Privacy policy
The honest version and the full version, both on one page.
The short version: SellFalcon is a website you sign in to, and the work happens on our servers, so what you use the tool for is stored in your account: your listings ledger, your eBay orders and the supplier costs and notes you record, your staged product drafts, your reports, your settings and your blocked-keyword list, and (from 24 August 2026) the text of the buyer messages the tool has read, kept for 2 months - or 12 if you choose - so your inbox opens instantly. When you connect eBay, we hold that connection encrypted, because the daily supplier watch, the order sync and publishing all run with your computer off. Your eBay password never reaches us, there is no AI key for you to supply on this website (the writing runs on ours), and your card details go into our payment provider's own form and never touch our servers. If you also use the browser extension, it reads pages in your own browser (AliExpress product and order pages, your eBay order pages, and Temu order pages) and keeps its own copy of that data on your computer as well; signing it out stops the syncing, and you can ask us to delete the server copy at any time. Two of those readings never reach us at all: the buyer address you copy for a supplier checkout, and Temu’s own tax invoices, both described below. If you invite team members, we also store each member's email, role and sign-in so they can work in your workspace (see “Users & Team” below). What else we store server-side is small: emails typed into the old waitlist form before it was retired (held only until each person is invited or asks us to delete), and, if you have an account (by invitation, or created by you when open sign-up is switched on), that account (your email, plus a salted password hash if you set a password, never the password itself). No analytics, and no cookies on sellfalcon.com, with two named exceptions: the optional Google or Microsoft sign-in sets one short-lived security cookie on our API's own domain (explained below), and opening the plan card or a Paddle payment link loads Paddle's checkout software into the page, which uses its own cookies to run the checkout (see “Paddle” in the services table).
1Who we are
SellFalcon is run by Khizar Hayat, a sole trader established in Pakistan, trading as SellFalcon; he is the data controller for the personal data described here. (This page said "based in the United Kingdom" until 15 August 2026. That was wrong, and it is corrected here rather than quietly: the tool is built for UK eBay sellers, but the person who runs it is in Pakistan, and you are entitled to know who is responsible for your data.) The services that store or process data for us are named in the table above, and where any of them keeps it outside your own browser is said in the section about that service. For anything in this policy, contact support@sellfalcon.com.
2What the extension stores, and where
Everything SellFalcon works with is stored locally in your browser's extension storage (chrome.storage) on your machine:
- Your settings, including your eBay API credentials and your AI engine key.
- Scraped product data, drafts and listing history.
- Your inventory ledger: published listings with their supplier costs and variant details.
- Orders synced from your own eBay account (these naturally include your buyers' eBay usernames), and the profit figures computed from them.
- From 10 September 2026, if you switch Invoices on under Features: your own AliExpress order history, read from the order pages you are signed in to. That is the order number, date and status, the items, quantities and prices, the seller's name, what you paid, the payment method as the page words it, and the delivery address on the order. The extension keeps the last four months of it on your machine. If you are signed in, each record is also copied to your SellFalcon account, which keeps twelve months so you still have the year after a reinstall or a new computer, and the extension only drops a record from your machine once your account has it. Your AliExpress password never reaches us, and the extension only ever reads pages you are already signed in to; it does not log in for you.
- From 11 September 2026, if Paste the buyer’s address at checkout is on under Features: one delivery address at a time, read off an eBay order page when you press Copy address. That is your buyer’s name, their address and their phone number as eBay shows them to you, plus the order number and which eBay site it came from. It is held so the next press at a supplier’s checkout can type it in, and a new copy replaces the last one. Alongside it the extension keeps the last five run logs: what the automation did step by step, which includes that same address and, on a failure, a snapshot of the supplier form it was filling, so a paste that went wrong can be explained rather than remembered. Both are kept in this computer’s extension storage and never in Chrome’s settings sync, so they do not travel to your other computers. Both are deleted automatically after 30 days, and Settings → Buyer addresses has a Clear now that removes them at once. None of it is ever sent to us, signed in or not, and it is not part of cloud sync. Copying also puts the address on your computer’s clipboard, as any copy would.
- From 11 September 2026, if Save Temu’s own tax invoices is on under Features: nothing is stored beyond the date range you last chose. On a Temu orders page the extension reads the order numbers and dates already shown to you; pressing Save invoice asks Temu, using the session you are already signed in with, for that order’s own tax invoice, assembles its pages into a PDF and saves it to your Downloads folder. The document is Temu’s, unaltered: the extension does not rewrite or recompute any of it. Your Temu password never reaches us, the extension only reads pages you are already signed in to, and no part of this reaches SellFalcon at all, which is why the feature works whether or not you are signed in or on a plan.
- The business details you type for those records (your company name, address, VAT and company numbers, contact details and logo). You type them, we do not collect them, and they are printed on the record and nowhere else.
By default none of this is transmitted to us. If you sign in to your SellFalcon account in the extension's Settings → Account, the extension additionally keeps a copy of the inventory ledger, the synced orders, your staged product drafts (so the web listing editor can open them), the short monitoring/orders preference list and, from 10 September 2026 if Invoices is on, your AliExpress purchase records, in your account (see "Cloud sync" below). The blocked-keyword (VeRO) word list is, from 16 September 2026, your account's own list rather than a copy of the extension's: the web Settings page and the extension both edit it, and the signed-in extension keeps a copy of it on your computer and sends its edits to the account. Neither the copied buyer address, its run logs, nor anything about Temu invoices is in that list, and neither is added to it by signing in. Everything else, including every key, token and credential, stays local no matter what. From 7 September 2026 that is true in a stricter sense as well: the extension keeps its keys and tokens in this computer's own extension storage only, so Chrome's own settings sync (which copies a browser's preferences between the computers signed in to one Google account) never carries them; a second computer needs the keys entered there, or a passphrase-protected backup. If you create a backup, it's a file encrypted with a passphrase you choose (AES-GCM), saved wherever you put it; without the passphrase it cannot be read, by us or anyone else.
