Privacy Policy — Voltky and the Voltky Chrome Extension

Who runs Voltky: NYBarginHunter LLC
Postal address: 20 South Oaks Blvd, Plainview, NY 11803, United States
Governing law: New York, United States
Effective date: 18 September 2026
Contact: support@voltky.com
Data protection contact: none appointed


What Voltky is

You have something to sell. Voltky helps you write the listing from photographs, puts it on your own accounts on several marketplaces, and takes those listings down when the item sells.

eBay is two things here, and it is easier to read the rest of this page knowing which is which. eBay is where most of your existing listings and sold history are read from. It is also a place we publish to, when you use the AI listing assistant. Both are true.

Six marketplaces, two different mechanisms. The Chrome extension works on four of them — Facebook Marketplace, Mercari, Poshmark and Depop — by filling their own forms in your own browser. eBay and Etsy are handled by our server through their official APIs, with no extension involved. That is why the extension is called "Cross-List to 4 Marketplaces" while this page names six.

The two people this page is about

You, the seller. You made an account and chose to use Voltky. Most of this page is about you.

Your buyer. When one of your eBay items sells, that buyer's name, address and phone number arrive in Voltky so you can print a shipping label. Your buyer never agreed to anything with Voltky. They have their own section, and we keep it separate on purpose.


Your photographs — the whole story, in one place

This is the part of Voltky that surprises people, so it is all here rather than spread across the page.

We keep the original file. When you upload photos to the AI listing assistant, the file is re-encoded and stored on our server, along with the draft it belongs to — your note, the AI's output, and the item details.

The link to each photo is public. Every stored photo has a web address that works for anyone who has it. There is no sign-in check on it. It has to work that way: eBay's servers fetch your photos directly from us when your listing goes live, and eBay has no Voltky account. The only thing protecting the file is a long random code in its address — too long for anyone to guess. But a link that leaks is a link that works.

We keep it after your listing sells, and after your listing ends. Nothing expires. Nothing is cleaned up.

Nothing deletes it, and you cannot ask the app to. There is no delete button for a photo or a draft, and no code behind one. This is the plainest example of the "indefinitely" in our retention table.

Why this is not a switch we can simply flip. People ask us to delete photos once the listing is published. We cannot do that as stated, because publishing is not one event. The same stored file is fetched again, from the same public link, every time you later cross-list that item to another marketplace — Facebook, Mercari, Poshmark and Depop each download it at their publish time, which can be days after the eBay listing went up. A photo deleted after the first publish would come back as a broken or missing image on the next one, and that failure is quiet rather than loud. If we build deletion, it has to be keyed on something later than "published" — the last marketplace having fetched the file, a fixed retention window, or your request. We are not promising it here, because it does not exist yet. If it is built, this section and the retention table below change with it.

Your photos are sent to our AI provider twice. Once when you press Generate — up to five photos plus the note you typed. Then again, automatically, with no button to press: whenever an eBay category is chosen or changed, the first three photos go a second time, along with the draft's title, brand, condition, colour and size. That second one also fires on a draft where you never pressed Generate at all.

We have not agreed any restriction with our AI provider about what happens next. Our code sends no instruction to them about retention or training. What they do with the photos after they arrive is governed by their terms, not by ours.

We strip the hidden data out of every photo. The camera make and model, the serial number, the time it was taken and any GPS coordinates are removed before the file is stored, and are not in anything sent to our AI provider. This was tested, not assumed.

We do not look at what is in the picture. No code inspects the image content. If a photo happens to show a room, a face, a document, a packing slip or a shipping label, it is stored and sent exactly like any other image — including, in the case of a label, your buyer's name and address.


What else we collect from you, and why

Your account. Your email address, and a scrambled version of your password that cannot be turned back into the password.

Your listing content. Titles, descriptions, prices, categories, conditions, sizes, weights and dimensions, plus the eBay inventory and sold history we sync for you.

Your ship-from address. Your name, street, city, state and postal code, as you typed them into Settings. Needed to quote shipping. This one is stored in plain text, not encrypted.

