Skip to content

Legal

Privacy Policy

Last updated: 11 May 2026

This policy explains what data foliascore (“we”) collects when you use the foliascore website (foliascore.com) and the foliascore application (app.foliascore.com), why we collect it, and what you can do about it. It's intentionally short. If anything here is unclear, email hello@foliascore.com.

Who we are

foliascore is an independent software product. You can reach the team at hello@foliascore.com.

What we collect

  • Account details. Your email address. If you sign up with Google, we receive your name and profile picture from Google so we can show them in the app.
  • Etsy OAuth tokens. Read-only access tokens we use to fetch your shop's orders, listings, and ad spend. We can see this data; we cannot change anything in your Etsy shop.
  • Your shop data. Orders, listings, fees, refunds, and ad spend that we pull from Etsy. Any expenses, materials, or product costs you enter yourself.
  • Usage analytics. Page views, broad device type, and referrer — collected via Plausible, which is cookieless and doesn't identify individual visitors.
  • Support communication. If you email us, we keep your message so we can reply and follow up.

What we don't collect

  • No Google Analytics, no Facebook Pixel, no advertising trackers.
  • No bank credentials — foliascore never asks for your bank login or connects to your bank.
  • No Etsy username or password — we use Etsy's OAuth flow, so your password never touches our servers.
  • No third-party data brokers. We don't buy, sell, or rent personal data.

Third parties we use

  • Etsy — for the OAuth connection and shop data sync.
  • Google — for Sign in with Google. We only receive the data Google chooses to share at sign-in.
  • A merchant-of-record payment provider (e.g. Paddle or Lemon Squeezy) handles paid subscriptions. Your card details go directly to them; we never see them.
  • Postmark for transactional email (sign-in links, receipts).
  • Vercel and Cloudflare host the marketing site and the application; standard server logs (IP, timestamp, requested URL) are retained for short periods for abuse prevention.
  • Plausible for marketing-site analytics. Cookieless.

Cookies

The marketing site (foliascore.com) sets no cookies. The application (app.foliascore.com) sets one essential cookie to keep you signed in; it isn't used for tracking.

How long we keep it

We keep your account data until you delete your account. Deleted data is removed from our live systems within 30 days and from backups within 90 days. Server logs are retained for up to 30 days. Aggregated, anonymised statistics may be kept indefinitely.

Your rights

You can access, export, or delete your data from inside the application at any time. You can also email hello@foliascore.com and we'll handle it within 7 days. Depending on where you live, you may have additional rights under GDPR (EU/UK), the CCPA (California), or the PDPA (Singapore) — we honour all of them.

Where data is stored

Shop data is stored on servers operated by our hosting providers. We don't have a guaranteed in-country storage option today; if that's a hard requirement for your business, please contact us before signing up.

Children

foliascore is built for businesses. We don't knowingly collect data from anyone under 16. If you believe a child has signed up, email us and we'll delete the account.

Changes to this policy

If we make a meaningful change to this policy, we'll email active users before it takes effect. Smaller changes will be reflected in the "Last updated" date at the top of this page.

Contact

Questions, requests, or concerns: hello@foliascore.com.