Privacy Policy
Effective September 16, 2026 · Last updated September 25, 2026
This policy explains what information Killion Apps collects, why, who we share it with, and what you can ask us to do about it. It covers our website at killionapps.com and our software, including Listing Hub and Customizer. The two products handle different information, so each has its own section.
1. Who we are
Killion Apps is an independent software studio based in Phoenix, Arizona, United States. We are the party responsible for the information described here. You can reach us at killioninvestments@gmail.com.
When you use Listing Hub, you are the owner of your own shop's data and we process it on your instructions. Where the GDPR or UK GDPR applies, you are the controller of that data and we act as your processor.
When you use Customizer, your buyers' information is processed on your instructions. You are the controller of your buyers' data and Killion Apps is the processor. We help you answer your buyers' requests about it, as section 10 describes.
2. The short version
- We collect what's needed to run your account, stage your listings, and fulfill personalized orders, and not more.
- We connect to your sales channels using tokens you authorize. We never see or store your passwords for those channels.
- Your designs and listing data are yours. We use them to do the job you asked for.
- Customizer handles your buyers' personalization. Each order's shipping name and address are read from Etsy at fulfillment, passed to Printify only to produce and deliver the order, and not retained. No email address or phone number is sent.
- We do not sell personal information, and we do not use advertising or cross-site tracking.
- You can disconnect a channel, export your data, or delete your account whenever you want.
3. Information we collect across the service
Account information
To create a Listing Hub account we collect your email address, a password (stored only as a salted cryptographic hash, never in readable form), your shop name, and your account and billing status.
Customizer has its own sign-in, on its own stack. Passwords are stored only as scrypt hashes, never in readable form, and each seller's data is kept within that seller's workspace.
Besides the password hash, a Customizer seller account holds your email address, your role in the workspace (owner or operator), and the workspace and its name. For the connected Etsy shop it holds the shop's identifier, the Etsy user ID of the shop's owner, the permissions granted, the connection's status and when it was last checked, and the shop's OAuth tokens, encrypted at rest.
If you contact support about either product, we keep that correspondence.
Text that is refused
Customizer checks the words a buyer asks to have printed against a list of slurs and hate terms, and refuses to put them on a product. When text is refused, Customizer records the text the buyer entered, which term it matched, and the time. That record exists so a wrongly refused order can be found and put right — a buyer who is refused by mistake usually just leaves, and without the record there is nothing to review.
Refusal records are deleted automatically 30 days after they are written. They are not used for anything else, and they are not shared.
A refusal is not the end of the order: the message a buyer sees tells them they can message the shop, and the shop can complete the order by hand.
Payment information
Listing Hub subscription payments are processed by our payment processor. We receive a customer reference, the plan, the amount, and whether the charge succeeded. We never receive or store your full card number. Customizer has no billing and takes no payments from you.
Technical and usage information
Our servers log IP address, browser user agent, pages or endpoints requested, and timestamps, for security, abuse prevention, and debugging. We record application errors and the actions taken in your account so we can investigate problems and show you an audit trail of what was published and when. Server logging covers buyers using Customizer's personalization pages too.
4. Listing Hub
Sales channel connections
Listing Hub only works if it can reach the places you sell. When you connect a channel — a marketplace, a social platform, or a print-on-demand fulfillment provider — you are sent to that provider's own login screen and you authorize the specific permissions involved. We receive an access token, not your credentials. Tokens are stored encrypted and are used only to perform actions you have asked for.
Through those connections we access shop and catalog information needed to build and publish listings: existing listings and product records, product and variant structures, production costs and shipping costs, fee and payout structures, order and sales volume where it is used to inform pricing, and the results of publish attempts.
Designs and listing content
We store the artwork files you upload, the mockups generated from them, and the listing content built around them — titles, descriptions, tags, prices, pricing rules, placement settings, and the version history of your edits.
