Privacy Policy
Last updated: February 12, 2026
1. Introduction
Polylisto ("we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, and protect your information when you use our Service at polylisto.com.
2. Information We Collect
Account Information
- Email address
- Full name
- Password (hashed, never stored in plain text)
Payment Information
Payment processing is handled by Stripe. We do not store your credit card number, CVC, or billing address. Stripe's privacy policy applies to payment data: stripe.com/privacy.
Product Listing Content
When you use the Service, you submit Amazon product listing content (titles, bullet points, descriptions, search terms). This content is processed to provide translations and localizations.
Usage Data
- Number of listings localized
- Marketplaces selected
- Feature usage (exports, keyword reports)
Affiliate and Referral Data
If you participate in our affiliate program or sign up via a referral link, we collect:
- Your unique referral code (auto-generated, not personally identifiable)
- Which user referred you (stored as an internal ID, not shared with the referrer)
- Commission records (payment amounts and commission calculations for affiliates)
Affiliates can see the number of users they referred and commission amounts, but cannot see the names, emails, or other personal information of referred users.
3. How We Use Your Information
- To provide and improve the Service
- To process your translations and localizations
- To manage your subscription and billing
- To send transactional emails (account confirmation, password resets)
- To respond to support requests
We do not sell your personal information. We do not use your content to train AI models.
4. Third-Party Services
We use the following third-party services to operate Polylisto:
- Supabase — Authentication and database hosting (EU/US servers)
- Stripe — Payment processing
- DeepL — Machine translation
- Anthropic (Claude) — AI-powered content adaptation and validation
- Vercel — Application hosting
- Upstash — Rate limiting
- Sentry — Error monitoring and performance tracking
Your product listing content is sent to DeepL and Anthropic for processing. These services process data according to their own privacy policies and do not retain your content beyond the processing request.
We also query publicly available Amazon autocomplete data to research local search terms for your target marketplaces. No personal data is sent to Amazon during this process.
5. Data Retention
We retain your account data for as long as your account is active. Translation history is retained for your reference. If you delete your account, we will delete your personal data within 30 days, except where we are legally required to retain it.
6. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest for sensitive data
- Row-level security on database tables
- Hashed passwords (never stored in plain text)
- Leaked password detection via HaveIBeenPwned (using k-anonymity)
- Rate limiting to prevent abuse
7. Cookies
We use essential cookies for authentication and session management. We do not use tracking cookies or third-party advertising cookies.
If you arrive at our site via an affiliate referral link (containing a ?ref= parameter), we set a polylisto_ref cookie to attribute your signup to the referring affiliate. This cookie expires after 30 days, is transmitted only over HTTPS (Secure flag), and contains only the referrer's anonymous referral code — no personal information. The cookie is automatically deleted after you complete signup.
8. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and associated data
- Export your data
- Withdraw consent for optional data processing
To exercise these rights, contact us at support@polylisto.com.
9. European Users (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, the following additional provisions apply:
Legal Basis for Processing
- Contract performance — Processing your listing content is necessary to deliver the Service you signed up for.
- Legitimate interest — Error monitoring (Sentry), rate limiting, and analytics to maintain and improve service reliability.
- Consent — Where required, such as optional marketing communications.
International Transfers
Your data may be transferred to and processed in the United States and other countries where our service providers operate. For transfers outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms.
Your GDPR Rights
In addition to the rights listed in Section 8, you have the right to:
- Request restriction of processing
- Object to processing based on legitimate interest
- Data portability (receive your data in a structured, machine-readable format)
- Lodge a complaint with your local data protection authority
To exercise any of these rights, contact us at support@polylisto.com.
10. California Users (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:
- Right to know — You can request what personal information we collect, use, and disclose.
- Right to delete — You can request deletion of your personal information.
- Right to opt out of sale — We do not sell your personal information to third parties.
- Non-discrimination — We will not discriminate against you for exercising your CCPA rights.
To make a CCPA request, contact us at support@polylisto.com.
11. International Data Transfers
Your data may be processed in the United States, European Union, or other jurisdictions where our service providers operate. We ensure appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses where required.
12. Children's Privacy
The Service is not intended for users under 18. We do not knowingly collect information from children.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the Service.
14. Contact
Questions about this Privacy Policy? Contact us at support@polylisto.com.