Last updated

Privacy Policy

RareSync, LLC

Last updated: September 1, 2026

RareSync, LLC ("RareSync", "we", "us") identifies your inventory from a photo, like a barcode, without printing and sticking labels. RareSync writes listings and crosslists to where you sell. This policy explains what personal information we collect, why we collect it, who we share it with, and what you can do about it.

If you have questions, email our Privacy Contact at privacy@raresync.com.


1. Who we are, and what this covers

RareSync, LLC is a New Mexico limited liability company based in Albuquerque, New Mexico. Our postal address is in section 13.

Our service is a business tool. RareSync identifies your inventory from a photo, like a barcode, without printing and sticking labels. Photograph a unique item. RareSync finds it in your catalog, or writes the listing if it is not there yet. You check the draft, then crosslist it to where you sell. Which brown basket is this? Point the camera at it. The listing comes right up. New stock gets a name and a write-up from the same photo. You read it over before it goes out. If it looks like something you already have, RareSync says so. RareSync ID identifies the item from your photos. We write the product name, description, category, tags, and SKU, and may look for matching items online. Our customers are resellers: people who sell one-of-a-kind goods and list them across more than one channel. We currently serve the United States only.

This policy covers the personal information of the people who use RareSync: account holders, workspace members, people who visit our website or Help Center, people who join our waitlist, and people who contact us.

Two different roles. Some of what sits in your account is your business's own records, for example your product catalog and your inventory data. For that material we act on your instructions: we process it to run the service for you, and we do not use it for our own purposes, except the one narrow exception in section 5 (training our own cataloging models), which you can turn off. For information about the people who use RareSync (your name, your email, how you use the app, your billing), we decide how it is handled, and this policy describes that.

What RareSync is not. There is no marketplace, no public profiles, no user-to-user messaging, and no public content. Nothing you put into RareSync is published by us.


2. What we collect

Account data

DataNotes
Name, email addressProvided when you sign up
PasswordStored as a hash, never in readable form
Profile or avatar imageOptional
Google account ID, email, name, avatarOnly if you choose "Sign in with Google"
IP address and user agentRecorded by our authentication provider in its authentication audit log and session records
Preferences and notification settingsYour settings inside the app
Onboarding status, role assignmentsWhere you are in setup, and your permissions in a workspace
Terms acceptance recordsWhich version you accepted, when, and the IP address and user agent at the moment you accepted
Model-training choiceYour section 5 setting, and when you last changed it

Business and workspace data

Workspace name and description, who is a member, and workspace settings: country, currency, timezone, and language.

Catalog data

Product names, descriptions (free text you or our AI write), SKUs, prices, categories, tags, variant barcodes, inventory counts, and images.

Integration data

If you connect Square or Shopify: OAuth access and refresh tokens, your merchant ID, your shop domain, and sync logs.

We ask for catalog, inventory, and order access so a sale on one channel can take the item down on the others. The permissions we request are:

  • Shopify: read_products, write_products, read_inventory, write_inventory, read_publications, write_publications, read_orders
  • Square: ITEMS_READ, ITEMS_WRITE, INVENTORY_READ, INVENTORY_WRITE, MERCHANT_PROFILE_READ, ORDERS_READ

We store the vendor's order id and line identifiers so the same sale is applied once. We do not request any customer or shopper-PII scope.

We do not request or receive your shoppers' or your customers' personal data.

Payment data

Your customer and subscription IDs at our payment processor, your plan, status, trial end date, and billing history: amount, currency, status, transaction and invoice IDs, and the reason a payment failed if one does. We also store your card brand and the last four digits of your card.

Payment happens through our payment processor's hosted checkout. We never receive or store your full card number.

Uploaded content

Product photographs, and mathematical image embeddings (numeric vectors) derived from them.

AI personalization data

When an explicit correction, accepted product type or name, or seller prompt reveals a stable preference, a separate AI check may save one short memory for that user and workspace. We do not save one-off jokes, ordinary typos, or low-confidence guesses. These memories are visible and deletable in Settings, and a used memory is held out of prompts for 14 days before it can be used again.

