Privacy Policy

Last updated: [DATE] — placeholder, set this when you actually publish.

This is a starting draft, not legal advice. It was written to accurately describe what data Key Issue's server actually collects and stores today (see the codebase — db.js — for the literal schema this is based on). Have a lawyer review it before relying on it, especially if you'll have customers in the EU/UK (GDPR), California (CCPA), or anywhere else with specific data-protection requirements this draft doesn't attempt to cover.

1. What we collect

DataWhy
Name, shop name, email, password (stored as a salted hash, never in plain text)Your account
Comic details you enter or that get identified from a photo (title, issue, publisher, grade, condition notes, suggested price)To generate and store your listing templates
eBay OAuth tokens, if you connect your eBay accountTo create draft listings on your behalf
Stripe customer/subscription IDs and plan statusTo manage your subscription and billing

2. About the photos you upload

Cover photos are sent to an automated image-recognition system to identify the book and assess its condition. The photo itself is used only for that identification and is not stored by us afterward — only the resulting structured details (title, issue, grade, condition notes, etc.) are saved to your account.

3. What we don't do

4. Third-party services we use

We rely on third-party services to operate Key Issue, each of which processes the minimum data needed for its purpose: an AI provider (for listing generation and photo identification), Stripe (for payment processing), and eBay (only for accounts you choose to connect). Each has its own privacy practices governing the data they process.

5. Data retention

We keep your account and template data for as long as your account is active. If you'd like your account and its data deleted, contact us at [YOUR SUPPORT EMAIL] — [YOUR DECISION: state your actual deletion timeline/process here].

6. Your rights

[YOUR DECISION, with a lawyer — depending on where your customers are located, you may need to describe specific rights here: access, correction, deletion, data portability, and how to exercise them (e.g. GDPR for EU/UK residents, CCPA for California residents).]

7. Security

Passwords are stored using salted one-way hashing, never in plain text. Payment processing is handled entirely by Stripe. As with any online service, no method of storage or transmission is 100% secure, and we can't guarantee absolute security.

8. Changes to this policy

We may update this policy from time to time. Continued use of the Service after a change means you accept the updated policy.

9. Contact

Questions about this policy or your data: [YOUR SUPPORT EMAIL].