ahalens Privacy Policy
Last updated: July 5, 2026
This Privacy Policy explains how Stonewell Studio ("ahalens," "we," "us," or "our") collects, uses, stores, and shares information when you use the ahalens website, web app, dashboard, and related services (the "Service").
ahalens is an analytics dashboard for Etsy sellers. The Service connects to Etsy only after you authorize access through Etsy OAuth. We use Etsy data to provide shop analytics, sync status, dashboard metrics, listing context, and in-app weekly summaries. We do not operate Etsy, and Etsy's own services are governed by Etsy's policies.
1. Information We Collect
Account information
When you create or use an ahalens account, we collect information needed to run your account, such as:
- Name.
- Email address.
- Password authentication data, stored through our authentication system and never stored as plain text.
- Login session records needed to keep you signed in, such as session tokens and expiration timestamps.
- Password reset and account verification records.
Etsy connection information
When you connect an Etsy shop, we collect and store information needed to maintain that connection, including:
- Etsy user and shop identifiers.
- Etsy shop name, shop title, shop currency, and shop country fields.
- The OAuth scopes granted for the connection.
- Encrypted Etsy OAuth access and refresh tokens.
- Connection status and security records for actions such as connecting Etsy, disconnecting Etsy, account closure, OAuth validation failures, and token failures.
Etsy shop analytics data
After you connect your Etsy shop and start sync, we collect and store the data needed to provide the current analytics product, including:
- Order and sales data from Etsy, such as order dates, order status, item details, quantities, prices, discounts, refunds, taxes, shipping amounts, buyer country where available, and listing information needed to show dashboard metrics.
- Etsy payment, fee, and refund data where needed to calculate aggregate earnings-related metrics.
- Sync status and dashboard metrics generated from synced Etsy data.
The current product syncs analytics through Etsy OAuth and does not accept user-uploaded CSV files as an analytics data source.
Settings and preferences
We collect settings you choose in ahalens, including:
- Shop reporting timezone.
- Weekly reporting start day.
- Account and shop connection preferences.
Technical and usage information
We may collect technical information needed to provide, secure, debug, and improve the Service, such as:
- Log events, request metadata, error categories, and diagnostic metadata.
- Browser, device, operating system, and approximate network information available through normal web requests.
- Cookie and session information needed for login and security.
We do not currently use third-party advertising cookies or third-party product analytics tools in the implemented Service. If we add those tools, we will update this policy before using them where required.
Communications
If you contact us for support or account help, we may collect the information you provide in that communication. We may also send transactional emails, such as password reset messages.
2. Etsy Permissions We Request
ahalens currently requests the minimum Etsy OAuth scopes needed for the implemented read-only dashboard:
shops_r: to identify the connected Etsy user and shop and read shop metadata.transactions_r: to read Etsy order, payment, fee, and refund data used for dashboard metrics.listings_r: to read narrow current listing context for dashboard top listings, such as thumbnails, listing state, and availability warnings.
We do not request Etsy write scopes for the current dashboard. ahalens does not create, edit, renew, publish, or delete Etsy listings; update, fulfill, or cancel Etsy orders or receipts; change Etsy shop settings; or read, send, or modify Etsy buyer messages.
You can disconnect your Etsy shop inside ahalens. Disconnecting clears the Etsy connection tokens stored by ahalens and stops future ahalens sync for that shop unless you reconnect. You can also manage app authorization from Etsy's integrations settings. If Etsy no longer authorizes the connection, ahalens will no longer be able to sync your Etsy data.
3. Information We Intentionally Avoid
For the current analytics scope, ahalens intentionally avoids collecting or storing:
- Buyer names, buyer email addresses, street addresses, postal codes, buyer/seller messages, gift messages, and raw Etsy API payloads as product data.
- Plain-text Etsy OAuth access or refresh tokens.
- Etsy OAuth credentials or app secrets in places accessible to your browser or frontend code.
We also avoid collecting or storing other sensitive buyer identity and message content unless a future feature requires it and this policy is updated before that collection where required.
4. How We Use Information
We use information to:
- Create, authenticate, and secure your ahalens account.
- Connect your Etsy shop after you authorize access.
- Sync Etsy data from server-side systems.
- Produce dashboard metrics such as sales, orders, item quantity, AOV, discounts, listing context, sync status, and Etsy Net Earnings.
- Show owner-facing dashboard views and in-app weekly summaries.
- Maintain sync status, connection status, and data coverage needed for accurate dashboard reporting.
- Process account actions such as password reset, Etsy disconnect, and account closure.
- Revoke other active sessions when you change or reset your password, for account security.
