Legal

Privacy Policy

Last updated: July 2026 · Hutsy Board (twostep.ecomhutsy.com)

How ECOMHUTSY LLC collects, uses, and protects seller and buyer data in the Hutsy Board product — separate from other EcomHutsy applications.

This Privacy Policy describes how ECOMHUTSY LLC ("we", "us") processes personal and business data through Hutsy Board, a multi-marketplace warehouse, procurement, and order-management application hosted at twostep.ecomhutsy.com. This policy applies only to Hutsy Board Warehouse — not to the EcomHutsy Sellerboard app or other EcomHutsy products.

1. Data we collect

  • Account & team data: user login credentials (hashed passwords), names, roles, branch/team assignments, selling account names, buying account names, warehouse locations, and operational audit logs.
  • Marketplace selling data: order exports and, when connected via Amazon Selling Partner API (SP-API) OAuth, order and inventory data from connected seller accounts — including buyer personally identifiable information (PII) such as ship-to name, address, and phone when required for order fulfillment. Buyer PII is accessed only through Amazon's Restricted Data Token (RDT) mechanism where applicable.
  • Procurement & warehouse data: purchase order IDs, item costs, shipping/tax amounts, receiving records, stock movements, and fulfillment shipments you enter or import.
  • Gmail purchase/shipping emails (optional): when a buying account owner connects Gmail via Google OAuth with read-only scope, Hutsy Board reads message metadata and body content from that mailbox to parse Walmart, Amazon, or Best Buy order-confirmation and shipping-update emails into procurement records. We do not send email on your behalf.
  • Encrypted credentials: Amazon LWA client secrets, refresh tokens, and Google OAuth tokens are stored encrypted in our database — never in application logs or environment files exposed to clients.

2. Why we use this data

  • Authenticate users and enforce role-based access within your organization.
  • Import and reconcile marketplace orders, inventory, and financial reports.
  • Place and track supplier purchases, receive goods into warehouse stock, and ship customer orders.
  • Parse purchase-confirmation emails to auto-fill procurement costs and tracking where parsers are enabled.
  • Maintain audit trails for operational and compliance review.

3. How data is stored and protected

  • Sensitive tokens and secrets use AES-256-GCM encryption at rest via a server-only master key (TWOSTEP_CREDENTIALS_MASTER_KEY). They are stored in the Hutsy Board database only.
  • Hutsy Board runs on a dedicated deployment and database (twostep_db), separate from the EcomHutsy Sellerboard application and other products.
  • Session cookies protect authenticated areas. Public pages (such as this policy) do not require login.

4. Retention & deauthorization

Operational business records (orders, procurements, inventory movements) are retained while your account is active and as needed for your business operations.

When a seller revokes Amazon SP-API access, Hutsy Board marks the marketplace connection as REVOKED, stops sync retries, and deletes cached buyer PII and encrypted OAuth tokens within 30 days of revocation unless a longer period is required by law or an active dispute.

When Gmail is disconnected, encrypted Google tokens are deleted promptly; previously parsed procurement fields derived from email remain as part of your business records unless you request deletion (see Section 7).

5. Third parties

  • Amazon SP-API — order, inventory, pricing, and report data for connected selling accounts.
  • Google Gmail API — read-only access to connected buying-account mailboxes for purchase email parsing.

We do not sell personal data. Data is shared with third parties only as necessary to provide the service (API calls initiated by your authorized users) or when required by law.

6. Your choices

  • Marketplace OAuth and Gmail connections are optional; manual report upload remains available.
  • Organization administrators can disconnect integrations at any time from the Connect screens.
  • Users with appropriate roles can deactivate accounts and export operational reports.

7. Contact & data-deletion requests

For privacy questions or to request deletion of personal data, contact us at support@ecomhutsy.com.

This policy is governed by the laws of the State of Wyoming, United States.