Keys and connections you choose to add. Your eBay tokens, your Etsy tokens, your EasyPost key and your Telegram bot token. These are stored encrypted. Everything except eBay is optional, and each one exists only because you connected it.

Billing, if you pay us. Your Stripe customer id, subscription id, status, plan and renewal date. Your card details never reach us — they go straight to Stripe.

A record of the work we do for you. Every cross-listing job the extension runs, and a ledger of AI generations used against your allowance.

Marketplace login sessions kept on our server. Some features drive a real browser on our server rather than in yours: the Poshmark sharer and follower, the deal scanner's Facebook searches, and the older server-side posting paths for Facebook, Mercari and Poshmark. If you connect one of those three marketplaces for that purpose, we copy that browser's saved session onto our server — the same thing your own browser keeps so that you do not have to log in again. It is not a password, but while it lasts it lets our server act as you on that marketplace. It stays until somebody removes it by hand. Nothing expires it, and there is no button for it. If you want yours removed, ask us and a person will delete it.

If you close your eBay account, nothing here is erased. eBay notifies us automatically when an eBay account closes. Today we record the notice and erase nothing — your Voltky data stays until you ask us to remove it by hand. What we write down is described under "Other people's information" below.

Server logs

Our server writes a log file. On the server we run today it rotates nightly and is kept for 14 days. (If we move to a hosted platform, logging goes to that platform's own log stream instead, with whatever retention the host applies — we will update this line when that happens.) In that window the log can contain:

Password reset tokens are no longer written to the log. Only a fingerprint of one is.

Your buyer's address is never written to our logs. That is structural rather than lucky: no code path anywhere sends an order, an address or a shipping destination to the log. The order fetch logs a count and nothing else. The only notes that quote page text come from listing forms, and Mercari's are passed through a redactor first.

Your IP address

It reaches our log as described above. It also reaches every outside service your browser contacts while a Voltky page is open — see the two tables below. This happens on every page, including the sign-in and sign-up pages — before you have an account at all. There is no cookie or consent banner anywhere in the app.


Your buyer's information

If you are a buyer and you found this page: this section is for you. You bought something from a seller who uses Voltky. You never agreed to anything with us, so here is what happens to your details, in plain terms, and what you can do.

What arrives, and when

When we sync a seller's eBay orders, eBay returns for each order: the buyer's eBay username, and their name, street address, city, state, postal code, country and phone number. We do not ask eBay for a reduced version — eBay's order call returns the whole block.

This is not limited to the moment a seller opens their Orders page. A background sync that runs with nobody present also receives the full block, as does the analytics call that reads order totals. Neither of those two reads the buyer's fields, but both receive them.

Where it is kept

Nothing eBay sends us about a buyer is written to our database. We checked every column of every table in both of our databases for anything buyer-shaped — name, address, street, recipient, phone, postal code, ZIP, city. There are none. The shipping-label records we do keep hold a cost and an order id, with no name, no address, no tracking number and no label link.

Your order details are held in our server's memory only, and never written to our database or our logs. That is structural rather than lucky: no code path anywhere passes an order, an address or a shipping destination to a log file.

There is no timer on it. It is dropped when the server restarts, or when that seller's orders are fetched again — and a re-fetch simply replaces it with a fresh copy of the same address. eBay returns every paid, unshipped order from the last 60 days, so an unshipped order's buyer stays in memory for as long as our server keeps running. Our server is not restarted on a schedule.

It is also dropped when a label purchase completes and eBay accepts the tracking number, which normally happens moments after the seller buys the label. If that last step fails — eBay errors, or the shipping provider returns no tracking code — it stays in memory like any other cached order.

One exception you should know about, because it is the same thing by another route: a photo a seller uploads can incidentally show a packing slip or a shipping label with a buyer's name and address on it. We do not look at what is in a photo. Those files are kept indefinitely, are reachable by anyone who has the link, and are sent to our AI provider. See the photographs section above.

Where it goes

We have tried to make this list complete. If you find something that reaches a party not named here, that is a bug in this page and we want to hear about it.

