Who runs Voltky: NYBarginHunter LLC
Postal address: 20 South Oaks Blvd, Plainview, NY 11803, United States
Governing law: New York, United States
Effective date: 18 September 2026
Contact: support@voltky.com
Data protection contact: none appointed
You have something to sell. Voltky helps you write the listing from photographs, puts it on your own accounts on several marketplaces, and takes those listings down when the item sells.
eBay is two things here, and it is easier to read the rest of this page knowing which is which. eBay is where most of your existing listings and sold history are read from. It is also a place we publish to, when you use the AI listing assistant. Both are true.
Six marketplaces, two different mechanisms. The Chrome extension works on four of them — Facebook Marketplace, Mercari, Poshmark and Depop — by filling their own forms in your own browser. eBay and Etsy are handled by our server through their official APIs, with no extension involved. That is why the extension is called "Cross-List to 4 Marketplaces" while this page names six.
You, the seller. You made an account and chose to use Voltky. Most of this page is about you.
Your buyer. When one of your eBay items sells, that buyer's name, address and phone number arrive in Voltky so you can print a shipping label. Your buyer never agreed to anything with Voltky. They have their own section, and we keep it separate on purpose.
This is the part of Voltky that surprises people, so it is all here rather than spread across the page.
We keep the original file. When you upload photos to the AI listing assistant, the file is re-encoded and stored on our server, along with the draft it belongs to — your note, the AI's output, and the item details.
The link to each photo is public. Every stored photo has a web address that works for anyone who has it. There is no sign-in check on it. It has to work that way: eBay's servers fetch your photos directly from us when your listing goes live, and eBay has no Voltky account. The only thing protecting the file is a long random code in its address — too long for anyone to guess. But a link that leaks is a link that works.
We keep it after your listing sells, and after your listing ends. Nothing expires. Nothing is cleaned up.
Nothing deletes it, and you cannot ask the app to. There is no delete button for a photo or a draft, and no code behind one. This is the plainest example of the "indefinitely" in our retention table.
Why this is not a switch we can simply flip. People ask us to delete photos once the listing is published. We cannot do that as stated, because publishing is not one event. The same stored file is fetched again, from the same public link, every time you later cross-list that item to another marketplace — Facebook, Mercari, Poshmark and Depop each download it at their publish time, which can be days after the eBay listing went up. A photo deleted after the first publish would come back as a broken or missing image on the next one, and that failure is quiet rather than loud. If we build deletion, it has to be keyed on something later than "published" — the last marketplace having fetched the file, a fixed retention window, or your request. We are not promising it here, because it does not exist yet. If it is built, this section and the retention table below change with it.
Your photos are sent to our AI provider twice. Once when you press Generate — up to five photos plus the note you typed. Then again, automatically, with no button to press: whenever an eBay category is chosen or changed, the first three photos go a second time, along with the draft's title, brand, condition, colour and size. That second one also fires on a draft where you never pressed Generate at all.
We have not agreed any restriction with our AI provider about what happens next. Our code sends no instruction to them about retention or training. What they do with the photos after they arrive is governed by their terms, not by ours.
We strip the hidden data out of every photo. The camera make and model, the serial number, the time it was taken and any GPS coordinates are removed before the file is stored, and are not in anything sent to our AI provider. This was tested, not assumed.
We do not look at what is in the picture. No code inspects the image content. If a photo happens to show a room, a face, a document, a packing slip or a shipping label, it is stored and sent exactly like any other image — including, in the case of a label, your buyer's name and address.
Your account. Your email address, and a scrambled version of your password that cannot be turned back into the password.
Your listing content. Titles, descriptions, prices, categories, conditions, sizes, weights and dimensions, plus the eBay inventory and sold history we sync for you.
Your ship-from address. Your name, street, city, state and postal code, as you typed them into Settings. Needed to quote shipping. This one is stored in plain text, not encrypted.
Keys and connections you choose to add. Your eBay tokens, your Etsy tokens, your EasyPost key and your Telegram bot token. These are stored encrypted. Everything except eBay is optional, and each one exists only because you connected it.