3What leaves your browser, and where it goes
The extension only talks to services that are necessary to do what you asked, always directly from your browser:
| Service | What is sent | Why |
|---|---|---|
| eBay (its official APIs) | Your listing content, prices, stock updates and order-sync requests, authorised by the token eBay issued to you | Creating and revising your listings, syncing your orders |
| AliExpress | Ordinary page visits in your own logged-in browser | Reading product data on pages you choose to scrape or monitor |
| Your AI provider | Product text (title, description, specifics) and, when the image checks are switched on (they are by default), links to the product photos so the model can read the pictures, with your own API key. If you press the Draft reply button on an eBay message page, the visible conversation and basic order facts from your own records are also sent, that one time, to draft the reply. The same is true of the Write me a reply button in the web tool's Messages screen: that one message's text and the facts the tool already holds about the matching order (whether it was dispatched, the tracking number you typed, the listing and its price) are sent once, from our server, to write a draft you then read and edit. Nothing is sent to eBay by that button. From the web listing editor the same kind of product text (the title, the supplier’s specification, the description text and the eBay category’s aspect names) is sent from our server instead of your browser, using a key we hold; your photos are not sent, and nothing is stored with the AI provider by us. From the extension, when you are signed in and have no AI key of your own (from 18 August 2026): the extension's AI requests - the same product text, and for the image checks the links to the photos - travel from your browser to our server first, then to the AI provider under the key we hold, counted against your plan's hourly AI allowance. We relay the request and hand the answer back; we keep no copy of either | Generating titles, descriptions and item specifics, checking the listing against its photos, and drafting buyer message replies you review and send yourself, each only when you ask |
| wsrv.nl (image proxy) | Image URLs you preview or attach from external sites | Loading cross-origin images, converting formats for previews, and converting description and variant images to JPEG when a listing is published (those listing images are then served via wsrv.nl) |
| eBay (when you connect on the website) | A sign-in you complete on eBay's own page (we never see the password), then order and listing data for your own account (including, since 17 August 2026, per order: the buyer's name, the postage address and phone number they gave eBay, the postage service they chose, eBay's delivery estimate and the paid breakdown), the buyer feedback that account has received - the rating, the comment text, the buyer's eBay username, the item it was left on and whether you have replied - your account's currently open return requests and cases: the buyer's eBay username, the item, the reason eBay records, the status, when it was opened and eBay's respond-by date, eBay's traffic report for your own listings (how many times each was seen, the click-through rate eBay calculates, and how many sold) - counts about your listings, with nothing about any individual shopper in them - the listings on that account that ended without selling: the item, its title and photo, the price it was listed at, when it ended and how many people were watching it, your Promoted Listings campaigns: the campaign name, which of your listings are advertised and the ad rate each is bidding, and the unanswered questions buyers have asked about your listings in the last 30 days - the subject line, the asker's eBay username, which listing it is about and when it arrived, and (from 14 August 2026) the LIST of buyer messages on that account - the last 60 days from 24 August 2026, 30 days before that: for each one the subject line, the sender's eBay username, the listing it is about, the date, and whether it has been read or answered. From 24 August 2026 the TEXT of the buyer messages the tool has read is also kept on our servers, so your inbox opens instantly, works from any computer, and eBay is never asked twice for the same words. You choose how long in Settings: 2 months unless you pick 12. Each message is deleted automatically when it is older than that, the lot is deleted if you disconnect that eBay account or delete your SellFalcon account, and support will delete it on request. eBay's own notices are not kept - only what people wrote. From 8 September 2026 the tool also reads the list of messages you have sent to buyers from that account (eBay's Sent folder, over the same 60 days: who each went to, which listing it is about, the date and the subject line) and keeps the text of those replies the same way as the buyer messages, so a conversation in the tool shows both sides; the same retention and the same three deletion paths apply to them. When you send a reply from inside SellFalcon we also record that you replied to that message and how long the reply was, so the tool cannot send it twice; the reply's own text reaches our servers only when the hourly read brings it back from eBay's Sent folder like any other reply you sent. If you attach a photo to a reply, the image travels from your browser through our server to eBay Picture Services, which hosts it on eBay's own image service; the reply carries eBay's link to that photo, and we keep no copy of the image | Connecting an eBay account directly to the web tool so it syncs your orders, manages your listings, shows the negatives and neutrals that need answering on your dashboard, and warns you before a return's deadline passes; the connection token is stored encrypted (see "Connecting eBay on the website"). We keep only the most recent 400 feedback entries per account, and only returns and cases that are still open - one that closes is deleted the next time we check. We never publish a reply, answer a return or issue a refund on your behalf, and nothing is sent to any third party |
| Google (when you connect a backup) | A sign-in you complete on Google's own page (we never see the password), then, from 19 August 2026, the contents of your backup spreadsheet: your inventory rows (title, item number, price, your cost, supplier link) and your order rows (order number, date, buyer's eBay username, item, totals, fees, your cost, supplier order number, tracking, status), written into a "SellFalcon backup" file in your own Google Drive; and, when you press "Save to Google Sheets" on the Reports page, that month's report rows exactly as the page shows them (including client and expense lines you typed), into a per-month "SellFalcon report" file | Keeping a copy of your records in a file you own, so losing access to either place never means losing your data. The narrow drive.file permission means SellFalcon can only touch files it created - never the rest of your Drive. The connection token is stored encrypted (see "Backing up to your Google account") |
| AliExpress (when you connect on the website) | A sign-in you complete on AliExpress's own page (we never see the password), then product prices, stock and photos for products you ask about, your own supplier orders and their tracking, and - only when you press Order at the supplier - the delivery details of the eBay order you are buying for: your buyer's name, address and phone number | Reading supplier prices and stock without your browser being open, and creating the supplier order you asked for; the connection token is stored encrypted (see "Connecting AliExpress on the website") |
| Paddle (payments; live since 16 August 2026) | Opening the plan card on the Settings page, or following a Paddle payment link, loads Paddle’s own checkout software from cdn.paddle.com into the page - so Paddle’s servers see your IP address and browser details - and that software sets its own cookies and storage to run the checkout. If you pay, the card details, name, address and email you type go into Paddle’s overlay directly; they never touch SellFalcon | Taking subscription payments as merchant of record, under Paddle’s own privacy policy. What we store is only what Paddle reports back: the customer and subscription references, the plan, the status, and the trial/renewal dates |
| Your email app | A message you compose | The extension's support form opens a pre-filled email; nothing is sent until you press send |
| SellFalcon's own API (Cloudflare) | Signed out: nothing on a schedule - the old standing licence/plan check is retired (from 16 August 2026); your plan now travels with your signed-in account and no separate check exists. Opening the extension's own Settings page asks our API one yes/no question - whether open sign-up is switched on - so the sign-in box can word itself correctly; that request carries no account data (our server, like any web server, sees the request's network address). If you sign in: your email + password at sign-in, then your inventory ledger, synced orders, your staged product drafts (full drafts: descriptions, image addresses, prices, variants), the extension's version number and a short list of monitoring/orders preferences and your blocked-keyword (VeRO) word list (shown on the web Settings page) on each cloud-sync push. From 18 August 2026, a signed-in extension with no keys of its own can also send our API the text of the AI requests you trigger (which our server passes to the AI provider under our key - see that row), and can ask our server for a short-lived eBay sign-in minted from the eBay connection stored for your account (see "Connecting eBay on the website"); the long-lived connection token never leaves the server. Never your API keys, eBay tokens or account connections | Wording one sentence on the extension's Settings page honestly, and (only when you're signed in) keeping a copy of your listings, orders and those preferences in your account for the web dashboard - which is also how the extension knows your plan |
Accounts on this website
If you create an account - by invitation, or by signing yourself up when open sign-up is switched on - we store your email, your password as a salted one-way hash (never the password itself), and sign-in session tokens, all in our database (Cloudflare D1). From 7 September 2026 you can also give the tool a display name on Your account ("Sam", say), so it greets you by it; it is optional, stored with your account's settings, shown only to you and your own team, changed or cleared on the same page, and deleted with the account. Disabling an account locks it out immediately (every sign-in and every data request refuses a disabled account); deleting an account removes its data. Ask support@sellfalcon.com to delete your account at any time. From 24 August 2026 there are two doors, and you choose: ask to pause your account and everything is kept exactly as you left it while sign-in is blocked, so coming back months later means picking up where you stopped rather than starting again - or ask to delete it and everything goes, permanently, including the messages, orders, reports and files described on this page, plus anything you sent the contact form before you had an account. Pausing is the friendly door for taking a break; deleting means what it says. From 8 September 2026 you can also add a profile photo on the same page: your browser shrinks it to a 96-pixel square of a few kilobytes before anything is sent, it is stored with your account's settings beside the name, shown only to you and your own team, and removed the moment you press Remove photo.
