Stashtab Sync

Privacy policy

Last revised July 18, 2026

Who this covers

Stashtab Sync (“Sync”) is operated by Stashtab, Inc. Sync is a business tool for game stores: you connect the marketplaces you already sell on, and Sync keeps your card inventory listed, priced, and taken down when it sells. This policy describes what Sync does with data belonging to you, the seller, and to the marketplace accounts you connect.

Your account

When you create a Sync account we store your name, email address, a hashed password, and session records. We do not store your password in a form we can read. If you join a waitlist for a marketplace Sync does not support yet, we store the email address you submit and the name of the platform you asked for.

Marketplace connections and credentials

Connecting a marketplace grants Sync access to that account on your behalf. For each connection we store the credentials the platform issues us — access tokens, refresh tokens, and webhook or notification secrets — along with the identity of the connected account (for example a Shopify store domain or an eBay seller account identifier), the scopes you granted, and expiry timestamps.

Every credential is encrypted at rest with AES-256-GCM using a key that is held in our deployment environment and never stored beside the data it protects. Credentials are decrypted only in memory, only to make a request to the marketplace that issued them. They are never logged, never shown in the Sync interface, and never shared with another seller or another platform.

You can disconnect any marketplace from Sync’s settings at any time. Disconnecting removes the stored credentials and asks the platform to remove the notification subscriptions Sync created.

What Sync reads and stores

Your inventory. The cards you list through Sync — the specific printing and finish, condition, language, quantity, your price, and which marketplaces you have chosen to list it on.

Your pricing and shipping settings. The pricing rules you configure (price source, adjustments, rounding, floors) and the shipping profiles you create or import from a connected store.

Sale notifications. When a connected marketplace tells Sync that something sold, we store a receipt of that notification so the same sale is not processed twice: the platform, the connection it arrived on, the platform’s own order and event identifiers, the time it occurred, and the line items as SKU and quantity. This is the minimum needed to decrement your stock and delist the card everywhere else.

Card catalog data. Sync maintains a catalog of card printings built from public card-data sources. This is public reference data about cards, not data about you or your customers.

What Sync does not collect

Sync does not store your buyers’ names, shipping addresses, email addresses, or contact details. It does not store payment card numbers, bank details, or payout information — Sync never handles the money for a sale. Sale notifications are reduced to order identifiers, SKUs, and quantities before they are written down, and buyer details in the incoming payload are not retained.

Analytics and error monitoring

We record product usage events — such as signing in, connecting a platform, or creating a listing — to understand how Sync is used, and we record error reports with diagnostic context when something fails. These are tied to your seller account identifier. We do not sell this data, and we do not use it for advertising.

Service providers

Sync relies on the following providers to operate. Each processes data on our instructions and for no other purpose.

  • NeonManaged Postgres database hosting

    Seller accounts, encrypted platform credentials, listings, pricing rules, shipping profiles, and sale receipts.

  • VercelApplication hosting, scheduled jobs, and private object storage

    Application traffic, scheduled job execution, and private storage of compressed public card-catalog snapshots.

  • PostHogProduct analytics

    Product usage events such as sign-in, platform connected, and listing created, keyed to a seller account identifier.

  • SentryError monitoring

    Error reports and diagnostic context from failed requests and background jobs.

The marketplaces you connect — such as Shopify, eBay, and Mana Pool — are not service providers of ours. They receive listing and inventory data because you directed Sync to publish to them, and their own privacy policies govern what they do with it.

How long we keep data

Account, listing, pricing, and shipping data is kept for as long as your Sync account is open. Credentials for a connected marketplace are kept until you disconnect it or the connection is deleted. Sale receipts are retained as an operational record of what Sync synchronized. Card catalog data is public reference data and is retained independently of any seller account.

Deleting your data

You can disconnect any marketplace from Sync at any time, which removes the credentials Sync holds for it. To close your Sync account and have its data deleted, email us at support@stashtab.gg.

Sync also honors eBay’s marketplace account-deletion notifications. eBay notifies Sync when an eBay user closes their account; Sync verifies the notification’s signature and then deletes every connection belonging to that eBay account, including its encrypted credentials. We retain only a one-way SHA-256 hash of the deleted account identifier, so that a later reconnection attempt for the same closed account can be recognized. The identifier itself is not kept.

Changes and contact

If this policy changes materially we will update the revision date at the top of this page. Questions about privacy, data handling, or a deletion request go to support@stashtab.gg.