Privacy Policy
Personal eBay selling assistant, operated by the eBay seller eduardothe3rd.
Effective 4 October 2026. Last updated 4 October 2026.
This policy covers a private, single-user application that connects to the eBay API so that its operator can administer their own eBay selling account with the help of a personal software assistant. The application is not a product, it is not offered to other people, and it has no user accounts other than the operator's own.
Current status. As of 4 October 2026 the application holds eBay production application credentials but no eBay account has been connected to it and no eBay API call has been made. The operator has, however, already shared information from their own eBay account with the assistant by hand, for example screenshots, so assistant transcripts can already contain eBay account information. The sections below describe what the application is authorised and intended to do once an API connection is made, and they say clearly which parts are planned rather than active.
1. Who is responsible
The application is built and operated by an individual, the holder of the eBay seller account
eduardothe3rd, acting in a personal capacity rather than on behalf of a company. That person is
the sole operator and the sole intended user. Contact details are in section 11.
2. What the application does
It acts as a personal assistant over the operator's own eBay selling account. The operator asks it questions or gives it instructions in a private chat interface, and it uses the eBay API, under an authorisation the operator grants to their own account, to carry those out.
Planned at launch: read-only access to the operator's own selling data, so the assistant can report on and summarise that account.
Possible later additions: creating or updating the operator's own listings, working with orders on the operator's own account, and reading and replying to buyer messages sent to that account. These are not active today. If any of them is enabled, it will be enabled by the operator for their own account, and this policy will be updated to reflect it.
3. What data the application handles
This page is a static document and asks visitors for nothing. The operator adds no analytics, no advertising tags and no cookies to it. It is served by a third party hosting provider, Cloudflare Pages, which records ordinary request data such as IP address, user agent and request time as part of delivering and protecting the site, under that provider's own terms. The operator does not use that data to identify or profile visitors.
Once an eBay account is connected, the data the application can receive is limited to what the eBay API returns for the operator's own account under the authorisation the operator has granted. Depending on which features are enabled, that can include:
- Listing and inventory information for the operator's own items.
- Order, transaction, shipping and selling performance information for the operator's own sales.
- eBay account and seller profile information for the operator's own account.
- If order and messaging features are enabled, information about buyers that eBay already provides to the seller as part of a transaction. That can include a buyer's eBay user ID, name, shipping address, order details and the content of messages the buyer sends to the seller.
The application does not ask for, and is not authorised to reach, other eBay members' accounts, and it does not attempt to collect buyer payment card or bank details, which eBay does not disclose to sellers. No special effort is made to gather data beyond what a given task requires.
4. Why the data is used
For one purpose only: personal administration of the operator's own eBay selling account. In practice that means answering the operator's questions about their own account, summarising it, and, if those features are later enabled, carrying out seller tasks the operator asks for.
The operator does not use the data for advertising, for building profiles of buyers, for marketing lists, or for any purpose unrelated to running their own selling account, and does not submit it for machine learning training. Because the assistant runs on third party model services, the operator cannot give a guarantee about how those providers handle data inside their own systems, including whether any of it is used for model training.
5. Data will not be sold
The operator undertakes that data obtained through the eBay API will not be sold, rented, licensed or otherwise traded, and will not be shared for anyone else's advertising or marketing. This is a standing commitment for how the application is operated going forward. It is stated as a commitment because the application is new and has not yet drawn any data through the eBay API.
6. Who else may process the data
The application is not a closed box, and this section is deliberately specific about that.
- eBay. eBay is the source of the data and handles it under eBay's own user privacy notice. This policy does not describe, interpret or alter eBay's practices.
- The assistant's underlying model and infrastructure providers. The assistant is built on third party large language model services and supporting software. Content the operator sends to the assistant, and eBay data the assistant works with, is transmitted to and processed by those providers in order to produce a response, under their own terms and privacy commitments. The operator does not control their internal retention.
- Service providers used to run the software, such as hosting, backup and error logging, each acting on the operator's behalf.
- Legal requirements. Data may be disclosed where the operator is required to do so by law, or where it is necessary to comply with eBay's developer requirements or to respond to a lawful request.
Beyond those, the data is not disclosed to third parties.
7. Retention, stated honestly
This section avoids promises the application cannot keep.
- eBay data the assistant works with is recorded in ordinary operational artefacts: assistant conversation transcripts, application run logs, local working files and the backups that cover them.
- There is no automatic purge and no fixed deletion schedule. Those artefacts can persist indefinitely, and copies can exist in more than one place, including backups taken before any deletion request.
- On request the operator will make reasonable efforts to delete active working copies, and will keep collection to what a task needs. The operator cannot guarantee the complete, verified removal of every copy from all historical logs, transcripts, third party provider systems and backups, and does not claim to be able to.
- If and when a retention or purge mechanism is built, this policy will be updated to describe it, with the date of the change.
Authorisation tokens for the eBay connection are held in a protected credential store and can be revoked by the operator at any time from their eBay account settings, which stops further access.
8. Security
The application runs on hardware controlled by the operator, with access restricted to the operator's own accounts. Application credentials and any access tokens are kept in a protected credential store rather than in source code or in plain configuration files, and the application exposes no public endpoint that accepts data from the internet. The only thing published for it is this static policy page, which takes no input.
These are reasonable measures, not absolute ones. No system can be guaranteed secure, and the operator does not represent that this one is immune to compromise, error or loss.
9. eBay members whose data may appear
If order or messaging features are enabled, information about buyers who transact with
eduardothe3rd may pass through the application as part of normal seller administration. The
buyer's relationship is with eBay, and an eBay member's primary route for access, correction or deletion
requests is eBay itself and eBay's own privacy notice.
A buyer may also contact the operator directly using the details in section 11 with a question or a request about their information. The operator will respond, will act on reasonable requests as described in section 7, and will be explicit about anything that cannot be done rather than implying more capability than exists.
10. Children
The application is a personal seller tool, is not directed at children, and is not used to collect information from children knowingly.
11. Contact
Questions about this policy, or about information handled by this application, can be sent to elawford@gmail.com.
12. Changes to this policy
This policy will be updated if what the application does changes, in particular if write access, order handling or buyer messaging is enabled, or if a retention and deletion mechanism is introduced. The effective date and the last updated date at the top of this page will change with it. Because the application has a single user, there is no separate notification list.