Beta

Legal

Privacy Policy

This Privacy Policy explains how Updely collects, uses, shares, protects and deletes personal data when you visit the website, create an account or connect a commerce platform.

Last updated:

Controller and contact details

The service is operated by JJ, a sole proprietorship established in Poland. For the purposes of applicable data protection law, this entity is the controller of personal data processed to provide Updely, except where it acts only on documented instructions as a processor for a customer. Tax Identification Number: 549-247-22-32.

Privacy questions and requests can be sent to [email protected]. General support is available at [email protected]. The public service address is https://updely.com.

Information we collect

The information processed depends on the features you use and the platforms you choose to connect. It may include:

  • Account and profile data, including name, email address, authentication identifiers, language, preferences and workspace membership.
  • Connected-store data such as shop identifiers, shop profile details, listings, products, inventory status, images, tags and performance information made available by the platform.
  • Order and transaction information made available by the connected platform, including identifiers, items, amounts, status and timestamps. Depending on the administrator's delivery configuration, Updely may use a buyer email returned in authorized Etsy receipt data, a recipient-provided listing variation, or an address confirmed manually by the seller.
  • Files, delivery rules, templates, notes, settings and other content you upload, create or configure in the service.
  • Technical, security and usage data such as IP address, browser, device, timestamps, logs, page interactions and diagnostic events.
  • Messages, attachments and other information you provide when contacting support, reporting a problem or participating in product research.

Sources of information

We obtain information from the following sources:

  • Directly from you when you create an account, configure the service, upload content or communicate with us.
  • From third-party commerce platforms that you deliberately connect through their authorization process, including Etsy and, when available, Shopify.
  • Automatically from your browser, device and use of the service through essential cookies, logs and security tooling.

Commerce platform integrations

You choose whether to connect a third-party platform. Updely uses platform-provided authorization mechanisms, such as OAuth, and requests only the permissions needed for enabled features. You can disconnect a store from Updely and may also revoke access from the platform account settings.

Third-party platforms independently determine which data they make available and apply their own terms, privacy policies, retention rules and technical limits. Updely does not receive your marketplace password and is not responsible for the independent privacy practices of those platforms.

Etsy API data and controls

When you connect your own shop, Updely may process shop identifiers and profile details, listings, products, variations, orders and transactions made available by Etsy within the approved permissions. Buyer contact details are used only when Etsy returns them in authorized order data and they are needed for a workflow configured by the seller.

Connecting Etsy is optional. Updely limits OAuth access to the features enabled by the seller, makes API requests from its protected server environment and safeguards stored credentials. Disconnecting a shop stops new synchronization and removes the stored integration tokens.

Updely does not currently process public Etsy listing, shop or search-result data for Listing Audit, Shop Audit or Listing Planner in production. If Etsy approves that scope, this Policy will be updated before release to describe the final approved fields, purposes and retention periods.

Sharing and service providers

We do not sell personal data. We share information only when necessary to operate the service, follow your instructions, protect rights and security, complete a business transaction or comply with law.

Vendors are selected for operational need and are expected to process data under appropriate confidentiality, security and data-protection obligations. Categories may include:

  • Cloud hosting, content delivery and infrastructure providers.
  • Authentication, database, storage and backup providers, including Supabase where configured.
  • Transactional email and delivery providers, including Resend where configured.
  • Security, monitoring, analytics and customer-support providers used to maintain the service.
  • Professional advisers, authorities or counterparties where disclosure is legally required or reasonably necessary for a corporate transaction or legal claim.

International data transfers

Service providers may process information in countries other than the country where you live. Those countries may have different data-protection laws.

Where required, we use appropriate safeguards for international transfers, such as adequacy decisions, standard contractual clauses or another lawful transfer mechanism, together with supplementary measures where appropriate.

Data retention

We retain account and workspace data while your account is active and for as long as reasonably needed to provide the service. Integration tokens are retained only while the relevant connection is active or until they are revoked, replaced or deleted.

After deletion or disconnection, some information may remain for a limited period in backups, security logs or records required by law, dispute resolution or fraud prevention. Retention periods depend on the data category, purpose and legal requirements.

Security

We use technical and organizational measures designed to protect information, including access controls, least-privilege practices, encrypted transport, protected credentials, logging and service-provider safeguards.

No internet service can guarantee absolute security. You are responsible for protecting your credentials, using appropriate account security and promptly reporting suspected unauthorized access.

Disconnecting integrations and deleting data

You can disconnect a connected store from the integration settings. Disconnecting stops new synchronization and causes the related authorization credentials to be revoked or deleted, but it does not automatically remove all account, billing, security or historical workspace records that must be retained for another lawful purpose.

To request deletion of your Updely account and associated personal data, contact [email protected] or [email protected] from the email address assigned to the account. We may verify your identity and authority before completing the request.

  • Account profile, workspace membership and user preferences.
  • Active platform authorization tokens and stored integration credentials.
  • Connected-store data, synchronized listings, orders and operational records, subject to legal retention requirements.
  • User-uploaded files, templates, rules and other workspace content that is not required to be retained.
  • Deletion is completed within the period required by applicable law; residual copies may remain temporarily in protected backups and security logs.

Your rights and choices

Subject to your location, applicable law and relevant exceptions, you may have the right to:

  • Request access to personal data and information about how it is processed.
  • Request correction of inaccurate or incomplete personal data.
  • Request deletion of personal data that is no longer needed or otherwise must be erased.
  • Request restriction of processing in circumstances provided by law.
  • Receive certain personal data in a structured, commonly used and machine-readable format.
  • Object to processing based on legitimate interests and withdraw consent where processing relies on consent.
  • Lodge a complaint with the competent data-protection authority. We encourage you to contact us first so we can try to resolve the concern.

Cookies and similar technologies

Updely may use cookies or local storage that are strictly necessary for authentication, language, security, session continuity and core functionality.

Optional analytics or marketing technologies will be used only when implemented and where the required notice and consent mechanism is available. You can also control cookies through your browser settings, although disabling essential storage may prevent parts of the service from working.

Children

Updely is intended for people who are legally able to operate a seller account and is not directed to children. We do not knowingly collect personal data from children below the age at which they may independently consent to online services in their jurisdiction.

Changes and contact

We may update this policy to reflect changes to the service, providers, law or data practices. The date shown at the top identifies the current version. Material changes will be communicated through the service or another reasonable channel where required.

To exercise a privacy right or ask a question, contact [email protected]. We may request information needed to verify identity, authority and the scope of the request before taking action.