There are no public app accounts or advertising trackers on this website. Google access supports the operator’s chosen artwork and listing workflow. Selected content may be sent to OpenAI for analysis and copy generation and to Printify, Etsy, or Pinterest for approved publishing. We do not sell personal data. You can revoke connections and request deletion.
1. Who we are and what this policy covers
Michiel de Ruiter, trading as LuxuriaPrintStudio in the Netherlands, is the controller responsible for this website and the tools described here. “We,” “us,” and “our” refer to that operator. EtsyAutomation is the private catalog and listing pipeline for LuxuriaPrintStudio and PadQuest. Luxuria Publisher is the related Pinterest publishing tool for LuxuriaPrintStudio. Both are restricted to authorized operators; neither is a public software service.
This policy covers website requests, correspondence, connected-account data, and the processing described below. It does not replace the privacy notices of Google, Pinterest, OpenAI, Printify, Etsy, or a storefront you visit. Contact [email protected] for questions or requests.
2. Information we process
- Website and correspondence: hosting providers may process IP addresses, request times, browser information, requested pages, and security signals. If you contact us, we receive your chosen contact details, message, and attachments.
- Catalog content: selected artwork, product images, source titles, prompts, listing copy, keywords, classifications, accessibility text, and links to source files and product pages.
- Connection credentials: access and refresh tokens where supported, granted permissions, expiry information, and connection status. Google OAuth credentials are retained locally so authorized jobs can run without repeated sign-in. The dashboard’s interactive Pinterest OAuth token is held in server memory; a separately configured runtime token may also be used. We do not request your Google or Pinterest password or session cookies.
- Operational records: source-file and spreadsheet references, generated results, approvals, schedules, publishing status, delivery references, error details, and usage/cost records. Etsy shop statistics and separately configured Google Ads keyword metrics support catalog research. These are not visitor profiles.
3. Google access: data, permissions, and purpose
Google authorization happens on Google’s own consent screen. The Google-connected application is named EtsyAutomation. The current Drive connection requests broad Drive access: it can technically read, create, change, share, and delete files accessible to that account. This is not a file-by-file permission grant.
- Google Drive: the pipeline reads selected artwork and its metadata, downloads it for processing, renames catalog files, creates processed images, and manages working folders and temporary staging files. Configured storage housekeeping may remove files from the working area.
- Google Sheets: where separately authorized or shared with our service account, we read listing titles, prompts, and artwork links from selected sheets and write generated listing content or processing results back to them.
- Google Ads: a separately configured integration retrieves keyword search-volume metrics for listing research. Authorizing Drive does not authorize Google Ads.
Access is used for the operator-selected catalog workflow, not to browse unrelated personal documents, contacts, or emails. Source content and generated results can be saved in the local catalog database, working files, model-run artifacts, and backups. The publicly hosted website has no access to those credentials or files.
Artwork sharing during publishing
For provider image ingestion, the pipeline can create an “anyone with the link” permission on selected artwork or processed staging images. Anyone who obtains that link can access the file. Do not select confidential material for that workflow. Temporary uploads are removed after use; a failed cleanup may require operator intervention. This does not make the rest of your Drive public.
Some operations use a service account with access granted by sharing files or folders with it. Revoking your personal OAuth connection does not remove service-account access; remove that sharing separately.
4. Google Limited Use and AI processing
EtsyAutomation’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, and the applicable Google Workspace user data policy. These limits also apply to data derived from Google data.
Selected artwork and listing text may be sent to OpenAI through the API or Codex, according to the configured generation profile, to produce image descriptions, classifications, keywords, and listing copy. This is inference for the chosen task. We do not train our own models with Google user data, and such data must not be supplied to a provider under settings that allow generalized model training or improvement. Operators must use suitable provider terms and disable training/data-sharing options before processing Google content. Provider retention and safety processing depend on that service and account configuration; we do not promise zero retention.
Google data is used only for the disclosed catalog features. Transfers are limited to authorized functionality, necessary security work, legal requirements, or a business transfer with required prior consent. It is not sold, used for advertising targeting, supplied to data brokers, or used to assess creditworthiness. Human access is limited to operator-authorized review, necessary security or legal work, or permitted anonymized internal analysis.