Billing, if you pay us. Your Stripe customer id, subscription id, status, plan and renewal date. Your card details never reach us — they go straight to Stripe.
A record of the work we do for you. Every cross-listing job the extension runs, and a ledger of AI generations used against your allowance.
Marketplace login sessions kept on our server. Some features drive a real browser on our server rather than in yours: the Poshmark sharer and follower, the deal scanner's Facebook searches, and the older server-side posting paths for Facebook, Mercari and Poshmark. If you connect one of those three marketplaces for that purpose, we copy that browser's saved session onto our server — the same thing your own browser keeps so that you do not have to log in again. It is not a password, but while it lasts it lets our server act as you on that marketplace. It stays until somebody removes it by hand. Nothing expires it, and there is no button for it. If you want yours removed, ask us and a person will delete it.
If you close your eBay account, nothing here is erased. eBay notifies us automatically when an eBay account closes. Today we record the notice and erase nothing — your Voltky data stays until you ask us to remove it by hand. What we write down is described under "Other people's information" below.
Our server writes a log file. On the server we run today it rotates nightly and is kept for 14 days. (If we move to a hosted platform, logging goes to that platform's own log stream instead, with whatever retention the host applies — we will update this line when that happens.) In that window the log can contain:
Password reset tokens are no longer written to the log. Only a fingerprint of one is.
Your buyer's address is never written to our logs. That is structural rather than lucky: no code path anywhere sends an order, an address or a shipping destination to the log. The order fetch logs a count and nothing else. The only notes that quote page text come from listing forms, and Mercari's are passed through a redactor first.
It reaches our log as described above. It also reaches every outside service your browser contacts while a Voltky page is open — see the two tables below. This happens on every page, including the sign-in and sign-up pages — before you have an account at all. There is no cookie or consent banner anywhere in the app.
If you are a buyer and you found this page: this section is for you. You bought something from a seller who uses Voltky. You never agreed to anything with us, so here is what happens to your details, in plain terms, and what you can do.
When we sync a seller's eBay orders, eBay returns for each order: the buyer's eBay username, and their name, street address, city, state, postal code, country and phone number. We do not ask eBay for a reduced version — eBay's order call returns the whole block.
This is not limited to the moment a seller opens their Orders page. A background sync that runs with nobody present also receives the full block, as does the analytics call that reads order totals. Neither of those two reads the buyer's fields, but both receive them.
Nothing eBay sends us about a buyer is written to our database. We checked every column of every table in both of our databases for anything buyer-shaped — name, address, street, recipient, phone, postal code, ZIP, city. There are none. The shipping-label records we do keep hold a cost and an order id, with no name, no address, no tracking number and no label link.
Your order details are held in our server's memory only, and never written to our database or our logs. That is structural rather than lucky: no code path anywhere passes an order, an address or a shipping destination to a log file.
There is no timer on it. It is dropped when the server restarts, or when that seller's orders are fetched again — and a re-fetch simply replaces it with a fresh copy of the same address. eBay returns every paid, unshipped order from the last 60 days, so an unshipped order's buyer stays in memory for as long as our server keeps running. Our server is not restarted on a schedule.
It is also dropped when a label purchase completes and eBay accepts the tracking number, which normally happens moments after the seller buys the label. If that last step fails — eBay errors, or the shipping provider returns no tracking code — it stays in memory like any other cached order.
One exception you should know about, because it is the same thing by another route: a photo a seller uploads can incidentally show a packing slip or a shipping label with a buyer's name and address on it. We do not look at what is in a photo. Those files are kept indefinitely, are reachable by anyone who has the link, and are sent to our AI provider. See the photographs section above.
We have tried to make this list complete. If you find something that reaches a party not named here, that is a bug in this page and we want to hear about it.
Your details are not sent to our AI provider. None of the four places where Voltky calls an AI model carries order data, an address or a phone number. The only way a buyer's details could reach it is inside a seller's photograph, as described above.