Your details are not sent to our AI provider. None of the four places where Voltky calls an AI model carries order data, an address or a phone number. The only way a buyer's details could reach it is inside a seller's photograph, as described above.

What we hold back

The phone number is never forwarded to a shipping provider. To be exact: we do receive it from eBay, and we do show it to the seller on their Orders page. Both label paths leave it out of what they send, and the seller's browser does not even include it in the request.

After it leaves us

Once an address is at EasyPost or at eBay, it is held under their policies and their retention periods. We cannot recall it or delete it there.

The purchased label is a further step: Voltky opens the label document directly from the shipping provider's own file host in a new browser tab. That document carries the buyer's name and full address. We do not store that link, do not sit in front of it, and cannot expire or revoke it. Anyone who gets hold of the link can open the label. Sellers: do not share it.

Two smaller points

Mercari and Poshmark order cards carry no buyer identity at all. Those cards are built on our side with an empty buyer name and an empty address, by design. Separately, the extension does visit a seller's own Mercari order-status pages — which are pages about a transaction with a buyer — but it takes only two things from them: the time the item sold and the price it sold for.

A second shipping route exists in the code but is switched off. eBay's own logistics service would receive the buyer's full name and address. It is disabled and has never been used: zero labels of that kind exist in either database.

If you are a buyer and you want something done

Who is responsible for what. The seller decides to sell the item, decides to buy a label, and decides which shipping provider to use. On their buyer's order data they are the controller; Voltky handles it on their instruction and for no purpose of its own.


Other people's information

eBay account-closure notices. eBay sends us an automatic notice whenever an eBay account is closed. These are about any eBay account holder — usually people who have no relationship with Voltky at all, including buyers. What we write down is a shortened form of eBay's own identifier for that person, in the clear, plus a scrambled form of their username. It sits in our log for 14 days. We acknowledge the notice and erase nothing, because no account on this deployment is linked to an eBay username.


Everyone who receives data

Two separate things happen, and mixing them up is the usual way a list like this goes wrong. Some data leaves your browser as you use the app. Other data leaves our server. Both are below.

Contacted by your own browser

Who What reaches them When Can you avoid it?
Cloudflare Every request between your browser and our server passes through Cloudflare's tunnel. Everything you send us travels through them Every page, every action No
jsDelivr and Google Fonts Your IP address, browser user-agent and the page you are on Every page load, including the signed-out sign-in and sign-up pages, before you have an account Not unless we host those files ourselves. There is no consent banner. The /privacy page is the one page that loads neither
eBay's image host (i.ebayimg.com) Your IP address, browser user-agent and the page you are on, once per photo shown Every time you open Inventory or Orders — your listing photos are loaded straight from eBay, not copied through us No. Your inventory is the core of the product
Poshmark's image host (di2ponv0v5otw.cloudfront.net) The same The same, for items you imported from Poshmark No
Facebook, Mercari, Poshmark, Depop Your listing, typed into their own forms by the extension, in the sessions you are already signed in to You cross-list to that marketplace Yes — per marketplace

At the time of the audit, the inventory table held 6,153 photo links pointing at eBay's image host and 280 pointing at Poshmark's. Loading a page of your inventory contacts those hosts once per photo shown. They therefore learn your IP address, your browser, and which Voltky page you were on when it happened.