5. Pinterest-specific commitments
Luxuria Publisher is intended to publish organic Pins to our own authorized business account. Every Pin’s creative, copy, destination, board, and timing must be individually selected and approved by an operator. Connecting an account alone does not approve publishing. Access uses the documented OAuth process or another supported authorization method and permissions needed for the chosen feature.
Board choices, publishing responses, and account or Pin analytics are requested from the official API. Analytics are displayed live rather than stored as an analytics dataset. Board and Pin identifiers are held only in the current server session, with no persistent API-data cache. Restarting or disconnecting clears those references; pending Pins require board selection and approval again. Local delivery records retain our creative hashes, approved copy, attempts, status, and timestamps to prevent duplicate publishing. They do not retain Pinterest identifiers, response payloads, or a copy of other people’s Pins. Published Pins remain on Pinterest until separately deleted.
- No scraping, competitor intelligence, or engagement manipulation.
- No automated follows, saves, comments, or messages.
- No sale of Pinterest information or off-platform ad targeting.
- We do not use Pinterest content or API information to train, fine-tune, or develop AI or machine-learning models, or send that information to our listing-generation AI workflow.
- No combining unrelated accounts into personal profiles.
Pinterest use is subject to its Developer Guidelines and applicable terms. We do not claim approval, endorsement, or unrestricted access.
7. Legal bases and international processing
Where the GDPR applies, we rely on legitimate interests for our proportionate business operations, security, and correspondence; performance of a contract where processing is necessary for an actual contract; consent where required; and legal obligations where applicable. Platform authorization controls access but does not by itself replace a required data-protection legal basis. You may object to processing based on legitimate interests or withdraw consent without affecting earlier lawful processing.
Local processing takes place on the operator’s systems in the Netherlands. Some platform and infrastructure providers process data outside the European Economic Area. Where required, transfers must rely on a valid adequacy decision, contractual safeguards such as standard contractual clauses, or another lawful mechanism. You may ask us about the relevant providers and safeguards.
8. Retention, revocation, and deletion
- Tokens: retained only for an authorized, needed connection; removed when the connection ends or a valid deletion request is fulfilled. A server restart clears the dashboard’s in-memory Pinterest OAuth connection.
- Catalog and generated content: retained while needed for the selected workflow, active catalog, support, or a justified business or legal record. Local databases, generated files, backups, and published copies do not disappear automatically when OAuth is revoked.
- Pinterest analytics: processed in memory for the requested display. Board and Pin identifiers remain in session memory only. Our own creative and publishing records may persist without those identifiers. Copies in backups outside the app’s control require separate removal by their owner.
- Correspondence: normally up to 24 months after resolution, unless a claim or legal requirement justifies longer.
- Temporary files and diagnostics: kept only as needed for processing, recovery, or security. Backups must be included in deletion handling and must not be used to reinstate deleted personal data into an active workflow.
Revoke EtsyAutomation in your Google account’s third-party connections, or revoke Luxuria Publisher in Pinterest’s connected-app settings. Stop pending jobs and remove service-account sharing separately where applicable. Email us to request deletion of retained data. See the data deletion instructions for details, timing, and how already published content is handled.
9. Security
Credentials and local catalog data are kept outside this public website. We restrict access to authorized operators, use HTTPS for external API connections, keep secrets out of public code and browser-delivered pages, and use validation and duplicate checks in publishing. Local records and backups require appropriate device protection. No storage or transmission method is risk-free; this statement is not a claim of independent security certification.
11. Your rights and requests
Where applicable, you can request access, correction, erasure, restriction, or portability of your personal data; object to certain processing; and withdraw consent. Email [email protected]. We ask only for proportionate information needed to verify authority and do not require you to send passwords or tokens. We respond to GDPR requests without undue delay and normally within one month; any permitted extension will be explained within that period.
You may complain to your local data-protection authority, including the Netherlands’ Autoriteit Persoonsgegevens. Listing classifications and SEO suggestions are business-content tools; they are not automated decisions about an individual’s credit, employment, or other legally significant eligibility.
12. Children and changes
The tools are for authorized adult business operators and are not directed to children. We do not knowingly collect information from children under 13. Contact us if you believe such information has been supplied.
We update this policy as practices or requirements change and revise the effective date. Materially different data use requires appropriate notice and any necessary consent before it begins. Our Terms of Service explain the authorized use of these tools. Privacy questions can always be sent to [email protected].