Who we are
Etsy Tracker is an independent research and tracking tool for Etsy sellers. It is not affiliated with, endorsed by, or partnered with Etsy, Inc. References to Etsy in this policy are descriptive only and identify the marketplace whose public pages sellers analyze while using the service.
This privacy policy explains how personal data is handled across the parts of the service a user normally interacts with: the public website, the authenticated dashboard, the browser extension used for on-page discovery, the billing and account flows, and the feedback, chat, and support channels attached to the product.
The policy is written for the whole service. Individual features may collect only a small subset of what is described below, and some categories only apply once a user signs in, installs the extension, or subscribes to a paid plan.
Data we collect
The categories of personal data handled by the service can be summarized as follows. Each category is explained in more detail in its own section further down.
- Account, session, and install-token data used to keep a user signed in and to associate activity with the correct account and workspace.
- Extension-submitted discovery data captured from Etsy pages the user opens in their own browser while using the extension.
- Workspace, shop, listing, and keyword tracking data created inside the dashboard, including snapshots and derived metrics.
- Feedback, chat, and support data submitted through the in-product widget or through direct support conversations.
- Billing identifiers and subscription status received from Paddle in connection with paid plans.
- Operational logs and anti-abuse signals needed to keep the service reliable, secure, and free of automated abuse.
Account, session, and install-token data
When a user signs in, the service stores the account email address and the minimum authentication state needed to keep the session working. A service session cookie is set on the user's browser to keep the user signed in between page loads.
A first-party service identity cookie and an install token are used to link the browser and the extension to the correct account and workspace, to enforce plan limits, to support referrals and link-account flows, and to detect anti-abuse patterns such as one install token being shared across many unrelated accounts.
Plan level, access status, workspace membership, limit counters, referral state, and anti-abuse state are stored against the account so that the dashboard, billing flows, and extension can behave consistently. Etsy Tracker does not ask for and does not store Etsy login credentials of any kind.
Extension data
Discovery of Etsy search results, shop pages, and listing pages happens browser-side through the WebExtension. The extension observes the pages the user opens in the user's own browser and forwards structured signals about those pages to the service so they can be organized inside the dashboard.
Backend does not scrape Etsy search pages server-side. There is no server-side crawler that opens Etsy search results, solves marketplace protections, or drives automated sessions against Etsy on behalf of the user.
- Search keywords the user is researching and the workspace context in which those keywords are being tracked.
- Organic search card signals such as visible position, title, and shop reference, where the extension can read them from the current page.
- Shop and listing identifiers, titles, URLs, and public shop signals visible on the pages the user opens.
- Snapshots of quantity, price, favorites, and status fields where those fields are exposed on the public listing page.
- Promoted and ad cards are filtered where they can be detected, so that paid placement does not contaminate organic movement analysis.
- The extension uses the first-party service identity and install token to associate submitted data with the correct account and workspace so that results appear where the user expects them.
Etsy data we do not collect
The service is deliberately narrow about what it reads from Etsy. The following statements apply to both the backend and the browser extension.
- We do not read Etsy cookies.
- We do not read Etsy localStorage.
- We do not read Etsy sessionStorage.
- We do not collect private Etsy account data such as order history, buyer information, seller finances, private messages, or shop admin state.
- We do not use browser fingerprinting as an identity mechanism. Identity is anchored to the first-party service session and install token, not to fingerprint hashes.
- We do not ask for or store Etsy passwords, two-factor codes, or any other Etsy authentication material.
- Etsy captcha, Cloudflare, and DataDome checks remain in the user's own browser. When the marketplace shows such a challenge, the user solves it in their normal browsing session; the service does not attempt to solve or bypass those checks server-side.
Dashboard, workspace, shop, listing, and keyword data
Data collected through the extension and through direct actions in the dashboard is organized into workspaces and projects that belong to the account. This lets a single account keep several research contexts separated.
- Workspaces and projects that group related research together.
- Saved keywords used to seed niche validation and to track how a keyword's competitive landscape evolves over time.
- Tracked competitor shops added to a workspace so their public listing set can be monitored.
- Tracked listings selected out of shops or discovered through the extension.
- A Found via provenance field that records the source context in which a listing entered the workspace, so historical attribution can be reviewed later.
- Listing snapshots including quantity, price, favorites, and status fields where those fields are exposed on the public listing page.
- Plan locks that hide unavailable views, historical views for older data, and closed or not-selling status where the service can infer it from public state.
- Data may be delayed, incomplete, or unavailable depending on Etsy marketplace changes, public page availability, extension coverage, and rate-limit conditions on public endpoints.
Feedback, chat, and support data
When a user contacts the service through the in-product feedback widget, through the chat widget, or through a direct support conversation, the content of the message is stored so the request can be answered and later referenced if the same user contacts support again.
- The text of feedback, chat, and support messages sent by the user.
- The account email and account context attached automatically to a support request, so the request can be matched to the correct account and plan.
- Screenshots or short screen recordings if the user chooses to attach them to a bug report.
- Structured bug report fields such as page URL, shop, listing, or keyword involved, expected behavior, and actual behavior.
Billing data via Paddle
Paid subscriptions are processed by Paddle as Merchant of Record. Paddle handles the checkout page, payment card data, receipts, tax calculation and collection where applicable, dunning on failed payments, and the overall subscription lifecycle.
Etsy Tracker receives from Paddle only the limited billing identifiers and status information needed to reflect the subscription inside the account. This typically includes the plan, a Paddle customer or subscription reference, a transaction reference, and renewal, cancellation, or failure status. Full payment card numbers, CVV codes, and bank details are not received by Etsy Tracker.