Usage and technical data

We use a third-party product analytics and error-tracking provider. It records:

  • pages viewed and interactions with the app;
  • IP address, from which an approximate location is derived;
  • device and browser information;
  • error reports, including stack traces; and
  • a user identifier, together with your name, email address, and plan, so that product usage can be attached to an account.

How analytics starts depends on which site you are on. See section 10.

We also keep an internal event log (who did what in your account, and when) and a notification history (emails we sent, including the recipient address, the subject, and whether it was delivered).

Marketing data

If you join our waitlist or submit a form: your name, email, phone number, and whatever you wrote in the form.


3. How we use it

PurposeWhat this means
Provide the serviceCreate and run your account and workspace, store your catalog, keep you signed in
Identify the item and write the listingSend your product photos to our AI processing providers so they can identify the item and return a name, description, category, tags, and SKU
Personalize generated contentUse a small rotating set of the AI memories visible in Settings to apply stable seller preferences
Look for matching items onlineWhen you ask us to, we look for matching items online, check public listings and reference pages, and show you the public sources
Sync to connected platformsPush and pull catalog and inventory data to the sales channels you connect, but only if you connect them
Bill youManage the subscription, trial, invoices, and payment failures through our payment processor
Support youAnswer your emails and troubleshoot problems
Keep the service secureAuthentication, session management, audit logging, rate limiting, and investigating suspicious activity
Communicate with youService and account emails, and marketing email if you asked for it
Improve the productUnderstand which features are used, find bugs, and fix them
Train our own cataloging modelsWe use your product images, your catalog data, and their derived captions and embeddings to train our own image-understanding models. Section 5 says exactly what that covers, and how to turn it off

We use this material to make RareSync's own cataloging better, and for nothing else. We do not sell it, we do not use it for advertising, and we do not give it to anyone else to train their models. Section 5 explains how to turn it off.


4. Who we share it with

Our service providers

We use a small number of service providers to run RareSync: cloud hosting and storage, a database and authentication provider, a payment processor, an AI processing provider, a web search provider, an email provider, and a product analytics provider. They process data only to provide their service to us, under contract, and none of them is permitted to use it for its own purposes.

We also send catalog and inventory data to the sales channels you connect, and only to the ones you connect. Those platforms are not our service providers; you have your own relationship with each of them, governed by their terms.

AI and your images

Our AI processing providers receive the product photographs you upload, and the accompanying text, so they can return a result to RareSync. They process that material to provide the service to us. RareSync's own use of your images to train RareSync's models is a separate thing, and section 5 describes it.

We do not sell your data

RareSync does not sell personal information.

Advertising platforms

Until you reject, we share the click identifiers from your landing URL, an advertising cookie identifier, and (after you create an account) a hashed email with Meta, Google, and Reddit so we can measure ads and conversions. Advertising tags run until you reject. Accept on the public notice records that analytics and advertising are allowed. Reject writes both denied and turns the tags off. We do not send your product catalog or your customers' personal data to these platforms.

Legal compliance

We may disclose information where we are required to by law, or in response to a lawful request from a government authority, a court, or law enforcement. We may also disclose information where we believe it is necessary to investigate, prevent, or act on suspected fraud or illegal activity, or to protect the safety of any person or the security of our service.

Business transfers

If RareSync is involved in a merger, acquisition, financing, reorganisation, or sale of all or part of its assets, your information may be transferred as part of that transaction. If that happens we will tell you by email and in the product, and the information stays subject to this policy until it is replaced by a new one.


5. Training our AI models on your images (on, and you can turn it off)

We train on your product images and catalog data. We use them to improve RareSync's own cataloging models: better names and descriptions, better duplicate detection, better visual search. That is the only thing we use them for. We do not sell them, we do not use them for advertising, and we do not hand them to anyone else's model. You can turn this off at any time in Settings, and we stop using your material going forward. We record your setting, the date you last changed it, and the policy version it was made under.

