1. Who is responsible for processing your data
This Policy applies to the EMAnalysis extension, its analysis service and the product website. EMAnalysis is an independent product and is not an official eBay product.
2. Data used for analysis
Analysis starts only when you request it. For listing analysis, the extension sends the identifier of the open listing and selected eBay marketplace to the service. For search results analysis, it sends the search phrase and marketplace. The service uses these parameters to request the relevant public eBay data and return the result to the extension.
You do not need to connect an eBay account. The extension does not ask for your eBay password or API key and is not designed to read private messages, payment details, basket contents or checkout information.
3. Data stored locally in Chrome
Comparable-listing selections, calculator values and analysed-listing history are stored in the local storage of your Chrome profile. This data is not synchronised with a server-side EMAnalysis account because no such account exists.
You can remove local data through the extension, by clearing the extension's data in Chrome or by uninstalling the extension. Removing local data does not delete a support request that has already been sent. Selection-correction comments and the precise link between the reference and comparable listing remain only in Chrome until you submit a diagnostic request through Report a problem. They are then copied into a snapshot of the current analysis, which the form warns you about before submission.
4. Technical events and feedback about results
Background product telemetry is disabled by default. If the operator explicitly enables it in future to monitor stability and improve the product, the extension may send only de-identified events: feature type, eBay marketplace, algorithm versions, normalised reasons and counts. These events do not contain analysis, category, item, variation, installation, device or user IDs, free text, titles, URLs, a search phrase, browser history, cookies, tokens or financial values.
The backend does not write individual telemetry events. Events that share the same classification context are written to the log only in non-overlapping groups of at least 20 events. An incomplete group in Redis expires within 48 hours.
5. Support requests
The Report a problem button in the extension sends a request only after an explicit action. It always includes a snapshot of the current feature: the original request, full analysis response, item ID, titles, URLs, prices, sellers, matching evidence, manual selections, comments, calculator values, technical IDs and the latest error. The form warns you before sending. The snapshot does not contain cookies, tokens, eBay account data or content from other browser pages.
Once enabled, the separate support form on the website will let you submit a subject, reply email address, description, optional public link or item number, and up to three screenshots. This form does not receive an automatic extension snapshot. Submitted information is used only to reply, reproduce the problem, protect the service and improve the product. Product-support intake remains closed until the form is enabled.
When the form is enabled, before upload the browser limits the longest side of each screenshot to 2,048 pixels, converts the image to WebP and removes the original metadata. Each prepared file is limited to 3 MB. The server independently checks the actual type, size and malware scan result, fully decodes only a static image, and creates a new WebP without the original metadata. Only that new file is stored with the support case in the same access-controlled storage.
Before submitting, remove names, addresses, private messages, order data, payment details and account identifiers from screenshots. By sending a request, you allow the service owner to read it and view the attached files to the extent needed to deal with the request.
Messages sent directly to the operator's addresses for administrative or personal-data enquiries are processed separately through Hostinger Email. That correspondence may contain sender and recipient addresses, a subject, message text, attachments and technical email headers. Do not send information that is unnecessary for your request.
6. Server logs and abuse prevention
For a requested analysis, the service creates operational logs containing request and analysis identifiers, result codes, versions and stage durations. The body of a rejected request is not logged. To rate-limit analysis and diagnostic requests, the network address is temporarily converted into an HMAC identifier. The telemetry endpoint uses a shared rate limit without a client address; Caddy and the API do not write an access/request log for this route.
Hosting and network providers may process ordinary connection data, including the IP address, request time and technical headers, to deliver the website and service, maintain security and diagnose failures.
7. Purposes and legal bases
EMAnalysis does not use this data to make decisions that produce legal or similarly significant effects for the user.
8. Who may receive the data
Data is received only by providers whose involvement is necessary for the requested feature: eBay receives the parameters needed to request public marketplace data; the hosting provider receives technical connection data and the request stored on the VPS; network intermediaries receive only technical connection data. When the website form is enabled, Cloudflare Turnstile will receive signals needed to protect it from bots. Turnstile will not receive form fields or attachments. Requests from the extension and website form are not delivered through a separate email service. Hostinger Email processes direct correspondence between a user and the operator through the published addresses, including the operator's replies.
We do not sell personal data or use it for personalised, retargeted or interest-based advertising. Disclosure for another purpose is permitted only with your separate permission, to comply with a legal requirement, to maintain security, or as part of a permitted reorganisation of the operator with applicable safeguards preserved.
9. Retention periods
Local extension data is retained until you delete it or uninstall the extension. Technical logs are kept only for the period needed to diagnose problems, prevent abuse and confirm release stability, after which they are deleted or aggregated. Requests from the extension and website form, including attachments, are retained in the SQLite system for no more than 90 days after receipt unless the law requires longer retention. A backup of that system is deleted no later than 30 days after the original record is deleted. Messages sent directly through Hostinger Email are not included in that backup: the operator deletes them after replying and completing the request unless longer retention is needed to meet a legal requirement.
10. International processing
Infrastructure providers may process data outside the user's country, and Cloudflare provides a global network service. The VPS hosting country, applicable Cloudflare contractual terms and required international-transfer mechanism are still being verified. The online support form and extension publication will not be enabled until that review is complete and this section has been updated. You can request current information from the privacy contact address.
11. Your rights
Depending on the applicable law, you may request access to, correction or deletion of your data, restriction of processing and data portability, and you may object to processing based on legitimate interests.
You have a separate right to object to personal-data processing based on legitimate interests. Use the operator's privacy contact address above to make a request.
You may also lodge a complaint with the competent data-protection authority where you live, work or believe an infringement occurred. Users in the United Kingdom may contact the Information Commissioner's Office; users in the European Union may contact their national supervisory authority.
12. Security and changes to this Policy
Data is transmitted over a secure HTTPS connection. Full access to support cases is restricted to the owner through the private SSH/Docker CLI for support, security and operational tasks. No storage or transmission method eliminates all risk, so do not send information that is unnecessary for an analysis or support request.
If the data collected or purposes of processing change materially, the Policy is updated before the new processing begins and the revision date is changed. This page, the extension's actual behaviour and the Chrome Web Store disclosures must remain consistent.
View support status