Privacy Policy
Contents
1. Who this applies to
This Privacy Policy describes how Resell4.me ("we," "us") collects, uses, and protects personal information when you use the Resell4.me web application (the "Service"). It applies to shop owners who create an account with us. It does not directly govern the personal information of your consignors or customers that you choose to enter into the Service — you are the controller of that information, and your own privacy notices and legal obligations apply to it.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Email address, password (stored as a cryptographic hash, never in plain text), account creation date | You, at signup |
| Shop data | Business name, address, inventory, consignors, customers, transactions, settlements, settings, uploaded photos | You, as you use the Service |
| Payment | Billing name, last four digits and brand of your card, Stripe customer and subscription IDs, and identifiers for optional connected-account card transactions. Full card numbers are collected and stored by Stripe, not by us. | You, through Stripe |
| Technical | IP address (for rate limiting and security), browser and device type, pages/actions accessed (basic usage logs), timestamps | Automatically, when you use the Service |
| Communications | Content of support emails and feedback submissions | You, when you contact us |
3. How we use it
- Provide the Service — storing and displaying your shop data, authenticating your logins, keeping your information in sync across devices.
- Process payments — charging subscription fees and, when a shop enables optional Stripe card processing, facilitating its customer card transactions. Stripe is not used to send consignor payouts.
- Communicate with you — transactional notifications (billing, password resets, account changes), occasional product updates, and responses to your support requests. We do not send marketing emails to users without consent.
- Keep the Service working — monitoring for errors, preventing abuse, enforcing rate limits, investigating security incidents.
- Improve the Service — reviewing aggregated, de-identified usage patterns to understand what works and what doesn't.
- Legal compliance — when required by law, legal process, or to protect rights, safety, or property.
4. What we don't do
- We do not sell your personal information or your shop data to anyone.
- We do not use your shop data for advertising or behavioral targeting.
- We do not use your shop data to train machine learning or AI models.
- We do not share your data with third parties except with the subprocessors listed below who help us run the Service, or as required by law.
- We do not run third-party advertising or analytics trackers inside the Service.
5. Subprocessors
We rely on the following third parties to operate the Service. Each handles only the data necessary for their specific function, and each has their own privacy practices, linked below:
| Provider | Purpose | Data handled |
|---|---|---|
| Supabase | Database, authentication, and serverless functions | Account info, shop data |
| Stripe | Subscription billing and optional connected-account card processing | Billing information, payment methods, connected-account and transaction identifiers |
| Anthropic | AI-assisted features inside the Service (the "Q" assistant) | Questions you ask the assistant and limited context from your shop to answer them |
| Resend | Transactional email delivery | Email address, message content |
| Cloudflare | Application and website delivery, security, and DNS | Connection and security logs (including IP address, timestamps, and URLs requested) |
| InMotion Hosting | Support mailbox hosting | Email addresses, message content, and mail-server logs |
We review this list periodically and will update it when providers change.
6. Cookies and local storage
The Service uses browser localStorage and sessionStorage to keep you signed in, cache your shop data for offline use, and remember your preferences. These are first-party only and are not used for tracking across sites. We do not run third-party advertising cookies or cross-site tracking pixels.
7. Your rights
You have the following rights regarding your personal information:
- Access — You can view and export most of your shop data at any time from within the Service (CSV export is available in Reports).
- Correction — You can edit your account info and shop data directly within the Service.
- Deletion — To delete your account and associated data, email support@resell4.me. We will process your request within 30 days. Note that we may retain certain records (e.g., billing history, invoices) to comply with tax and legal obligations.
- Portability — Your shop data can be exported via CSV from within the Service; you can also request a broader export by email.
- Objection and restriction — You may object to or request restriction of certain processing by contacting us.
If you are a resident of the European Economic Area, the United Kingdom, or California, you have additional rights under applicable law (GDPR, UK GDPR, CCPA/CPRA), including the right to lodge a complaint with your local data protection authority. To exercise any right described here, email support@resell4.me.
8. Data retention
- While your account is active: we keep your data indefinitely so the Service works for you.
- After a deletion request: we mark your account for deletion and remove it within 30 days. During that window the data can still be recovered if you change your mind.
- After cancellation (no deletion request): we retain your data in case you return. If your subscription lapses and you do not return or respond to communications for 12 months, we may delete your data after reasonable notice.
- Billing and tax records: retained for the period required by applicable law (typically 7 years in the United States).
- Backups: our infrastructure providers may keep encrypted backups for disaster recovery for a limited period after deletion; these backups are not accessible for normal operations and age out automatically.
9. Security
We take reasonable measures to protect your information, including:
- Encryption in transit (HTTPS/TLS) for all connections to the Service.
- Encryption at rest for stored data, provided by our database and storage infrastructure.
- Row-level security policies that prevent users from accessing each other's data.
- Password hashing (we never store plain-text passwords).
- Routine rotation of credentials and secrets.
No system is perfectly secure. If we learn of a data breach affecting your personal information, we will notify you and applicable authorities as required by law.
10. Children
The Service is intended for use by adults operating a business. It is not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
11. International users
Resell4.me is operated from the United States. If you access the Service from outside the United States, you understand and consent to the transfer and processing of your information in the United States, which may have different data protection laws than your country of residence.
12. Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email or through the Service at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact
Questions, concerns, or requests regarding this Privacy Policy or your data? Email support@resell4.me.