The phone number is never forwarded to a shipping provider. To be exact: we do receive it from eBay, and we do show it to the seller on their Orders page. Both label paths leave it out of what they send, and the seller's browser does not even include it in the request.
Once an address is at EasyPost or at eBay, it is held under their policies and their retention periods. We cannot recall it or delete it there.
The purchased label is a further step: Voltky opens the label document directly from the shipping provider's own file host in a new browser tab. That document carries the buyer's name and full address. We do not store that link, do not sit in front of it, and cannot expire or revoke it. Anyone who gets hold of the link can open the label. Sellers: do not share it.
Mercari and Poshmark order cards carry no buyer identity at all. Those cards are built on our side with an empty buyer name and an empty address, by design. Separately, the extension does visit a seller's own Mercari order-status pages — which are pages about a transaction with a buyer — but it takes only two things from them: the time the item sold and the price it sold for.
A second shipping route exists in the code but is switched off. eBay's own logistics service would receive the buyer's full name and address. It is disabled and has never been used: zero labels of that kind exist in either database.
Who is responsible for what. The seller decides to sell the item, decides to buy a label, and decides which shipping provider to use. On their buyer's order data they are the controller; Voltky handles it on their instruction and for no purpose of its own.
eBay account-closure notices. eBay sends us an automatic notice whenever an eBay account is closed. These are about any eBay account holder — usually people who have no relationship with Voltky at all, including buyers. What we write down is a shortened form of eBay's own identifier for that person, in the clear, plus a scrambled form of their username. It sits in our log for 14 days. We acknowledge the notice and erase nothing, because no account on this deployment is linked to an eBay username.
Two separate things happen, and mixing them up is the usual way a list like this goes wrong. Some data leaves your browser as you use the app. Other data leaves our server. Both are below.
| Who | What reaches them | When | Can you avoid it? |
|---|---|---|---|
| Cloudflare | Every request between your browser and our server passes through Cloudflare's tunnel. Everything you send us travels through them | Every page, every action | No |
| jsDelivr and Google Fonts | Your IP address, browser user-agent and the page you are on | Every page load, including the signed-out sign-in and sign-up pages, before you have an account | Not unless we host those files ourselves. There is no consent banner. The /privacy page is the one page that loads neither |
eBay's image host (i.ebayimg.com) |
Your IP address, browser user-agent and the page you are on, once per photo shown | Every time you open Inventory or Orders — your listing photos are loaded straight from eBay, not copied through us | No. Your inventory is the core of the product |
Poshmark's image host (di2ponv0v5otw.cloudfront.net) |
The same | The same, for items you imported from Poshmark | No |
| Facebook, Mercari, Poshmark, Depop | Your listing, typed into their own forms by the extension, in the sessions you are already signed in to | You cross-list to that marketplace | Yes — per marketplace |
At the time of the audit, the inventory table held 6,153 photo links pointing at eBay's image host and 280 pointing at Poshmark's. Loading a page of your inventory contacts those hosts once per photo shown. They therefore learn your IP address, your browser, and which Voltky page you were on when it happened.
