Legal Policies

Privacy Policy

Last Updated: July 24, 2026

The term 'Etsy' is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.

1. Data We Access and Cache

OrbitSKU links to Shopify, Etsy, and eBay APIs to sync inventory numbers. We access and temporarily cache product titles, SKUs, active quantities, and image URLs. We do not store buyer names, shipping addresses, or payment credentials.

2. API Credentials Safety

The OAuth access and refresh tokens we store for your connected stores are encrypted at rest with AES-256-GCM, individually per value. They are decrypted only in memory, only to execute the sync actions you have asked for. Our own marketplace application credentials are held as server configuration and are never written to the database.

3. Cookies and Analytics

OrbitSKU utilizes secure session cookies to remember authentication tokens for logged-in accounts. We do not engage in cross-site tracking or sell user data to advertising aggregators.

4. Your Right to Delete Data

You can delete store access links at any time in your Settings portal. Doing so wipes all associated cached product logs and credentials from our databases instantly.

5. Our Role as a Service Provider (Data Processor)

When you connect a store, OrbitSKU acts as a service provider and data processor on your behalf, and you remain the controller of your store's and your customers' data. We access data through each platform's official API (including the Etsy API) and process it solely to provide the inventory-sync services you request — reading listings, SKUs, quantities, prices, and order events to keep stock levels accurate across channels. We request only the minimum data and permissions needed for these services, retain it no longer than reasonably necessary, secure it with encryption in transit and at rest, and never sell it, use it to train AI models, or share it with third parties except the platforms you have connected. You control what we may access and can revoke access and delete your data at any time from Settings. We process all data in accordance with applicable privacy laws and each platform's developer terms.

6. Data Incidents

If we discover or reasonably suspect that data accessed through a connected platform has been compromised, we will investigate promptly and notify affected users, and where required the relevant platform (for example, Etsy), within the timeframes required by applicable law and the platform's developer terms. Report any suspected security issue to support@orbitsku.com.

7. Shopify Order Data

When you connect a Shopify store, OrbitSKU reads order data solely to detect that a sale has occurred, so that the remaining stock can be decremented on your other connected channels and overselling is prevented. From each order we read only the order timestamp and each line item's SKU and quantity. We do not request, receive, or store customer names, email addresses, phone numbers, or shipping addresses. Order data is processed transiently to calculate an inventory adjustment and is not retained — OrbitSKU stores no order or customer records.

8. Etsy API & Trademark Disclaimer

When you connect an Etsy shop, OrbitSKU accesses listing, inventory, and sales/transaction data needed for multi-channel stock sync only. We do not request or store buyer email addresses or other unnecessary buyer personal contact data through the Etsy API. The term 'Etsy' is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.