Last updated: February 9, 2026
This Privacy Policy describes how Sooks Labs LLC ("Company", "we", "us", "our") collects, uses, and protects your information when you use the Secondhand MCP service ("Service"). We are committed to keeping your data minimal and your privacy respected.
When you create an account, we collect:
Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account details, or other payment credentials on our servers. We receive only a Stripe customer ID and subscription status.
We track aggregate usage metrics per account per calendar month:
These counters are used solely for enforcing plan limits. We do not store the content of your search queries, search results, or listing data.
If you choose to connect eBay, your eBay Developer API credentials are encrypted using AES-256 encryption before storage. They are decrypted only momentarily during request processing and are never logged or transmitted to any third party.
When you connect the Service to an AI assistant (Claude, ChatGPT, etc.), OAuth access tokens are issued and stored as cryptographic hashes. We cannot reverse these hashes to obtain the original tokens.
We do not collect, store, or log:
| Data | Purpose |
|---|---|
| Email address | Authentication, account notifications, billing receipts |
| Usage counts | Enforcing plan limits, displaying usage on account page |
| Stripe customer ID | Managing subscriptions and billing |
| eBay credentials | Authenticating with eBay API on your behalf |
We do not sell, rent, or share your personal information with third parties for marketing purposes.
The Service relies on the following third-party providers, each with their own privacy policies:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database & authentication | Email, encrypted credentials, usage data |
| Stripe | Payment processing | Email, payment details (entered directly with Stripe) |
| Resend | Transactional email delivery | Email address (for sending auth emails) |
| Fly.io | Application hosting | Standard server logs |
When you delete your account, all associated data (profile, usage, credentials, tokens) is permanently deleted from our database.
The Service uses minimal cookies strictly necessary for authentication (Supabase session tokens). We do not use tracking cookies, analytics cookies, or advertising cookies. No third-party trackers are loaded on our pages.
We implement industry-standard security measures to protect your data:
No system is 100% secure. While we take reasonable measures to protect your information, we cannot guarantee absolute security.
You have the right to:
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). If you are an EU/EEA resident, you have additional rights under the General Data Protection Regulation (GDPR). Contact us to exercise these rights.
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will promptly delete it.
We do not sell your personal data. We have not sold personal data in the preceding 12 months, and we have no plans to do so.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice on the Service. The "Last updated" date at the top of this page indicates when this policy was last revised.
For questions or concerns about this Privacy Policy or your data, contact us at:
Sooks Labs LLC
support@secondhandmcp.com