Privacy policy
Last updated 4 September 2026 · Applies to storevitals.app and the StoreVitals application.
StoreVitals ("we", "us") is a diagnostic tool for Etsy sellers. This policy explains what we collect, why, and what we do with it. The short version: we read your shop's data so we can show it back to you with a diagnosis; we do not sell it, we do not write to your shop, and we store as little as we can.
Who we are
StoreVitals is operated by [confirm: legal entity name and country]. You can reach us at hello@storevitals.app.
What we collect, and why
Waitlist. If you join the waitlist we store the email address, shop URL, order-volume range and Google Analytics answer you give us, the page you submitted from, and the time. We use these to contact you about early access and to understand who is asking. We do not add you to any other list.
Account. When the application launches, signing in creates an account holding your email address and a randomly generated workspace identifier. Authentication is handled by a managed identity provider; we do not store your password.
Etsy shop data. With your permission, granted through Etsy's own authorisation screen, we read your shop's listings, orders, transactions, payment ledger and reviews. We request read-only scopes and never write to, publish to, or change anything in your shop. This data is what the product runs on: it is stored in your workspace and used to compute the findings, verdicts and figures shown to you.
Review text is not stored. For reviews we keep the star rating, the date and whether the review had text. We never store a buyer's words.
Google Analytics. If you choose to connect a Google Analytics property, we read aggregated traffic and engagement data for your shop pages. This data carries no personal information about your visitors and no money figures; it is joined to your Etsy data by listing only.
Costs you enter. Cost-of-goods figures and supplier invoices you upload are used only to compute your profit. Invoice files are parsed for a column mapping and the resulting figures; we do not use them for anything else.
Questions you ask. Questions typed into "Ask your shop" are sent, together with the relevant figures from your workspace, to a third-party language-model provider to compose the answer. The provider is contractually prohibited from training on this data. [confirm: name the provider and link its data-processing terms.]
Technical logs. Standard server logs (request paths, timestamps, error details) are kept for a limited period to keep the service running and to investigate problems.
What we do not do
- We do not sell or rent your data, and we do not share it with advertisers.
- We do not write to your Etsy shop or act on your behalf.
- We do not use your shop's data to build models or benchmarks unless you explicitly opt in to anonymised benchmarking, which is off by default.
- We do not place tracking cookies on this website. The application uses a session cookie strictly to keep you signed in.
Where your data is stored
Data is stored with Amazon Web Services in the Sydney region (ap-southeast-2). Access tokens for Etsy and Google are encrypted at rest. [confirm: whether a different region is used for any component.]
How long we keep it
Waitlist entries are kept until launch and for a reasonable period afterwards, then deleted unless you have created an account. Workspace data is kept for as long as your account exists. When you delete your account, or ask us to, your workspace and its data are deleted within 30 days, and revoking our access in your Etsy or Google account settings stops any further reads immediately.
Your rights
You can ask us at any time what we hold about you, ask for it to be corrected or deleted, or ask for a copy. Email hello@storevitals.app. If you are in the UK, EU or Australia you also have the rights set out in the applicable privacy law, including the right to complain to your supervisory authority.
Third parties we rely on
- Amazon Web Services: hosting and storage.
- Etsy, Inc.: the source of your shop data, under Etsy's API terms.
- Google: Google Analytics data, if you connect it, and sign-in.
- Stripe: payments, when paid plans launch. Card details go to Stripe directly and never touch our servers.
- A language-model provider for narration and "Ask your shop" [confirm: name].
Changes to this policy
If we change this policy in a way that matters, we will email account holders and update the date at the top of this page.