Last updated: March 9, 2026
Privacy Policy
Introduction
Summary: We protect your privacy. This policy explains what data we collect and how we use it.
ShopShield ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our listing compliance checking service.
By using ShopShield, you consent to the practices described in this policy. If you do not agree, please do not use our service.
Information We Collect
Summary: We collect only what's necessary: your email, password, and Etsy listing data. We never access your sales, financial info, or customer data.
Account Information
When you create an account, we collect:
- Email address
- Password (stored securely using industry-standard bcrypt hashing)
- Name (optional)
Etsy Shop Data
When you connect your Etsy shop, we access only the data necessary to provide our service:
- Listing titles, descriptions, and tags
- Listing images (for AI compliance scanning)
- Basic shop information (shop name, URL)
We do NOT access: Your sales data, revenue, financial information, customer data, personal messages, or any other sensitive information.
Payment Information
Payment processing is handled entirely by Stripe. We do not store credit card numbers or banking details on our servers. We only receive confirmation of payment status.
How We Use Your Information
Summary: We use your data to scan listings, provide recommendations, and improve our service. That's it.
We use the information we collect to:
- Scan your listings for potential trademark and policy violations
- Provide risk assessments and actionable recommendations
- Generate AI-powered suggestions for fixing flagged content
- Push listing updates to Etsy on your behalf (when you authorize it)
- Process your subscription payments
- Send you service-related notifications and emails
- Improve our compliance detection algorithms
AI-Powered Analysis
Summary: We use AI models hosted by Alibaba Cloud (Dashscope) to analyze your listings for compliance issues. Your data is processed via API and is not used to train their models.
We use artificial intelligence to analyze your listings for potential compliance issues:
Alibaba Cloud / Dashscope (Currently Active)
- Image scanning: The
qwen-vl-maxvision model analyzes product images for potential intellectual property violations - Listing analysis: The
qwen-pluslanguage model generates safe alternative wording for flagged text - Data sent: Listing images, titles, descriptions, and tags
- Data retention: Data submitted via API is not retained for model training purposes
View Alibaba Cloud's privacy policy: alibabacloud.com/privacy
Important: We do not permanently store your images on our servers. Images are transmitted to the AI provider for analysis and then discarded. You can opt out of image scanning by not uploading images.
Third-Party Services
Summary: We integrate with Etsy (for shop access), Stripe (payments), Alibaba Cloud/Dashscope (AI analysis), Resend (emails), Google Analytics (analytics), and Umami (self-hosted analytics). Each has their own privacy policy.
| Service | Purpose | Data Shared |
|---|---|---|
| Etsy API | Shop & listing sync | OAuth tokens, listing data |
| Stripe | Payment processing | Payment info (not stored by us) |
| Alibaba Cloud (Dashscope) | AI compliance analysis | Listing content & images (temporary) |
| Resend | Transactional email | Email address |
| Google Analytics | Website analytics | Anonymized usage data, page views |
| Umami (self-hosted) | Privacy-friendly analytics | Page views, referrer (no personal data) |
These services have their own privacy policies. We encourage you to review them.
Data Sharing and Disclosure
Summary: We never sell your data. We only share what's necessary with our service providers.
We do not sell your personal information or listing data. Ever.
We may share data only:
- With Etsy, to perform authorized actions on your listings
- With Stripe, to process payments
- With Alibaba Cloud (Dashscope), to analyze your listings for compliance issues
- With Resend, to send you service emails
- If required by law or to protect our legal rights
Data Security
Summary: We use encryption, secure password hashing, and OAuth to protect your data. Your Etsy password is never shared with us.
We implement industry-standard security measures to protect your data, including:
- Encrypted data transmission: All data is transmitted via HTTPS/TLS
- Secure password hashing: We use bcrypt with appropriate salt rounds
- OAuth 2.0 authentication: Your Etsy password is never shared with us
- Secure infrastructure: Our servers are hosted in secure data centers
- Regular security reviews: We continuously monitor and update our security practices
Cookies and Tracking
Summary: We use essential cookies for login and session management. With your consent, we also use Google Analytics for website analytics.
We use minimal cookies for essential functionality:
- Session cookies: Keep you logged in during your session
- Preference cookies: Remember your settings and preferences
- Security cookies: Help protect against CSRF attacks
- Analytics cookies (optional): With your consent, Google Analytics (GA4) cookies help us understand how visitors use our site. You can manage this via the cookie banner.
We do NOT use:
- Third-party advertising cookies
- Cross-site tracking
- Browser fingerprinting for advertising (we use fingerprinting solely for rate-limiting free scans)
- Retargeting pixels
You can disable cookies in your browser settings, but some features may not work properly.
Data Retention
Summary: We keep your data while your account is active. Delete your account and we'll delete your data immediately.
We retain your account data and scan history for as long as your account is active. If you delete your account, we will delete your personal data immediately, except where we are required to retain it for legal or compliance purposes.
Listing images: Are not permanently stored. They are transmitted to Alibaba Cloud (Dashscope) for analysis and then discarded.
Scan results: Are retained to provide you with historical compliance data and to improve our service.
International Data Transfers
Summary: Your data may be processed in the United States and Singapore by our service providers.
To provide our services, your data may be transferred to and processed in countries outside your country of residence:
- United States: Stripe (payment processing), Google Analytics (website analytics)
- Singapore: Alibaba Cloud Dashscope (AI-powered listing analysis using qwen-vl-max and qwen-plus models)
These transfers are protected by Standard Contractual Clauses (SCCs) and each provider's data protection commitments. We only share the minimum data necessary for each service to function.
Your Rights (European Users - GDPR)
Summary: EU users have specific rights including access, correction, deletion, and data portability. Contact [email protected] to exercise them.
If you are located in the European Economic Area (EEA), you have specific rights under the General Data Protection Regulation (GDPR):
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Data Portability: Receive your data in a portable, machine-readable format
- Right to Object: Object to certain processing activities
- Right to Withdraw Consent: Withdraw consent at any time for consent-based processing
Our legal basis for processing:
- Contract performance: Providing the service you signed up for
- Legitimate interests: Improving our service, preventing fraud
- Consent: Marketing emails, optional features
To exercise these rights, email: [email protected]
California Privacy Rights (CCPA)
Summary: California residents have additional privacy rights. We do not sell your personal information.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: What personal information we collect, use, and share
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the sale of personal information (note: we do NOT sell personal information)
- Right to Non-Discrimination: Equal service and pricing regardless of privacy choices
To submit a CCPA request, email: [email protected]
Children's Privacy
Summary: Our service is for adults only. We do not knowingly collect data from children under 18.
Our service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately at [email protected].
Changes to This Policy
Summary: We may update this policy. We'll notify you of significant changes by email.
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons.
We will notify you of any significant changes by email or through a prominent notice on our service. Your continued use of ShopShield after changes take effect constitutes acceptance of the revised policy.
Contact Us
Summary: Questions? Reach out to us. We're happy to help.
If you have questions about this Privacy Policy or our data practices, please contact us:
Privacy inquiries:
[email protected]
Response time: Within 30 days
General support:
Data Processing Contact
For data processing inquiries, data subject access requests, or questions about how your data is handled by our third-party processors:
[email protected]
Response time: Within 30 days