Automated drafting of listing content
Listing Hub uses a third-party large language model provider to draft listing titles, tags, and descriptions. What we send is the design and product information needed for that draft — design name and description, product type, garment specs, and your own style preferences. We do not send your customer data, your account credentials, or your channel tokens. Our provider processes this to return the draft and, under our agreement, does not use it to train its models. Every draft is shown to you for review and editing before anything is published.
What Listing Hub does not collect
Listing Hub does not collect your customers' names, addresses, or payment details. It does not collect precise device location, contacts, biometric identifiers, or any special-category personal data, and we ask that you not put such information into free-text fields in the app.
5. Customizer
Customizer is in private beta. It lets a buyer personalize your design on a page linked from your Etsy listing and approve their own proof. The approved design is matched to the paid Etsy order and sent to Printify, where production begins according to your own Printify order-approval setting. Doing that means handling information about your buyers, not only about you. This section describes what that information is and what happens to it.
Customizer runs separately from Listing Hub. It is hosted on Render, keeps its database in SQLite on a persistent disk there, and stores private artwork as files on the same disk. Sections 3 and 9 describe its sign-in and security.
What the buyer supplies
The buyer personalizes your design on a Killion Apps page, not in Etsy's personalization field. They reach it from a link in your Etsy listing. Links expire, and the page keeps its own buyer session. Depending on the design, the buyer can supply:
- text they type
- colors they pick, or type in where a custom color is allowed
- choices among set options
- images they upload
We store what the buyer supplies and generate a proof from it. Because the page is ours, the server logging in section 3 and the cookies in section 13 apply to buyers as well as to you.
Buyer sign-in with Etsy
The buyer signs in with Etsy on the page. Customizer asks Etsy only for basic profile access (the profile_r permission), takes the buyer's numeric Etsy user ID, and discards the Etsy token. The ID is kept with the buyer session so the buyer's paid order can be matched to the proof they approved.
Text rendered by an image model
For each text element on a design, you choose how the buyer's text is rendered:
- With a font — nothing is sent to any model.
- With the AI strategy — the text the buyer types for that element is sent to OpenAI's image model as part of the edit request that renders it into the design.
Approval
The buyer reviews the proof and approves it on the page before buying. You review order matches and any exceptions. Production begins according to your own Printify order-approval setting. Setting it to Manual is a setup precondition: Printify exposes that setting to no other software, so Customizer cannot check it or change it.
Reading Etsy orders
Customizer reads your Etsy orders through the connection you authorized. A paid order is matched to an approved proof by the buyer's numeric Etsy user ID together with the listing, variation, and quantity. From each order it keeps exactly these fields:
- the buyer's numeric Etsy user ID
- the receipt ID and transaction ID
- the listing ID and SKU
- the variation property and value IDs
- the quantity
- the time of the order
- whether the order is paid, and whether it is cancelled
It does not keep the buyer's name, email address, phone number, gift message, or order note. It does not keep the order total or the payment method. Shipping details are handled separately, at fulfillment, as described next.
Sending the order to Printify
At fulfillment, Customizer reads the shipping details from the paid Etsy order and passes these eight fields to Printify with the approved print file:
- the recipient's first name and last name. Etsy gives the recipient's name as one line, so Customizer divides it into the two; a one-word name is sent as the first name, with the last name left empty.
- address lines 1 and 2, city, region, ZIP code, and country
No email address or phone number is sent to Printify: Etsy does not provide the buyer's, and Customizer does not put anyone else's in their place. The eight fields are passed so Printify can produce and deliver the order, and for nothing else. Customizer reads them at fulfillment and does not retain them. Printify handles them under its own privacy policy.
Payment information
Customizer does not receive or store card numbers or payment credentials. It does not store the order total or the payment method either. The only payment-related thing it keeps is whether the order is paid.