Sign in with Google or Microsoft (optional). When these buttons are switched on, choosing one takes you to Google's or Microsoft's own sign-in page; you never type any password on our pages, and we never see the password you use there. All the provider tells us is which email address you proved you own (plus basic token bookkeeping we do not store), and we use that email for exactly one thing: matching you to your invited SellFalcon account. No account is ever created from it, nothing is posted to your Google or Microsoft account, and we store no extra data about you compared to a password sign-in (an SSO-only account simply has no password hash). During the handoff our sign-in service (which runs on our API's own domain, not sellfalcon.com) sets one short-lived security cookie purely to protect the exchange against forgery; it expires within ten minutes. What Google or Microsoft record about their own sign-in pages is governed by their privacy policies, not this one.
Connecting eBay on the website (optional)
Some accounts can connect an eBay account directly on the Settings page, so the tool works without the browser extension. When you do, you sign in on eBay's own page and approve SellFalcon; we never see or store your eBay password. eBay then gives us a connection token (a "refresh token") that lets us fetch your orders and manage your listings on your behalf. That token is stored encrypted in our database (Cloudflare D1) using AES-GCM with a key that is not kept in the database, so a copy of the database alone cannot read it. We use the connection for one thing: keeping your SellFalcon orders (and, as those features arrive, your listings) in sync, including an automatic refresh about once an hour so your numbers stay current even with no browser open. We do not sell, share or use it for anything else. One addition from 18 August 2026: the connection can also serve your own signed-in extension. If the extension has no eBay developer setup of its own, our server mints a short-lived access token from this connection and hands it to the extension, so the extension can list and manage listings on the same eBay account with nothing to configure. The refresh token itself never leaves the server, the short-lived token expires on its own within minutes, and only the account owner's own sign-in can ask for one - a team member's cannot. From 19 August 2026 the signed-in extension is also told each website connection's display name (the label you set, or the eBay username) and whether it is working - never any token - so its own Settings page can say which eBay account listing runs through instead of claiming no store is connected; the same owner-only rule applies. Your synced orders include your buyers' eBay usernames and, since 17 August 2026, the order details eBay already shows you in Seller Hub: the buyer's name, the postage address and phone number they gave eBay, the postage service they chose, eBay's delivery estimate and the paid breakdown - stored in your account's private space so the tool's own order page and packing slip work without a trip to eBay, aged out with the order (roughly the last 45 days). The extension's own sync carries none of that - usernames only. You can disconnect at any time on the Settings page, which deletes the stored connection and the orders synced from it, and you can also revoke SellFalcon from your eBay account's "connected apps" settings. Deleting your SellFalcon account removes all of this too. If you use the extension instead, nothing changes for you: this section only applies once you connect eBay on the website.
Connecting AliExpress on the website (optional)
You can also connect the AliExpress account you buy from - or several, one per client's eBay account if you run more than one shop - on the same Settings page. You sign in on AliExpress's own page and approve SellFalcon; we never see or store your AliExpress password. If you pair an AliExpress account with one of your eBay accounts, we store that pairing (just the two connection ids) so the daily supplier checks for that shop's listings run through its own account and never through another client's. You can also give each connection a name of your own choosing (AliExpress's autogenerated id tells you little); the name is stored with your account, shown on the owner-only Settings card, and deleted with the connection. AliExpress then gives us a connection token, which we store encrypted in our database (Cloudflare D1) using AES-GCM with a key that is not kept in the database, exactly as we do for eBay. We use it to read product information (prices, stock, photos and variants) for products you ask about, and - as those features arrive - your supplier orders and their tracking. It is never used to buy anything without you asking, and we do not sell or share it.
Ordering at the supplier. From 11 September 2026 the connection can also create an order, and only ever because you pressed a button that showed you what it would buy first. When you do, the delivery details of that eBay order are sent to AliExpress so the parcel reaches your buyer: their name, their address and their phone number. That is the same information you would type into the supplier's checkout by hand, sent to the same supplier, for the same reason. If eBay gave no phone number for the order, the number you put in Settings is used and the order says so; a phone number is never invented. What we keep afterwards is the supplier's own order number and, once it exists, the tracking number, both stored against that eBay order in your account's private space and deleted with it.
Two things this cannot do, and there is no setting that changes either. It cannot pay: AliExpress's dropshipping API has no payment call at all, so every order it creates is unpaid in your own AliExpress account for you to pay yourself, and AliExpress cancels an order left unpaid for 24 hours. And SellFalcon never holds, stores, enters or uses a card of yours or anybody else's, for this or for anything: the only card details in this product go into our payment provider's own form, as the billing section says. Ordering is OFF unless you switch it on in Settings, and marking the eBay order dispatched when the supplier ships is a separate switch, also off.
Disconnecting on the Settings page deletes the stored connection, and you can also revoke SellFalcon from your AliExpress account settings. Deleting your SellFalcon account removes it too. Connecting AliExpress is entirely optional and nothing else changes if you skip it.
Backing up to your Google account (optional)
From 19 August 2026 you can connect the Google account you own, on the Settings page, and
SellFalcon keeps a copy of your records in your own Google Drive: a spreadsheet
named "SellFalcon backup" holding your inventory (title, item number, price, your cost, the
supplier link) and your orders (order number, date, the buyer's eBay username, item, totals,
fees, your cost, supplier order number, tracking, status). You sign in on Google's own
page; we never see or store your Google password. Google then gives us a connection
token that is stored encrypted in our database (Cloudflare D1) using AES-GCM
with a key that is not kept in the database, exactly as we do for eBay and AliExpress. The
permission we ask for is deliberately the narrow one (Google calls it drive.file):
it lets SellFalcon touch only files SellFalcon itself created - we cannot read,
list or change anything else in your Drive, ever. The backup is written when you press
Back up now and roughly once a day while you use the tool; nothing about it is sent to
anyone but Google, under your own account. Disconnecting on the Settings page deletes the stored
connection immediately - the spreadsheet stays in your Drive, because it is yours - and you can
also revoke SellFalcon from your Google account's own security settings. Deleting your SellFalcon
account removes the stored connection too. Connecting Google is entirely optional: your data
lives in SellFalcon either way, and the backup only adds a copy you own. The monthly sheet you
build on the Reports page can be saved the same way: pressing "Save to Google Sheets" writes
that month's rows - exactly as the page shows them, including any client and expense lines you
typed - into a spreadsheet named "SellFalcon report" for that month, one per month, updated in
place when you save again.
