Privacy policy
Last updated: June 3, 2026
TL;DR
We store the minimum data needed to reprice your marketplace listings. We never sell your data. We never look at your customer order data — our marketplace API permissions only request pricing and listing scopes. We use Stripe for billing; card numbers never touch our server.
What we collect
- Account info: email, display name, password (hashed), timezone, currency preference.
- Marketplace OAuth tokens (Amazon LWA refresh token, eBay OAuth2 refresh token, Walmart Consumer ID + Private Key). Used only to read your competitor offers and update your prices.
- Your product catalog: SKU, ASIN/Item ID, title, cost, floor/ceiling, repricing rules.
- Pricing telemetry we generate: every price change we make (audit log), competitor offer snapshots, Buy Box history.
- Billing data: Stripe customer ID, subscription ID, invoice history. Card numbers stored on Stripe, not us.
- Login/security: session cookies, IP + user agent of each login, 2FA secret if enabled.
What we do NOT collect
- Customer order data on your marketplace accounts (scope not requested).
- Any data from buyers of your products.
- Credit card numbers / CVV / bank details — Stripe handles all of those.
Who we share with
- Amazon / eBay / Walmart: we call their APIs on your behalf using your delegated tokens.
- Stripe: subscription billing only.
- SMTP / email provider (your choice via /admin_config.cgi): outbound notification emails.
- That's it. No ad trackers, no analytics SaaS, no "data partners."
Your rights (GDPR / CCPA)
- Export your data: request a JSON dump at /account_export.cgi.
- Delete your account: request closure at /account_close.cgi. 30-day grace window in case it's a mistake; after that everything is purged (Stripe invoice records retained for tax/legal reasons, 7 years).
- Correct your data: edit at /profile.cgi.
- Revoke marketplace access: click Disconnect on /marketplaces.cgi; tokens wiped immediately.
Security
Marketplace OAuth tokens encrypted at rest. Passwords SHA-256 hashed. 2FA available with backup codes. Sign-in sessions revocable individually at /sessions.cgi.
Cookies
We use one first-party cookie (repricer_session, set on sign-in). One additional cookie (repricer_cookie_ok) records that you dismissed the cookie banner. No third-party cookies, no advertising pixels.
Children
RePricer is a B2B SaaS. We don't knowingly collect data from anyone under 16. Email privacy@repricer.3dshawn.com if you believe we've received data from a minor.
Changes
Material changes are emailed to every active user and posted on /changelog.cgi.
Contact
Privacy questions: privacy@repricer.3dshawn.com.