How long Customizer data is kept
| Data | What happens to it |
|---|---|
| Buyer personalization link | Expires 365 days after it is created; a test link expires after 1 day. The expired link's record is not deleted. |
| Buyer session, including the buyer's numeric Etsy user ID and the text and choices they entered | Expires when its link expires or after 2 days, whichever comes first. The session record is not deleted. |
| Refused buyer text, with the term it matched | Deleted automatically 30 days after it is written. |
| Buyer uploads and previews | Deleted automatically after 3 days, unless their session has been approved or is being prepared for production. Those are not deleted. |
| Approved final renders | Access expires after 365 days. The file is not deleted. |
| Etsy order fields listed above | Not deleted |
| Shipping details | Not retained. Read at fulfillment and passed to Printify. |
Two cleanups run automatically and do not wait for anyone to ask: the one that deletes buyer uploads and previews, and the one that deletes refused buyer text after 30 days. Nothing currently deletes buyer session records, the text and choices a buyer entered on the way to a proof, expired links, stored Etsy order fields, or approved final renders.
Deleting data from Customizer does not delete any copies that Etsy, Printify, OpenAI, or Sentry hold under their own policies.
Error monitoring. Customizer reports technical errors to Sentry, an error-monitoring service, so we can find and fix problems. A report says what went wrong and where: the error, the page or step it happened on, and the identifiers of the customization, order or Etsy receipt involved. It does not include your buyers’ names, shipping addresses, email addresses or payment details. Reports are built to leave out the text a buyer types; the one exception is an unexpected error whose own message quotes part of it, which is rare. Sentry receives the connecting IP address, as any web service does. It is set not to store that address, but it does keep an approximate location worked out from it: the city, region and country. We do not use Sentry for tracking or analytics.
Who else is involved
- Etsy — the marketplace where your buyer shops and pays. Customizer reads your Etsy orders, through the connection you authorize, to match each paid item to its approved proof and to read shipping details at fulfillment. Buyers sign in with Etsy so their order can be matched to them.
- Printify — the print-on-demand service that prints and ships the order, through the print provider it assigns. Customizer sends it the approved print file and the order's shipping details, and production begins according to your order-approval setting.
- OpenAI — renders buyer text into the design, only for text elements you set to the AI strategy.
- Render — hosts Customizer, its database, and its artwork files.
- Sentry — receives Customizer’s error reports, as described above.
The term “Etsy” is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.
6. Why we process it
- To provide the service — staging, pricing, and publishing your listings, and keeping them in sync.
- To generate listing copy — drafting titles, tags, and descriptions from the design information you provide.
- To produce personalized orders — generating proofs for buyers to approve, rendering buyer text with an image model where you choose that, matching approved proofs to paid Etsy orders, and sending them to Printify, where your order-approval setting decides when production starts.
- To bill you — managing Listing Hub subscriptions and receipts.
- To support you — answering questions and diagnosing failures.
- To keep the service secure and working — detecting abuse, preventing fraud, and fixing defects.
- To meet legal obligations — tax, accounting, and lawful requests.
Where the GDPR applies, our legal bases are performance of our contract with you, your consent for optional integrations (which you may withdraw), our legitimate interest in securing and improving the service, and compliance with legal obligations.
7. Who we share information with
We do not sell personal information and we do not share it for advertising. We share it only with service providers who help us run the software, each under contract and only for that purpose. For Listing Hub:
| Provider role | What they handle |
|---|---|
| Application hosting and database | Runs the app and stores account and listing records |
| Object storage | Stores uploaded design files and generated mockups |
| Language model provider | Drafts listing copy from product information |
| Payment processor | Handles subscription billing |
| Email delivery | Sends account and support email |
For Customizer:
| Provider | What they handle |
|---|---|
| Render | Hosts Customizer, and the persistent disk that holds its SQLite database and private artwork files |
| OpenAI | Renders buyer text into a design, only for text elements set to the AI strategy |
| Sentry | Receives error reports: what failed, where, and the identifiers involved. No names, addresses, email addresses or payment details |
Separately, we transmit data to the sales channels and fulfillment providers you connect, because publishing your listings and fulfilling your orders is the point of the service. For Customizer, that is your buyers' shipping names and addresses, sent to Printify as section 5 describes; no buyer email address or phone number is sent. Those platforms handle that data under their own privacy policies.