Users & Team (optional)
Your plan includes a number of team seats. If you invite a team member from the Settings page, we store their email address, their role (admin or VA), a licence key (every account row has one) and which workspace they belong to; once they choose a password, their account works like any other (salted hash, revocable sessions). A team member signing in on sellfalcon.com sees your workspace: the same listings, orders (including your buyers' eBay usernames), drafts, activity, reports and settings you see, and the actions they queue go into the same action queue, so make sure you invite only people you trust with that data, and that they are happy for you to give us their email. Team accounts work on this website only; they cannot connect an extension or push data. Roles limit what they can change (a VA cannot change the extension's settings; only the owner manages the team). Removing a member deletes their sign-in and account immediately; their edits to your workspace stay, because the work is yours. Members can also ask us to delete their account at any time: support@sellfalcon.com.
Cloud sync (optional, off until you sign in)
When you sign in to your account inside the extension, it mirrors your inventory ledger (listings, supplier costs, monitor state) and your synced eBay orders (which naturally include your buyers' eBay usernames, but no addresses) to our database (Cloudflare D1), in a space that belongs to your account alone. That is the whole point: the web dashboard at sellfalcon.com/dashboard reads it so you can see your business from any computer. Honest limit: sync is one-way (extension to cloud) today and is not a restore service; to move your data to a new or reinstalled browser, use the encrypted backup file in the extension's Settings. Your eBay connection, your AI key and your account credentials are never included; of the extension's settings, only the short monitoring/orders preference list and the blocked-keyword (VeRO) word list shown on the web Settings page travel (so you can change those from the web), plus the names you gave your connected eBay stores (name and internal id only, never tokens, so the web tool can say which store is which), the extension's recent-activity feed (short lines like "Daily check finished", shown on the dashboard's Recent activity card) and each product you are preparing to list - since 9 August 2026 this is the FULL draft (title, description, image addresses, prices, quantities, variants, item specifics, eBay category and the supplier product link), because the web listing editor at sellfalcon.com lets you finish and publish these drafts without the extension; before that date only a short summary travelled. If you use the dashboard's action buttons (including Add product by link and settings changes), we also store that small action queue (which listing or link, what to do, and the result your extension reported back) in the same private space. The Orders tab also lets you attach details to an order - the supplier cost, the supplier's order number, a private note, and the tracking number you dispatch with; those are stored in the same private space and feed the profit figures shown across the tool. Pause sync with one toggle, or sign out to stop it entirely; the extension keeps working exactly the same. Ask support@sellfalcon.com to delete your synced data or your whole account at any time.
Your AliExpress purchase records (optional, from 10 September 2026)
If you switch Invoices on in the extension's Features tab and you are signed in, each AliExpress order the extension reads is also copied to your account's private space in our database (Cloudflare D1). This is one arrangement with two halves, and the reason for both is the same: only a signed-in browser tab can read your AliExpress order pages, so the extension does the reading and keeps four months, while your account keeps twelve so the year is still there after a reinstall, a cleared browser or a new computer. The extension will not delete a record from your machine until your account has it.
What is copied is the record as read from your own order pages: the order number, date and status, the items with their quantities and prices, the seller's name, what you paid and in which currency, the payment method as the page words it, any tracking number on the order, and the delivery address on the order - which, for a dropshipped order, is your buyer's address. It is stored in your account alone, shown to you at sellfalcon.com/reports under "Purchase records", and never shared with anyone. A record older than twelve months is deleted automatically, judged by the order's own date; a record whose date could not be read is kept rather than guessed at. Switching Invoices off stops new records being read and copied; deleting your account, or asking support@sellfalcon.com, deletes what is already there. Your AliExpress password never reaches us and we never sign in to AliExpress for you.
One shared sign-in between this website and the extension
From 13 August 2026 the extension no longer asks you to sign in a second time. When you are signed in on sellfalcon.com and the extension is installed in the same browser, the extension reads the sign-in token this website keeps in your browser's own storage for this site, and exchanges it with our API for a separate token of its own. The website's token is never stored by the extension, and the swap is a hand-over, not extra access: it can do exactly what you can already do, for your account only. Because the two tokens are separate, signing out on this website does not silently leave the extension running - we tell it to sign out as well - and changing your password still ends both, like every other signed-in device. You can sign the extension in or out yourself at any time on Settings → Account → Your extension, or in the extension's own Settings → Account.
Two small things travel with this. The extension marks the pages of this website so the site can see that it is installed in this browser (that is how the tool can say "your extension is picking it up now" instead of guessing), and when the extension asks our server for queued work - about once a minute while it is signed in - the server records when it last asked, the extension's version number and the random install id it already sends with every sync. That is what the "Last asked for work" line on the Settings page and the queued-actions notice on the dashboard are reading. No page addresses, no browsing history, and nothing about any other website: the extension only runs on sellfalcon.com, AliExpress product pages and eBay, exactly as listed above.
Monthly reports and invoices (optional)
The reports page at sellfalcon.com/reports builds monthly sheets and invoices from your synced orders. What you type there is saved to your account's private space in our database (Cloudflare D1): your chosen sheet columns, expense lines, per-order extras (supplier order numbers, postage label costs, refunds, notes), profit-share settings, invoice lines (from 20 August 2026 with an optional unit cost and quantity per line, plus the invoice's due date, purchase order number, currency, tax rate, discount and shipping figures, and - later the same day - an optional small logo image you pick for that one invoice, stored shrunken with that month's report data), and the business details you enter for the invoice (your own and your client's name, address, contact details and - from 20 August 2026 - company registration numbers and the bank account details printed in the invoice's payment section; bank details you choose to print on an invoice are, by that choice, shared with whoever receives the invoice). We store the client details exactly as you type them, only so your invoices can show them; it is your responsibility to have your client's OK to use their details this way. Everything is deleted with your account, or on request.
Your logo and company files (optional)
From 20 August 2026 you can upload a logo on the Settings page (Business details); it is stored in our database (Cloudflare D1) with your account and printed top-right on your invoices. You can replace or remove it any time, and it is deleted with your account. The same page has a small company file cabinet: up to 15 files of up to 20MB each (contracts, registration papers, past invoices - whatever your business leans on), stored in Cloudflare R2 object storage in our account, indexed against your account alone. Only the workspace owner can see, download or delete these files - team members cannot - and we never read, share or process them; they are stored bytes until you download or delete them. Deleting a file removes it from storage immediately, and deleting your account removes the whole cabinet the same way.
The waitlist (retired 16 August 2026)
This site used to carry a waitlist form. It is gone: accounts are created on the sign-in page (or arranged by email while sign-up is invitation-only), and no new waitlist emails are collected. Emails people typed into the old form are still held only so we can invite them, and each is deleted when its owner is invited, creates an account, or asks: support@sellfalcon.com.
Verification and password-reset codes
When you set your first password, or ask to reset a forgotten one, we email you a 6-digit code and store a one-way hash of it (never the code itself) in our database (Cloudflare D1) alongside your email address, what the code is for, and when it was made. It stops working after 15 minutes, after five wrong tries, or once it has been used - whichever comes first - and asking for a new code cancels the old one. We keep these rows only so a code can be checked once; they are deleted with your account.
