complete storage inventory and instructions for changing your choice, see our Cookie Policy.
7. Data Retention and Deletion
We retain information only for as long as needed for the purposes described in this policy, including to provide the Service, comply with law, resolve disputes, and enforce agreements.
| Data category | General retention approach |
|---|---|
| Account and organization data | Retained while the account or organization is active, then deleted or de-identified subject to legal, security, and backup requirements. |
| API request logs | Generally retained for 7, 30, or 90 days according to the applicable plan; a configured enterprise period may differ. |
| Generated exports | Configured to expire automatically after approximately one hour. |
| API-key records | Retained while the key exists or as needed for audit and security. The complete API key is not stored. |
| Billing and transaction records | Retained as required for tax, accounting, fraud prevention, dispute resolution, and other legal purposes. |
| Analytics data | Retained according to the configured analytics settings and consent state. |
| Security and rate-limit records | Retained for the period reasonably necessary to investigate incidents, enforce limits, and protect the Service. |
| Cached marketplace responses | Retained according to endpoint-specific cache periods and then expired or replaced. |
Deletion from active systems may not immediately remove information from encrypted backups or records we must retain by law. Those records remain protected and are deleted or overwritten through normal retention cycles.
8. International Data Transfers
SoldFetch and its providers may process information in countries other than the country where you live. Where applicable law requires transfer safeguards, we rely on an adequacy decision, approved contractual terms, or another recognized transfer mechanism, and we assess or supplement safeguards where required.
9. Your Privacy Rights
Depending on your location and subject to legal exceptions, you may have the right to:
- request access to, correction of, or deletion of your personal information;
- request restriction of processing or object to certain processing;
- receive certain information in a portable format;
- withdraw consent without affecting processing already completed on the basis of consent;
- opt out of non-essential marketing communications; and
- appeal a decision about a privacy request or complain to a data-protection authority.
Where the California Consumer Privacy Act applies, California residents may also have rights to know, delete, or correct personal information; opt out of its sale or sharing; limit certain uses of sensitive personal information; and receive equal service when exercising their rights. SoldFetch does not sell personal information or share it for cross-context behavioral advertising.
To exercise a right, email contact@soldfetch.com. We may verify your identity and authority before completing a request. Organization administrators can manage member access and certain account information directly in the dashboard.
10. Security
We use technical and organizational measures designed to protect personal information, including encrypted transport, access controls, private database schemas, monitoring, scoped credentials, and reveal-once API keys stored as cryptographic digests rather than recoverable plaintext.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to prevent unauthorized access, use, alteration, or disclosure and to respond to security incidents as required by law.
11. Children's Privacy
The Service is designed for businesses and developers and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact contact@soldfetch.com so we can investigate and take appropriate action.
12. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our Service, providers, practices, or legal obligations. We will update the "Last Updated" date and, where required, provide additional notice of a material change. We encourage you to review this page periodically.
13. Contact Us
For questions, concerns, or requests relating to this Privacy Policy or our privacy practices, contact:
SoldFetch
Email: contact@soldfetch.com
You may also contact the data-protection or consumer-protection authority in your jurisdiction if you believe your rights have been infringed.