Legal
Privacy Policy
Effective June 16, 2026 · Operated by Crater Ink Studios LLC, doing business as Hivara.
1. Information we collect.
- Account information: name, email, account credentials (passwords are stored hashed, not in plain text), and billing information (processed by Stripe).
- Business / platform data: product information, material costs, inventory records, purchase orders, production and labor tracking, uploaded files, and reports/calculations you create.
- Imported third-party data: data you choose to import — including sales exports from platforms such as Etsy, Amazon, eBay, or Poshmark — which may contain personal information about your own customers (for example, their names and addresses). See §5.
- Connected marketplace data: if you connect a marketplace or sales-channel account (for example, Amazon or Etsy), the business and operational data Hivara syncs from it through its official API — your listings, inventory, orders, sales totals, and fees. See §15.
- Usage information: device/browser, IP address, pages visited, feature usage, session activity, and error/performance logs.
2. How we use information. To provide and operate Hivara; store and organize your data; process subscriptions and payments; improve the service; provide support; monitor performance and security; develop analytics, automation, and reporting; and communicate service updates. Our use of aggregated and anonymized data — including for AI features and industry benchmarking — is described in the Data Usage & AI Policy.
3. Aggregated & anonymized data. We may use anonymized and aggregated data to improve the platform, its features, trends analysis, forecasting, and automation. Aggregated and anonymized data does not publicly identify any individual or business. We publicly commit not to attempt to re-identify de-identified or aggregated data; see the de-identification commitment in the Data Usage & AI Policy.
4. Data ownership. You retain ownership of your business data. Hivara does not sell or share personal data — see §11 for the CCPA-specific statement.
5. Imported third-party personal information. Hivara lets you import data, including sales exports, that may contain personal information about your own end customers (such as names and addresses). For that imported data, you are the controller and Hivara is your processor / service provider. Hivara processes imported customer personal information solely to provide the service to you, on your instructions, and not for Hivara's own independent purposes except as permitted by the Data Processing Addendum. You are responsible for having a lawful basis to upload that data and for giving your customers any notices and obtaining any consents they are owed. The terms governing this processing — security, sub-processors, breach cooperation, and deletion/return — are in the Data Processing Addendum.
6. How we share data. We share data with trusted third-party service providers — payment processing (Stripe), cloud hosting and database (Supabase and our hosting provider), analytics, authentication, email delivery, and AI/automation infrastructure — with only the access necessary to perform their function, under contract. The current sub-processors are listed in the Data Processing Addendum. We may also access, review, or disclose data — including Your Content — where we have a good-faith basis to do so (for example, where required by law, to enforce our policies, to investigate abuse or security concerns, or to protect the security, rights, or safety of Hivara, our users, or others); and we will report illegal content, such as CSAM, to NCMEC and/or law enforcement and preserve it as required by law. We do not sell or share personal data.
7. Data security. We use reasonable administrative, technical, and organizational measures to protect data. No method of transmission or storage is completely secure.
8. Data retention. We retain data as long as necessary to provide the service or as required by law, then delete or anonymize it. You may request deletion (see §10 and the Data Processing Addendum on deletion/return at termination).
9. Data-breach / incident response. Hivara maintains an incident-response posture and, in the event of a data-security incident affecting personal information, will assess and provide notifications as required by applicable law. For imported customer personal information, Hivara will cooperate with you (the controller) as set out in the Data Processing Addendum.
10. Your rights. You may access, correct, delete, or export your data via contact@hivara.app.
11. CCPA/CPRA notice for California residents.
- Categories of personal information collected: identifiers (name, email, account credentials, IP address); commercial/account information (billing details processed by Stripe; subscription records); internet/usage activity (device, pages, feature usage, logs); and, via your imports, personal information about your end customers (names, addresses).
- Sources: directly from you; automatically from your use of the service; and from data you import.
- Business/commercial purposes: to provide, operate, secure, support, and improve the service; to process subscriptions; and for aggregated/anonymized analytics, AI features, and benchmarking as described in the Data Usage & AI Policy.
- Categories disclosed and to whom: disclosed to service providers (Stripe, Supabase, hosting, analytics, authentication, email delivery, AI/automation infrastructure) for business purposes only.
- Sale/share: Hivara does not sell or share personal information.
- De-identification commitment: Hivara commits that it will not attempt to re-identify any data it maintains in de-identified or aggregate form, will take reasonable measures to prevent re-association, and will contractually obligate recipients to the same.
- Consumer rights: the right to know/access, delete, and correct personal information; to opt out of any sale/share (to the extent applicable); to limit the use of sensitive personal information (if any is collected); and to non-discrimination for exercising these rights.
- Retention: personal information is retained per §8.
- How to exercise: contact contact@hivara.app.
12. Cookies & analytics. We use cookies, analytics, and similar technologies. See the Cookie Policy. You can manage cookies via your browser.
13. Third-party services. Integrations (payment, cloud storage, external apps) are subject to their own privacy policies.
14. Children's privacy. Hivara is not intended for individuals under 18, and we do not knowingly collect personal information from anyone under 18.
15. Connected marketplace accounts. Hivara lets you connect your own third-party marketplace or sales-channel accounts (for example, Amazon, Etsy, or Shopify) so that Hivara can sync your business data automatically rather than by manual file import. This optional feature works as follows:
- What we access. When you authorize a connection, Hivara accesses — through the marketplace’s official API, using the access you grant — your business and operational data from that account: your listings and products, inventory quantities, orders and order status, sales totals, and fees and financial summaries. We request the minimum access needed to provide the service.
- Buyer personal information. These connections are designed to pull business and operational data, not the personal information of your buyers (such as buyer names or shipping addresses). Where a marketplace would return such data only under a separate, restricted permission, Hivara does not request that permission unless a feature requires it and you separately enable it; if that ever applies, the data is handled as imported customer personal information under §5 and the Data Processing Addendum.
- How we use it. Solely to provide the service to you — to keep your inventory, sales, costs, and reports in sync. Hivara acts as your service provider in accessing this data on your behalf. We do not sell it, do not use it for our own independent purposes, and do not include connected-account data in any aggregated or anonymized reuse, AI-model improvement, or benchmarking.
- Credentials and security. The access tokens that authorize a connection are stored encrypted and are used only to retrieve your data for the service; they are protected under §7.
- Your control. Connecting is optional, and you can disconnect at any time from your settings. Disconnecting stops the sync and deletes the stored connection credentials. You may also revoke Hivara’s access from within the marketplace’s own settings.
- The marketplace’s own terms. Your account on each marketplace remains governed by that marketplace’s own terms and privacy policy, and Hivara’s access is subject to the marketplace’s developer terms.
16. Changes & contact. We will post updates with a revised effective date. Questions: contact@hivara.app.