Email we send you about your account
When your request to join is approved, and for a small number of other account matters (verifying your address, a welcome note when your account is created, resetting your password, and important notices about your account), we send you an email. If you switch on alert emails in Settings under Notifications, the daily supplier check also emails you when it finds something waiting for your decision - a supplier price change, an out-of-stock, or a supplier page that has gone; these are off unless you turn them on and stop the moment you turn them off. If you subscribe to a paid plan, we also send at most two kinds of billing notice: one reminder before a free trial ends (so the first charge is never a surprise), and a note when a subscription payment fails (so you can fix the card while you still have access). Both are service emails about your own account, never marketing. To do that, your email address and the message itself are passed to Resend, the service that delivers our email for us; their servers for our account are in Ireland, inside the EU. We do not use these emails for marketing, we do not send newsletters, and we do not track whether you open them or click their links - link and open tracking are switched off on our account. Support does not run on email: it runs in the chat inside the tool, described below.
Support chat on this website
Support is a chat: if you start a conversation from the support page, we store the conversation - your messages, our replies, the category you picked and, if you are not signed in, the email address you give - in our database (Cloudflare D1), so the answer can appear in the same chat when you come back. It is read only by us, used only to help you, and deleted once the conversation is resolved, or sooner if you ask. From 6 September 2026 three small things sit beside a conversation: we may write ourselves a private note on it (our own words, stored with the conversation, never shown to you, deleted with it); when a conversation starts, or when you ask for access, a payment of yours fails, or your extension has been quiet for two weeks, one email naming your address goes to the person who runs SellFalcon through the same email service named above, so nothing waits unread; and if you ask for access and we approve or decline, we keep your email address, the decision and the date as a record of it, which is deleted with your account or on request. A conversation started while signed out is tied to a random key kept in your browser; clearing your browser data discards that key, so start a new conversation (or email us) if that happens. Emailing support@sellfalcon.com directly works exactly as well.
Messages in a conversation can carry attachments: pictures, PDFs, plain text files or a short voice note. They are stored with the conversation, are visible only to you and us, and are deleted with it. A voice note is a recording of your own voice, so send one only if you are happy for us to hear and store it until the conversation is resolved.
Feedback
The signed-in feedback page lets you send us bugs, feature requests and suggestions, with optional screenshots or files. We store what you send (message, category, attachments, and which account sent it) in our database so we can read it and improve the tool. Pictures are shrunk in your browser before they are sent, and you can attach a short voice note instead of typing. Feedback is not a conversation - nothing is sent back - and you can ask us to delete anything you sent at any time.
The extension's own support email can attach optional diagnostics: version numbers, item counts and recent error messages. They never include your API keys, tokens or passphrases.
Error reports from this website
If a page of this website hits a script error, your browser sends us a short technical report: the error message, which script and line it came from, which page it happened on, and the site version. It carries nothing about you - no account, no email, no cookies, and there is no user column in the table it lands in. Identical errors are stored once with a counter, the store is hard-capped, and each entry is deleted about 14 days after the error last happened. These reports exist so we can fix bugs before most people ever meet them.
4What we never do
- No analytics or tracking in the extension, and none on this website.
- No cookies on sellfalcon.com. Your light/dark theme choice is kept in your own browser's local storage and never transmitted. (Two exceptions, both named: during an optional Google or Microsoft sign-in, our API's own domain sets a single security cookie for up to ten minutes, described under "Accounts on this website"; and opening the plan card or a Paddle payment link loads Paddle's checkout software into this page, which sets its own cookies to run the checkout - that overlay is how your card details reach Paddle and never us.)
- No selling, sharing or renting of data. What we hold is a waitlist email, an account if you have one, and, only if you use cloud sync, your own listings and orders, visible to nobody but you and us as the operator.
- No access to other sellers' accounts or listings. The extension acts only on your own account. Your order records naturally include your buyers' eBay usernames; they stay in your browser unless you switch on cloud sync, in which case they are also stored in your account's private space.
5Browser permissions, explained
Chrome will list these permissions when you install. Here's what each is actually for:
| Permission | Used for |
|---|---|
storage, unlimitedStorage | Keeping your settings, listings, ledger and orders on your machine (the ledger can outgrow Chrome's small default quota) |
tabs, scripting, activeTab | Reading the AliExpress product page you're on, and opening source pages briefly in background tabs for the daily checks |
sidePanel | The listing panel that opens next to the product page |
alarms | Scheduling the daily price/stock checks |
notifications | One summary notification per check that found changes (on by default; switch it off in Settings) |
clipboardRead | Pasting a product link into the add-a-product box |
identity | Part of the eBay account connection flow |
Host access is limited to the sites the tool works with: AliExpress and its image hosts, eBay and its API domains, the AI provider's API endpoint, the wsrv.nl image proxy, and SellFalcon's own API (for cloud sync when you sign in, and the sign-up wording question described in the services table above).
6Your rights and choices
- Everything lives on your machine, so you can inspect, back up or delete it at any time. Uninstalling the extension removes its stored data. If you used cloud sync, email us and we delete the server copy too.
- Monitoring, notifications and auto-reprice are all controlled in Settings; destructive actions are off or alert-first by default.
- Under UK GDPR you have rights over personal data a controller holds about you. Our honest position: we hold your waitlist or account email if you gave us one, and your synced listings and orders if you use cloud sync. All of it is deleted on request.
