Privacy Policy
What data we process, why, how long we keep it, and your rights.
Version 3 · Effective date: 2026-07-25
This text is a draft and will be reviewed by a lawyer before publication.
1. Data controller and contact
The data controller is Umut Palabıyık, trading as a sole proprietorship established in Türkiye. The exact registered title, registered address and address for notices will be published before commercial launch (see the final section).
For privacy and data-protection requests, the contact address is [email protected].
With respect to Etsy Member data, the Operator acts as a service provider to the relevant Etsy seller under Etsy API Terms §4 and processes such data only to deliver the service to you.
2. Data processed
Account and authentication data: email address, an irreversible hash of your password, interface language preference, creation/update timestamps.
Session data: the web session cookie, and for the desktop client a short-lived access token plus a rotatable refresh-session record (device label, creation/revocation time).
Content you provide: listing titles, descriptions, tags, your presets, imported files and instructions.
Image assets are kept in two distinct classes: (a) your print designs — the production files uploaded to Printify; (b) your sales-gallery mockups — images shown only in the Etsy gallery. The two are never conflated.
Data the Application generates: price calculations, SKUs, version history, publish jobs, bulk operations and audit records.
Printify-derived data: blueprint/variant catalogue information, shop list, product states and mockup images.
Etsy-derived data (read-only): shop name, currency, shop/user identifiers and listing identifiers used for reconciliation. Listing content read from Etsy (title/description/tags) is not stored.
Connection secrets: Etsy access/refresh tokens and the Printify personal access token, stored encrypted with AES-256-GCM at the application layer, never sent to the client, never included in an export and never logged.
Technical records: error and operation logs, with tokens, passwords and personal data redacted. In addition, to limit abuse, the client source IP address of sign-in attempts is held in memory as a short-lived counter key; it is not stored persistently.
NO third-party analytics, advertising or crash telemetry is used.
3. Purposes and legal basis
Data is processed to deliver the service, prepare and validate listings, run publishing through Printify, verify the result on Etsy, keep the service secure and prevent abuse, and to meet legal obligations.
The legal basis is the performance of a contract, legitimate interest (security and service integrity) and legal obligation (KVKK art. 5; GDPR art. 6(1)(b), 6(1)(c) and 6(1)(f)). This notice also serves the disclosure duty under KVKK art. 10.
Your data is not used for any purpose other than providing the service to you. It is never sold, rented or shared for advertising.
4. Tenant isolation and access
Every record that belongs to you is tied to one account (tenant) and every query over those records is scoped to that account. Access to another user's data is prevented both at the query layer and in API responses; the very existence of another tenant's record is not disclosed. (The shared Printify product catalogue is not personal data; it is cached once for everyone and is therefore not account-scoped.)
The Operator holds the minimum access needed for system administration and troubleshooting. Connection secrets are stored encrypted and cannot be viewed in plain text.
5. AI: data-source boundaries
Only a whitelisted context is sent to the AI provider: fields describing your own product and listing (for example product type, theme, colours, materials, variant options, SEO preferences such as target audience and tone, keywords, target language and market), your current draft text and the instructions you give. The whitelist is defined in code and pinned by a regression test; no field outside it is sent.
NO Etsy-API-derived data is ever sent to the AI provider. This boundary is enforced in code and protected by regression tests; it also satisfies Etsy's own prohibition on using its API data for analytics or model training.
Tokens, passwords and account credentials are never sent to the AI provider under any circumstances.
AI output is a draft suggestion and never becomes publish-ready without your approval.
6. Transfers and sub-processors
Printify: content and images required to create and publish products are sent to the Printify API. Printify is an independent third-party service governed by its own terms and privacy policy.
Etsy: only read-only verification and reconciliation requests are made. Etsy is an independent third-party service.
AI provider: the whitelisted context above is sent. The provider is determined by configuration; in the default configuration no call is made to a real provider (mock).
Payment provider: Polar (merchant of record) is PLANNED; it is neither approved nor integrated. As of today no data is transferred to any payment provider.
Hosting/infrastructure — Render: the web application, the PostgreSQL database and the Key Value (Redis-compatible) service run on Render. These resources were created in Render's Frankfurt region.
Hosting/infrastructure — Cloudflare: DNS, TLS and proxying, and the private R2 object storage that holds the files you upload, are provided by Cloudflare. Cloudflare operates a global edge network, so traffic may pass through the edge location nearest to you, and the physical location of R2 objects is not guaranteed to be confined to a single country.
Both of these providers are in active use today. The remainder of the sub-processor list (the payment provider and the name of the email provider) will be published on this page before commercial launch (see the final section).
Email: messages sent to the support address are routed by an external email provider. Because KVKK applications also arrive at that address, this correspondence passes through that provider. Its name will be published with the final sub-processor list before commercial launch.
Etsy Member data is never transferred to, sold to or commercialised with third parties.
