AListEngine Privacy Policy
Last updated: August 18, 2025
This Privacy Policy explains how AListEngine (“AListEngine,” “Company,” “we,” “our,” or “us”) collects, uses, shares, and protects information in connection with our software-as-a-service platform that helps prepare product listings from images using AI and export them to marketplaces (e.g., auction platforms, eBay, Etsy).
1. Scope & Definitions
This Policy applies to personal information we handle when you visit our website, create an account, or use our Service. We act as:
- Controller for our own business purposes (e.g., accounts, billing, communications, analytics).
- Processor for Customer Data you upload or connect (e.g., product photos, descriptions, marketplace credentials, end-customer/order data) where you are the Controller.
2. Information We Collect
Account & Contact: name, email, company name, role, and password (hashed).
Billing: payment method and transaction details handled by our payment processor (e.g., the last4, card brand, billing address). We don’t store full card numbers.
Customer Data you provide: images, product details, categories, pricing, SKU/stock info, marketplace account identifiers, and any end-customer data included in listings you import or generate.
Usage & Device: log data (IP address, timestamps, pages/features used), device/browser type, app version, and error/diagnostic events.
Integrations: tokens/credentials necessary to publish to platforms you authorize (e.g., eBay, Etsy, auction platforms). We store only what’s needed to maintain the connection.
Support: messages, attachments, and feedback you send us.
Cookies/Similar Tech: see Cookies & Tracking.
3. How We Use Information
- Provide, operate, and support the Service (including AI-based description generation and publishing to marketplaces you connect).
- Authenticate you, secure accounts, prevent fraud/abuse, and debug.
- Process payments, send invoices, and manage subscriptions.
- Respond to support requests and improve our features and models.
- Send important service notices; with your consent or as permitted by law, send product updates or promotions (you can opt out).
- Comply with legal obligations and enforce our Terms of Service.
4. Legal Bases (GDPR/UK)
Where the GDPR/UK GDPR applies, we process personal data under these bases: performance of a contract (to provide the Service), legitimate interests (to secure, improve, and market our Service), consent (where required, e.g., certain cookies/marketing), and legal obligation.
6. AI Processing & Training
To generate descriptions from images and other inputs, we may route Customer Data to our AI models or third-party AI providers under data-processing terms. We use reasonable technical and organizational measures to protect the data in transit and at rest.
Model improvement: By default, we use aggregated, de-identified telemetry to improve quality and safety. We do not use your identifiable Customer Data (e.g., your product photos or descriptions) to train models in a way that would disclose your content to other customers, unless you give us explicit permission or enable a clearly labeled opt-in feature.
8. Data Retention
We keep personal data only as long as necessary to provide the Service and for legitimate business needs (e.g., security, fraud prevention, accounting), or as required by law. You may request deletion of your account data at any time (see Your Rights & Choices). Backups and logs are purged on a rolling schedule.
9. Security
We implement reasonable administrative, technical, and physical safeguards (e.g., encryption in transit, access controls, least-privilege). No system is 100% secure; you are responsible for safeguarding your credentials and promptly notifying us of any suspected unauthorized access.
10. Your Rights & Choices
- Access, correct, delete your account information via in-app settings or by contacting us.
- Portability (export) where applicable.
- Object/Restrict/Withdraw consent for certain processing (e.g., marketing, non-essential cookies).
- Regional rights: If you’re in the EEA/UK/California or similar jurisdictions, you may have additional rights under GDPR/UK GDPR/CPRA. We will not discriminate against you for exercising your rights.
To exercise rights, email [email protected]. For security, we may verify your request.
11. Children
Our Service is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child provided personal information, contact us and we will take appropriate steps to remove it.
12. International Transfers
We may process data in the United States and other countries. Where required, we use appropriate safeguards for cross-border transfers (e.g., Standard Contractual Clauses and supplementary measures).
13. Customers & Data Processing Addendum
When we process Customer Data on your behalf, you (the customer) are the Controller and responsible for notices, consents, and the lawfulness of that data.
We primarily serve U.S. customers and therefore don't issue a Data Processing Addendum (DPA) as a standard part of onboarding. However, if your organization requires one, we're happy to accommodate. Please note that preparing the DPA (including SCCs) may take additional time to complete. To request a DPA, contact [email protected].
14. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you (e.g., by email or in-app notice). Your continued use of the Service after the effective date means you accept the updated Policy.
15. Contact
Questions or requests? Email [email protected].