| Who | What reaches them | When | Can you avoid it? |
|---|---|---|---|
| Anthropic (our AI provider) | Up to 5 of your photos, plus the note you typed | You press Generate on the AI listing page | Yes — the hand-filled listing page never sends your photos to the AI. It can still make the category call in the row below, if you press the button for it |
| Anthropic | The first 3 of the same photos, plus the draft's title, brand, condition, colour and size | Automatically, when an eBay category is chosen — there is no button. Again on every category change, and even for a draft where Generate was never pressed | Only by not using the AI listing page |
| Anthropic | Your listing title, its eBay category and its item specifics. No photos | Working out the matching category on another marketplace, when we have not seen that category before | Partly. On the inventory cross-list screens it is automatic and cannot be declined. On the AI and hand-filled forms it happens only if you press "Ask the AI to match…" |
| Anthropic | Your listing title and eBay category name. No photos | Opening the Etsy category picker for an item with no remembered category (Pro plan) | Yes — Etsy lane only |
| Stripe | Your account email or stored Stripe customer id, your Voltky user id, and which plan you picked. No card data passes through us | You press Subscribe, Buy credits, or Manage subscription | Yes — every account starts on Free and never touches Stripe |
| EasyPost | Your buyer's name and street address, your ship-from address, and the parcel's weight and size — authenticated with your own EasyPost key | You press Get Rates, then Buy | Yes, for you — nothing happens unless you save an EasyPost key. Your buyer cannot avoid it |
| eBay | Your listing content and your eBay token, for publishing, revising, ending and syncing. After a label purchase, the order id, tracking number and carrier | Using Voltky at all | No — this is what the product is |
| eBay (search, categories, finances) | Search keywords, a free-text category query, or a date range | The deal scanner, the category picker, expense reconciliation | Search and finances are optional; the category lookup is not |
| Etsy | Your Etsy tokens, your listing content, and the raw image files of up to 10 photos | You connect Etsy and push an item | Yes, entirely — opt-in |
| eBay's and Poshmark's image hosts | A request from our server for each of your own photos, with no cookies attached, so the file can be forwarded to Etsy | Each Etsy push. (Separately from the browser-side loads in the table above) | With the Etsy lane |
| OpenStreetMap's address lookup service | Your postal code | Setting up the deal scanner's location | Yes — deal scanner only |
| Telegram | Your deal-alert text and a photo link, sent to your own bot and your own chat | A deal-scanner alert | Yes — nothing is sent unless you save a bot token |
| Facebook and OfferUp (through a browser running on our server) | Your search keywords and a radius | The deal scanner's search loop | Yes — scanner only |
The extension does the cross-listing work in your own browser, using the marketplace sessions you are already signed in to. It signs into nothing and never handles a marketplace password.
Three, and only three:
tabs — to open a marketplace tab, bring it to the front for the moments a page will not accept typing while hidden, put you back on the tab you were on, and close it when the job is done.storage — to hold the listing while it is being published and the result afterwards. A marketplace page's own security rules block the extension from reporting to us directly, and a successful publish navigates the page away before any request in flight can finish. See below for exactly what is held, and for how long.alarms — two repeating alarms, thirty seconds apart: one checks Voltky for queued work, the other re-sends a publish report our server refused. Chrome shuts down an idle extension, and an alarm is what wakes it. If you are not signed in to Voltky, the check returns immediately and no request is made.On app.voltky.com (our own app), on Facebook Marketplace's create, "you" and item pages, on www.mercari.com, poshmark.com and www.depop.com. It also fetches images from i.ebayimg.com (your own eBay photos) and reads your shop list from webapi.depop.com, which is Depop's own API.
Its script on our own app runs on every Voltky page — including the Orders page, where your buyer's name, address and phone are on screen. It reads nothing there. That script contains no code that reads the page at all: it checks for a marker tag, records our address, and passes listings through.
Everything the extension sends goes to Voltky's own server, except for the marketplace requests listed at points 3 to 6 below. Here is the complete list:
How the destination is decided. The address the extension reports to is the address of the Voltky page you last had open, recorded by the extension only while it is running on a Voltky page. It is never taken from a marketplace page. Ten places in the extension's code carry a leftover developer fallback for the case where that record is missing: an address on your own machine (localhost), which reaches nothing outside your computer and simply fails.
No site can send the extension instructions through Chrome. The extension declares no channel for that, so no web page can reach it through Chrome's messaging system. The one exception is deliberate and narrow: the extension's own script on the Voltky app page accepts messages from that page only, checked against the page's own address, because that is how you press "list this" and the app tells the extension what to do.
Progress updates while a form is being filled. The extension sends Voltky a percentage and a one-line status it wrote itself, such as "Setting the item condition". These are not scraped from the marketplace page. One Mercari update includes a count of your own photos. There is no setting to turn this off. We keep them in memory for an hour, and a shortened copy sits in the server log for 14 days.