7. International processing
Etsy, Printify and AI providers may be established outside Türkiye, so using those services can mean your data is processed abroad.
The hosting infrastructure was created in Render's Frankfurt region, and Cloudflare operates a global edge network, so data is processed outside Türkiye. Completing the necessary legal basis under the KVKK cross-border transfer regime and — to the extent it applies to you — the GDPR transfer mechanisms is part of the lawyer review that precedes commercial launch, and the outcome will be explained on this page.
8. Retention and stale-data behaviour
Listing content read from Etsy is not stored; where it is displayed it is never more than six (6) hours old.
Etsy-derived shop information (the shop name and the fields shown with it) is never displayed more than twenty-four (24) hours old: the limit is applied at request time, the value is withheld once the window has elapsed, and a stale value is never presented as current. On the shops page the withheld value is accompanied by a re-authorization link. The shop identifier (id) is the stable key of the connection: it stays readable even when the name is withheld — otherwise you could not tell your own shops apart when you have more than one — and for the same reason it is included in your data export. The Etsy listing identifiers held in reconciliation mappings, on your listing records and in publishing job records are record keys rather than content; the ones in reconciliation mappings are deleted when you disconnect and re-derived when reconciliation runs again. These identifiers are included in your data export so that you can match your own records.
When you disconnect Etsy, Etsy-derived caches and the encrypted tokens are deleted.
Your account and content data are kept until you delete them. Deleting your account permanently deletes everything attached to it, including stored files. There are two exceptions: records subject to a statutory retention obligation, if any, which are kept for the period the applicable law requires; and, in rare cases, a stored file that could not be removed, which may remain in object storage (see the Data Deletion page).
9. Cookies and sessions
The Application uses functional cookies only: the authentication cookies that keep you signed in (the session cookie together with the CSRF and callback cookies the authentication library sets), and a cookie that remembers your interface language.
No advertising, profiling or third-party tracking cookies are used, which is why no cookie-consent banner is shown.
On the desktop client the refresh token lives in the operating-system keychain and never reaches the interface layer.
10. Age limit
The Application is a business tool for sellers running their own shops and is not directed at children. To open an account you must be at least 18 years old, or otherwise have the capacity to enter into a contract where you live.
Children's data is not knowingly collected. If such data is found to have been processed, it is deleted.
11. Your rights
Under KVKK art. 11 you have the right to learn whether your personal data is processed, to request information, to learn the purpose of processing, to request rectification or erasure, to know the third parties to whom it is transferred, to object to processing and to claim compensation for damage.
To the extent the GDPR or a US state privacy law applies to you, you also have the access, rectification, erasure, restriction, portability and objection rights that law provides. This policy makes no claim of full compliance with every jurisdiction's law; your rights are determined by the law that applies to you.
For access and portability you can export your data as JSON from inside the Application; the export contains no token, no password hash and no provider credential.
For erasure you can permanently delete your account from inside the Application. You can also disconnect Etsy or Printify only. (Revoking all of your desktop sessions lives in the desktop client and is available once the current Terms are accepted.)
Export, disconnection and account deletion do not depend on you having accepted the current Terms.
For other requests, including KVKK applications: [email protected]. Your right to complain to the Turkish Personal Data Protection Authority (KVK Kurumu) — or to your local supervisory authority where one applies to you — is reserved.
12. Security and breach notification
Tokens are encrypted with AES-256-GCM; on the desktop client the refresh token lives in the operating-system keychain. Passwords are stored as irreversible hashes.
Sign-in attempts are throttled per account and per client, and the desktop API can be switched off entirely if abuse is suspected.
If a breach affecting Etsy Member data accessed through the Etsy API is discovered, Etsy ([email protected]) and the affected seller are notified within twenty-four (24) hours, as required by Etsy API Terms §7.
Suspected credential-security issues are reported to Etsy at [email protected].
No system can be absolutely secure; the above describes the technical and organisational measures taken, not a guarantee of absolute security.
13. Changes
This policy may be updated. When a new version takes effect you are asked to accept it again the next time you open the Application (on the web, on the next page load); the version, the locale and the timestamp of your acceptance are recorded.
The data-subject-rights functions remain accessible even if you have not accepted the new version.
14. Official business details pending before commercial launch
The following official details have not been published yet and WILL be published on these pages before commercial launch (that is, before any paid subscription goes on sale). They are never guessed at or filled in with placeholders:
- The exact registered title of the sole proprietorship
- Tax identification (VKN) and invoicing details, where legally required
- The registered business address and the address for notices
- The exact competent-court and enforcement-office wording
- The final hosting provider, the sub-processor list and the processing locations
- Lawyer approval of the Terms, the Privacy Policy and the Refund Policy
Until these are settled, ListBeast is not offered for sale and these texts remain drafts. You can write to [email protected] with any question.