Last updated
Privacy Policy
RareSync, LLC
Last updated: September 1, 2026
RareSync, LLC ("RareSync", "we", "us") identifies your inventory from a photo, like a barcode, without printing and sticking labels. RareSync writes listings and crosslists to where you sell. This policy explains what personal information we collect, why we collect it, who we share it with, and what you can do about it.
If you have questions, email our Privacy Contact at privacy@raresync.com.
1. Who we are, and what this covers
RareSync, LLC is a New Mexico limited liability company based in Albuquerque, New Mexico. Our postal address is in section 13.
Our service is a business tool. RareSync identifies your inventory from a photo, like a barcode, without printing and sticking labels. Photograph a unique item. RareSync finds it in your catalog, or writes the listing if it is not there yet. You check the draft, then crosslist it to where you sell. Which brown basket is this? Point the camera at it. The listing comes right up. New stock gets a name and a write-up from the same photo. You read it over before it goes out. If it looks like something you already have, RareSync says so. RareSync ID identifies the item from your photos. We write the product name, description, category, tags, and SKU, and may look for matching items online. Our customers are resellers: people who sell one-of-a-kind goods and list them across more than one channel. We currently serve the United States only.
This policy covers the personal information of the people who use RareSync: account holders, workspace members, people who visit our website or Help Center, people who join our waitlist, and people who contact us.
Two different roles. Some of what sits in your account is your business's own records, for example your product catalog and your inventory data. For that material we act on your instructions: we process it to run the service for you, and we do not use it for our own purposes, except the one narrow exception in section 5 (training our own cataloging models), which you can turn off. For information about the people who use RareSync (your name, your email, how you use the app, your billing), we decide how it is handled, and this policy describes that.
What RareSync is not. There is no marketplace, no public profiles, no user-to-user messaging, and no public content. Nothing you put into RareSync is published by us.
2. What we collect
Account data
| Data | Notes |
|---|---|
| Name, email address | Provided when you sign up |
| Password | Stored as a hash, never in readable form |
| Profile or avatar image | Optional |
| Google account ID, email, name, avatar | Only if you choose "Sign in with Google" |
| IP address and user agent | Recorded by our authentication provider in its authentication audit log and session records |
| Preferences and notification settings | Your settings inside the app |
| Onboarding status, role assignments | Where you are in setup, and your permissions in a workspace |
| Terms acceptance records | Which version you accepted, when, and the IP address and user agent at the moment you accepted |
| Model-training choice | Your section 5 setting, and when you last changed it |
Business and workspace data
Workspace name and description, who is a member, and workspace settings: country, currency, timezone, and language.
Catalog data
Product names, descriptions (free text you or our AI write), SKUs, prices, categories, tags, variant barcodes, inventory counts, and images.
Integration data
If you connect Square or Shopify: OAuth access and refresh tokens, your merchant ID, your shop domain, and sync logs.
We ask for catalog, inventory, and order access so a sale on one channel can take the item down on the others. The permissions we request are:
- Shopify: read_products, write_products, read_inventory, write_inventory, read_publications, write_publications, read_orders
- Square: ITEMS_READ, ITEMS_WRITE, INVENTORY_READ, INVENTORY_WRITE, MERCHANT_PROFILE_READ, ORDERS_READ
We store the vendor's order id and line identifiers so the same sale is applied once. We do not request any customer or shopper-PII scope.
We do not request or receive your shoppers' or your customers' personal data.
Payment data
Your customer and subscription IDs at our payment processor, your plan, status, trial end date, and billing history: amount, currency, status, transaction and invoice IDs, and the reason a payment failed if one does. We also store your card brand and the last four digits of your card.
Payment happens through our payment processor's hosted checkout. We never receive or store your full card number.
Uploaded content
Product photographs, and mathematical image embeddings (numeric vectors) derived from them.
AI personalization data
When an explicit correction, accepted product type or name, or seller prompt reveals a stable preference, a separate AI check may save one short memory for that user and workspace. We do not save one-off jokes, ordinary typos, or low-confidence guesses. These memories are visible and deletable in Settings, and a used memory is held out of prompts for 14 days before it can be used again.
