Privacy information
How the current product handles seller data.
This page describes behaviour present in the current EcomRankUp project. It is written for clarity and is not a substitute for a lawyer-reviewed privacy notice.
Account information
Google sign-in uses a stable Google account identifier and verified email. The project can also store a display name and avatar URL supplied by Google, login and logout events, account role, shop memberships and hashed session records. Existing legacy account records may contain a phone number.
Google credentials and passwords are not provided to EcomRankUp. Browser sessions use HttpOnly cookies, and refresh and extension tokens are stored as hashes rather than plaintext tokens.
Uploaded settlement files
The current upload flow accepts supported Meesho settlement XLSX files. The file is read for parsing; the original XLSX binary is not stored by the upload endpoint.
EcomRankUp stores upload metadata such as filename and size and stores parsed information needed for the dashboard, including supported order-payment and advertising-cost records. A filename can contain personal information, so sellers should use the original marketplace report only when necessary.
Seller and shop information
The service stores seller-shop records, membership relationships, supplier identifiers where captured, catalogs, products, orders, settlements, costs, returns, findings and synchronization status. Queries are designed to scope this information to an authenticated seller membership and selected shop.
Extension data
A paired extension can send supported Supplier Panel responses, relevant request details and page context to EcomRankUp for parsing. It uses an opaque, revocable extension token tied to the paired account. The server stores captured responses and derived seller records.
Listing autofill profiles can remain local without pairing. The extension does not require a seller to provide a Meesho password to EcomRankUp. Sellers should revoke or re-pair the extension when changing the connected shop.
Listing profiles and AI drafts
Optional cloud synchronization stores a versioned listing-profile document under the selected seller. Deleted synced profiles can be represented by tombstones so changes synchronize consistently.
Where the AI Listing Generator is enabled, product facts and images are sent to the configured OpenAI service for generation. EcomRankUp does not store the uploaded image bytes in the listing draft; it stores filenames, seller-entered facts, generated output and draft history. The seller controls review and final submission.
Claim evidence
Where the Claim Analyser is enabled, image and video evidence is stored through private local or S3-compatible storage rather than inside PostgreSQL. The database stores ownership, file metadata, hashes, extracted-frame references, analysis results and claim events. Downloads require seller authorization.
When a seller requests analysis, selected evidence frames, order facts and catalog-image references are sent to the configured Anthropic service. Cleanup tooling exists for terminal claim evidence, but its production schedule and final legal retention period require owner and lawyer confirmation.
Contact form
The public form collects name, email, optional phone, topic, message and consent. After validation and spam checks, it uses a support delivery service to send the request. Full messages are not included in application error logs. If your message cannot be delivered, the form shows an error so you can try again.
Service providers
The service can use Google for sign-in; hosting, database and storage providers selected by the owner; a contact delivery provider; OpenAI for requested listing generation; Anthropic for requested claim or assistant analysis; and private storage for claim evidence.
Which providers are enabled in production, their locations, contracts, subprocessors and international-transfer safeguards require owner and lawyer confirmation. AI services receive data only when the related feature is requested.
Retention and deletion
No final public retention schedule has been approved. Database records remain until removed through an implemented deletion path, cascading shop deletion, configured cleanup process or reviewed administrative operation.
An authenticated member can remove a shop when another shop remains. If no memberships remain for that shop, the seller record and seller-linked database rows are deleted through database cascades. This is not the same as complete account deletion. A self-service full-account deletion flow is not currently available.
For a privacy request, use the public contact form and choose “Privacy request” once delivery is configured. Identity and shop ownership must be verified before any disclosure, correction or deletion.
Security
The project uses server-issued sessions, rotating refresh sessions, Origin and CSRF checks for sensitive browser actions, hashed stored tokens, seller-membership checks and private evidence access. File type, signature, size and duplicate checks are applied to claim uploads where that feature is enabled.
No service can guarantee absolute security. Do not submit marketplace passwords, access tokens, buyer addresses, payment credentials or unrelated personal data through the contact form.
Independence from Meesho
EcomRankUp is an independent seller tool and is not affiliated with, endorsed by or sponsored by Meesho. Marketplace names are used only to describe supported seller workflows.
Contact method
Use the public contact form and select the relevant topic. An official postal address, privacy email and response timetable require owner confirmation and are not invented here.