Privacy Policy
Last updated June 26, 2026
ebayeasy helps you take your own items from a photo to a finished, shipped eBay sale — it identifies items, prices them from real sold comps, drafts listings, and helps you manage offers, buyer messages, orders, and shipping. This policy explains what data ebayeasy handles and why. It covers people who use ebayeasy to sell (account holders), and the buyer information ebayeasy necessarily processes to complete your sales.
Connecting your eBay account
You connect your own eBay account through eBay’s official OAuth sign-in. ebayeasy never sees or stores your eBay password — eBay returns a token that authorizes ebayeasy to act on your behalf within the permissions you grant (viewing and managing your inventory, listings, offers, orders, account/business policies, messaging, and finances, and reading your basic eBay identity to label the connection).
That authorization is a long-lived refresh token. We store it encrypted at rest with AES-256-GCM (a unique key, held only in our server environment and never in our code), along with the short-lived access token derived from it. The tokens are used only to perform the actions you ask ebayeasy to do. You can disconnect at any time from Settings — that immediately deletes the stored tokens.
What we store
- Items you add — photos you upload, plus the brand, model, condition, and notes you or our AI identify.
- Research & listings — sold-comp data we gather to price an item, and the AI-drafted listing copy, pricing strategy, and offers you create.
- Orders — when your items sell: the order, amounts, the buyer’s eBay username, and the shipping address, so you can fulfill and ship.
- Messages — buyer–seller messages on your listings, so you can read and reply.
- Your eBay account settings we read (business policies, inventory location) to publish listings correctly.
Account data is stored in a Postgres database (Neon) with per-account isolation enforced at the database level, photos in private object storage (Cloudflare R2), and connection tokens encrypted as described above. Data is encrypted in transit (HTTPS).
Buyer information & eBay’s deletion program
To complete your sales, ebayeasy processes buyer information that eBay provides with your orders and messages (such as the buyer’s username and shipping address). We use it only to help you fulfill those orders and communicate about them — never for advertising, and we don’t sell it. ebayeasy is subscribed to eBay’s Marketplace Account Deletion program: when eBay notifies us that a user requested deletion, we purge that buyer’s personal information (message contents, username, and shipping address) from our records.
Service providers
We rely on a small set of providers to run ebayeasy, and share only what each needs:
- eBay — the marketplace your account and listings live on.
- Anthropic (Claude) — to identify items and draft listing copy and reply suggestions; the relevant item photos and text are sent for processing and are not used to train models.
- Cloudflare R2 — private storage for your item photos.
- Neon — the database; Vercel — hosting; Resend — transactional email (e.g. sign-in and digest emails).
Your choices
You can disconnect your eBay account at any time, which deletes the stored tokens. You can request deletion of your ebayeasy account; when you do, your items, photos, listings, research, orders, messages, and connection tokens are removed. To exercise any of these, contact us at brian@loew.com.
Changes & contact
We’ll update this page if our data practices change and revise the date above. Questions about privacy: brian@loew.com.