Privacy policy
Last updated 25 July 2026 · Nordia Tools · support@nordiatools.com
This policy explains what Nordia collects when a seller connects an Etsy shop, what we do with it, how long we keep it, and how to make us delete it. It applies to the service at nordiatools.com and to any Nordia interface that reads or writes Etsy data.
1. Who we are
Nordia is operated by Nordia Tools (“Nordia”, “we”). We are the data controller for account data about our own users, and a data processor acting on the seller's instructions for the Etsy shop data we handle on their behalf. Write to privacy@nordiatools.com for any question in this policy.
2. What we collect
2.1 Account data
- Name, email address and password hash for the Nordia account.
- Billing contact and subscription record. Card details are held by our payment processor, never by us.
- Product usage logs: pages viewed, jobs run, errors encountered.
2.2 Data from a connected Etsy shop
Only after the seller grants OAuth consent, and only within the scopes they approved:
- Shop and seller data — shop id and name, sections, shipping profiles, return policies, the seller's Etsy account email and public profile.
- Listing data — titles, descriptions, tags, prices, images, variations, quantities, listing state and performance counts.
- Order data — receipt id, line items, quantities, personalisation notes, order totals, ship-by dates and order status.
- Buyer data — the shipping address on the receipt, the buyer's name, and where the seller has enabled post-purchase email and Etsy has granted us the field, the buyer's email address.
- OAuth tokens — the access and refresh tokens issued for that shop.
3. What we use it for
- Creating, updating and deleting listings the seller has queued.
- Keeping listing quantities in step with the seller's stock across their channels.
- Building the fulfilment queue, producing shipping labels, and passing the address to the print or fulfilment partner responsible for that specific order.
- Writing tracking numbers back to the Etsy receipt.
- Sending transactional post-purchase email about a specific order, through the seller's own email provider, where the seller has enabled it.
- Showing the seller their own performance data.
- Support, security monitoring, fraud prevention and billing.
4. What we never do
- We do not sell, rent or trade Etsy data.
- We do not use buyer email addresses for marketing, newsletters, list building or any message not about the order the buyer placed.
- We do not use seller or buyer data to train machine learning models.
- We do not share one seller's data with another seller. Aggregate figures, if we publish any, cannot be traced back to a shop.
- We do not access shops that have not granted consent.
5. Legal basis
For sellers in the EEA and UK we rely on: performance of a contract for running the service; legitimate interests for security, abuse prevention and product improvement; consent where the seller switches on optional features such as post-purchase email; and legal obligation for tax and accounting records.
6. Who we share it with
- Cloud hosting — servers and managed databases in the provider's data centres.
- Payment processing — for subscription billing only.
- Email delivery — the provider chosen by the seller for their own post-purchase mail, and our own provider for operational alerts to sellers.
- Fulfilment partners — the address for a given order goes to the partner producing and shipping that order, and to no one else.
- Authorities — only where we are legally required, and where permitted we tell the seller first.
Every processor is bound by a written agreement limiting them to our instructions. Transfers out of the EEA rely on Standard Contractual Clauses.
7. How long we keep it
- OAuth tokens — until the seller disconnects or revokes access, then deleted immediately.
- Order and buyer data — while the order is open, then 30 days after fulfilment to cover returns and disputes, then deleted. Deleted immediately on disconnection if the seller asks.
- Listing and shop data — only while the shop is connected, and only as a cache to serve that seller. Deleted within 24 hours of disconnection, because we are no longer providing the service it was held for.
- Account and billing records — for the life of the account, and afterwards only as long as tax law requires.
- Security logs — 12 months.
8. Security
- TLS 1.2 or better on all connections.
- AES-256 encryption at rest for tokens and buyer data, with keys in a managed secrets store.
- Tokens and buyer addresses are redacted from application logs.
- Production access limited to named staff with two-factor authentication, reviewed quarterly, with all access logged.
- Regular dependency patching and periodic penetration testing.
9. Your rights
Depending on where you live, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to a use, or port it elsewhere. Write to privacy@nordiatools.com. We acknowledge within 5 business days and answer within 30 days. If you are unhappy with our answer you may complain to your local data protection authority.
10. Deleting your data
Disconnecting an Etsy shop in Nordia deletes the tokens at once and starts the deletion schedule in section 7. To have everything erased immediately, including backups, email privacy@nordiatools.com from the address on your Nordia account with the shop name. We confirm when it is done.
11. Buyers
If you bought from a shop that uses Nordia and want to know what we hold about your order, or want it erased, write to privacy@nordiatools.com with the order number. We will pass the request to the seller, who is the controller of that data, and act on their instruction. To stop post-purchase emails, use the unsubscribe link in any of them.
12. Cookies
Our marketing site uses no advertising or third-party tracking cookies. The signed-in application uses a session cookie that is strictly necessary to keep you logged in, plus first-party analytics that record page views without profiling you across other sites.
13. Children
Nordia is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
14. Changes
If we change this policy materially we email account holders at least 14 days before it takes effect and update the date at the top of this page.
15. Contact
Nordia Tools · privacy@nordiatools.com · Security reports: security@nordiatools.com