Imperium Backbone eBay application privacy notice

Effective date: 26 September 2026

Imperium Backbone is operated by ARC HOSPITALITY, ENTERTAINMENT AND MAINTENANCE LTD, a company registered in England and Wales under number 15003072, with registered office at Norwich Accountancy, 19 Upper King Street, Norwich, NR3 1RB, United Kingdom. Contact us about this application at privacy@imperium.store.

The application is designed for independently operated eBay seller accounts. Each seller remains responsible for its own selling activity and customer privacy information. This notice explains what the application operator does. Connecting another seller account requires a separate agreement, privacy-role review and permission grant. It does not make the application operator the seller for that account.

Information and purposes. eBay sends the application signed Marketplace Account Deletion notifications. We verify a notification and retain its identifier, event dates and keyed digests of eBay account identifiers in a restricted queue. We use these to identify information held by the application that may need review for deletion or justified retention. The queue does not itself delete records. We do not store the raw eBay username, user ID or EIAS token in that queue.

With a seller's separate authorisation, the application can verify that seller's eBay account and read its inventory and offer information for that seller's stock review. An initial seller connection using account-identity and inventory-read permissions is active. The Identity API may return account profile fields; the application uses the username for comparison and does not save the additional response fields. The initial connection does not have permission to read buyer messages, send replies, change listings or perform selling actions.

A buyer-message review pilot is planned for a separately authorised seller, but is not active at this notice's publication. If activated following a separate permission grant, eBay notifications about messages and questions addressed to that seller may contain the buyer's eBay identifier, message text, conversation and listing references, and timestamps. The application will verify notifications, keep the necessary contents encrypted in a restricted, seller-specific review queue, and prepare a proposed response for the seller or their specifically authorised reviewer. The initial pilot will not send replies automatically. We will not use one seller's messages for another seller's account.

Our role and lawful basis. We determine how to secure and administer this application and reconcile its deletion-notification queue. For these limited purposes, we rely on our legitimate interests in providing the requested service securely, preventing wrong-account access and identifying information needing a deletion review. We limit access and scope. Where we process a seller's customer information solely on that seller's documented instructions, we act for that seller; the seller is responsible for its own applicable lawful basis and customer notice. A different purpose or jointly determined activity requires a separate assessment.

Sharing and location. Authorised application personnel and the relevant seller receive only the information needed to handle an account-specific matter. If the buyer-message pilot begins, a specifically authorised reviewer may see the necessary message content for that seller. An operational alert may go to a restricted business mailbox without buyer text, buyer identifier or order details. Cloudflare hosts the notification endpoints and restricted queues. IONOS provides privacy-email forwarding. eBay supplies notifications and separately authorised seller API data. These providers may process information outside the UK. We use applicable provider data-processing terms and transfer safeguards where required; contact us for details. A European Union database location does not mean every part of the service stays in the UK or EU. The initial message pilot does not send buyer-message text to an AI model provider.

Retention. We do not keep the full Identity API response. Access tokens are used for the active call or session; a refresh token is kept in encrypted storage only while a seller connection remains authorised and needed. The initial connection does not save inventory snapshots. A longer-term stock-history feature would require a revised notice and retention rule before use. Minimal connection and authorisation evidence is reviewed for removal no later than 12 months after connection end, subject to a documented case-specific need.

Deletion-notification identifiers remain in a restricted queue while reconciliation is unresolved. The queue has no automatic deletion process. An unresolved identifier is needed until we determine whether the application holds matching information and what action is required. A matched record is retained only where a specific documented legal obligation or actual claim or dispute applies, using the minimum necessary fields and a recorded review date. We have not yet established a maximum period for unresolved notifications. We will explain the status of a particular request through the privacy contact above. Any separate privacy-case evidence has a documented review date; no general period is operating for it.

If the buyer-message pilot is activated, routine encrypted message and draft content in Backbone's active review queue will be removed 30 days after the review closes, and a minimal keyed event and action audit will be kept for 90 days after closure. Unreviewed messages will be escalated rather than silently removed. A documented complaint, dispute or legal obligation may require specific information to be kept longer, with a review date. Removal from the active queue does not immediately remove a copy from Cloudflare's D1 recovery history. On the present Workers Free plan, its available point-in-time restore window is seven days; a different plan or provider record may have a different period. This policy applies to Backbone's copies, not eBay's records or the independently operated seller's own records. The current Cloudflare Workers Free plan ordinarily keeps Worker diagnostic logs for three days; other provider records may follow different rules. These periods and criteria do not replace separately justified accounting, dispute or legal-hold retention.

Your rights and contact. You can contact privacy@imperium.store about information held by this application. We will identify the relevant seller and coordinate a request with that seller where the information concerns its account. You may also contact the seller directly. Depending on the circumstances, you may have rights to access, correct, erase or restrict your information. You may object to processing based on our legitimate interests. We will review requests, including any justified reason to retain information, and explain the outcome. You can complain to the UK Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.

We will update this notice before materially expanding the information or permissions the application uses. Granting or withdrawing an eBay app permission controls future authorised API access but does not by itself decide whether existing information must be erased or retained.