Imperium Backbone eBay application privacy notice

Effective date: 10 October 2026

Imperium Backbone is operated by ARC HOSPITALITY, ENTERTAINMENT AND MAINTENANCE LTD, a company registered in England and Wales under number 15003072, with registered office at Norwich Accountancy, 19 Upper King Street, Norwich, NR3 1RB, United Kingdom. Contact us about this application at privacy@imperium.store.

The application is designed for independently operated eBay seller accounts. Each seller remains responsible for its own selling activity and customer privacy information. This notice explains what the application operator does. Connecting another seller account requires a separate agreement, privacy-role review and permission grant. It does not make the application operator the seller for that account.

Information and purposes. eBay sends the application signed Marketplace Account Deletion notifications. We verify a notification and retain its identifier, event dates and keyed digests of eBay account identifiers in a restricted queue. We use these to identify information held by the application that may need review for deletion or justified retention. The queue does not itself delete records. We do not store the raw eBay username, user ID or EIAS token in that queue.

With a seller's separate authorisation, the application can verify that seller's eBay account and read its inventory and offer information for that seller's stock review. An initial seller connection using account-identity and inventory-read permissions is active. The Identity API may return account profile fields; the application uses the username for comparison and does not save the additional response fields. For an authorised own-listing stock watch, the application reads the exact seller account and listing selected by that seller. It retains the seller account identifier, listing ID, product key and title, price, available quantity, cumulative quantity sold, listing status and observation time. It uses these facts only for read-only stock and sales-velocity review. This feature does not retain buyer, order, message, address or tracking data. The connection does not send replies, change listings or perform selling actions.

A buyer-message service is being prepared for separately authorised sellers. If enabled for a seller, it will use necessary buyer and order information, message text, conversation references, timestamps and any tracking email provided to handle that seller's customer correspondence. Alongside reviewed draft replies, a seller may separately authorise routine automatic follow-ups for its account: requesting an optional email address solely for carrier tracking updates after an eligible purchase; acknowledging receipt of that address; and, for a verified repeat purchase of the same listing within the previous 90 days, where the existing conversation already contains the buyer's email, sending one account-approved repeat-order acknowledgement. A different listing follows the ordinary email-request process. These messages use the seller's order and conversation information and checks intended to prevent duplicate or inappropriate replies. Ambiguous history, conversation or message state is referred for human review. Separately authorised message receipt and a limited routine courtesy pilot are active. AI-generated replies are not sent automatically. We will not use one seller's customer information for another seller's account.

Our role and lawful basis. We determine how to secure and administer this application and reconcile its deletion-notification queue. For these limited purposes, we rely on our legitimate interests in providing the requested service securely, preventing wrong-account access and identifying information needing a deletion review. We limit access and scope. Where we process a seller's customer information solely on that seller's documented instructions, we act for that seller; the seller is responsible for its own applicable lawful basis and customer notice. A different purpose or jointly determined activity requires a separate assessment.

Sharing and location. Authorised application personnel and the relevant seller receive only the information needed to handle an account-specific matter. If the buyer-message pilot begins, a specifically authorised reviewer may see the necessary message content for that seller. An operational alert may go to a restricted business mailbox without buyer text, buyer identifier or order details. Cloudflare hosts the notification endpoints and restricted queues. IONOS provides privacy-email forwarding. eBay supplies notifications and separately authorised seller API data. These providers may process information outside the UK. We use applicable provider data-processing terms and transfer safeguards where required; contact us for details. A European Union database location does not mean every part of the service stays in the UK or EU. A separately authorised seller may enable a supervised AI draft pilot. For that pilot, we send OpenAI only the message text and verified product facts needed to suggest a reply. We remove direct customer and order identifiers where detectable and exclude sensitive or unresolved cases, but this does not guarantee anonymity. A human checks each draft before any separately authorised reply is sent. OpenAI may process this information outside the UK. We keep optional model-training data sharing disabled and request no stored API response. OpenAI may still retain content in abuse-monitoring logs for up to 30 days by default, or longer where legally required or reasonably necessary to protect its services or third parties from harm. AI drafting is not enabled until the seller's instructions and the applicable provider data-processing and transfer arrangements have been checked.

Retention. We do not keep the full Identity API response. Access tokens are used for the active call or session; a refresh token is kept in encrypted storage only while a seller connection remains authorised and needed. Own-listing stock-watch observations are kept for up to 90 days and older observations are removed when a new accepted observation is recorded. Disconnecting the seller account stops new collection. A documented complaint, dispute or legal obligation may require specific information to be kept longer, with a review date. Minimal connection and authorisation evidence is reviewed for removal no later than 12 months after connection end, subject to a documented case-specific need.

Deletion-notification identifiers remain in a restricted queue while reconciliation is unresolved. The queue has no automatic deletion process. An unresolved identifier is needed until we determine whether the application holds matching information and what action is required. A matched record is retained only where a specific documented legal obligation or actual claim or dispute applies, using the minimum necessary fields and a recorded review date. We have not yet established a maximum period for unresolved notifications. We will explain the status of a particular request through the privacy contact above. Any separate privacy-case evidence has a documented review date; no general period is operating for it.

If the buyer-message pilot is activated, routine encrypted message, draft and necessary follow-up content in Backbone's active review queue will be removed 30 days after the review closes, and a minimal keyed event and action audit will be kept for 90 days after closure. Unreviewed messages will be escalated rather than silently removed. A documented complaint, dispute or legal obligation may require specific information to be kept longer, with a review date. Removal from the active queue does not immediately remove a copy from Cloudflare's D1 recovery history. On the present Workers Free plan, its available point-in-time restore window is seven days; a different plan or provider record may have a different period. This policy applies to Backbone's copies, not eBay's records or the independently operated seller's own records. The current Cloudflare Workers Free plan ordinarily keeps Worker diagnostic logs for three days; other provider records may follow different rules. These periods and criteria do not replace separately justified accounting, dispute or legal-hold retention.

In the supervised AI draft pilot, the local drafting session does not save the submitted text or generated draft as a new persistent record. This does not remove the original seller conversation, existing authorised Backbone records or OpenAI's provider records. Saving a draft into a longer-term review queue requires a separately approved retention arrangement.

Your rights and contact. You can contact privacy@imperium.store about information held by this application. We will identify the relevant seller and coordinate a request with that seller where the information concerns its account. You may also contact the seller directly. Depending on the circumstances, you may have rights to access, correct, erase or restrict your information. You may object to processing based on our legitimate interests. We will review requests, including any justified reason to retain information, and explain the outcome. You can complain to the UK Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.

We will update this notice before materially expanding the information or permissions the application uses. Granting or withdrawing an eBay app permission controls future authorised API access but does not by itself decide whether existing information must be erased or retained.