Legal
Privacy Policy
Last updated 13 August 2026.
1. What we collect
When you create a Deathpile account we store your email address and display name. If you use a password, we store its hash and never the plain-text password. If you choose Google sign-in, we store Google's stable account subject and the Google email observed when you link and most recently sign in. We do not receive or store a Google password, access token, refresh token, or permission to use Google services such as Gmail or Drive. A change to your Google profile email does not automatically change your Deathpile contact email. We also store the workspace, tub, item, and listing data you enter while using the service, the main job you ask Deathpile to solve, and a session cookie used to keep you signed in. If you choose a finding-stock or picking goal, you may also give us an estimated range for how long finding one sold item took before Deathpile.
2. Payments and billing
Paid plans are billed through Stripe, our payment processor. Stripe collects and stores your payment card details directly. Deathpile never sees or stores your full card number. We store the billing information Stripe shares back with us: your subscription plan, billing interval, trial and renewal dates, and cancellation status, so we can show your billing state in Settings and keep your account entitlements in sync. Stripe's own privacy policy governs how it handles the payment details you give it directly.
3. Marketplace integrations (eBay and Shopify)
If you connect an eBay or Shopify account, Deathpile stores encrypted credentials and reads your own listings, including SKU, title, price, quantity, and images. If you enable sale detection, Deathpile also stores a limited order reference, item details, quantity, price, and status needed to show and reconcile the sale. Buyer names, email addresses, phone numbers, payment details, and shipping or billing addresses are removed before storage. For eBay, we store a one-way keyed digest of the account's stable identifier so a future marketplace account-deletion notice can be matched without retaining that identifier in readable form.
We store the marketplace permissions granted and their expiry dates so we can renew credentials safely and tell a workspace owner when fresh consent is genuinely required. Shopify offline credentials are rotated automatically where possible. Fixed eBay authorization expiries can trigger service reminders 14, 7, and 1 day before expiry. When assisted listing removal is turned on, Deathpile sends the selected listing change only after an owner chooses the corresponding action.
4. Cookies and analytics
Deathpile sets a single session cookie required for you to stay signed in. It isn't used for advertising. The service uses Vercel Speed Insights to measure page performance (aggregated, non-identifying metrics such as load times), and Google Analytics 4 to understand how visitors find and use the site. Google Analytics may set its own cookies and processes usage data on our behalf; we do not use it for advertising and do not sell your data. You can opt out of Google Analytics with Google's browser add-on or by blocking analytics cookies.
If you start a pick run, we record server timestamps, the number of items in the run, successful outcomes, duration, mode, and whether the run was completed, cancelled, or abandoned. We use qualifying completed runs to show you measured retrieval time and, where enough evidence exists, a conservative estimate of time saved against the range you provided. We do not turn this estimate into money or project it across work you have not completed.
5. Email and communication preferences
Deathpile sends essential account and service emails such as verification, password, security, and workspace invitation messages. Account owners may also receive trial setup, progress, expiry, and relevant Deathpile product emails based on their direct account relationship with us. Signup clearly discloses this use. Every commercial email contains a no-login unsubscribe option, and you can also change the preference in Settings. Unsubscribing from commercial email does not stop essential account or service messages. We store consent, preference, delivery, bounce, complaint, and unsubscribe records so we can operate the service and honour communication choices. Trial and product emails may use your selected workspace goal, factual inventory outcomes, and qualifying retrieval measurements to explain what changed and suggest the next useful action.
Marketplace authorization-expiry reminders are essential service messages rather than commercial lifecycle email. We send them only to a verified workspace owner when a stored credential has a real expiry or a marketplace requires fresh consent. We retain the reminder stage, delivery state, and credential expiry used to prevent duplicate or stale notices; marketplace tokens are never placed in an email or delivery record.
6. How we protect your data
Passwords are hashed with argon2. Marketplace tokens and other secrets are encrypted at rest. Workspace data is only accessible to accounts you've added as members of that workspace. We don't sell your data, and we don't share it with third parties except the services required to run Deathpile itself (hosting, database, email delivery, error monitoring, Stripe for payment processing, and eBay's and Shopify's own APIs where you've connected an account).
7. Retention and deletion
We keep your account and workspace data for as long as your account is active. You can ask us to delete your account and associated data at any time by contacting us below. Connected marketplace integrations can be disconnected from Settings, which removes stored credentials and stops future sync. A disconnected marketplace account and its imported data remain until the workspace owner removes them. Removing an integration deletes stock originally imported from that account and its synced listing data while preserving manually created Deathpile stock. When Shopify sends a verified shop-redaction request after uninstall, we erase the matching Shopify-derived store, listing, order, and sale data. When eBay sends a verified marketplace account-deletion notice, we remove matched credentials, account mappings, listing caches, sale records, provider identifiers, images, prices, and generated provider-reference notes. The workspace owner's physical inventory, locations, quantities, and item names remain but are detached from eBay. Minimal request audit records are removed after 180 days. Workspace goal history and pick-run records are retained with the workspace so later estimates remain auditable. Completed or suppressed marketplace authorization reminder records are removed after 180 days, or earlier when the associated marketplace account or workspace is deleted.
8. Changes to this policy
If this policy changes materially, we'll update the “last updated” date above and, where appropriate, let you know directly.
9. Contact
For privacy questions or data requests, contact legal@deathpile.io.