v2026.2.0
Privacy Policy
eListSync · Last updated August 17, 2026 · v2026.2.0
Last updated: August 17, 2026
This Privacy Policy explains how eListSync ("we", "us") collects, uses, and shares information when you visit elistsync.com, read our documentation, contact support, or use the operator application (the "Service"). It is written for merchants and site visitors. It is not a substitute for the Data Processing Addendum, which covers catalog and destination data we process on your instructions as a processor.
If you have questions, email support@elistsync.com or call +92 302 6210978.
1. Who this policy covers
This policy covers personal data we process as a controller: account and billing identifiers, support communications, website analytics of a limited kind, and security logs.
When you ingest products or connect Shopify, Amazon, TikTok Shop, WooCommerce, Medusa, Walmart, or eBay, much of that catalog and credential data is processed on your behalf as described in the DPA. You are responsible for telling your own customers how you use marketplace data.
2. Information we collect
Account and contact data. Email address, name, workspace name, phone number if you give it, and messages you send to support@elistsync.com or social channels.
Catalog and integration data (typically as processor). Product titles, descriptions, images, variants, SKUs, prices, stock, GTINs, destination IDs, OAuth tokens and API keys you connect, and sync logs. Secrets are encrypted at rest. We do not use your catalog to train public AI models.
Technical data. IP address, user agent, timestamps, approximate region derived from IP, cookie identifiers needed for session and theme preference, and request logs for security and debugging.
Legal and security records. If workspace access requires acceptance of Terms, we may store legal name, IP, user agent, timestamp, and SHA-256 hashes of the accepted document versions. Those records are kept for the period required to demonstrate consent.
Payment data. When paid billing is live, our payment processor collects card or invoice details. We receive subscription status, plan, and limited billing identifiers — not full card numbers — unless a processor dashboard we operate shows them under their terms.
We do not intentionally collect special-category data. Please do not put government ID numbers or health data into product listings.
3. How we use information
We use information to:
- Provide, secure, and improve the website, docs, and operator app
- Authenticate sessions, enforce plan limits, and operate ingest, transform, and publish pipelines
- Connect to the destinations you choose and write sync logs you can audit
- Respond to support, abuse, and security reports
- Send transactional mail (password, billing, incident notices). We do not sell marketing lists
- Comply with law and enforce our Terms
Legal bases (where GDPR/UK GDPR apply) include performance of a contract, legitimate interests in running a secure SaaS product, consent where we ask for it, and legal obligation.
4. Cookies and similar technology
We use cookies or local storage for session authentication, CSRF protection, and remembering light/dark theme. We do not run third-party advertising pixels on the marketing site as of the date above. If that changes, we will update this policy.
You can block cookies in your browser; the site may then lose theme preference or login.
5. Sharing
We share data with:
- Infrastructure providers for hosting, object storage, databases, Redis-style queues, and error monitoring, bound by contract
- Payment processors when you pay
- Marketplaces and storefronts you connect, to the extent needed to list products and sync inventory
- Professional advisers or authorities if required by law or to defend a claim
We do not sell personal information as that term is used in the CCPA/CPRA. We do not share data with data brokers for cross-context advertising.
6. International transfers
We may process data in the country where our hosting and support team operate, including Pakistan, and in regions used by our cloud providers. Where a transfer restriction applies, we use appropriate safeguards such as standard contractual clauses with processors, or your explicit instruction to publish to a marketplace in that region.
7. Retention
Account data is kept while the workspace is active and for a reasonable period after closure (typically up to 24 months) unless you request earlier deletion and no legal hold applies.
Sync logs and operational telemetry follow workspace settings and our need to debug incidents; we aim not to keep verbose request bodies longer than necessary.
Legal signature hashes and billing records are retained for the duration required by applicable law (often several years).
Backups rotate on a fixed schedule. Deletion from backups occurs as those snapshots expire.
8. Security
We use HTTPS in transit, access controls, encryption of destination secrets at rest (AES-GCM in our architecture), tenant isolation (including Postgres row-level security in the operator stack), and circuit breakers so a failing destination does not cascade. No method of transmission or storage is 100% secure. Report suspected vulnerabilities to support@elistsync.com.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict personal data, to object to certain processing, and to withdraw consent. You may also lodge a complaint with a supervisory authority.
To exercise rights, email support@elistsync.com from the address on the account and describe the request. We may need to verify identity. We will not delete records we are required to keep (for example hashed Terms acceptance or invoices).
If we process catalog data only as your processor, we will redirect consumer requests about that data to you, or act on your documented instruction.
10. Children
The Service is not directed to children under 16 (or 13 where that is the applicable age). We do not knowingly collect their data. If you believe we have, contact support@elistsync.com and we will delete it.
11. Changes
We will post updates here and change the "Last updated" date and version. Material changes for account holders may also be noted by email or in-app notice.
12. Contact
eListSync