7Changes to this policy
When the architecture changes, this policy is updated before that ships, with the date above and a plain-English note about what changed. Changed on 16 September 2026 (one blocked-word list): the blocked-keyword (VeRO) word list belongs to your account now. Until this date it lived in the extension and reached us only as part of the extension’s settings copy; now the website’s Settings reads and saves it directly, and a signed-in extension keeps a copy on your computer, sends any word you add or remove there to your account, and takes the account’s list when it changes. The words are the brand names and terms you choose to be warned about; nothing else travels with them. With an extension that is signed out, the list stays on your computer only, as before. Also from this date, an eBay store that is already connected to another SellFalcon account cannot be connected to a second one: you are told, and nothing about that store is stored under the second account. Changed on 11 September 2026 (ordering at the supplier): the AliExpress connection can now CREATE an order, which is the first time anything about your buyer is sent out of SellFalcon rather than only stored. When you press Order at the supplier on an eBay order - in the tool’s Orders tab or on eBay’s own orders list - the tool shows you what it would buy, and on a second press sends AliExpress the product, the variant, the quantity and the delivery details of that order: your buyer’s name, address and phone number. It is the same information you would type into the supplier’s checkout yourself. What comes back and is kept is the supplier’s order number, and later the tracking number, stored against that eBay order in your account’s private space. Three things are true of every one of these orders and cannot be switched off: it is created UNPAID for you to pay in your own AliExpress account (their API has no payment call), SellFalcon never holds or uses a card of any kind, and nothing is ordered without a press. Ordering is off unless you turn it on, and marking the eBay order dispatched when the supplier ships is a second switch, also off. The "Connecting AliExpress on the website" section above has the full description. Changed on 11 September 2026: two features that read a page in your browser and send us nothing. First, Paste the buyer’s address at checkout: pressing Copy address on an eBay order reads your buyer’s name, address and phone so the next press at a supplier’s checkout can type them in. One address is held at a time, with the last five run logs beside it, in this computer’s storage only and never in Chrome’s settings sync; both are deleted after 30 days or at once from Settings → Buyer addresses. It is the first thing the extension keeps that is about your BUYER rather than about you, which is why it says so here, keeps only one, and forgets it quickly. Second, Save Temu’s own tax invoices: on a Temu orders page, saving an invoice asks Temu for its own tax-invoice pages with the session you are already signed in with, assembles them into a PDF and puts it in your Downloads. Nothing is stored and nothing is sent to us: not the order numbers, not the invoice, not the fact that you saved one. Reading a Temu page needs permission for temu.com, and reading an eBay order on the market you sell in needs permission for those eBay sites, so Chrome asks you for both when the extension updates; that is a permission to READ those pages, and neither feature sends anything from them anywhere. Changed on 10 September 2026: purchase records. Switching on Invoices in the extension lets it read your own AliExpress order history from the pages you are signed in to; the extension keeps four months of it on your machine, and - if you are signed in - each record is also copied to your account, which keeps twelve, so the year survives a reinstall or a new computer. What is copied includes the delivery address on the order, which for a dropshipped order is your buyer's address. The new "Your AliExpress purchase records" section above says exactly what is stored, for how long, where you see it, and what deletes it. Changed on 8 September 2026: the optional profile photo on Your account, described under "Accounts on this website"; eBay's own feedback percentage for each connected account is read with the hourly sync (one figure, no new personal data); and the replies you send to buyers on eBay are read from that account's Sent folder and kept with the buyer messages, so a conversation shows both sides, described under "eBay". Changed on 6 September 2026: private notes on support conversations, the one-email alerts to the person who runs SellFalcon, and the record of access decisions, all described under "Support chat on this website". Changed on 3 August 2026: added the optional cloud sync: signed-in users can keep a copy of their listings ledger and orders in their account for the web dashboard. Nothing changed for signed-out users. Changed on 7 August 2026: added the monthly reports and invoices section above: what you type on the reports page (expenses, per-order extras, profit-share settings, and your and your client's business details for invoices) is saved to your account. Also from 7 August: the AI provider row covers the optional buyer-message reply drafts, and cloud sync now includes the short monitoring/orders preference list so the dashboard's Extension settings card can show and change those preferences. Changed on 8 August 2026: added the optional "Sign in with Google or Microsoft" section above: the provider tells us only your verified email, which we match against invited accounts; nothing else changes and nothing new is stored. Also from 8 August: the support page's contact form stores your message and reply email until it is handled (see "The support form on this website"). Changed on 9 August 2026: added the Users & Team section above: inviting a team member stores their email, role and sign-in, and gives them access to your workspace data; removing them deletes their account. Also from 9 August: the synced preference list now includes your blocked-keyword (VeRO) word list, so the web Settings page can edit it, and the extension settings card moved from the dashboard to the new Settings page. Changed on 9 August 2026 (later): cloud sync now also carries the names you gave your eBay stores (name and internal id only, never tokens), so the web tool and your team see real store names instead of internal ids. Changed on 9 August 2026 (evening): added the optional "Connecting eBay on the website" section above: accounts that connect eBay directly on the site have an encrypted connection token stored so the tool can sync orders and manage listings without the extension; it is deleted on disconnect or account deletion. This changes nothing for extension-only users. Changed on 9 August 2026 (night): the web listing editor: cloud sync now carries your full staged drafts (description, image addresses, prices, variants, item specifics and the supplier link - previously only a short summary), so you can edit them at sellfalcon.com/editor and publish straight to an eBay account connected on the website. Publishing uses the same encrypted eBay connection described above; a published or discarded draft is deleted from the server copy. Changed on 10 August 2026: the Orders tab stores the per-order details you type (supplier cost, supplier order number, a private note, tracking) in your account's private space, and dispatching from the web sends the fulfilment - with your tracking number - to eBay through your connected account or your extension. Changed on 10 August 2026 (later): the tool can now read the private notes you write on your own eBay orders (through your connected eBay account) and store what it finds - the supplier cost, supplier order number and tracking number - in your account's private space, so your profit figures fill in on their own; a tracking number read this way is only ever shown to you, and is never sent to eBay unless you press dispatch yourself. Also from 10 August: you can optionally connect your AliExpress account on the Settings page, which stores an encrypted connection token so the tool can read supplier product prices and stock without your browser being open (see "Connecting AliExpress on the website"). Changed on 10 August 2026 (evening): once you link a listing to its AliExpress product, SellFalcon checks that product's price and stock about once a day on our own servers, with no browser open, and stores what it finds so it can tell you when your supplier's price or stock changes. It only reports unless you switch automation on. Changed on 10 August 2026 (later still): you can now turn on automatic changes in Settings. With them on, SellFalcon updates your eBay price when your supplier's price moves (working out a price that keeps your profit, never copying the supplier's price) and sets your eBay stock to 0 when the supplier sells out, restoring it when they restock. Both are OFF unless you switch them on, both run on our servers, and every change is listed for you under Notifications. Changed on 12 August 2026: support became a chat that lives on this website (see "Support chat on this website"): conversations are stored until resolved so replies can appear in the chat, and a signed-out conversation is tied to a random key in your browser. Also from 12 August: the signed-in feedback page stores what you choose to send us - message, category and optional attachments - so we can improve the tool. Changed on 12 August 2026 (later): support conversations and feedback can now carry attachments, including short voice notes; they are stored with the conversation or the feedback and deleted with it. Changed on 13 August 2026: one shared sign-in (see the section of that name above): the extension can now sign itself in from the session this website already holds in your browser, instead of asking you for your password a second time, and it is signed out when you sign out here. The extension also marks this site's pages so the tool knows it is installed in this browser, and our server now records when an extension last asked for its queued work, with its version and install id, so the tool