Users should never send full card numbers, CVV codes, or full bank credentials into support messages. Paddle transaction and subscription references are enough to resolve almost every billing question.
Logs, security, and anti-abuse
Operational logs are recorded so the service can be run reliably and investigated when something goes wrong.
- Timestamps, request context, and error diagnostics that describe how a request was handled.
- Rate-limit counters and abuse or security signals collected to detect scripted traffic, credential-stuffing attempts, and repeated failures.
- Linked-device and install-token misuse detection, used to notice when the same install token is being reused across many unrelated accounts.
- Plan-limit enforcement counters that track how much of a plan quota has been consumed.
- Fraud, chargeback, credential-sharing, resale, and mass-export abuse indicators that inform account decisions when abuse is suspected.
How we use data
The data described above is used for the following purposes only.
- Provide the dashboard, tracking, import, and snapshot features that the product is built around.
- Connect extension submissions to the correct account, workspace, and Found via context.
- Enforce plan limits and access rules so that each account gets what its plan describes.
- Process billing status received from Paddle and reflect it in the account.
- Respond to support requests and feedback.
- Debug reliability problems and investigate errors so they can be fixed.
- Prevent abuse and security incidents, including automated extraction attempts and credential sharing.
- Improve product reliability by studying aggregate failure modes and by tightening code paths that misbehave.
Legal bases
Depending on the user's location, different legal bases may apply to the processing described above. The service does not claim jurisdiction it has not confirmed, but the following neutral bases generally apply.
- Performance of a contract or service delivery, for processing that is needed to actually run the account and deliver the features the user signed up for.
- Legitimate interests, for security, anti-abuse, reliability, support, and product improvement, weighed against user rights.
- Consent or user choice, where required for optional cookies or optional communications.
- Legal obligations, for billing, tax, accounting, and dispute records that must be retained for a defined period.
Processors and third-party services
The service uses a small set of third parties to actually run. Processors only receive the data they need for their specific task.
- Paddle, verified as the payment processor and Merchant of Record for paid subscriptions.
- Hosting, database, and infrastructure providers that run the servers and storage the service depends on.
- Email, support, chat, and monitoring providers used as a general category to deliver notifications, support conversations, and uptime signals. Specific vendors in this category are not named here unless they are separately confirmed inside the product.
- Professional advisers in legal, accounting, and security roles where their involvement is necessary to run the business.
Data retention
Personal data is retained only for as long as it is needed for the purposes described above, or as long as required by a legal, billing, or security obligation.
- Account data is retained as long as the account and service relationship require it.
- Dashboard, workspace, and tracking history is retained in line with the plan's history depth and with product needs such as showing longer-term movement.
- Support and feedback conversations are retained so service history can be reviewed and so disputes or security incidents can be investigated.
- Billing records may be retained for the period required by Paddle, by applicable tax and accounting rules, and by chargeback and dispute handling.
- Deletion, export, and correction requests can be submitted through the website chat widget or Feedback on the website.
- Some operational, security, and legal records may be retained even after an account closes, where retention is required by law or by legitimate security needs.
User rights
Depending on the user's location, applicable law may give the user rights over their personal data. Where those rights apply, the service will honor them subject to reasonable verification and to any legal or operational limits.
- The user may request access to the personal data associated with the account.
- The user may request correction of inaccurate personal data.
- The user may request deletion of personal data where deletion is possible under applicable law and does not conflict with billing, security, or legal retention.
- The user may request an export of personal data associated with the account.
- The user may request restriction of, or object to, certain processing where applicable law provides that right.
- Requests should be submitted through the website chat widget or Feedback on the website.
- Reasonable identity and account verification may be required before a request is fulfilled, so that data is not disclosed to the wrong person.
- Some requests may be limited by legal, billing, security, anti-abuse, or operational obligations. When a request cannot be fully honored, the service will explain the reason.
Security
The service uses reasonable technical and organizational safeguards to protect personal data. These include access controls, encrypted transport for public endpoints, and separation between production and non-production environments.
No online service can be guaranteed to be one hundred percent secure. Users are expected to protect their own account, session, and browser access, including by using strong unique passwords, by locking devices, and by keeping the browser and extensions up to date.
Users should not send full payment card numbers, CVV codes, or account passwords into any support message. This information is never needed to resolve a support request.
Children
The service is not intended for children and is not designed to be used by children. Personal data of children is not knowingly collected.
If a parent or guardian believes that a child's personal data has been submitted to the service, they should contact us through the website chat widget or Feedback on the website so the account and data can be reviewed and, where appropriate, removed.
International users and transfers
The service and its providers may operate in different countries. Personal data may be processed or transferred to countries where the infrastructure providers, Paddle, support providers, or other service providers operate.
Where legally required, appropriate safeguards are used for such transfers. The service does not attempt to describe every jurisdiction here; users with specific transfer questions can request more detail through the support route.
Changes
This privacy policy can be updated as the service, its providers, or applicable law change. When the policy is updated, the Last updated date at the top of the page will change.
Material changes may also be communicated through the site or the account, where that is appropriate. Continued use of the service after an update means the updated policy applies going forward.
Contact
Privacy questions, rights requests, and other privacy-related messages can be submitted through the website chat widget or Feedback on the website. Please include the account email and enough context to locate the account or the data the request is about.
No fake or placeholder support email address is listed on this page. A dedicated public privacy address may be added here later; when it is available, it will appear on this page.