What we use, and for what. We use your product images, your catalog data, and the captions and image embeddings derived from them, to train, fine-tune, evaluate, and develop RareSync's own image-understanding models. We use this material for one purpose: to train models that improve product cataloging, the automatic writing of product names and descriptions, duplicate detection, and visual search in RareSync. We do not use it for any other purpose, and we do not use it for advertising.

What is excluded. This covers product images, catalog data, and their derived captions and embeddings only. It does not cover your personal information, your account or billing data, your customers' personal data, or any content that carries personal information.

What turning it off does. You can turn it off at any time from the control in your settings, or by emailing privacy@raresync.com. When you turn it off, we stop using your product images, catalog data, and their derived captions and embeddings for training going forward, and we remove them from training sets we have prepared but not yet used to train a model. We cannot pull material back out of a model that has already been trained, and we will not pretend otherwise: once a model has learned from a set of images, that particular contribution cannot be isolated and removed, so we do not promise to remove it from an existing model or to retrain a model to undo it. That is a limit of how machine-learning models work.

De-identified operational signals are separate from this setting. This control governs your product images and their captions. It does not govern the de-identified operational signals the Service produces as you work, such as whether you merged or dismissed a suggested duplicate and the numeric image embeddings behind that decision. Those signals are aggregated and de-identified: they do not name you, your business, your items, or your customers, and they carry almost no personal information. We use them as your service provider to improve the quality of the Service we provide you, including the accuracy of duplicate detection and cataloging, and that use does not depend on this control being on.

Merchants in the EU, the EEA, and the United Kingdom. If your business is established in the European Union, the European Economic Area, or the United Kingdom, we keep your product images and their captions out of the training corpus whatever this setting says. That is a standing rule, not a temporary hold, and it applies even where you have left the setting on.


6. Where data is processed

Your information is processed in the United States. Our application, our database, our file storage, and every service provider in the categories listed in section 4 process data in the United States. We do not transfer your information outside it.


7. How long we keep it

DataRetention
Account data, including workspace and catalog dataFor as long as your account is open
Product images and their derived embeddingsFor as long as your account is open; deleted within 30 days of account deletion
AI personalization memoriesUntil you delete each memory in Settings or delete your account
Everything in a deleted accountDeleted within 30 days of account deletion
Billing recordsUp to 7 years, for tax and accounting purposes
Logs and analyticsUp to 12 months
Marketing contacts (waitlist, forms)Up to 24 months from last contact

Deleting your account removes your catalog, your images, and your workspace data from our systems within 30 days. Billing records are kept for the period above because tax law requires it.

If you turn model training off (section 5), we stop using your images for training and remove them from training sets we have not yet used, as described in that section. Images already incorporated into a trained model cannot be pulled back out of that model.


8. Your choices and your rights

You can do all of the following, wherever you live.

What you wantHow to do it
See what we hold about youMost of it is visible in the app. For anything else, email privacy@raresync.com
Get a copy of your dataUse Export Data in Account settings. If you cannot sign in, email privacy@raresync.com
Correct your informationEdit your name, email, avatar, and preferences in Settings. For anything you cannot edit yourself, email us
Review or delete AI memoriesOpen Settings → Listing AI → AI memory
Delete your account and your dataUse Delete account in Account settings. We delete your account and its data within 30 days. If you cannot sign in, email privacy@raresync.com
Turn model training offUse the control in your settings, or email privacy@raresync.com. See section 5
Stop marketing emailUse the unsubscribe link in any marketing email, or change your notification preferences in Settings. You will still receive essential service emails about billing, security, and your account
Turn off analyticsSee section 10

9. Security

Here is what we actually do:

  • Encryption in transit. Traffic between you, RareSync, and our providers travels over encrypted connections (HTTPS and TLS).
  • Access controls. Accounts are protected by a password (stored as a hash) or by Sign in with Google. What each person can do inside a workspace is governed by role assignments.
  • Isolation between workspaces. Our database enforces row-level rules so that one workspace cannot read another workspace's data.
  • Restricted internal access. Access to production systems is limited to the people who need it to run and support the service.
  • Audit logging. We keep an internal record of the actions taken in an account.

