We treat your data the way we'd want ours treated. Here's exactly what we do.
Encryption
TLS 1.3 + AES-256
Disclosure SLA
24h first response
Security contact
hello@listomize.com
TLS 1.3 in transit. AES-256 at rest. All passwords hashed with bcrypt. No exceptions.
Least-privilege principle. Two-factor auth on all admin accounts. Audit logs on every access.
Hosted on global edge infrastructure + managed Postgres. All providers SOC 2 Type II compliant. 99.9% uptime SLA.
WAF, DDoS protection, rate limiting on every API, automated dependency scanning.
We collect minimum data. Anonymize IPs after 30 days. AI inputs are never stored. No third-party trackers.
Found a vulnerability? Email hello@listomize.com. We respond within 24 hours and credit researchers.
The data, compliance, and incident response questions sellers actually ask.
Application data lives in a managed Postgres provider with primary regions in EU + US, encrypted at rest with AES-256. Etsy listing snapshots are cached short-term on our edge network (no PII). We never copy your Etsy session cookies, payment data, or buyer information. Verified customers can request the named vendors via hello@listomize.com.
Yes. Both. We honor data subject rights — access, portability, rectification, deletion — within 30 days. EU customers can access our DPA at /dpa. Email hello@listomize.com for any rights request. We never sell personal data to third parties, ever.
We notify affected users within 72 hours per GDPR requirements, post a public incident report on /changelog within 14 days, and email every impacted account with specifics (what data, what we did, what you should do). Root cause analysis is published publicly — no hidden incidents.
Two ways: (1) Dashboard → Settings → Delete Account triggers immediate purge of your profile, listings, and saved generations. (2) Email hello@listomize.com for assisted deletion. Encrypted backups are purged within 90 days per retention policy. We send a deletion confirmation when complete.
If you discover a security vulnerability, please report it responsibly:
Please don't: publicly disclose vulnerabilities before we've had time to patch (typically 90 days), or test on real user accounts. Use a test account.