ResellIQ Ltd ("ResellIQ", "we", "us", "our") operates the ResellIQ web application at reselliq.app, the ResellIQ browser extension for Google Chrome, and related services (together, the "Service"). This policy explains what data we collect, why we collect it, the legal basis on which we process it, how we store and protect it, and your rights in relation to it.
ResellIQ Ltd is the data controller responsible for your personal data. We are registered in the United Kingdom. By using the Service you acknowledge the data practices described below.
This page also serves as the privacy policy for the ResellIQ Chrome extension listed in the Chrome Web Store.
1. Data we collect
1.1 Account information
When you create an account we collect your email address, password (stored as a hash — we never see or store your plaintext password), username, selected plan, and locale-derived currency preference. If you sign up via Google or Apple, we receive your name, email, and profile photo from those providers. During signup and password reset, we send a partial hash (the first five characters of a SHA-1 hash) of your password to the Have I Been Pwned API to check whether it has appeared in known data breaches — your full password is never transmitted.
1.2 Inventory, listings, and financial data
Data you enter into ResellIQ — item records, descriptions, prices, costs, expenses, receipts, storage maps, order records, and financial summaries — is stored in our database and associated with your account. This data is not accessible to other users unless you make it visible through your public shop profile.
1.3 Product images, avatars, and receipts
You may upload product photos, a profile avatar, a banner image, and expense receipts. Product images and avatars are stored in publicly accessible storage buckets so they can be displayed on your public shop page and used by the browser extension during cross-listing. Receipt uploads are stored in a private bucket accessible only to you. By uploading product images, you acknowledge that they will be accessible via public URLs.
1.4 Public shop profile
If you use the public shop feature, your username, avatar, banner, bio, accent colour, social links, listed items, item descriptions, sale prices, and product images are publicly visible at reselliq.app/shop/[your-username]. Purchase cost data is never displayed publicly.
1.5 Gmail integration and Google OAuth
If you connect your Gmail account (available on paid plans), ResellIQ initiates a Google OAuth 2.0 authorisation flow. The consent screen lists the exact scopes we are requesting and the Google Account that will be connected. You can review and revoke this access at any time from your Google Account at myaccount.google.com/permissions or by clicking “Disconnect Gmail” in your ResellIQ settings, which revokes the token with Google and deletes the stored credentials.
We request the following scopes: https://www.googleapis.com/auth/gmail.readonly (read-only access to your Gmail messages and settings, used to search for and read marketplace order emails), https://www.googleapis.com/auth/userinfo.email (your email address, used to identify the connected Google Account inside ResellIQ), and openid (standard OpenID Connect identifier). We never request gmail.send, gmail.modify, gmail.compose, gmail.labels, or full-mailbox access. We do not send, compose, modify, label, archive, or delete any emails on your behalf.
We use this access only to search for and parse order, sale, payout, and shipping confirmation emails from supported marketplaces (currently eBay, Depop, Vinted, Poshmark, Mercari, Grailed, Etsy and Whatnot) and to extract order details such as item names, prices, fees, shipping information, and buyer identifiers so they can be turned into structured sales records inside your ResellIQ dashboard. For low-confidence parses we may temporarily store a sanitised version of the email HTML for review, which is automatically deleted after 30 days. We do not read, store, index, or process emails from senders that are not on our marketplace allow-list. Your Gmail OAuth tokens (access and refresh tokens) are encrypted at rest using AES-256 encryption and are accessible only to authorised server-side processes.
Google API Services User Data Policy — Limited Use disclosure. ResellIQ’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Gmail through Google APIs is used only to provide and improve user-facing features of ResellIQ that are visible in our interface (parsed orders, sales, payouts and associated reporting). We do not use Gmail data to serve advertisements; we do not transfer Gmail data to third parties except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger or acquisition with appropriate notice; we do not allow humans to read Gmail data unless we have obtained your explicit consent for specific messages, it is necessary for security purposes (such as investigating abuse), required by law, or the data has been aggregated and anonymised; and we do not use Gmail data to develop, improve, or train generalised AI or machine-learning models.
1.6 eBay integration and OAuth
If you connect your eBay account, ResellIQ initiates an eBay OAuth 2.0 authorisation flow. We request only the scopes required to sync your listings, orders, sold-history and selling-account data (including sell.inventory, sell.account, sell.fulfillment, commerce.identity.readonly and the read-only buy/browse scopes). We store the resulting access and refresh tokens encrypted at rest using AES-256 and use them to sync your eBay listings, orders, and sold comparable data. We do not use these tokens to make purchases on your behalf. If you disconnect your eBay account from your ResellIQ settings, we revoke the tokens with eBay and delete your eBay connection data. You can also revoke ResellIQ’s access at any time from your eBay account settings.
1.7 Chrome extension permissions and data
The ResellIQ Chrome extension runs only on supported ResellIQ, Vinted, Depop, and eBay UK pages relevant to the workflow you start. Depending on the action you choose, it may receive listing data from your ResellIQ inventory page, read publicly visible listing data from a Depop product page for import, or populate the Vinted, Depop, or eBay sell form for you. Data involved may include the item title, description, brand, size, condition, colour, price, category selections, hashtags, and product photos.
The extension uses Chrome permissions as follows: storage and unlimitedStorage to hold pending listing payloads and temporary image data in chrome.storage.local; activeTab and tabs to detect, reuse, or open the supported Vinted, Depop, or eBay tab you asked us to use; and scripting plus narrowly scoped host permissions to run the autofill and import scripts only on supported ResellIQ, Vinted, Depop, eBay, and related asset/API endpoints needed to complete that workflow. We do not use these permissions to monitor unrelated browsing activity, read browsing history, or capture passwords or keystrokes from unrelated sites.
For cross-listing, listing data is passed between the ResellIQ web page and the installed extension on your device so the destination form can be completed on Vinted, Depop, or eBay. Product photo URLs may be fetched by the ResellIQ page and converted into browser-local data URLs before autofill so marketplace upload fields can be populated correctly. For import workflows, publicly visible Depop listing data is only added to your ResellIQ account if you choose to import it.
The extension does not sell your data, inject third-party advertising trackers, or read content from websites outside the supported ResellIQ, Vinted, Depop, and eBay flows.
1.8 Vinted profile import
If you use the Vinted import feature, we retrieve publicly visible data from the Vinted seller profile URL you provide — including item titles, prices, brands, sizes, conditions, images, and listing URLs — and import them into your ResellIQ inventory. This retrieval is performed at your direction and on your behalf.
1.9 AI-processed data
When you use AI features (item scanning, description generation, pricing analysis, the business assistant, screenshot analysis, or Pokemon vision), we send relevant data — which may include your item photos, item metadata, inventory context, and screenshots you provide — to OpenAI for processing. As of the date of this policy, OpenAI's API data usage policy states that API inputs and outputs are not used to train their models; however, OpenAI's policies may change and you should review their current terms if this is a concern. AI outputs including descriptions, price estimates, grading suggestions, and authenticity assessments are stored in our database alongside your item records.
1.10 Analytics and telemetry
We collect usage data including session identifiers, event names, page paths, user agent strings, screen dimensions, and timestamps. This data may be collected from both authenticated and anonymous users. We strip sensitive keys before storage. We do not use third-party advertising trackers. We use this data solely to understand how the Service is used and to improve it. Session identifiers are pseudonymous and do not directly identify you without cross-referencing other data.
1.11 Billing data
Payment processing is handled entirely by Stripe. We do not see, store, or process your credit card number or bank details. We receive from Stripe your subscription status, plan, trial dates, and payment event notifications (successful payments, failures, refunds, and cancellations) which we store to manage your account.
1.12 Feedback
If you submit feedback through the in-app widget, we collect your message, the page you were on, and optionally your email address if you choose to provide it. Providing your email is entirely voluntary and is used only if we need to follow up on your feedback.
1.13 Market and price reference data
We periodically collect publicly available sold listing data from eBay and, where configured, other marketplace sources via third-party services. This data is used to power pricing analysis and AI grounding features. It is aggregated market data and does not contain personal information.
2. Lawful basis for processing
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we rely on the following lawful bases for processing your personal data:
Contractual necessity (Article 6(1)(b)): processing your account information, inventory data, financial data, and billing data is necessary to provide the Service you have signed up for. Processing AI features, cross-listing, and marketplace integrations falls within the contract to provide the Service.
Legitimate interests (Article 6(1)(f)): we process analytics and telemetry data and aggregated market reference data to improve the Service, monitor performance, detect fraud, and ensure security. Our legitimate interests do not override your fundamental rights; we minimise data collection and pseudonymise analytics data where practicable.