can tell you whether anything is actually listening. Nothing new about your selling data is stored. Changed on 14 August 2026: returns and cases: for an eBay account connected on this website, SellFalcon now also reads the return requests and cases that are currently OPEN on that account, and stores them in your account's private space so the dashboard can warn you before eBay's respond-by date passes. What is stored per request is small and comes from eBay: the buyer's eBay username, the item, the reason and status eBay records, when it was opened and the deadline. Only open ones are kept - when a return closes, it is deleted the next time we check. SellFalcon never answers a return, accepts one, sends a label or issues a refund on your behalf: every row links to eBay for you to decide, because that is your money. Changed on 14 August 2026 (later): listing traffic: for an eBay account connected on this website, SellFalcon now also reads eBay's traffic report for your own listings - how many times each listing was shown, the click-through rate eBay works out, and how many sold over the last 30 days - and stores the busiest 300 per account so the dashboard can show which listings are being scrolled past. These are aggregate counts about your listings; they contain nothing about any individual shopper. If you press “Suggest better titles” on one of them, that listing’s current title is sent to the AI provider (with a key we hold) exactly as the listing editor already does, and if you then press “Use this” the new title is sent to eBay through your connected account. Both are one press each, on one listing at a time, and neither happens on its own. Changed on 14 August 2026 (evening): ended listings: SellFalcon now also reads which of your listings ended without selling and have not been relisted, and stores up to 60 of them per account so the dashboard can show you what is still worth bringing back. If you press “Relist” on one, that single listing is relisted on eBay through your connected account - one listing per press, never in a batch and never on its own. Changed on 14 August 2026 (later that evening): ad rates: SellFalcon now also reads your running Promoted Listings campaigns and the rate each advertised listing is bidding, so the dashboard can tell you which ads cost more than the listing earns. This is read-only - SellFalcon never changes a bid, starts or stops a campaign, or spends your advertising budget. Changed on 14 August 2026 (night): questions: SellFalcon now also reads the questions buyers have asked about your listings and not yet been answered, so the dashboard can tell you one is waiting. What is stored is the subject line, the asker's eBay username, the listing and the date - not the full message body. SellFalcon never sends a reply: you answer on eBay, where the extension can draft the wording for you to change and send yourself, exactly as it already does. Changed on 14 August 2026 (late): the dashboard now has a Check eBay now button, which asks eBay for the same things the hourly sync asks for - your returns, listing traffic, ended listings, ad rates, questions and feedback - instead of waiting for the next hour. It only reads: nothing behind that button changes a listing, sends a message, answers a return or spends anything. Changed on 14 August 2026 (billing): if paid plans are switched on and you subscribe, the payment is taken by our payment provider on their own checkout page - SellFalcon never sees, handles or stores your card details. What we store is the provider's customer and subscription reference, the plan you chose, the status they report (trialing, active, cancelled and so on) and the trial/renewal dates, so the tool knows what you are entitled to. Cancelling is done in the provider's own portal; this tool cannot end a subscription for you. Updated 16 August 2026: paid plans went live on that date, so this paragraph applies from then on (it previously ended by saying paid plans were not switched on yet). Changed on 14 August 2026 (messages): the web tool now has a Messages screen. For an eBay account connected on this website, SellFalcon stores the LIST of your buyer messages from the last 30 days - subject, sender's eBay username, the listing, the date, and whether each has been read or answered - so the screen can tell you who is waiting. The TEXT of a message was not stored on our servers when this entry was written: it was read from eBay each time and kept only in your browser. That changed on 24 August 2026 - see that entry below for exactly what is kept now, for how long, and what deletes it. If you press Write me a reply, that message's text and the order facts the tool already holds are sent once to the AI provider, exactly as the extension's older Draft reply button does. Nothing is sent to a buyer unless you press Send yourself - there is no automatic reply in this tool, and there will not be one. When you do send, we record which message you replied to, when, and how long the reply was (never the words), so a double press cannot message a buyer twice. Any saved replies you write are stored in your account until you delete them. Changed on 15 August 2026 (who runs this): this policy said SellFalcon was "an independent service based in the United Kingdom". That was wrong. SellFalcon is run by Khizar Hayat, a sole trader established in Pakistan, trading as SellFalcon, and he is the data controller. Nothing about what is collected, where it is stored or who it is shared with has changed - the services and their locations are unchanged and still listed above; what changed is that the person responsible is now named correctly. Changed on 15 August 2026 (sign-up): accounts can now be created two ways: by invitation, as before, or - when open sign-up is switched on - by you, by proving your email address with a one-time code. What we store for an account is identical either way and is described above; the code itself is stored only as a one-way hash and expires within fifteen minutes. Open sign-up is off unless we switch it on. Changed on 15 August 2026 (the payment overlay): the billing entry of 14 August said payment would be taken “on our payment provider’s own checkout page”. The flow that actually shipped is better described and is now described correctly: pressing a plan (or following a Paddle payment link with ?_ptxn= in it) opens Paddle’s checkout as an OVERLAY on our own page, drawn by Paddle’s software loaded from cdn.paddle.com - and that software is fetched as soon as the plan card is shown, so the overlay opens quickly, which means Paddle’s servers see your IP address and browser details when you view the plan card, not only when you pay. Your card details still go into Paddle’s form directly and never touch SellFalcon; what we store is unchanged and listed in the new Paddle row of the services table above. Changed on 16 August 2026 (the licence ping): the extension’s standing licence/plan check is retired - a signed-out extension no longer contacts our API on any schedule, and a signed-in one learns its plan from its own account session, as the services table now says. One small request was added at the same time: opening the extension’s Settings page asks our API whether open sign-up is switched on, so its sign-in box can describe the door correctly; the question carries no account data. Also from 16 August: complimentary access granted by hand has an end date, and that date - with the plan and where it comes from - is shown to you in Settings, in the extension, and stored with your account so every surface can agree. Changed on 16 August 2026 (the waitlist): the public waitlist form is retired and no new waitlist emails are collected; the handful already held are kept only until each person is invited, creates an account, or asks for deletion, exactly as before. Changed on 16 August 2026 (the short version, corrected): the summary at the top of this page still described the tool as it worked in its first week - "unless you sign in and use cloud sync, your selling data never touches our servers", with your API keys on your own computer and the AI running on a key you configure. That stopped being true when the work moved onto our servers, and three other answers on this page already said so, which means the summary was the one paragraph contradicting the rest of its own policy. It now describes what actually happens: an encrypted eBay connection on our servers, your ledger and orders in your account because the daily watch and the order sync run there with your computer off, no AI key for you to supply on this website, and card details that go into the payment provider's own form. Nothing about what is collected changed today; what changed is that the summary now matches the sections under it. Changed on 17 August 2026 (support conversations): two small changes to the support chat. A conversation you start signed OUT now follows you INTO your account when you sign in on the same browser: the random key in your browser is exchanged once for account ownership of that conversation, so the answer reaches you on the Support page instead of being stranded. And signing out now also clears that random key from the browser, so on a shared computer the next person cannot open your conversations. What is stored about a conversation is unchanged. Changed on 17 August 2026 (order details): for an eBay account connected on this website, the hourly order sync now also stores, per order, what eBay already shows you in Seller Hub: the buyer’s name, the postage address and phone number they gave eBay, the postage service they chose, eBay’s delivery estimate, the paid breakdown (item price, postage, total), and the note you yourself wrote on the order on eBay. This is so the tool’s own order page can show a whole order - and its packing slip can carry the address - without a trip to eBay. These details live in your account’s private space, come only from eBay, age out with the order (the sync keeps roughly the last 45 days), and are deleted with your account. Changed on 17 August 2026 (message labels): you can now put a label of your own choosing on a message conversation (like eBay’s folders); the label and which conversation it belongs to are stored in