Privacy Policy
SellWren ("the Service", "we", "us") is an Etsy seller toolkit offering free guest tools and connected-shop analytics. This policy explains what data we collect, how we handle data received from the Etsy API, and the rights you have. We built SellWren on a simple principle: your shop data is yours, and we take only what is needed to serve you.
Last updated: August 27, 2026At a glance
- Guest tools store nothing — no account, no personal information, input never retained.
- Official Etsy API only — we never scrape or read etsy.com pages.
- Etsy tokens encrypted at rest (AES-256-GCM), used only against your own shop.
- We never sell, rent, or share your data or Etsy data.
- Delete anytime — disconnect your shop and data is removed within 30 days.
- Built to Etsy's API Terms of Use and Developer Policy standards.
On this page
01 What we collect
- Guest tool users. No account and no personal information. Our free tools (tag verifier, title builder, IP screen, description builder) run instantly in your session and store nothing you enter. Rate-limiting uses transient request identifiers (such as IP-derived values) retained briefly for abuse prevention only, then discarded.
- Connected users & administrators. Email address, authentication secrets (passwords stored only as salted hashes; two-factor secrets encrypted), and the Etsy shop IDs you choose to connect.
- Etsy OAuth tokens. When you connect a shop, Etsy issues an access token via the official OAuth 2.0 flow. We store it encrypted and use it only to serve requests against your own shop.
- Shop data you sync. Listings, orders, views, and favorites pulled from the official Etsy API for your connected shops, cached so dashboards load quickly without re-querying Etsy on every page view.
- Operational logs. Minimal error and audit records needed to run, debug, and secure the Service. No advertising trackers, no third-party analytics cookies.
02 Etsy data & API compliance
SellWren is built exclusively on the official Etsy API v3 and operates in accordance with Etsy's API Terms of Use and Developer Policy. Specifically:
- Official API only. We never scrape, crawl, or otherwise read etsy.com pages. Every Etsy data point in the Service comes from Etsy's own API endpoints.
- Minimum necessary scopes. Shop connections request only the permission scopes the features you use require (for example, reading your listings, receipts, and shop details).
- Your shop only. Each seller authorizes their OWN shop with their OWN token. Cross-shop access is technically impossible by design; a token is never used against any shop other than the one that issued it.
- Rate limits respected. We enforce our own conservative rate ceilings below Etsy's published limits, cache responses to minimize API traffic, and automatically halt requests on any warning signal from Etsy.
- No resale of Etsy data. Data received via the Etsy API is used solely to provide the Service to the shop owner who connected it. It is never sold, licensed, or shared with third parties, and never used to build products for other users.
- Honest presentation. Metrics about shops other than your own are computed only from public API fields and are clearly labeled as estimates — never presented as fact, in line with Etsy's rules against misrepresenting data.
- Revocation honored immediately. If you revoke SellWren's access (in the Service or in your Etsy account settings), we stop using your token at once and delete it per section 7.
Etsy itself controls how it collects and uses your data on its platform; see Etsy's Privacy Policy for the Etsy side of the relationship.
03 What we never do
- We do not sell or rent personal data or Etsy data.
- We do not read, harvest, or scrape etsy.com pages — official Etsy API only.
- We do not share your shop data with other users. If anonymized aggregate benchmarks are ever offered, they will be statistically protected and opt-out will be honored.
- We do not use your tokens against any shop but yours.
- We do not display your tokens or keys. Credentials are masked in the interface and never returned to the browser.
04 How we use data
We use collected data solely to operate the Service: displaying your shop analytics, running optimization and screening tools, enforcing rate limits and safety controls, preventing abuse, and improving reliability. We do not profile you for advertising and do not use your shop data to train general-purpose AI models.
AI features: where a tool uses an AI provider, only the minimum context needed (for example, a listing title you submit) is sent to that provider to produce your result.
05 Legal bases
We process data under three bases: performance of contract (providing the Service you use), legitimate interest (security, abuse prevention, reliability), and consent for optional features. Where you connect an Etsy shop, processing is necessary to fulfill the connected features you requested.
06 Security measures
- Encryption at rest (AES-256-GCM) for Etsy tokens and sensitive secrets.
- TLS 1.2+ for all data in transit.
- Passwords stored as salted hashes; optional two-factor authentication.
- Secrets isolated in a dedicated encrypted store, separate from application data and never in application code.
- Rate limiting, anomaly detection, and automatic halt on suspicious Etsy API signals to protect your shop.
- Role-based access controls; every data path is scoped server-side to the signed-in user.
No system is perfectly secure; we maintain these controls and review them regularly, and we will notify affected users of any breach as required by law.
07 Retention & deletion
Shop data is kept while your connection is active. When you disconnect a shop or delete your account, we delete or anonymize that data — including the Etsy access token — within 30 days, except audit records we must retain for security or legal reasons, which we minimize accordingly. Guest tool input is never retained at all.
08 Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, export, or object to processing of your data. Submit requests to [email protected]; we respond within statutory timeframes. You can also revoke SellWren's access to your Etsy shop at any time — either in the Service or directly in your Etsy account settings — and revocation stops further data access immediately.
09 Processors & subprocessors
We rely on a small set of trusted providers to run the Service. None of them receive your Etsy data for their own purposes:
- Hostinger — application and database hosting.
- Cloudflare — DNS, CDN protection, and the encrypted secrets store.
- AI providers — configured for AI-assisted features; only minimum prompt context is sent.
- Payment processor — will be added here if paid plans launch; card data never touches our servers.
A current list is maintained on this page.
10 International transfers
The Service is operated globally. Where data is transferred across borders, we rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) consistent with applicable law.
11 Children
The Service is intended for Etsy sellers and is not directed to children under 16. We do not knowingly collect data from children.
12 Changes to this policy
Material changes will be announced on the Service before they take effect, and the "last updated" date above will change. Continued use after changes become effective constitutes acceptance.
13 Contact
SellWren is built and run by an independent developer. Questions, concerns, or privacy requests: [email protected].