Account and billing
Privacy and security
What Reskale stores, how marketplace credentials are handled, and who can see them.
What Reskale stores, how marketplace access is handled, and who can see it.
This page describes how the system works. The binding legal documents are the privacy policy and terms.
Marketplace passwords
Reskale never sees your marketplace passwords. You log in on each marketplace's own site. No password is ever typed into Reskale, transmitted to it, or stored by it.
That is true for both connection types, for different reasons: OAuth marketplaces never share a password with any application, and session marketplaces are logged into by you, in your own browser.
Marketplace access, precisely
Two mechanisms, and they have genuinely different properties.
OAuth — eBay, Discogs
The marketplace issues Reskale a token after you approve it on their consent screen. The token grants specific permissions, and you can revoke it from your marketplace account settings at any time without changing your password.
Session — Mercari, Depop, Vinted
These publish no API, so there is no token to issue. Reskale uses the session your own browser holds after you log in.
That session credential is transmitted to Reskale's servers and stored there, encrypted. Being straight about this, because it is the part people most want to know:
- It is sent over TLS.
- It is stored encrypted at rest with AES-256-GCM, using a key held server-side and never in the database.
- It is scoped to your account, and attempts to read another user's credentials are blocked at the database level as well as in application code.
- It is never returned by the API — no Reskale endpoint will hand a credential back, including to you.
The reason it is stored at all is background sync. Syncing new sales while your browser is closed requires the server to hold a working session; a design that kept everything in the browser could only sync while you had a tab open.
Revoking access
Two ways, both immediate:
- Disconnect in Reskale — deletes the stored credential.
- Log out on the marketplace — invalidates the session everywhere, including for Reskale.
For OAuth marketplaces, revoking in your eBay or Discogs account settings works too.
What the extension can access
The extension declares access to eBay, Mercari, Poshmark, Depop and Vinted, and their image CDNs. Nothing else. It cannot read your email, your bank, or any other tab, because it has no permission to.
Within those sites it reads your own seller pages, fills sell forms when you crosspost, and takes listings down when you delist.
It does not run remote code. Everything it executes ships in the extension package and is reviewed by the Chrome Web Store — nothing is fetched from a server and run.
Your data
Stored in your account: inventory, listings, sales, orders, offers, messages, shipments, bookkeeping entries, and photos.
- Scoped to your user. Enforced in application code and again by row-level security in the database, so a bug in one layer does not expose data through the other.
- Not sold. Not shared with third parties for their own purposes.
- Not used to compete with you. Your sourcing and pricing data is yours.
Third parties
Reskale uses a small number of services to operate:
- Supabase — database and authentication.
- Stripe — payments. Stripe holds card details; Reskale does not.
- Sentry — error reporting, so failures are found and fixed.
- PostHog — product analytics.
- Google Gemini — image identification and receipt reading, for the images you submit to those features.
The marketplaces themselves receive what you send them when you list.
Errors and diagnostics
When something fails, Reskale records the error to fix it. Diagnostic data is sanitised — credentials and personal detail are stripped, and what remains is the shape of the failure rather than its contents.
This matters in a specific way worth knowing: some marketplace API responses contain more than you would expect. eBay's Best Offer response, for example, includes a buyer container that can carry an email address. Responses are handled accordingly rather than logged wholesale.
Account safety
The security posture that most affects you is not cryptographic. It is what the tool is willing to do on your marketplace accounts.
Reskale does not do follow-spam, engagement automation, or anything designed to look like activity that is not. Requests are paced deliberately. Poshmark was removed entirely because its bot detection suspends sellers — the reasoning.
A tool that gets your selling account banned has failed you regardless of how well it encrypted anything.
Reporting a vulnerability
Email support@reskale.xyz with "security" in the subject. Reports are taken seriously and answered.
Related
Something here wrong or out of date? Tell us.