your account’s private space until you remove them, and deleted with your account. The text of messages was still browser-only when this entry was written; from 24 August 2026 read messages are kept on our servers too - see that entry below for what is kept, for how long, and what deletes it. Nothing about any of it is shared with anyone. Changed on 18 August 2026 (a photo flow named, and a section corrected): two fixes to this page itself. First, attaching a photo to a message reply (added 17 August) sends the image from your browser through our server to eBay Picture Services, which hosts it; the reply then carries eBay's link to the photo and we keep no copy - the services table now says so, and this sentence dates when the flow began. Second, the "Connecting eBay on the website" section still said synced orders carry only buyer usernames; that stopped being the whole truth on 17 August when the order details described above (name, address, phone, postage service, delivery estimate, paid breakdown) began syncing, and the section now names them. What is collected did not change on 18 August; what changed is that this page now describes all of it in the sections people actually read, not only in this footnote. Changed on 18 August 2026 (the extension is set up by signing in): two new flows for a signed-in extension, both optional in the sense that your own keys always take priority. First, AI without a key: when the extension has no AI key of its own, its AI requests travel through our server to the AI provider under a key we hold, counted against your plan's hourly allowance - the AI provider row above describes exactly what is in such a request, and we keep no copy. Second, eBay without a developer app: the extension can ask our server for a short-lived eBay access token minted from the eBay connection you made on this website, so it can list on that account with nothing to configure; the long-lived connection token never leaves our server, the short-lived one expires within minutes, and only the account owner's sign-in can request one. Nothing new is stored about you by either flow. Changed on 19 August 2026 (a backup you own): you can now connect your own Google account on the Settings page, and SellFalcon keeps a copy of your inventory and orders in a "SellFalcon backup" spreadsheet in your own Google Drive - written when you press Back up now and roughly daily while you use the tool. The connection token is stored encrypted like the eBay and AliExpress ones, the permission is the narrow one that reaches only files SellFalcon itself created, disconnecting deletes our stored connection while the spreadsheet stays yours, and the whole thing is optional: nothing changes if you skip it. The same day added "Save to Google Sheets" on the Reports page: that month's sheet, written into a per-month spreadsheet in the same Drive, updated in place on a re-save. The new "Backing up to your Google account" section above has the full description of both. Changed on 19 August 2026 (the ad rate you choose): the ad-rates entry of 14 August said SellFalcon never changes a bid or spends your advertising budget, and until today that was the whole truth. From today there is exactly one exception, and it only happens on your own press: if you type an ad rate while publishing a listing from the web editor, that one listing is added to your running Promoted Listings campaign at that rate (or its bid is updated to the rate you typed, if it is already advertised) through your connected eBay account. One listing per publish, never on its own, never a campaign created for you - and everything else about ad rates remains read-only. The same day: you can connect several AliExpress accounts and pair each with one of your eBay accounts, as the AliExpress section above now describes; what is stored per connection is unchanged, plus the pairing itself (two connection ids). Changed on 19 August 2026 (the extension learns your connections' names): the signed-in extension is now told the display name and working/not-working status of each eBay connection on your account - never a token - so its Settings page and account menu can name the account listing runs through instead of claiming no store is connected. Owner sign-ins only, like the short-lived eBay token above; nothing new is stored anywhere by this. Changed on 19 August 2026 (naming your AliExpress accounts): you can now give each connected AliExpress account a name of your own choosing, stored with your account and deleted with the connection - the AliExpress section above says so. Two behaviour fixes the same day, with nothing new stored: signing into an AliExpress account that is already connected now refreshes that connection instead of failing (the several-accounts feature announced earlier on 19 August had kept an old one-account check in the final step of the connect flow, so a second account was still refused - that check is gone), and how many AliExpress accounts each account can connect is now a per-account setting we can adjust, shown on the Settings card. Changed on 20 August 2026 (the invoice generator grew up, and a place for your logo and files): the Reports page's invoice now carries everything the documents you already send carry - due date, purchase order, currency, unit cost and quantity per line, discount, tax rate, shipping and a bank-details payment block - all typed by you and saved in the same per-month report space described above. The Settings page's Business details tab gained a logo (stored with your account, printed top-right on your invoices) and a company file cabinet: up to 15 files of 20MB each, stored in Cloudflare R2, owner-only, never read or processed by us, each deletable in one press and all of it deleted with your account. The new "Your logo and company files" section above has the full description. Later the same day: the invoice can also carry a one-off logo you pick just for it (for an invoice made for someone other than your own company); it is shrunk to print size and stored with that month's report data, deleted with the month or your account like everything else there. Changed on 20 August 2026 (alert emails, off unless you switch them on): the daily supplier check can now email you when it finds something waiting for your decision - a supplier price change with a suggested new price, an out-of-stock or restock, or a supplier page that has gone. One email per check at most, sent through the same email service named above, listing only your own listings' names and the supplier figures the check read. It is OFF unless you turn it on in Settings under Notifications, exactly as this tool promised when the switch did not exist yet, and turning it off stops it at once. Nothing new is stored: the email describes alerts the tool already records. Changed on 20 August 2026 (billing notices): two billing emails now exist, and only these two. Before a free trial ends you get one reminder naming the end date and, when the payment provider confirms it, the price, so the first charge is never a surprise; and when a subscription payment fails you get one note saying you keep access while the provider retries and where to fix the payment method. What we store to make that work is one small row per notice sent (which account, which notice, when), deleted with your account. Changed on 20 August 2026 (error reports): the website's pages now report their own script errors to us, as the new "Error reports from this website" section above describes: the error text, script, line, page and site version, nothing about you, deduplicated, capped, and deleted after about 14 quiet days. Changed on 23 August 2026 (listing templates): the web listing editor can now save a listing template - your own description wording, item specifics, condition, brand, fee and cost settings, margin and price ending - so you do not retype them on every listing. A template is stored with your account until you delete it, and is deleted with your account. It holds nothing about any buyer, and by design it cannot hold a listing title, category, photo, item cost or variant: those belong to a single product rather than to how you list. Nothing is sent to eBay or anyone else by saving or using one. Changed on 23 August 2026 (messages stay readable offline): the text of your buyer messages is still never stored on our servers - that promise is unchanged. What changed is how long the copy in your own browser lasts: it used to be wiped the moment you closed the tab, so the tool asked eBay for the same messages again every time you came back. It now stays in your browser for up to 30 days, which is what lets the tool leave eBay alone. It never leaves your computer, it is tied to the account that read it, and signing out deletes it - so on a shared computer the next person cannot read your messages. Clearing your browser data removes it too. (Superseded on 24 August 2026: read messages are now also kept on our servers - see that entry.) Changed on 24 August 2026 (messages are kept on our servers now): this reverses the promise above, openly rather than quietly, on the owner's decision and for one stated reason: so your inbox opens instantly, from any computer, without asking eBay again for words it already gave us. What is kept: the cleaned text of each buyer message the tool has read - the tool reads the newest two months by itself, so your inbox is ready before you click - plus the sender, subject and date it already held. What is NOT kept: eBay's own notices, and anything older than your setting. How long: 2 months unless you choose 12 in Settings; every message older than that is deleted automatically, judged by the message's own date. What else deletes it: disconnecting the eBay account it came from, deleting your SellFalcon account, or asking support@sellfalcon.com. Choosing 12 months only reaches messages eBay still holds - history eBay has already cleared cannot be recovered. Nothing about this is shared with anyone, ever.
8Contact
Questions, complaints or requests: support@sellfalcon.com. A human answers.
Anything here that reads as though it were written to protect us rather than to tell you the truth is a bug. Write to support@sellfalcon.com and it gets rewritten.