Welcome to Xalista (the "Service"), operated by VantageLogic LLC ("we," "us," or "our"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information about you when you use our web application and browser extension.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Service.
Information We Collect
We collect information you provide directly and information generated automatically through your use of the Service.
Information you provide:
- Account information — your name and email address when you register.
- Payment information — billing details when you subscribe to a paid plan (processed via Lemon Squeezy).
- Listing Data — photos, titles, and descriptions you upload for processing.
- Platform Session Data — authentication cookies from third-party marketplaces (Poshmark, Depop, Mercari) captured via our browser extension to enable cross-listing features.
- Google Photos — when you use the photo picker, we receive the file name, media URL, thumbnail URL, and MIME type of photos you explicitly select from your Google Photos library.
Information collected automatically:
- Usage data — pages visited, features used, clicks, and error logs.
- Device & browser data — IP address, browser type, and operating system.
- Cookies — strictly necessary cookies for authentication and security.
How We Use Your Information
- Provide, operate, and improve the Xalista AI engine and cross-listing automation.
- Authenticate your account with third-party marketplaces to perform actions on your behalf (e.g., creating drafts, updating listings).
- Process payments and manage your subscription status.
- Send transactional emails (e.g., account verification, password resets).
- Analyze usage trends to enhance features (e.g., listing accuracy).
- Detect and prevent fraud or abuse.
We do not sell your personal data. Your listing photos, descriptions, and session data are processed solely to facilitate your use of the Service and are not used to train public AI models without your consent.
Marketplace Connectivity & Browser Extension
To provide automation for platforms that do not offer public API access (including Poshmark, Depop, and Mercari), Xalista utilizes a browser extension ("Xalista Connector") to securely bridge your marketplace sessions.
Limited Scope
The extension only activates on authorized marketplace domains and only reads the specific session cookies required for authentication.
No Password Storage
We never see or store your marketplace passwords. We only capture the encrypted session token generated by your browser after you log in.
Secure Vaulting
Captured session data is filtered locally, transmitted over HTTPS, and encrypted at rest in our secure backend vault.
You can disconnect a marketplace at any time through the Xalista dashboard, which will immediately purge the associated session tokens from our active vault.
Payment Information
All payment transactions are processed by our Merchant of Record, Lemon Squeezy. We do not store full credit card numbers or sensitive payment details on our servers.
By making a purchase, you are also subject to Lemon Squeezy's privacy policy.
Google User Data & Limited Use Disclosure
Xalista integrates with Google Photos via the Google Photos Picker API to let you select photos from your own Google Photos library for use in product listings. This section describes how we handle data received from Google APIs.
What we access
When you use the photo picker, we request the photospicker.mediaitems.readonly scope. This allows us to receive the file name, media URL, thumbnail URL, and MIME type of the photos you explicitly select through the Google Photos picker interface. We do not browse, scan, index, or access any photos you have not selected.
How we use it
The selected photos are downloaded and securely stored in our infrastructure solely to attach images to your product listings within Xalista. We do not use Google user data for advertising, market research, or any purpose unrelated to providing the Service to you.
How we store it
When you select photos via Google Photos, we download and re-upload them to our secure storage infrastructure so that your listings have permanent, reliable image URLs. We store the resulting image files and associated metadata (file name, MIME type) necessary to display your selected photos within your listings. The original Google Photos URLs are not retained after the transfer is complete. OAuth access tokens are held in memory during your active browser session and are never persisted to any database, file system, or log. If you delete a listing or your account, the associated images and metadata are deleted within 30 days.
How we share it
We do not share Google user data with any third parties except as strictly necessary to provide the Service (for example, a file URL may be passed to our AI processing provider to generate a listing description from your selected photo). We never sell, lease, or trade Google user data.
Google API Services User Data Policy Compliance: Xalista's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We only use Google user data to provide and improve user-facing features of Xalista that are apparent to you in the application's interface.
- We do not transfer Google user data to third parties unless it is necessary to provide or improve user-facing features, you provide affirmative consent, it is necessary for security purposes, or it is required to comply with applicable law.
- We do not use or transfer Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data unless we have obtained your affirmative consent, it is necessary for security purposes, it is required to comply with applicable law, or the data has been aggregated and anonymized and used for internal operations in accordance with applicable privacy and other legal requirements.
Revoking access
You can revoke Xalista's access to your Google account at any time by visiting your Google Account Permissions page and removing Xalista. Revoking access will prevent future photo selection from Google Photos but will not automatically delete images already saved to existing listings. To remove those, delete the relevant listings or your account.
Data Security & Storage
We implement industry-standard security measures to protect your data. This includes:
- Encryption: All sensitive data, including marketplace session tokens, is encrypted at rest using AES-256 encryption within our secure database.
- Transmission: All data transferred between your browser, the extension, and our servers is encrypted via TLS/SSL.
Data Retention
We retain your account data for as long as your account is active. If you delete your account via the Dashboard, your personal data, active session tokens, listing history, and associated images (including those imported from Google Photos) will be deleted from our live databases and storage within 30 days.
Contact Us
If you have any questions about this Privacy Policy, how we handle your data (including Google user data), or wish to exercise your data rights, please contact us: