Trovewright — privacy policy
What we collect, what we keep, what we never sell.
Trovewright runs a resale floor on your behalf across six marketplaces. This page explains, in plain English, what data flows through the floor, who sees it, and how you can ask for a copy or have it deleted. If you want the same answer in two minutes instead of ten, the founder's inbox is the fastest route.
What we collect
To run an AI-staffed floor on your behalf, we store the minimum data each shift needs to do its job:
- Account data. The name and email you sign up with, and the email our auth layer uses to keep you signed in.
- Inventory you load. Titles, descriptions, measurements, brand, condition, and the photos you upload for each item.
- Marketplace tokens.When you connect eBay, Etsy, Poshmark, Mercari, Shopify, or Vinted, we store a scoped OAuth token so the agents can list, reprice, and answer buyers on those channels. Tokens are stored with least-privilege scope (we request only what each listing action needs) and can be revoked from your dashboard or from each channel's own connected-apps page.
- Payment metadata. The Stripe billing module handles your actual card; we store the billing receipts (amount, currency, when, what for) so your dashboard can show transaction history. We never see or store your card number, CVV, or expiry date.
- Operational logs. Standard request metadata (IP, user agent, timestamps) used for security, abuse detection, and reconstructing what agents did when something goes wrong on a shift.
How we use it
The same data set powers a handful of specific jobs — and nothing else:
- Running the sourcing, listing, repricing, buyer-message, and shipping-label agents on your behalf.
- Sending transactional email: charge receipts, shift-error alerts, security notices.
- Enforcing per-channel compliance — eBay, Poshmark, Mercari, Etsy, Shopify, and Vinted each have rules about listing copy, prohibited items, and counter-signals; the floor checks each output against them before publish.
- Improving the product: aggregated counters (how many picks a week, how fast a bot replies) used to tune agent defaults. Pick-by-pick traces are never shared, sold, or advertised against.
We do not sell personal data; we do not run advertising retargeting; we do not enrich your profile from third-party data brokers.
Marketplaces, AI partners, and other processors
Item data, photos, and messages flow through several processors that operate as our sub-contractors:
- Marketplace channels (eBay, Etsy, Poshmark, Mercari, Shopify, Vinted). Listings, messages, and shipping labels traverse each channel under their own terms of service. A refusal or takedown on a channel is governed by that channel's policy, not ours.
- AI generation (OpenAI, via the Polsia proxy). Listing copy and buyer-reply drafts are generated against your shop voice, then reviewed before send. Prompts and responses are processed under our agreement with the provider and are not used to train their base models.
- Payments (Stripe). Subscriptions, one-time charges, and per-sale settlement metadata are handled by the installed billing module.
- Email delivery.Transactional email (receipts, security alerts, onboarding) is sent through Polsia's authenticated email proxy.
- Hosting and database. A managed Postgres instance plus serverless compute; both sit behind TLS and per-tenant row isolation.
Cookies and authentication
The floor uses a single session cookie issued by our auth provider (better-auth) to keep you signed in. We do not use third-party advertising cookies, third-party analytics cookies, or cross-site tracking pixels. Clearing that cookie in your browser signs you out; clearing the cookie does not delete your account or your inventory.
Payment data
Payment instruments are handled entirely by Stripe through the installed billing module. We do not see or store card numbers, CVV codes, or expiration dates — those flow directly to Stripe and back. We do keep billing receipts (amount, currency, when, what for) so your in-app transaction history is useful for bookkeeping. PCI-DSS handling is Stripe's, not ours.
Refunds and cancellation
Refund and cancellation terms — including how a subscription is stopped, what happens to your inventory when it stops, and which fees settle per-sale versus refund — live on our terms of service page, which is the canonical version of those rules.
Your rights
You can ask for any of the following, and a human (the founder) will answer:
- Access. A copy of every row we hold tied to your account: inventory, photos, agent logs, billing receipts.
- Correction.A fix to anything that's wrong — a typo in your shop address, a misread measurement, an outdated photo.
- Export. A machine-readable dump of your data so you can move to another tool. We will not make this hard.
- Deletion. A full erasure of your account, inventory, photos, and billing history, subject to the records we are legally required to retain (tax receipts generally stay seven years; that is the law, not us).
Automated decisions — for example, a refund routing on a return case, or a counterfeit-risk flag on a new listing — are surfaced for human review before we act on them. The founder looks at edge cases personally.
How we keep it safe
Data in transit is encrypted with TLS; data at rest is encrypted by the underlying database provider. OAuth tokens are stored with least-privilege scope and are rotated on demand. Production access is gated behind single-sign-on hardware keys and per-environment credentials. We do not claim our security is unhackable — no honest operator does — but we do commit to notifying you within 72 hours of any breach that touches your data, in plain English, with what was exposed and what to do.
Questions, exports, deletions
Reach the founder directly.
For privacy questions, a copy of your data, or a deletion request, email trovewright-10@polsia.app with “Privacy / data request” in the subject. The founder answers personally, usually within one business day.
Data controller
Trovewright — single-operator product.
Contact email: trovewright-10@polsia.app
Last updated: 2026-08-11