One tab address is sent. When a job finishes, the extension reads the address of the tab it opened itself and sends a shortened copy — 160 characters — with the result, so we can say truthfully where the tab ended up rather than guess that a listing died. It reads the address of no other tab. To put you back where you were, it does look up which tab in that window was active before it took over, and uses nothing but that tab's internal number — not its address, not its title, not its contents.
The extension uses chrome.storage.local only. It never uses chrome.storage.sync, so nothing it stores leaves your machine through Chrome. There are fourteen keys in total. These are the ones that matter:
There is no button that clears any of this. The extension offers no way to erase its own storage. To remove it, uninstall the extension or clear its storage from Chrome's own settings.
| What | How long |
|---|---|
| Server logs | 14 days on the server we run today, then deleted automatically. On a hosted platform, the host's own retention applies |
| Buyer names, addresses and phone numbers, as eBay sends them | In server memory only, never on disk. No timer: until the server restarts, until that seller's orders are fetched again, or until a label purchase completes and eBay accepts the tracking number. Two things outlive all of that and we cannot expire either: the label document held at the shipping provider, and a buyer's address that happens to be visible in an uploaded photo |
| Fill-progress updates | 1 hour in memory; 14 days in the log |
| Depop fill notes | 15 minutes in memory; the log copy lives 14 days |
| Your uploaded photo files | Indefinitely. Nothing deletes them. |
| Your photo drafts | Indefinitely. Nothing deletes them — there is a delete function in our code and nothing calls it |
| Your listing inventory and sold history | Indefinitely. You can delete an individual item; there is no expiry and no bulk delete |
| Your job history | Indefinitely |
| Your ship-from address (plain text) | Indefinitely |
| Your eBay, Etsy, EasyPost and Telegram credentials (encrypted) | Indefinitely, unless you disconnect — see below |
| Your billing and AI-credit records | Indefinitely, including after you cancel, so "Manage billing" keeps working |
| Marketplace login sessions kept on our server | Indefinitely. Nothing expires them. Removable by hand on request |
| Database backups | Made by hand, not on a schedule. Each run keeps the newest 14 copies in the backups folder; separately named snapshots taken before risky changes are never pruned and go back to August 2026 |
| Category matches learned from your listings | Indefinitely, and they are shared. See below |
| What the extension stores in your browser | See the extension section. Two items stay until you uninstall |
"Indefinitely" means what it says: there is no timer, no expiry job and no delete button. It does not mean "as long as necessary".
A note about learned categories. When we work out that a particular eBay category matches a particular Mercari or Poshmark category, we remember it. That memory is shared across everyone using Voltky — it has no owner attached — and some entries are AI suggestions nobody has confirmed yet. It holds no personal information: it is category-to-category only. If you asked us to delete your data, this contribution would stay, because there is nothing in it that identifies you to remove.
Cancelling a subscription moves you to the Free plan. It deletes nothing. Your listings, your photos, your drafts, your job history, your ship-from address and your connected credentials all stay exactly as they are, under the retention above, and your billing record is kept so that "Manage billing" keeps working. If you want any of it removed, you have to ask — see the next section.
You can do these yourself, right now:
These are not possible today. We would rather say so than promise them:
If you ask us to erase your data, here is exactly what that means today. A person does it by hand, and that is not the same as everything disappearing.
If we change what we do with your information, we will change this page. We have no mail system, so we cannot email you about it — checking this page is the only way to see a change.
Email support@voltky.com. A person reads it. The product itself sends no email, so nothing will reply automatically.
This page was written from a line-by-line audit of Voltky's source code and databases on 18 September 2026 — 143 data flows traced, every claim tied to a specific line of code, and every reassuring sentence handed to someone whose job was to disprove it. Twenty-three were disproved and removed. A second review then raised 70 further objections to the draft of this page — 27 of them blocking — and all 70 were answered before publication: each one either changed the text above, or was checked against the code and found not to apply.
Where this page says "nothing deletes it", that is a description of our code, not a figure of speech. If you find a sentence here that the product does not do, write to us and we will correct it.