Skip to content

Last updated: 6 October 2026

Privacy Policy

Effective date: 6 October 2026

These documents apply to ecomassist.net and the EcomAssist panel. Questions: legal@ecomassist.net.

  1. 1.Who we are

    EcomAssist is software for online sellers, operated by the team behind ecomassist.net ("EcomAssist", "we", "us"). This policy explains what personal data we process when you use the website and the EcomAssist panel, and what we do with data we receive from marketplaces such as eBay.

    For data about your own account we act as controller. For buyer data that reaches us through your connected store we act on your behalf, as your processor.

  2. 2.Data we collect

    Account data you give us: name, email address, password (stored only as a hash), language and plan.

    Store data from marketplaces you connect: listings, prices, quantities, orders and tracking numbers.

    Buyer data contained in your orders: the buyer's name and shipping address, needed to fulfil and track that order.

    Technical data: IP address, browser type and sign-in times, used for security.

    We never collect or store payment card numbers. Card details stay with your payment provider or your supplier account.

  3. 3.Data by module

    Each module only processes data while you use it. The table lists what is stored, why, and for how long.

    ModuleDataPurposeKept for
    AccountName, email, password hash, languageSign-in and account managementWhile the account is active
    BillingPlan, amount, date, payment status (no card numbers)Subscription and accountingAs long as accounting law requires
    eBay connectionEncrypted OAuth tokens, eBay user ID, username, marketplaceActing on your store through the eBay APIUntil you disconnect or eBay sends an account-deletion notice
    Listings & queueSKU, title, price, quantity, eBay item ID, change historyPublishing and updating listingsWhile the store is connected
    Product finder & monitoringSupplier product IDs (e.g. ASIN), title, price, stock, imagesPrice and stock syncWhile the product is tracked
    OrderseBay order ID, items, totals, statusOrder management and profit reportsWhile the store is connected
    Buyer detailsBuyer name and shipping address from the eBay orderFulfilling and tracking that orderDeleted 90 days after tracking upload
    TrackingCarrier and tracking numberUploading tracking to eBayWith the order record
    Supplier orderingSupplier account label and ordering settings (no passwords or card numbers)Placing supplier orders you approveUntil you remove the supplier account
    AI listing copyProduct title and features you submitGenerating titles and descriptionsUntil you delete the draft
    SupportMessages and attachmentsAnswering your requests12 months after the ticket closes
    SecurityIP address, browser, sign-in attemptsPreventing abuse90 days
  4. 4.eBay data

    You connect eBay through eBay's own OAuth consent page. We receive an access token and a refresh token; we never see or store your eBay password. Tokens are encrypted at rest with AES-256-GCM.

    We use eBay data only to provide the features you switch on: publishing and updating your listings, reading your orders, and uploading tracking. We do not sell eBay data, do not use it for advertising, and do not combine it with other sellers' data.

    Buyer information received through eBay is used only to fulfil and track that buyer's order. Shipping addresses are deleted automatically 90 days after tracking has been uploaded.

    We are subscribed to eBay Marketplace Account Deletion notifications. When eBay tells us a user has closed their account, we verify the notification, delete the connected store with its listings and orders, and remove that user's name and address from any remaining records — immediately on receipt, and in every case within 30 days.

    You can revoke our access at any time in your eBay account settings (Third-party app access); revoking stops all API access at once.

  5. 5.How we use data

    To run the service: syncing listings, calculating prices, managing orders and uploading tracking.

    To keep the service secure, prevent abuse and fix errors.

    To send service messages such as failed orders, limit warnings and billing notices. We do not send marketing email without your consent.

  6. 6.Sharing and sub-processors

    We share data only with sub-processors that help us run the service, under agreements that require them to protect it:

    netcup GmbH (Germany) — server hosting for the website, panel and database.

    Anthropic — generates listing titles and descriptions from product text you submit. Only product information is sent, never buyer data.

    Product data provider (Rainforest API) — receives supplier product IDs such as ASINs to return price and stock. No personal data is sent.

    Tracking provider — receives carrier and tracking numbers to return delivery status.

    Marketplaces and suppliers you connect receive the data needed for the action you request (for example a listing or a tracking upload).

    We disclose data to authorities only when the law requires it. We never sell personal data.

  7. 7.Cookies

    We use only cookies that the service needs: a session cookie that keeps you signed in, and small preferences such as language and theme. We do not use advertising or cross-site tracking cookies.

  8. 8.Security

    All traffic uses HTTPS. Marketplace tokens are encrypted at rest. Production access is limited to the people who operate the service, and the server is kept patched.

    If a breach affects your data we will tell you without undue delay and, where required, inform the authorities.

  9. 9.Retention and deletion

    Account data is kept while your account is active. Buyer addresses are deleted 90 days after tracking upload. Security logs are kept for 90 days.

    When you delete your account or disconnect a marketplace, related data and tokens are deleted within 30 days; backups roll over within a further 30 days. Billing records are kept as long as accounting law requires.

    See the data deletion page for step-by-step instructions.

  10. 10.Your rights

    You can access, correct, export or delete your data at any time by emailing us; profile details can also be edited in the panel.

    Buyers whose data we process on a seller's behalf can contact the seller or us; we will help the seller respond.

    If you are in the EU, UK or another region with data protection law, you may also object to processing and complain to your local data protection authority.

  11. 11.Children

    EcomAssist is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.

  12. 12.Changes to this policy

    If we change this policy we will update the date above and, for material changes, notify account holders by email before the change takes effect.

  13. 13.Contact

    Questions about privacy or a deletion request: email legal@ecomassist.net. We reply within 30 days, usually much sooner.

legal@ecomassist.net