Last updated: 6 October 2026
Privacy Policy
Effective date: 6 October 2026
These documents apply to ecomassist.net and the EcomAssist panel. Questions: legal@ecomassist.net.
1.Who we are
EcomAssist is software for online sellers, operated by the team behind ecomassist.net ("EcomAssist", "we", "us"). This policy explains what personal data we process when you use the website and the EcomAssist panel, and what we do with data we receive from marketplaces such as eBay.
For data about your own account we act as controller. For buyer data that reaches us through your connected store we act on your behalf, as your processor.
2.Data we collect
Account data you give us: name, email address, password (stored only as a hash), language and plan.
Store data from marketplaces you connect: listings, prices, quantities, orders and tracking numbers.
Buyer data contained in your orders: the buyer's name and shipping address, needed to fulfil and track that order.
Technical data: IP address, browser type and sign-in times, used for security.
We never collect or store payment card numbers. Card details stay with your payment provider or your supplier account.
3.Data by module
Each module only processes data while you use it. The table lists what is stored, why, and for how long.
Module Data Purpose Kept for Account Name, email, password hash, language Sign-in and account management While the account is active Billing Plan, amount, date, payment status (no card numbers) Subscription and accounting As long as accounting law requires eBay connection Encrypted OAuth tokens, eBay user ID, username, marketplace Acting on your store through the eBay API Until you disconnect or eBay sends an account-deletion notice Listings & queue SKU, title, price, quantity, eBay item ID, change history Publishing and updating listings While the store is connected Product finder & monitoring Supplier product IDs (e.g. ASIN), title, price, stock, images Price and stock sync While the product is tracked Orders eBay order ID, items, totals, status Order management and profit reports While the store is connected Buyer details Buyer name and shipping address from the eBay order Fulfilling and tracking that order Deleted 90 days after tracking upload Tracking Carrier and tracking number Uploading tracking to eBay With the order record Supplier ordering Supplier account label and ordering settings (no passwords or card numbers) Placing supplier orders you approve Until you remove the supplier account AI listing copy Product title and features you submit Generating titles and descriptions Until you delete the draft Support Messages and attachments Answering your requests 12 months after the ticket closes Security IP address, browser, sign-in attempts Preventing abuse 90 days 4.eBay data
You connect eBay through eBay's own OAuth consent page. We receive an access token and a refresh token; we never see or store your eBay password. Tokens are encrypted at rest with AES-256-GCM.
We use eBay data only to provide the features you switch on: publishing and updating your listings, reading your orders, and uploading tracking. We do not sell eBay data, do not use it for advertising, and do not combine it with other sellers' data.
Buyer information received through eBay is used only to fulfil and track that buyer's order. Shipping addresses are deleted automatically 90 days after tracking has been uploaded.
We are subscribed to eBay Marketplace Account Deletion notifications. When eBay tells us a user has closed their account, we verify the notification, delete the connected store with its listings and orders, and remove that user's name and address from any remaining records — immediately on receipt, and in every case within 30 days.
You can revoke our access at any time in your eBay account settings (Third-party app access); revoking stops all API access at once.
5.How we use data
To run the service: syncing listings, calculating prices, managing orders and uploading tracking.
To keep the service secure, prevent abuse and fix errors.
To send service messages such as failed orders, limit warnings and billing notices. We do not send marketing email without your consent.
8.Security
All traffic uses HTTPS. Marketplace tokens are encrypted at rest. Production access is limited to the people who operate the service, and the server is kept patched.
If a breach affects your data we will tell you without undue delay and, where required, inform the authorities.
9.Retention and deletion
Account data is kept while your account is active. Buyer addresses are deleted 90 days after tracking upload. Security logs are kept for 90 days.
When you delete your account or disconnect a marketplace, related data and tokens are deleted within 30 days; backups roll over within a further 30 days. Billing records are kept as long as accounting law requires.
See the data deletion page for step-by-step instructions.
10.Your rights
You can access, correct, export or delete your data at any time by emailing us; profile details can also be edited in the panel.
Buyers whose data we process on a seller's behalf can contact the seller or us; we will help the seller respond.
If you are in the EU, UK or another region with data protection law, you may also object to processing and complain to your local data protection authority.
11.Children
EcomAssist is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
12.Changes to this policy
If we change this policy we will update the date above and, for material changes, notify account holders by email before the change takes effect.
13.Contact
Questions about privacy or a deletion request: email legal@ecomassist.net. We reply within 30 days, usually much sooner.