Consent (Article 6(1)(a)): we rely on your explicit consent for: connecting your Gmail account and accessing your emails; opting in to optional weekly summary and sourcing emails; and providing your email address in feedback submissions. You may withdraw consent at any time by disconnecting the relevant integration, updating your notification preferences, or contacting us. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Legal obligation (Article 6(1)(c)): we may retain certain billing, transaction, and account records where required to comply with tax, accounting, or regulatory obligations.
3. How we use your data
We use your data to: operate and improve the Service; manage your account and subscription; provide AI-powered features including item analysis, description generation, pricing estimates, and business advice; parse marketplace order emails and create order records; sync your eBay listings and orders; enable cross-listing via the browser extension; display your public shop profile; send transactional emails (welcome, trial reminders, payment confirmations, and account notifications); send optional weekly summary and sourcing emails where you have opted in; analyse pseudonymised usage patterns to improve the Service; and respond to your feedback and support requests.
4. Third-party services
We use the following third-party services to operate ResellIQ. Each processes data in accordance with their own privacy policies, which we encourage you to review:
Supabase — database, authentication, and file storage. Vercel — application hosting and serverless functions. OpenAI — AI-powered item analysis, description generation, pricing, and chat features. Stripe — payment processing and subscription management. Resend — transactional and notification emails. Google — OAuth authentication and Gmail API for order email parsing. Apple — OAuth authentication. eBay — OAuth authentication, listing sync, order sync, and sold comparable data. Have I Been Pwned — password breach checking during signup and password reset. Upstash — caching layer for AI and pricing responses. Apify — marketplace data collection for price reference features, where configured.
We do not sell your personal data. We share your data with third parties only as described in this policy, and only to the extent necessary to operate the Service.
5. Data security
All data transmitted between your browser and our servers is encrypted via TLS (HTTPS). Database access is governed by row-level security policies ensuring users can only access their own data. OAuth tokens for Gmail and eBay are encrypted at rest using AES-256. We regularly review our security practices and take reasonable technical and organisational measures to protect your data, but no internet service can guarantee absolute security. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office in accordance with our obligations under UK data protection law.
6. Data retention
Browser extension data is designed to be temporary. Pending Vinted, Depop, and eBay autofill payloads are removed from local extension storage as soon as the destination form reads them. A scraped Depop import payload may remain in local extension storage until your ResellIQ session consumes it or it is replaced by a later import action. Sanitised email HTML retained for low-confidence order parses is automatically deleted after 30 days. All other web application data is retained for as long as your account is active. If you delete your account, all associated data — including items, images, orders, expenses, storage maps, integrations, tokens, and analytics — is permanently removed within 30 days, except where we are required to retain certain records for legal, tax, fraud-prevention, or billing purposes. Where data is retained after account deletion, it is held for the minimum period required by applicable law and then deleted.
7. Your rights
Under UK data protection law (UK GDPR and the Data Protection Act 2018) you have the right to: access the personal data we hold about you; correct inaccurate data; request deletion of your data (subject to legal retention obligations); restrict or object to certain processing; request portability of your data in a structured, commonly used, machine-readable format where technically feasible; withdraw consent where processing is based on consent (without affecting the lawfulness of prior processing); and lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been infringed. The ICO can be contacted at ico.org.uk.
To exercise any of these rights, contact us at the address below. We will respond within 30 days. We may ask you to verify your identity before acting on your request.
8. Communications
We send transactional emails related to your account (welcome, trial reminders, payment confirmations, failure notifications, and account changes). These are necessary for the performance of our contract with you and cannot be opted out of while your account is active. We may also send optional weekly summary and sourcing emails if you have enabled notifications in your account settings. You can disable these at any time through your notification preferences or by contacting us.
10. Children
The Service is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. International data transfers
Some of our third-party service providers (including Supabase, Vercel, OpenAI, Stripe, and Resend) may process data outside the United Kingdom. Where data is transferred internationally, we take reasonable steps to ensure it is protected by appropriate safeguards as required by UK data protection law. These may include transfers to countries with adequacy decisions, standard contractual clauses, or other approved transfer mechanisms. You may contact us for more information about the specific safeguards in place.
12. Changes to this policy
We may update this policy from time to time. For material changes that affect how we process your personal data, we will provide reasonable notice via the Service or by email before the changes take effect. The "last updated" date and version number at the top of this page will be revised accordingly. Continued use of the Service after changes constitutes acknowledgement of the revised policy. Where a change requires your consent under data protection law, we will seek that consent separately.
13. Contact and complaints
If you have questions about this policy, your data, or wish to exercise your rights, email us at privacy@reselliq.app.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.