We may also disclose information if required by law or valid legal process, to protect our rights or someone's safety, or in connection with a merger or sale of the business — in which case we will tell you before your information becomes subject to a different policy.
8. Retention
| Data | Kept for |
|---|---|
| Account, designs, and listing records | While your account is active; deleted within 30 days of account deletion |
| Customizer personalization, proofs, and order data | As set out in section 5 |
| Channel access tokens | Until you disconnect the channel or delete your account; deleted immediately on disconnect |
| Listing Hub billing records | As long as tax and accounting law requires, typically 7 years |
| Refused buyer text | 30 days, deleted automatically |
| Server logs | Up to 90 days |
| Customizer error reports (Sentry) | Kept by Sentry for the retention period of our Sentry plan, currently 30 days, then deleted automatically |
| Audit trail | Append-only. Customizer's audit records cannot be changed or deleted, by us or by anyone, and are kept for as long as the account exists. |
| Support email | Up to 24 months |
9. Security
Data is encrypted in transit using TLS. Channel access tokens and other secrets are encrypted at rest. Access to production systems is limited to the people who operate the service and is protected by multi-factor authentication. We keep dependencies patched and we log administrative actions. No system is perfectly secure, and we will not pretend otherwise — if a breach affects your information, we will notify you and any required authority without undue delay.
Customizer, on its own stack, also writes private artwork outside the web root with owner-only file permissions, encrypts provider OAuth tokens at rest, stores buyer links only as hashes that expire, and verifies incoming webhooks by signature within a timestamp window.
10. Your rights and choices
Depending on where you live, you have some or all of the following rights: to access the personal information we hold about you, to correct it, to delete it, to receive a portable copy, to object to or restrict certain processing, to withdraw consent, and not to be discriminated against for exercising any of them.
You can do most of this yourself: disconnect a channel in settings, export your listing data, or delete your account. For anything else, email killioninvestments@gmail.com and we will respond within 30 days. If you are in the EEA or UK you may also complain to your local data protection authority. We do not sell personal information or share it for cross-context behavioral advertising, so there is no such sale to opt out of.
If you bought through a Customizer page, the seller you bought from is the controller of your personalization, uploads, and order details, so send requests to access or delete them to that seller. We help the seller answer them, on the seller's instructions. If you write to us directly at killioninvestments@gmail.com, we will not turn you away: we forward your request to the seller and help them answer it. Include your Etsy order number. Buyers have no account, so that is how we find the order and its seller.
11. International transfers
We operate in the United States and our providers may process data there. If you are outside the US, your information will be transferred to and processed in the US. Where required, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism with our providers.
12. Children
Our software is not directed to children. Customizer's buyers are consumers of whatever age Etsy permits. We do not knowingly collect personal information from children under the age applicable law sets. If you believe a child has given us information, contact us and we will delete it.
13. Cookies
Our marketing website is static and sets no cookies. The applications set only essential cookies:
- Listing Hub — a single cookie to keep you signed in.
- Customizer — one cookie,
kc_merchant, to keep a seller signed in, and one cookie for each buyer session, namedkc_b_followed by the session ID. A buyer with two sessions has two.
We do not use advertising, analytics, or cross-site tracking cookies.
14. Changes
If we change this policy we will update the date at the top of this page, and for material changes we will email account holders before the change takes effect. Continued use after that means you accept the revised policy.
The email commitment applies to account holders, meaning sellers. Buyers have no account, so they see the current policy at this address.
This version, effective September 16, 2026, replaces the version effective August 6, 2026. It is a material change: it adds Customizer, a second product, information about your buyers, and the processing that goes with it.
15. Contact
Killion Apps · Phoenix, Arizona, United States
killioninvestments@gmail.com