Privacy Policy

Last updated: February 9, 2026

This Privacy Policy describes how Sooks Labs LLC ("Company", "we", "us", "our") collects, uses, and protects your information when you use the Secondhand MCP service ("Service"). We are committed to keeping your data minimal and your privacy respected.

1. Information We Collect

Account Information

When you create an account, we collect:

Payment Information

Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account details, or other payment credentials on our servers. We receive only a Stripe customer ID and subscription status.

Usage Data

We track aggregate usage metrics per account per calendar month:

These counters are used solely for enforcing plan limits. We do not store the content of your search queries, search results, or listing data.

eBay API Credentials (Optional)

If you choose to connect eBay, your eBay Developer API credentials are encrypted using AES-256 encryption before storage. They are decrypted only momentarily during request processing and are never logged or transmitted to any third party.

OAuth Tokens

When you connect the Service to an AI assistant (Claude, ChatGPT, etc.), OAuth access tokens are issued and stored as cryptographic hashes. We cannot reverse these hashes to obtain the original tokens.

2. Information We Do Not Collect

We do not collect, store, or log:

3. How We Use Your Information

DataPurpose
Email addressAuthentication, account notifications, billing receipts
Usage countsEnforcing plan limits, displaying usage on account page
Stripe customer IDManaging subscriptions and billing
eBay credentialsAuthenticating with eBay API on your behalf

We do not sell, rent, or share your personal information with third parties for marketing purposes.

4. Third-Party Services

The Service relies on the following third-party providers, each with their own privacy policies:

ProviderPurposeData Shared
SupabaseDatabase & authenticationEmail, encrypted credentials, usage data
StripePayment processingEmail, payment details (entered directly with Stripe)
ResendTransactional email deliveryEmail address (for sending auth emails)
Fly.ioApplication hostingStandard server logs

5. Data Retention

When you delete your account, all associated data (profile, usage, credentials, tokens) is permanently deleted from our database.

6. Cookies

The Service uses minimal cookies strictly necessary for authentication (Supabase session tokens). We do not use tracking cookies, analytics cookies, or advertising cookies. No third-party trackers are loaded on our pages.

7. Data Security

We implement industry-standard security measures to protect your data:

No system is 100% secure. While we take reasonable measures to protect your information, we cannot guarantee absolute security.

8. Your Rights

You have the right to:

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). If you are an EU/EEA resident, you have additional rights under the General Data Protection Regulation (GDPR). Contact us to exercise these rights.

9. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will promptly delete it.

10. Sale of Personal Data

We do not sell your personal data. We have not sold personal data in the preceding 12 months, and we have no plans to do so.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice on the Service. The "Last updated" date at the top of this page indicates when this policy was last revised.

12. Contact

For questions or concerns about this Privacy Policy or your data, contact us at:

Sooks Labs LLC
support@secondhandmcp.com