Contacted by our server

Who What reaches them When Can you avoid it?
Anthropic (our AI provider) Up to 5 of your photos, plus the note you typed You press Generate on the AI listing page Yes — the hand-filled listing page never sends your photos to the AI. It can still make the category call in the row below, if you press the button for it
Anthropic The first 3 of the same photos, plus the draft's title, brand, condition, colour and size Automatically, when an eBay category is chosen — there is no button. Again on every category change, and even for a draft where Generate was never pressed Only by not using the AI listing page
Anthropic Your listing title, its eBay category and its item specifics. No photos Working out the matching category on another marketplace, when we have not seen that category before Partly. On the inventory cross-list screens it is automatic and cannot be declined. On the AI and hand-filled forms it happens only if you press "Ask the AI to match…"
Anthropic Your listing title and eBay category name. No photos Opening the Etsy category picker for an item with no remembered category (Pro plan) Yes — Etsy lane only
Stripe Your account email or stored Stripe customer id, your Voltky user id, and which plan you picked. No card data passes through us You press Subscribe, Buy credits, or Manage subscription Yes — every account starts on Free and never touches Stripe
EasyPost Your buyer's name and street address, your ship-from address, and the parcel's weight and size — authenticated with your own EasyPost key You press Get Rates, then Buy Yes, for you — nothing happens unless you save an EasyPost key. Your buyer cannot avoid it
eBay Your listing content and your eBay token, for publishing, revising, ending and syncing. After a label purchase, the order id, tracking number and carrier Using Voltky at all No — this is what the product is
eBay (search, categories, finances) Search keywords, a free-text category query, or a date range The deal scanner, the category picker, expense reconciliation Search and finances are optional; the category lookup is not
Etsy Your Etsy tokens, your listing content, and the raw image files of up to 10 photos You connect Etsy and push an item Yes, entirely — opt-in
eBay's and Poshmark's image hosts A request from our server for each of your own photos, with no cookies attached, so the file can be forwarded to Etsy Each Etsy push. (Separately from the browser-side loads in the table above) With the Etsy lane
OpenStreetMap's address lookup service Your postal code Setting up the deal scanner's location Yes — deal scanner only
Telegram Your deal-alert text and a photo link, sent to your own bot and your own chat A deal-scanner alert Yes — nothing is sent unless you save a bot token
Facebook and OfferUp (through a browser running on our server) Your search keywords and a radius The deal scanner's search loop Yes — scanner only

The Chrome extension

The extension does the cross-listing work in your own browser, using the marketplace sessions you are already signed in to. It signs into nothing and never handles a marketplace password.

Permissions it asks for

Three, and only three:

Where it runs

On app.voltky.com (our own app), on Facebook Marketplace's create, "you" and item pages, on www.mercari.com, poshmark.com and www.depop.com. It also fetches images from i.ebayimg.com (your own eBay photos) and reads your shop list from webapi.depop.com, which is Depop's own API.

Its script on our own app runs on every Voltky page — including the Orders page, where your buyer's name, address and phone are on screen. It reads nothing there. That script contains no code that reads the page at all: it checks for a marker tag, records our address, and passes listings through.

What it reads on a marketplace page

What it sends, and where

Everything the extension sends goes to Voltky's own server, except for the marketplace requests listed at points 3 to 6 below. Here is the complete list:

  1. Job checks, claims and results, to Voltky's own server, carrying your Voltky session cookie.
  2. Publish results, to Voltky's own server.
  3. Anonymous, signed-out requests to a public Poshmark, Mercari or Facebook listing page, to read whether your listing is still live. These send no cookies.
  4. Your own photos, downloaded from eBay's image host or from Voltky, so they can be uploaded to the new marketplace. Anything that is not an image is refused.
  5. Your closet, read from Poshmark's own pages.
  6. Your shop list, read from Depop's own API — this one does send your Depop cookies and your Depop username, because that is how Depop identifies your shop. It goes to Depop, and to nobody else.

How the destination is decided. The address the extension reports to is the address of the Voltky page you last had open, recorded by the extension only while it is running on a Voltky page. It is never taken from a marketplace page. Ten places in the extension's code carry a leftover developer fallback for the case where that record is missing: an address on your own machine (localhost), which reaches nothing outside your computer and simply fails.

No site can send the extension instructions through Chrome. The extension declares no channel for that, so no web page can reach it through Chrome's messaging system. The one exception is deliberate and narrow: the extension's own script on the Voltky app page accepts messages from that page only, checked against the page's own address, because that is how you press "list this" and the app tells the extension what to do.

Progress updates while a form is being filled. The extension sends Voltky a percentage and a one-line status it wrote itself, such as "Setting the item condition". These are not scraped from the marketplace page. One Mercari update includes a count of your own photos. There is no setting to turn this off. We keep them in memory for an hour, and a shortened copy sits in the server log for 14 days.

