1. Who We Are
This Privacy Policy explains how Hive Mind Nestor Private Limited ("Hive Mind Nestor", "we", "us", or "our") collects, uses, shares, and protects your personal data when you use ESeller360 (the "Service"), a seller productivity application for Etsy shop owners.
This Policy applies specifically to ESeller360. We are the data controller for the personal data we process about you, except where we process Etsy shop data on behalf of a seller, in which case we act as a data processor for that seller.
Registered office: MMIG-4, Shaheed Nagar, Agra-282001, Uttar Pradesh, India
Privacy contact: info@hivemindnestor.com
2. Data We Collect
We collect the following categories of data:
- Account information: name, email address, and password hash when you register for an ESeller360 account.
- Etsy OAuth tokens: when you connect your Etsy shop, we receive and store access tokens and refresh tokens issued by Etsy through the OAuth 2.0 authorization flow. We never receive, request, or store your Etsy login credentials.
- Etsy shop data: through the Etsy Open API v3, and only after you authorize the connection, we access shop details, listings, receipts and transactions (orders), and inventory levels for the shop you connect.
- Usage data: IP address, browser type, device identifiers, pages visited, actions taken, and timestamps, collected automatically through cookies and server logs.
- Communications data: messages you send us via email, contact forms, or support channels.
3. How We Use Your Data
We process data for the following purposes:
- To provide, operate, and maintain the ESeller360 Service;
- To make authenticated requests to the Etsy Open API v3 on your behalf;
- To power listing management, bulk editing, order management, inventory monitoring, and analytics features;
- To perform actions you explicitly initiate on your own Etsy shop;
- To communicate with you about your account, service updates, and support requests;
- To detect, prevent, and investigate fraud, abuse, and security incidents;
- To comply with legal obligations, including tax and accounting requirements.
4. Etsy API Data Handling
ESeller360 integrates with Etsy's Open API v3. Our handling of Etsy data is governed by the following commitments:
- Etsy shop data is accessed only via the official Etsy Open API v3, and only after you complete Etsy's OAuth 2.0 authorization flow;
- During authorization we request only the scopes required for the Service:
listings_r,listings_w,transactions_r,transactions_w,shops_r,shops_w,inventory_r, andinventory_w; - Etsy shop data is used exclusively to power the features you have enabled within ESeller360 for your own shop, and is never aggregated across sellers, sold, or shared with third parties;
- Etsy data is accessed only for the shop you connect — ESeller360 never accesses any shop other than your own;
- Access tokens and refresh tokens are stored securely, encrypted, and rotated automatically before expiry;
- You can disconnect your Etsy shop and revoke ESeller360's access at any time from within the application settings.
5. Third Parties We Share Data With
We do not sell your data. We share data only with the following categories of third parties:
- Etsy, Inc. — to retrieve and update shop data on your behalf, under your authorization, via the Etsy Open API v3;
- Cloud infrastructure providers — for hosting, storage, and compute of the Service;
- Payment processors — to handle ESeller360 subscription billing;
- Professional advisors and authorities — lawyers, accountants, and regulators, where necessary and lawful.
6. Data Retention
We retain data only as long as necessary to provide the Service and to comply with our legal obligations:
- Account data and Etsy shop data are retained for the duration of your active subscription;
- OAuth tokens and Etsy shop data are permanently deleted within 30 days of account closure or upon you disconnecting your Etsy shop;
- Billing records are retained as required by applicable tax and accounting law;
- Server and access logs are retained for up to 12 months.
7. Your Rights
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request deletion of your data;
- Restrict or object to processing;
- Data portability;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, email info@hivemindnestor.com. We will respond within 30 days.
8. Security
We implement technical and organizational measures appropriate to the sensitivity of the data we process, including encryption in transit (TLS), encryption at rest for sensitive fields such as OAuth tokens, role-based access control, audit logging, and regular security reviews. Despite our efforts, no system is perfectly secure, and we cannot guarantee absolute protection.
If you become aware of a security incident affecting your data, please report it to info@hivemindnestor.com.
9. Disconnecting & Revoking Access
You may disconnect your Etsy shop from ESeller360 at any time within the application settings. Disconnecting revokes ESeller360's access to your Etsy shop and triggers deletion of the associated OAuth tokens and Etsy shop data within 30 days. You may also revoke access directly from your Etsy account settings.
10. Children's Data
ESeller360 is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe we have collected data from a minor, please contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to you by email or through a notice within the Service. Continued use of ESeller360 after updates take effect constitutes acceptance of the revised Policy.
12. Contact Us
For any privacy-related questions or to exercise your data protection rights, contact us at info@hivemindnestor.com.
The term "Etsy" is a trademark of Etsy, Inc. ESeller360 uses the Etsy API but is not endorsed or certified by Etsy, Inc.