Usage and technical data
We use a third-party product analytics and error-tracking provider. It records:
- pages viewed and interactions with the app;
- IP address, from which an approximate location is derived;
- device and browser information;
- error reports, including stack traces; and
- a user identifier, together with your name, email address, and plan, so that product usage can be attached to an account.
How analytics starts depends on which site you are on. See section 10.
We also keep an internal event log (who did what in your account, and when) and a notification history (emails we sent, including the recipient address, the subject, and whether it was delivered).
Marketing data
If you join our waitlist or submit a form: your name, email, phone number, and whatever you wrote in the form.
3. How we use it
| Purpose | What this means |
|---|---|
| Provide the service | Create and run your account and workspace, store your catalog, keep you signed in |
| Identify the item and write the listing | Send your product photos to our AI processing providers so they can identify the item and return a name, description, category, tags, and SKU |
| Personalize generated content | Use a small rotating set of the AI memories visible in Settings to apply stable seller preferences |
| Look for matching items online | When you ask us to, we look for matching items online, check public listings and reference pages, and show you the public sources |
| Sync to connected platforms | Push and pull catalog and inventory data to the sales channels you connect, but only if you connect them |
| Bill you | Manage the subscription, trial, invoices, and payment failures through our payment processor |
| Support you | Answer your emails and troubleshoot problems |
| Keep the service secure | Authentication, session management, audit logging, rate limiting, and investigating suspicious activity |
| Communicate with you | Service and account emails, and marketing email if you asked for it |
| Improve the product | Understand which features are used, find bugs, and fix them |
| Train our own cataloging models | We use your product images, your catalog data, and their derived captions and embeddings to train our own image-understanding models. Section 5 says exactly what that covers, and how to turn it off |
We use this material to make RareSync's own cataloging better, and for nothing else. We do not sell it, we do not use it for advertising, and we do not give it to anyone else to train their models. Section 5 explains how to turn it off.
4. Who we share it with
Our service providers
We use a small number of service providers to run RareSync: cloud hosting and storage, a database and authentication provider, a payment processor, an AI processing provider, a web search provider, an email provider, and a product analytics provider. They process data only to provide their service to us, under contract, and none of them is permitted to use it for its own purposes.
We also send catalog and inventory data to the sales channels you connect, and only to the ones you connect. Those platforms are not our service providers; you have your own relationship with each of them, governed by their terms.
AI and your images
Our AI processing providers receive the product photographs you upload, and the accompanying text, so they can return a result to RareSync. They process that material to provide the service to us. RareSync's own use of your images to train RareSync's models is a separate thing, and section 5 describes it.
We do not sell your data
RareSync does not sell personal information.
Advertising platforms
Until you reject, we share the click identifiers from your landing URL, an advertising cookie identifier, and (after you create an account) a hashed email with Meta, Google, and Reddit so we can measure ads and conversions. Advertising tags run until you reject. Accept on the public notice records that analytics and advertising are allowed. Reject writes both denied and turns the tags off. We do not send your product catalog or your customers' personal data to these platforms.
Legal compliance
We may disclose information where we are required to by law, or in response to a lawful request from a government authority, a court, or law enforcement. We may also disclose information where we believe it is necessary to investigate, prevent, or act on suspected fraud or illegal activity, or to protect the safety of any person or the security of our service.
Business transfers
If RareSync is involved in a merger, acquisition, financing, reorganisation, or sale of all or part of its assets, your information may be transferred as part of that transaction. If that happens we will tell you by email and in the product, and the information stays subject to this policy until it is replaced by a new one.
5. Training our AI models on your images (on, and you can turn it off)
We train on your product images and catalog data. We use them to improve RareSync's own cataloging models: better names and descriptions, better duplicate detection, better visual search. That is the only thing we use them for. We do not sell them, we do not use them for advertising, and we do not hand them to anyone else's model. You can turn this off at any time in Settings, and we stop using your material going forward. We record your setting, the date you last changed it, and the policy version it was made under.
