Privacy Policy
Resale Station · EaseTrade LLC · Version 2026-09-13
Who we are and what this covers
Resale Station is business operations software operated by EaseTrade LLC ("we", "us"). References in this notice to the Service include the Resale Station website, the application at app.resalestation.com, and the related software identified as FavoliHub, which EaseTrade LLC's own resale business runs on the same platform. This notice explains our handling of personal information about account holders, website visitors, support contacts and other individuals whose information we process.
Business customers use the Service to manage information about their buyers, employees, contractors and operations. For information we process on a customer's behalf under its instructions, our customer agreement and the Data Processing Addendum govern that processing: the customer is responsible for its own notices and lawful instructions, and we remain responsible for our own legal and contractual obligations. We act for ourselves — not for a customer — for account, billing, security and website records.
What we collect, from where, and why
| Category | Examples and source | Purpose |
|---|---|---|
| Subscriber and authorized-user records | Name, email, business name, a password we hold only as a salted hash, role in the company, sign-in times and the kind of device used. From you. | Account administration, authentication, permissions, support, and telling a company's owner who has access. |
| Billing | Plan, subscription status, invoice history and Stripe's identifiers for the customer and subscription. From Stripe. Card details are entered on Stripe's pages; Stripe tells us only the card's last four digits and expiry, and we do not receive or store the number. | To know what a company has paid for and switch features accordingly; tax and accounting records. |
| Marketplace and fulfilment records | Listings, orders, buyers' usernames, names and shipping addresses, SKUs, tracking, offers and buyer messages, as eBay, Whatnot or Walmart supply them under the access a customer granted. Show records, bin and pack scans. | The work the software does for that customer: listing, pricing, picking, packing, shipping and answering that buyer's order. Used for nothing else. |
| Workforce records | Employee profiles, roles, schedules, time-clock punches, PIN hashes, and — where a company switches the tablet camera on — a photograph at clock-in and clock-out. A mobile number where the person opted in to text messages. From the customer and the person. | Under the customer's instructions: the schedule, the time clock, pay for hours worked, and texting a schedule to those who opted in. Photographs are for a person to look at when a punch is questioned; they are not analysed, and no facial template or biometric identifier is created from them. |
| Files and evidence | Show reports, packing slips and labels a customer generates, company logos, documents a customer uploads. | Stored for the customer; visible only inside its company. |
| Integrations and authorization | OAuth grants and tokens for eBay, Whatnot, Walmart and QuickBooks Online; sync logs. We never see or store a marketplace password. | To act on the customer's instructions through the access it granted. Disconnecting revokes the stored access and stops new processing; records already imported stay the customer's to export or delete. |
| QuickBooks (optional add-on) | Through Intuit's OAuth 2.0: the employee list, and weekly total income where the customer enables the payroll target. We write hours recorded by the time clock. We do not read or store transactions, customers or bank data. | So hours are not typed twice. Revocable in QuickBooks Online under Apps or from the Service; revoking deletes the tokens. |
| Poshmark (optional add-on) | The cross-listing extension runs in the customer's own browser with the customer's own Poshmark login. We hold what the extension reports about listings it created; never a Poshmark password or session. | To keep listings in step. |
| Support and platform events | Emails you send us; a log of significant account events (company created, marketplace connected, trial ending, a person switched on or off, a subscription change). | To help you, and to run the Service. |
| Website and diagnostics | Server logs with IP address, browser type and the pages requested; error reports from the application that name the screen and the browser. The application keeps a sign-in session in your browser. The marketing site sets no cookies and we use no advertising or analytics trackers. | Security, debugging and keeping you signed in. |
AI-assisted features are not part of the Service at the date of this notice. If we add any, this notice will say, before they process your data, exactly what is sent, to which provider, and on what terms.
Who can see what
Your company, and only your company. Every record belongs to one company and the database enforces that boundary on every query, not only in the screens. Within a company, what a person can see and do is limited by the role their company gives them. We test the boundary by signing in as real users of two different companies before changes ship.
Us. A small number of named EaseTrade LLC staff can see across companies to run the Service — to answer support, see that a company's connections work, or act on billing. That access is through named platform-administrator accounts and is logged. We look at a company's business records only to help that company.
Who else receives information
We disclose personal information to service providers that perform the hosting, communications, support, security, payment and other functions described in this notice, subject to contractual restrictions on their use of it. We also transmit information to connected services when an authorized customer enables the relevant feature; those services process it under their own terms and privacy notices. We may make other disclosures required or permitted by law, to protect legal rights, or in a business transaction, subject to applicable protections. Our current providers, what each does and where it processes, are listed at /subprocessors; we update that page when a provider changes and tell company owners of material changes as the DPA describes.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Security
All connections use HTTPS. Marketplace and QuickBooks tokens are stored on the company's own record and are never shown to any user, including the company's owner. Passwords are held as salted hashes by our authentication provider. Access from our side requires a named platform administrator account. No method is perfect. If we learn of a security breach affecting personal information we hold, we will notify the affected customer without undue delay and in accordance with the law that applies, and cooperate with the customer's own notification duties.
How long we keep things
- Business and workforce records: for as long as the company's account exists. When a trial ends or a subscription lapses, the account becomes read-only; nothing is deleted.
- Time-clock photographs: 90 days from the day they were taken, then deleted automatically by a daily job; the punch keeps its time but no longer has a photograph.
- Marketplace and QuickBooks tokens: until the customer disconnects, or the grant expires.
- eBay account deletion notices: when eBay tells us an eBay user has closed their account, we redact that user's identifiers from the orders we hold, keeping only what tax and accounting law requires of the order itself.
- Billing and tax records: as long as tax law requires.
- Deleted companies: a company's owner may ask us to delete the company; we delete its records within 30 days, except records we must keep for tax or legal reasons, or that are subject to a lawful hold. Copies in encrypted backups are overwritten on the backup cycle (up to 30 days) and, if a backup is ever restored, deleted records are removed again.
Your choices and rights
- A company's owner can see, correct and export the company's data inside the Service, add and remove people, and disconnect any marketplace or QuickBooks.
- A crew member can ask their company, or us, to see or correct what is held about them; the Notice to crew members explains what the time clock records.
- A buyer whose details reached us through a marketplace order should ask the seller (our customer) or the marketplace; if you write to us we will route the request to the right company and help it answer.
- Text messages stop when you reply STOP. Consent to texts is separate from accepting the Service's terms; see the text-message terms.
- Where a privacy law gives you rights — to know, to correct, to delete, to a copy, or not to be discriminated against for exercising them — email us and we will honour them, verifying who you are first, within the time the law allows, with a route to appeal. We do not promise unconditional deletion of records we must keep.
Children
The Service is a business tool, is not directed at children, and we do not knowingly collect information from anyone under 13.
Contact and changes
Privacy questions: [email protected], or by post to EaseTrade LLC, 964 High House Rd #2009, Cary, NC 27513. When this notice changes we update the version at the top and, for material changes, tell company owners by email before they take effect. The version in force is the one at this address; earlier versions are available on request.