Legal Last updated: 20 August 2026 · Effective: 20 August 2026

Privacy Policy

ArbiKey is operated by Elmas Group LLC ("we", "us", "our"), a limited liability company registered in New Mexico, USA. This policy describes what personal data we collect, how we use it, and what rights you have over it. Our service is hosted entirely within the EU, and we process data in compliance with the General Data Protection Regulation (EU) 2016/679.

Plain language summary. We collect your email and the business data you type in. We never sell it, never share it with advertisers, and you can export or delete it at any time. Our servers are inside the EU.

1. Data Controller

The data controller for all personal data processed through arbikey.com is:

Elmas Group LLC
1209 Mountain Road Pl NE, Ste R
Albuquerque, NM 87110, USA

Email: privacy@arbikey.com

2. What We Collect and Why

CategoryDataLegal Basis
Account identityEmail address; hashed password; Google OAuth profile (email, name, avatar) if you use "Sign in with Google".Contract performance — needed to provide your account.
Business dataProducts, supply costs, sale prices, order records, returns, expenses, store names and identifiers you enter into the product.Contract performance — this is the core of the service.
eBay connectioneBay OAuth access and refresh tokens; your eBay seller ID; order and listing data fetched on your behalf.Contract performance; your explicit consent when you authorise the eBay connection.
Billing metadataSubscription tier, renewal date, subscription ID. Card details are handled exclusively by Paddle (our merchant of record) and are never stored by us.Contract performance; legitimate interest in managing subscriptions.
Technical and security dataIP address; browser and device type; error logs; authentication events.Legitimate interest — keeping the service secure and operational.
CommunicationsEmails you send to support@arbikey.com or privacy@arbikey.com.Legitimate interest — responding to your enquiry.

3. What We Do Not Collect

4. How We Use Your Data

We do not use your data for any purpose not described above without your prior consent.

5. Data Storage and Security

All data is stored with Supabase on servers located in the European Union (Ireland, eu-west-1). Access to your rows is enforced at the database level using Row-Level Security (RLS) — even ArbiKey engineers cannot query your data through the normal application interface. All changes to business data are written to an append-only audit log.

Data in transit is encrypted using TLS 1.2 or higher. Passwords are never stored in plain text.

6. eBay Integration

When you connect an eBay account, ArbiKey requests the minimum OAuth scopes required to fetch your orders and listings. We store only what is necessary to display your own figures. You can disconnect your eBay account at any time from the Integrations section of the app, and we will delete the stored tokens and marketplace data. We honour eBay's account-closure notifications and delete associated data within 30 days of receipt.

7. Cookies

We use essential cookies only. These are strictly necessary to authenticate your session and keep the service secure. We do not use advertising, tracking, or analytics cookies. There is no cookie consent banner because we do not set any non-essential cookies.

CookiePurposeDuration
sb-auth-tokenSupabase session authenticationSession / up to 1 week
sf_modeYour interface theme preference (light/dark)1 year (localStorage, not a cookie)

8. Third-Party Sub-Processors

Sub-processorPurposeLocation
SupabaseDatabase, authentication, edge functionsEU (Ireland)
CloudflareCDN, DDoS protection, static asset hostingEU and global edge
PaddlePayment processing, subscription management, merchant of recordUK/EU
ResendTransactional email deliveryEU

9. Transfers Outside the EU

We do not knowingly transfer personal data outside the European Economic Area. All primary storage and processing occurs in EU data centres. If any sub-processor transfers data outside the EEA, they are contractually required to provide an equivalent level of protection (e.g. Standard Contractual Clauses).

10. Your Rights Under the GDPR

To exercise any of these rights, email privacy@arbikey.com. We will respond within 30 days. If you believe we have infringed your rights, you may lodge a complaint with your national data protection authority.

11. Data Retention

We retain your account and business data for as long as your account is active. If you request account deletion, we will erase your data within 30 days, except where retention is required by applicable law (e.g. billing records may be retained for up to 7 years for tax compliance). Deleted accounts cannot be recovered.

12. Children

ArbiKey is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, please contact us and we will delete it promptly.

13. Changes to This Policy

We may update this policy to reflect changes to our service or applicable law. If a change materially affects your rights, we will notify you by email at least 14 days before it takes effect. The current version is always available at arbikey.com/privacy/.

14. Contact

Data protection enquiries: privacy@arbikey.com
General support: support@arbikey.com