No system is completely secure. If we become aware of a breach affecting your personal information, we will notify you.


10. Cookies and similar technologies

We use a small number of cookies and browser storage entries. Advertising tags from Meta, Google, and Reddit run until you reject.

TypeWhat it isPurpose
Strictly necessaryAuthentication and session cookies (sb-*-auth-token), set by our authentication providerKeep you signed in on the app. The app does not work without them
Strictly necessaryOAuth state cookiesProtect against cross-site request forgery when you connect a sales channel, or sign in with Google
Strictly necessaryBilling notice dismissal cookieRemembers that you dismissed a billing banner, so we do not show it again
Strictly necessaryAnalytics choice (raresync_analytics_consent)Remembers whether you accepted or rejected analytics on our website or Help Center, so we do not ask again. Shared across raresync.com, help.raresync.com, and app.raresync.com
Strictly necessaryAdvertising choice (raresync_ads_consent)Remembers whether advertising tags are allowed. Accept writes granted. Reject writes denied. Shared across raresync.com, help.raresync.com, and app.raresync.com
FunctionalTheme and sidebar preferencesStored locally in your browser. Remembers light or dark mode, and whether the sidebar is collapsed
AnalyticsProduct analytics (ph_*)Sets an identifier used to measure product usage and to attach error reports to a session. Written on the website or Help Center unless you reject, and by default in the app unless you have already rejected
AdvertisingMeta Pixel (_fbp, _fbc)Measures visits and conversions for Meta ads (Facebook and Instagram). Written on the website or Help Center unless you reject
AdvertisingGoogle tag (_gcl_aw, _gcl_gb)Measures visits and conversions for Google ads, including YouTube. Written on the website or Help Center unless you reject
AdvertisingReddit Pixel (_rdt_uuid)Measures visits and conversions for Reddit ads. Written on the website or Help Center unless you reject

Website and Help Center (raresync.com and help.raresync.com). We collect analytics and run advertising tags until you reject. A notice in the bottom-right of the page tells you this. Accept records that analytics and advertising are allowed. Reject turns both off and we do not write a ph_* cookie or load advertising tags. Until you reject, we send analytics events, we write a ph_* cookie, and we load advertising tags. We store your answers in the raresync_analytics_consent and raresync_ads_consent cookies for one year. You do not need an account to make that choice.

The app (app.raresync.com). Analytics is on by default, and we do not show a consent banner. If you rejected analytics on the website or Help Center, the app honours that rejection and does not capture. We record basic web and product analytics about how you use the app: the pages you view, and the actions and clicks you take. Text is masked before an analytics event leaves your browser, so what you type into a form is not captured, and we do not record your keystrokes. The signed-in app does not load advertising tags. Signup and billing conversions can still be sent from our servers to Meta, Google, and Reddit unless you rejected advertising cookies.

How to turn off analytics and advertising. On the website or Help Center, choose Reject on the notice. That turns analytics off and writes advertising consent denied. In the app, use the control in Settings to turn off analytics. You can also email privacy@raresync.com and we will disable analytics for your account, or block it with your browser's tracking protection or a content blocker. Turning analytics off does not affect anything else in the app. Denied advertising consent leaves every advertising tag and conversion destination off.

You can clear or block cookies in your browser settings, but blocking the strictly necessary cookies will stop you from signing in.


11. Children

RareSync is a business tool. It is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, email privacy@raresync.com and we will delete it.


12. Changes to this policy

We update this policy when the service changes. Before a material change takes effect we will notify you by email and in the product. The "Last updated" date at the top always reflects the current version.


13. Contact

Privacy Contact RareSync, LLC 1209 Mountain Road Pl NE Ste R Albuquerque, NM 87110 United States