- Protect the Service, detect failures, investigate abuse, and keep audit records.
- Respond to support requests.
- Comply with legal obligations and enforce our terms.
We do not sell your personal information.
Current in-app weekly summaries are generated from dashboard metrics and do not use third-party AI providers. We do not use Etsy API data to train AI models or share Etsy API data with third-party AI providers under the current implementation.
5. How We Share Information
We share information only as needed to provide, secure, and operate the Service, including with:
- Hosting and serverless infrastructure providers, currently Vercel.
- Database infrastructure providers, currently Neon Postgres.
- Transactional email providers, currently Resend for production password reset email delivery.
- Etsy, when you authorize OAuth access and when our backend makes authorized Etsy API requests for your connected shop.
- Professional advisors, legal authorities, or other parties when required by law, to protect rights and security, or in connection with a business transaction such as a merger, acquisition, financing, or sale of assets.
Service providers may process information only for the services they provide to us. We do not share seller, buyer, order, or token data with third-party marketing or advertising platforms under the current implementation.
We refresh or stop displaying Etsy listing content according to Etsy API caching and freshness requirements. Historical dashboard metrics may remain in ahalens.
6. Cookies and Similar Technologies
ahalens uses cookies and similar technologies for essential purposes, including login, session management, security, and account administration.
You can control cookies through your browser settings. Blocking essential cookies may prevent you from signing in or using parts of the Service.
7. Data Storage and Security
We use safeguards designed to protect your information, including encrypted Etsy connection tokens, server-side Etsy API access, account ownership checks, limited logging of sensitive information, and security monitoring for connection and account actions.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we design the Service to reduce unnecessary collection and exposure of sensitive seller, buyer, order, and token data.
8. Data Retention, Disconnect, and Account Closure
We keep information for as long as needed to provide the Service, maintain security, comply with legal obligations, resolve disputes, and enforce agreements.
If you disconnect an Etsy shop:
- ahalens clears the Etsy connection tokens stored by ahalens for that shop.
- Future Etsy sync is stopped unless you reconnect.
- Historical synced dashboard data remains available in ahalens unless you separately close your account or request deletion where available.
- Disconnecting in ahalens does not delete Etsy-side data and does not remove ahalens from Etsy's own authorized-app list. You can separately manage Etsy-side app authorization from Etsy's integrations settings.
If you close your ahalens account:
- ahalens deletes your account, connected shop records, locally synced Etsy data, dashboard metrics, sync records, sessions, and authentication records from the active application database.
- ahalens clears Etsy connection tokens before deletion.
- ahalens may keep a limited security record of the account closure where required for security and operational integrity.
- Account closure is immediate in the active application database and is not reversible by the application.
- Database backups may retain deleted information until the hosting or database provider's backup retention period expires.
- Account closure does not delete or modify your Etsy shop, Etsy listings, Etsy orders, Etsy receipts, Etsy payments, or other Etsy-side records.
If a sync operation is actively running, account closure or disconnect may be delayed and you may need to try again after the operation finishes.
9. Your Choices, Access, and Complaints
You can use available in-product controls to disconnect an Etsy shop or close your ahalens account. Disconnecting stops future ahalens Etsy sync for that shop and clears Etsy connection tokens stored by ahalens. Closing your ahalens account deletes your local account and locally synced ahalens data, subject to the retention notes above.
You may contact us at hello@ahalens.pro to:
- Ask a privacy question.
- Request access to personal information we hold about you.
- Ask us to correct inaccurate or out-of-date personal information.
- Request deletion or account closure where available.
- Make a privacy complaint.
We may need to verify your identity before completing a privacy request. Some information may be retained where required for security, legal compliance, dispute resolution, or backup integrity.
If you make a privacy complaint, we will review it and respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au/.
10. International Data Transfers
ahalens may process, store, or disclose personal information using service providers located in Australia, the United States, and other countries where our providers operate. Current provider examples include Vercel, Neon, Resend, and Etsy.
Those countries may have data protection laws different from the laws where you live. Where required, we use appropriate safeguards for international transfers.
11. Children's Privacy
The Service is intended for Etsy sellers and is not directed to children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided information to us, contact us at hello@ahalens.pro.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date above. If changes are material, we may provide additional notice in the Service or by email where appropriate.
13. Contact Us
For privacy questions, access or correction requests, deletion or account closure requests, or privacy complaints, contact:
Stonewell Studio hello@ahalens.pro
The term "Etsy" is a trademark of Etsy, Inc. This Application uses Etsy's API, but is not endorsed or certified by Etsy.