What we use, and for what. We use your product images, your catalog data, and the captions and image embeddings derived from them, to train, fine-tune, evaluate, and develop RareSync's own image-understanding models. We use this material for one purpose: to train models that improve product cataloging, the automatic writing of product names and descriptions, duplicate detection, and visual search in RareSync. We do not use it for any other purpose, and we do not use it for advertising.
What is excluded. This covers product images, catalog data, and their derived captions and embeddings only. It does not cover your personal information, your account or billing data, your customers' personal data, or any content that carries personal information.
What turning it off does. You can turn it off at any time from the control in your settings, or by emailing privacy@raresync.com. When you turn it off, we stop using your product images, catalog data, and their derived captions and embeddings for training going forward, and we remove them from training sets we have prepared but not yet used to train a model. We cannot pull material back out of a model that has already been trained, and we will not pretend otherwise: once a model has learned from a set of images, that particular contribution cannot be isolated and removed, so we do not promise to remove it from an existing model or to retrain a model to undo it. That is a limit of how machine-learning models work.
De-identified operational signals are separate from this setting. This control governs your product images and their captions. It does not govern the de-identified operational signals the Service produces as you work, such as whether you merged or dismissed a suggested duplicate and the numeric image embeddings behind that decision. Those signals are aggregated and de-identified: they do not name you, your business, your items, or your customers, and they carry almost no personal information. We use them as your service provider to improve the quality of the Service we provide you, including the accuracy of duplicate detection and cataloging, and that use does not depend on this control being on.
Merchants in the EU, the EEA, and the United Kingdom. If your business is established in the European Union, the European Economic Area, or the United Kingdom, we keep your product images and their captions out of the training corpus whatever this setting says. That is a standing rule, not a temporary hold, and it applies even where you have left the setting on.
6. Where data is processed
Your information is processed in the United States. Our application, our database, our file storage, and every service provider in the categories listed in section 4 process data in the United States. We do not transfer your information outside it.
7. How long we keep it
| Data | Retention |
|---|---|
| Account data, including workspace and catalog data | For as long as your account is open |
| Product images and their derived embeddings | For as long as your account is open; deleted within 30 days of account deletion |
| AI personalization memories | Until you delete each memory in Settings or delete your account |
| Everything in a deleted account | Deleted within 30 days of account deletion |
| Billing records | Up to 7 years, for tax and accounting purposes |
| Logs and analytics | Up to 12 months |
| Marketing contacts (waitlist, forms) | Up to 24 months from last contact |
Deleting your account removes your catalog, your images, and your workspace data from our systems within 30 days. Billing records are kept for the period above because tax law requires it.
If you turn model training off (section 5), we stop using your images for training and remove them from training sets we have not yet used, as described in that section. Images already incorporated into a trained model cannot be pulled back out of that model.
8. Your choices and your rights
You can do all of the following, wherever you live.
| What you want | How to do it |
|---|---|
| See what we hold about you | Most of it is visible in the app. For anything else, email privacy@raresync.com |
| Get a copy of your data | Use Export Data in Account settings. If you cannot sign in, email privacy@raresync.com |
| Correct your information | Edit your name, email, avatar, and preferences in Settings. For anything you cannot edit yourself, email us |
| Review or delete AI memories | Open Settings → Listing AI → AI memory |
| Delete your account and your data | Use Delete account in Account settings. We delete your account and its data within 30 days. If you cannot sign in, email privacy@raresync.com |
| Turn model training off | Use the control in your settings, or email privacy@raresync.com. See section 5 |
| Stop marketing email | Use the unsubscribe link in any marketing email, or change your notification preferences in Settings. You will still receive essential service emails about billing, security, and your account |
| Turn off analytics | See section 10 |
9. Security
Here is what we actually do:
- Encryption in transit. Traffic between you, RareSync, and our providers travels over encrypted connections (HTTPS and TLS).
- Access controls. Accounts are protected by a password (stored as a hash) or by Sign in with Google. What each person can do inside a workspace is governed by role assignments.
- Isolation between workspaces. Our database enforces row-level rules so that one workspace cannot read another workspace's data.
