Privacy Policy
How Cratewake handles your store data.
Last updated: 2026-08-18
What Cratewake is
Cratewake is a back-office tool for one-person Shopify, Amazon, and Etsy sellers. When you connect a store, we read and manage your inventory, pricing, orders, and customer messages on your behalf so the morning brief and the safety guardrails can do their job — and so a single operator can keep up with three marketplaces in a day.
This policy explains which data Cratewake collects, where it comes from, what we do with it, and the choices you have. The short version: we only see what you authorize through each marketplace's developer API, and you can revoke the connection at any time.
Data we collect
Cratewake collects data in three categories. Each one corresponds to a different kind of authorization on a marketplace's developer platform.
Account data
When you create a Cratewake account, we store your email address, the display name you pick, a hashed password, and any preferences you set inside the app (notification cadence, which channels the morning brief covers, etc.). We use this to log you in and to address the emails we send.
Connected-store data
When you wire a store to Cratewake, you authorize Cratewake through that marketplace's developer platform — via the Shopify Partner app install flow, the Amazon Selling Partner API (SP-API) authorization, or the Etsy Open API OAuth flow. Once authorized, Cratewake reads and writes the data needed to operate the morning brief and the pricing guardrail/auto-repricer:
- Inventory levels, SKUs, variants, and listings.
- Pricing, including list price, compare-at price, and channel-specific overrides.
- Orders, including order headers, line items, fulfillment state, and any associated tracking numbers we surface in the dashboard.
- Customer messages on the connected marketplace — the questions and replies Cratewake surfaces in the inbox.
We store this data so we can keep showing you the brief, keep the guardrails current, and keep the inbox state across reloads. We never sell it, and we never share it with anyone outside the subprocessor list below.
Customer message data
Customer messages from your marketplace inboxes are aggregated into a single inbox inside Cratewake. We read them via the marketplace APIs, store them alongside the conversation thread ID the marketplace assigned them, and keep them until you delete them or revoke the connector. Cratewake does not use the content of buyer messages to train any model.
How we use data
We use the data described above only to operate Cratewake for you:
- To generate the morning brief and any alerts you have subscribed to.
- To compute and enforce margin floors, the maximum reprice delta, and the auto-repricer on/off switch.
- To surface and triage customer messages from your marketplaces in one inbox.
- To authenticate you, send transactional email (account, security, and billing), and maintain session integrity.
Cratewake does not run advertising, does not sell data, and does not share data with third parties for their own purposes.
How we share data
We share data only with the subprocessors required to run Cratewake. The current list:
- Hosting and database infrastructure — the platform that stores your data at rest.
- Transactional email — the provider that delivers account, security, and Cratewake-to-you notifications.
- Marketplace developer APIs — Shopify, Amazon SP-API, and Etsy Open API. We send only the data those APIs require to perform actions you've authorized (e.g. a reprice write, an inbox reply).
We will update this list as subprocessors change. We do not currently use any payment processor; billing is not wired up at this time.
Legal requests
If we receive a legal request for data, we will review it, narrow it to what is strictly required to comply, and — unless a binding order forbids it — notify you before disclosing anything so you can challenge it.
Data retention
We keep your account data for as long as your account is active. Connected-store data is kept while the connector is active; when you revoke a connector (via the marketplace's app-installation page or the disconnect button in Cratewake), we delete the corresponding tokens on our side within seven days. Backup copies age out within thirty days. If you delete your Cratewake account, we purge the related store data within thirty days.
Security
Marketplace API tokens are stored encrypted at rest. Access to production data is limited to the operator(s) of Cratewake and is logged. We use TLS in transit. We rotate marketplace credentials when the marketplace platform offers rotation, and we let you revoke any connector from inside the app or from the marketplace's own app-installation page — whichever is faster for you.
No system is perfectly secure. If we discover a security incident affecting your data, we will notify you without undue delay.
Your rights
You can, at any time:
- Disconnect any connected store — from inside Cratewake or from the marketplace.
- Export the data Cratewake holds for your account.
- Delete your Cratewake account, which purges the related store data.
- Ask us what data we hold and what we have done with it.
Reach the contact address below; we'll acknowledge within a few business days and complete the request within thirty days.
Contact
Questions, requests, or concerns about privacy — write to cratewake-n4tra9@polsia.app.