One tab address is sent. When a job finishes, the extension reads the address of the tab it opened itself and sends a shortened copy — 160 characters — with the result, so we can say truthfully where the tab ended up rather than guess that a listing died. It reads the address of no other tab. To put you back where you were, it does look up which tab in that window was active before it took over, and uses nothing but that tab's internal number — not its address, not its title, not its contents.

What it stores in your browser, and for how long

The extension uses chrome.storage.local only. It never uses chrome.storage.sync, so nothing it stores leaves your machine through Chrome. There are fourteen keys in total. These are the ones that matter:

There is no button that clears any of this. The extension offers no way to erase its own storage. To remove it, uninstall the extension or clear its storage from Chrome's own settings.


What we do not do

Things we checked in the code, and can show you

Things we promise


How long we keep things

What How long
Server logs 14 days on the server we run today, then deleted automatically. On a hosted platform, the host's own retention applies
Buyer names, addresses and phone numbers, as eBay sends them In server memory only, never on disk. No timer: until the server restarts, until that seller's orders are fetched again, or until a label purchase completes and eBay accepts the tracking number. Two things outlive all of that and we cannot expire either: the label document held at the shipping provider, and a buyer's address that happens to be visible in an uploaded photo
Fill-progress updates 1 hour in memory; 14 days in the log
Depop fill notes 15 minutes in memory; the log copy lives 14 days
Your uploaded photo files Indefinitely. Nothing deletes them.
Your photo drafts Indefinitely. Nothing deletes them — there is a delete function in our code and nothing calls it
Your listing inventory and sold history Indefinitely. You can delete an individual item; there is no expiry and no bulk delete
Your job history Indefinitely
Your ship-from address (plain text) Indefinitely
Your eBay, Etsy, EasyPost and Telegram credentials (encrypted) Indefinitely, unless you disconnect — see below
Your billing and AI-credit records Indefinitely, including after you cancel, so "Manage billing" keeps working
Marketplace login sessions kept on our server Indefinitely. Nothing expires them. Removable by hand on request
Database backups Made by hand, not on a schedule. Each run keeps the newest 14 copies in the backups folder; separately named snapshots taken before risky changes are never pruned and go back to August 2026
Category matches learned from your listings Indefinitely, and they are shared. See below
What the extension stores in your browser See the extension section. Two items stay until you uninstall

"Indefinitely" means what it says: there is no timer, no expiry job and no delete button. It does not mean "as long as necessary".

A note about learned categories. When we work out that a particular eBay category matches a particular Mercari or Poshmark category, we remember it. That memory is shared across everyone using Voltky — it has no owner attached — and some entries are AI suggestions nobody has confirmed yet. It holds no personal information: it is category-to-category only. If you asked us to delete your data, this contribution would stay, because there is nothing in it that identifies you to remove.


If you cancel, or stop using Voltky

Cancelling a subscription moves you to the Free plan. It deletes nothing. Your listings, your photos, your drafts, your job history, your ship-from address and your connected credentials all stay exactly as they are, under the retention above, and your billing record is kept so that "Manage billing" keeps working. If you want any of it removed, you have to ask — see the next section.


What you can ask for today, and what we cannot yet do

You can do these yourself, right now:

These are not possible today. We would rather say so than promise them:

If you ask us to erase your data, here is exactly what that means today. A person does it by hand, and that is not the same as everything disappearing.


Changes to this page

If we change what we do with your information, we will change this page. We have no mail system, so we cannot email you about it — checking this page is the only way to see a change.

How to reach a human

Email support@voltky.com. A person reads it. The product itself sends no email, so nothing will reply automatically.


How this page was checked

This page was written from a line-by-line audit of Voltky's source code and databases on 18 September 2026 — 143 data flows traced, every claim tied to a specific line of code, and every reassuring sentence handed to someone whose job was to disprove it. Twenty-three were disproved and removed. A second review then raised 70 further objections to the draft of this page — 27 of them blocking — and all 70 were answered before publication: each one either changed the text above, or was checked against the code and found not to apply.

Where this page says "nothing deletes it", that is a description of our code, not a figure of speech. If you find a sentence here that the product does not do, write to us and we will correct it.