- Restricted internal access. Access to production systems is limited to the people who need it to run and support the service.
- Audit logging. We keep an internal record of the actions taken in an account.
No system is completely secure. If we become aware of a breach affecting your personal information, we will notify you.
10. Cookies and similar technologies
We use a small number of cookies and browser storage entries. Advertising tags from Meta, Google, and Reddit run until you reject.
| Type | What it is | Purpose |
|---|---|---|
| Strictly necessary | Authentication and session cookies (sb-*-auth-token), set by our authentication provider | Keep you signed in on the app. The app does not work without them |
| Strictly necessary | OAuth state cookies | Protect against cross-site request forgery when you connect a sales channel, or sign in with Google |
| Strictly necessary | Billing notice dismissal cookie | Remembers that you dismissed a billing banner, so we do not show it again |
| Strictly necessary | Analytics choice (raresync_analytics_consent) | Remembers whether you accepted or rejected analytics on our website or Help Center, so we do not ask again. Shared across raresync.com, help.raresync.com, and app.raresync.com |
| Strictly necessary | Advertising choice (raresync_ads_consent) | Remembers whether advertising tags are allowed. Accept writes granted. Reject writes denied. Shared across raresync.com, help.raresync.com, and app.raresync.com |
| Functional | Theme and sidebar preferences | Stored locally in your browser. Remembers light or dark mode, and whether the sidebar is collapsed |
| Analytics | Product analytics (ph_*) | Sets an identifier used to measure product usage and to attach error reports to a session. Written on the website or Help Center unless you reject, and by default in the app unless you have already rejected |
| Advertising | Meta Pixel (_fbp, _fbc) | Measures visits and conversions for Meta ads (Facebook and Instagram). Written on the website or Help Center unless you reject |
| Advertising | Google tag (_gcl_aw, _gcl_gb) | Measures visits and conversions for Google ads, including YouTube. Written on the website or Help Center unless you reject |
| Advertising | Reddit Pixel (_rdt_uuid) | Measures visits and conversions for Reddit ads. Written on the website or Help Center unless you reject |
Website and Help Center (raresync.com and help.raresync.com). We collect analytics and run advertising tags until you reject. A notice in the bottom-right of the page tells you this. Accept records that analytics and advertising are allowed. Reject turns both off and we do not write a ph_* cookie or load advertising tags. Until you reject, we send analytics events, we write a ph_* cookie, and we load advertising tags. We store your answers in the raresync_analytics_consent and raresync_ads_consent cookies for one year. You do not need an account to make that choice.
The app (app.raresync.com). Analytics is on by default, and we do not show a consent banner. If you rejected analytics on the website or Help Center, the app honours that rejection and does not capture. We record basic web and product analytics about how you use the app: the pages you view, and the actions and clicks you take. Text is masked before an analytics event leaves your browser, so what you type into a form is not captured, and we do not record your keystrokes. The signed-in app does not load advertising tags. Signup and billing conversions can still be sent from our servers to Meta, Google, and Reddit unless you rejected advertising cookies.
How to turn off analytics and advertising. On the website or Help Center, choose Reject on the notice. That turns analytics off and writes advertising consent denied. In the app, use the control in Settings to turn off analytics. You can also email privacy@raresync.com and we will disable analytics for your account, or block it with your browser's tracking protection or a content blocker. Turning analytics off does not affect anything else in the app. Denied advertising consent leaves every advertising tag and conversion destination off.
You can clear or block cookies in your browser settings, but blocking the strictly necessary cookies will stop you from signing in.
11. Children
RareSync is a business tool. It is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, email privacy@raresync.com and we will delete it.
12. Changes to this policy
We update this policy when the service changes. Before a material change takes effect we will notify you by email and in the product. The "Last updated" date at the top always reflects the current version.
13. Contact
Privacy Contact RareSync, LLC 1209 Mountain Road Pl NE Ste R Albuquerque, NM 87110 United States
- Privacy questions, data requests, and deletion: privacy@raresync.com
- Everything else: support@raresync.com