Legal

Privacy Policy

Last updated: 31 August 2026

This policy covers both the ListingFi web app and the ListingFi Chrome extension. In plain terms: we hold the email address you sign in with, the Amazon and Shopify pages you choose to capture, and copies of the images from those pages. We do not sell data and we do not build profiles of you.

Who we are

ListingFi is a research tool for Amazon and Shopify creative — a Chrome extension, a curated library and a CRO audit. We are the data controller for the personal data described here. Contact us at __FILL_ME__.

What we collect

  • Account data — the email address and basic profile returned by Google when you sign in through Supabase, plus your workspace and credit balance.
  • Captured pages — the Amazon listings and Shopify product pages you choose to save: URL, ASIN, title, brand, price, ratings, copy, and the public reviews attached to them.
  • Captured images — main images, gallery images, A+ module images, carousel slides and brand-story panels from those pages, copied into our Supabase storage so your library keeps working after the source page changes.
  • Page screenshots — when you use the extension's page-capture tool, a full-page screenshot of the tab you are on. This works on any site, not only Amazon, and it captures the page as YOU see it — including content behind a login, if you are signed in to that site. It is taken only on the tab you have open, only when you click, and it is uploaded to your workspace. Do not capture a page containing anything you would not want stored in your library.
  • Work you create — audits, notes, collections, tags and API keys you generate inside the app.
  • Billing data — the Lemon Squeezy customer and subscription identifiers for your workspace, and a ledger of credits granted and spent. Card details go to Lemon Squeezy directly and never reach our servers.
  • Technical logs — ordinary server logs from our host, including IP address, user agent and request path, used to keep the service running and to rate-limit abuse.

What we do not collect

  • Your Amazon Seller Central or Shopify admin credentials. We never ask for them and the extension has no access to them.
  • Your browsing history. The extension reads a page only at the moment you click it, and only the tab you are looking at. It does not watch, log or transmit where else you go.
  • Advertising or cross-site tracking identifiers. We do not run third-party ad or analytics trackers on the app.

The Chrome extension

The extension is how you save a listing without leaving Amazon. It requests the narrowest set of permissions that makes that work:

  • storage — keeps your sign-in session token in the browser's local extension storage so you don't have to sign in on every page. Nothing else is stored there.
  • identity — used only to run the Google sign-in flow (chrome.identity.launchWebAuthFlow) and return a session for your ListingFi account.
  • activeTab — grants access to the tab you are currently looking at, and only when you click the ListingFi toolbar button.
  • scripting — runs the reader script on the page you are on. On an Amazon listing it reads the public content (title, price, gallery, A+ modules, reviews); on any other page, it is what performs the full-page screenshot when you ask for one.
  • Host access to Amazon domains — the extension runs automatically only on Amazon storefronts (amazon.com, amazon.co.uk, amazon.de, amazon.ca, amazon.fr, amazon.it, amazon.es, amazon.com.au, amazon.co.jp, amazon.in, amazon.com.mx, amazon.com.br, amazon.nl, amazon.se, amazon.sg, amazon.ae, amazon.sa, amazon.pl) plus our own API and Supabase endpoints, so it can send what you captured to your library. Beyond those, it reaches a page only through activeTab — that is, one tab, at the moment you click.

The extension reads a page only when you act on it, and only the tab you are looking at. It never reads other tabs and it sends nothing to our API unless you click to save, download, scan or capture. On Amazon it reads publicly visible listing content; the page-capture tool works on any site and records what is on your screen, so treat it as you would a screenshot you were about to upload. Extension data is used solely to provide the features you invoked — never sold, never used for advertising, never transferred to third parties except the processors listed below.

Why we hold it

  • To provide the service you asked for — saving listings, downloading assets, running audits, showing the library. This is performance of our contract with you.
  • To take payment and meter credits. This is performance of our contract and a legal obligation for tax and accounting records.
  • To keep the service secure and working — logs, rate limits, abuse prevention. This is our legitimate interest.

Who processes it

We use a small number of third-party processors. Each receives only what it needs to do its job.

Supabase
Database, file storage and Google sign-in. Holds your account record, your saved listings and the images copied into storage.
Vercel
Hosting for the web app and its API. Processes request logs, including IP addresses, as part of serving the site.
Lemon Squeezy
Payments, as our merchant of record. Lemon Squeezy sells the subscription in its own name, collects and stores your card details directly, and handles tax and invoicing — we never see or store a card number. We store the Lemon Squeezy customer and subscription identifiers against your workspace so a renewal can be matched to your account.
Apify
Scraping of public Amazon and Shopify pages you ask us to capture. Receives the page URL or ASIN you submit.
OpenRouter
AI analysis. Receives the listing text, images and reviews being analysed so a model can score them and mine voice-of-customer.
OpenAI
Image generation and editing. Receives the prompt and any reference image when an image is generated or edited.
Google (Gemini API)
AI analysis on the Gemini model path. Receives the same listing content as OpenRouter when that provider is selected.

These providers operate internationally, so your data may be processed outside your country, including in the United States. We do not sell personal data, and we do not share it for advertising or any purpose unrelated to running ListingFi.

How long we keep it

Captured listings, images and audits stay in your workspace until you delete them or ask us to delete the account. Billing and credit-ledger records are kept as long as tax and accounting rules require. Server logs are short-lived and retained by our host on their standard schedule.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Depending on where you live, you may also have the right to object to or restrict processing, to data portability, and to complain to your local data protection authority.

To exercise any of these, email __FILL_ME__ from the address on your account. Deletion is handled by request — write to us and we will remove your account, your captured listings and the images stored for them. Uninstalling the extension removes the session token held in your browser but does not by itself delete what is already saved in your library.

Security

Data is held in Supabase with row-level security so a workspace can only read its own records. Traffic is encrypted in transit. API keys you generate can be revoked at any time from the app, which immediately stops anything using them.

Children

ListingFi is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes

If this policy changes we will update the date at the top of this page. Material changes will be flagged in the app.

Contact

Questions, requests or complaints: __FILL_ME__. See also our Terms of Service.