Privacy Policy
This policy explains what data IVY Shield (the “Application”) collects, how it is used, stored, secured and shared, and what control you have over it.
1. Who is responsible
The data controller is Noir Pixel Studio Iwona Bielecka, Palestyńska 1a, 03-321 Warsaw, Poland, VAT ID PL5242492216. Contact: ivysystemco@gmail.com.
2. What we collect
- Account data: your email address and, if you pay, your name and billing details as provided to Stripe (we receive a customer ID, not your card details).
- Connected shop data: the shop name and address you connect, and the titles, tags, descriptions and links of the shop's active listings, read through the Etsy API (for Etsy shops) or the store's public product catalogue (for Shopify). We do not access orders, payments, buyers, messages or any other private shop data.
- Etsy access tokens: when you use “Connect with Etsy”, Etsy gives us access tokens for your shop (permissions: read shop, read listings, edit listings). We store them encrypted and use them only to scan your listings and to apply fixes you confirm. Disconnecting Etsy or removing the shop deletes them.
- Scan data: phrases you check and the results (matching USPTO trademark records, which are public data).
- Technical data: a session cookie that keeps you signed in, and a one-way hash of your IP address used only to limit free previews.
- Optional settings: alert preferences, webhook addresses and the brand name you choose for PDF reports.
3. How we use it
- To provide the Service: run checks, scan connected shops, show results and generate reports.
- To send alerts you asked for (new risks, new USPTO filings matching your listings) and sign-in links.
- To manage your subscription and meet tax and accounting obligations.
Legal bases (GDPR): performance of our contract with you (Art. 6(1)(b)), legal obligations (Art. 6(1)(c)) and our legitimate interest in protecting the Service from abuse (Art. 6(1)(f)). We do not sell your data, use it for advertising or share Etsy data with anyone except the processors listed below, who handle it only to run the Service.
4. Where it is stored and who processes it
- Cloudflare — website hosting and account database.
- Hetzner Online (Germany, EU) — the server that runs the USPTO database and shop scans.
- Stripe — payments and invoices.
- Resend — sending sign-in links and alert emails.
Data is transmitted over encrypted connections (HTTPS). Sign-in tokens and session tokens are stored only as hashes. Access to servers is restricted to the Application Developer.
5. How long we keep it
- Listing titles and tags are refreshed at every scan and are kept only as long as needed to show your results and send alerts.
- When you disconnect a shop, its listing data and results are deleted.
- Account data is kept while you have an account; billing records are kept as required by tax law (in Poland, 5 years).
6. Your rights and controls
You can disconnect shops, switch email alerts off and delete webhooks yourself in the panel. Under the GDPR you also have the right to access, correct, delete, restrict or export your data and to object to processing. Email ivysystemco@gmail.com and we will respond within 30 days. You can also lodge a complaint with the Polish supervisory authority (Prezes UODO) or your local authority.
7. Cookies
We use one strictly necessary cookie (ivy_session) to keep you signed in. We do not use advertising or tracking cookies on IVY Shield.
8. Etsy
The term 'Etsy' is a trademark of Etsy, Inc. This Application uses Etsy's API, but is not endorsed or certified by Etsy. Etsy's own privacy policy applies to your use of Etsy.
9. Changes
We will post updates on this page and notify you by email about material changes.