Privacy Policy — Integrated E-commerce Management System

Last updated: October 5, 2026
Software provider: Chengdu Caststar Artificial Intelligence Technology Co., Ltd.
Privacy contact: hello@astrafoundryai.com

1. Scope and Current Status

This policy explains information handling in the Integrated E-commerce Management System ("the Software"), a Windows desktop application with a local Go backend and PostgreSQL database. References to "we" and "us" mean the software provider named above.

Current V1.0: This is a pre-release local application. Shop, listing and order demonstrations use synthetic data. The Software does not currently connect to Etsy through OAuth or the Etsy API, and it does not use real Etsy tokens. Local accounts, preferences and information entered into local drafts are separate from those synthetic records. The Etsy practices in Section 4 describe a planned integration.

The current deployment runs in the customer's own Windows environment. It does not use a provider-hosted business-data service or cloud relay for business data. Information you choose to send us for support is separate from the records stored in your installation.

2. Information Processed by the Current Version

CategoryExamplesPurpose
Local application accountsLocal username, password verification material, roles and session informationLocal sign-in and access control; these are not Etsy account credentials
Local business records and draftsSynthetic shop, listing and order records; information entered into local drafts; necessary draft version and recovery informationOffline display, draft creation and editing, local persistence, conflict handling and recovery
Local preferencesSelected interface languageRemembering your language choice within the relevant application environment
Messages sent to usYour email address, message and any information you choose to includeResponding to your questions and support requests

Saving a local draft does not publish it on Etsy. Do not enter Etsy passwords, tokens, database credentials or unnecessary buyer personal information into draft fields or support messages.

3. Storage, Access and Sharing

Local application accounts and persisted business records are held in the customer's PostgreSQL installation. Local settings are stored in the customer's environment. Review and Internal installations use separate backends, databases, credentials, sessions and logs.

The current Software provides local sign-in and role controls. A shop filter controls what is displayed; it is not shop-level authorization. Etsy shop authorization and connection isolation remain part of the planned integration.

The customer controls access to the host computer, database and backups. The Software's local deployment does not send its business database to us. If you send information to our contact email, that information is received by us through the email services handling the message. Do not send passwords, tokens, database credentials or unredacted customer records through ordinary support messages.

Planned public hosting: Cloudflare Pages is the proposed host for this static policy page. If the page is deployed there, Cloudflare may process network request information, such as IP addresses, browser or device information, requested URLs and request times, to deliver and secure the page. This website traffic is separate from the Software's customer-hosted business database. See Cloudflare's Privacy Policy for its information-handling practices. Any enabled analytics or cookie-based features must be reflected in the published policy after the deployment settings are checked.

4. Planned Etsy Integration

The intended data path is the seller's Windows application, the seller's self-hosted backend, and Etsy's official OAuth and API services. Each shop would require the relevant seller authorization. The application would not ask for the seller's Etsy password.

Planned dataPurpose and boundary
Authorization records and OAuth tokensEstablishing and maintaining an authorized shop connection; tokens are intended for a protected store on the customer's backend, not the desktop client or the software provider
Shop, listing and inventory informationDisplaying and managing only authorized shop content and approved product fields
Minimum order and transaction fieldsOrder status and item display, and approved fulfillment checks using necessary identifiers, amounts, dates and tracking information

The plan does not require buyer_email access, which is a separately controlled field rather than an OAuth scope. It does not include buyer contact, address-book or mailing-list services.

Unnecessary buyer names, addresses, phone numbers, email addresses, buyer identifiers and messages are not intended to be persisted or sent to the desktop, logs or backups. If an authorized Etsy response contains such fields, the planned adapter must filter them during request processing. That filtering is not implemented or validated by the current synthetic-data demonstration.

The intended use is the authorized seller's shop operations. The plan excludes selling or transferring customer business data, advertising uses, competitive analysis and AI model training. This does not exclude the direct communications with Etsy necessary for an authorized API operation.

PKCE, HTTPS callbacks, application-secret distribution, token protection, revocation handling and deletion still require implementation and validation. Real Etsy integration is not available in V1.0. Before it is offered, this policy must be updated to reflect the actual implementation, approved features and applicable Etsy requirements.

5. Retention and Deletion

The current version has no real Etsy API data or tokens to retain. Local accounts and locally saved drafts can persist in customer-managed storage. Closing the application or stopping the backend does not erase saved database records.

A complete automated retention and deletion lifecycle has not been implemented and validated for this pre-release version. This policy does not promise automatic deletion when a local account is disabled, fixed log-retention periods, backup rotation or an in-app deletion function. The installation administrator must manage local records and backups, including copies outside the active database.

We retain support correspondence only as long as necessary to respond to and manage the request and meet applicable obligations. Support emails are separate from the local installation and its backups.

For the planned Etsy integration, data retention must be limited to what is necessary for the authorized purpose and permitted by applicable Etsy requirements. Disconnecting or revoking a shop must stop further authorized use and trigger the appropriate deletion process. The final rules and implemented controls must cover active records, tokens, caches, derived data and backup copies before the integration is released.

Restoring a backup must not reintroduce deleted business data or reactivate a revoked authorization. Reapplying deletion records after restoration is a planned safeguard, not an implemented V1.0 feature.

6. Your Choices and Contact

You control the customer-managed installation and the information entered into local drafts. Ask the administrator of that installation about access to or removal of locally stored information, including backups. Local data removal is separate from any future Etsy authorization controls.

For questions about this policy or information you have sent to us, email hello@astrafoundryai.com. You may also use this address to request access to, correction of or deletion of information you have provided to us, subject to applicable legal limits. Email information is handled through the relevant mailbox and email service; it is not covered by the local database's deletion process.

7. Security

The current local release provides sign-in and role controls and separates Review and Internal resources. Those measures do not establish that the planned Etsy security controls have been completed.

The customer manages the security of its host computer, operating system, database access, local network and backups. Do not disclose passwords, tokens or database connection credentials through ordinary support messages.

8. Changes to This Policy

The "Last updated" date identifies this policy version. Changes to information handling, including a real Etsy integration or new provider-operated data services, require corresponding updates to the policy.

9. Trademark Notice

The term "Etsy" is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.

This notice identifies the planned API relationship; the current V1.0 does not make live Etsy API calls.