Last Updated: August 19, 2026 · Version: 2026-08-19
Interim attorney-review draft. This Privacy Notice is a working document for qualified legal review. It is not legal advice, has not been approved by an attorney, and is not a guarantee of compliance with any privacy law.
Beams Vault (“we,” “us,” or “our”), operated by Manners & Moonbeams LLC, explains here how we collect, use, disclose, and safeguard information when you use the Beams Vault software and website (the “Service”). This notice does not replace the privacy notices of marketplaces, Auth0, Stripe, Google, or other third parties you use.
Beams Vault is designed around data minimization and third-party specialization. If a trusted provider can securely handle sensitive information without Beams Vault receiving or storing it, Beams Vault uses that provider rather than duplicating the data. This notice describes information Beams Vault actually receives and what it retains. It does not invent extra collection, retention periods, or deletion promises to look more complete. Marketplace APIs may include buyer or customer fields; Beams Vault may receive those fields transiently and does not retain unnecessary buyer or customer personal information. Beams Vault retains the minimum information necessary for inventory, transaction economics, financial reporting, and marketplace references; marketplace-specific customer and order details remain with the marketplace.
We collect information you provide, information created by your use of the Service, and limited identifiers from providers you connect. Based on the current application, that includes:
Account and authentication. Email address; hashed password for local email-and-password accounts; Auth0 user identifier when Auth0 sign-in is used; session tokens stored in cookies; Terms and Privacy acceptance timestamps and document versions; optional marketing opt-in. Auth0 handles authentication; it is not treated as Beams Vault’s customer-data store. Beams Vault stores the email and Auth0 user identifier needed to associate that person with a Beams Vault account. Beams Vault does not store Auth0 passwords and does not copy Auth0 given name, family name, or other unused profile fields. A country code may be recorded from the signup request or a profile field you enter so the application can apply its United States service-territory gate. Profile fields you choose to enter for listing readiness may include first name, last name, business name, phone, country code, street address, city, region, postal code, and optional warehouse or dispatch address.
Billing and subscription. Stripe customer ID, Stripe subscription ID, price ID, subscription status, current period end, cancel-at-period-end flag, trial-used flag, and plan/tier fields. Payment-card information never reaches Beams Vault. We do not collect or store raw credit-card numbers, expiration dates, or CVV codes. Stripe processes payment credentials on Stripe-hosted checkout or portal pages.
Marketplace integrations. OAuth state tokens (short-lived); encrypted marketplace credentials/API tokens; shop domain; provider account identifiers; nicknames; connection status and settings; eBay terms-consent timestamp when you start eBay OAuth; and marketplace shipping-policy or inventory-location identifiers where the integration references those provider resources. Direct OAuth/API connections currently exist for eBay, Shopify, and Etsy. Other marketplaces may receive inventory data you export or publish (for example CSV/XLSX) without storing that marketplace’s login password in Beams Vault.
Connected marketplace order, receipt, uninstall, and privacy webhooks or APIs may include buyer or customer personal information (for example a Shopify customer object, an Etsy receipt buyer_email, or an eBay buyer username). Beams Vault may receive those fields while processing the event because the marketplace APIs include them. It does not retain unnecessary buyer or customer personal information. From those payloads Beams Vault keeps seller transaction economics, inventory facts, and marketplace references: SKU, quantity, proceeds, fees where reported, dates, order and line identifiers, refund or cancellation state, marketplace policy or location identifiers, and, when Etsy reports a shipment, carrier and tracking identifiers. It does not retain marketplace buyer or customer names, emails, shipping addresses, or customer identifiers. You may optionally enter a buyer label on a sale for your own bookkeeping. Older sales records or stored finance-evidence JSON may still contain leftover marketplace buyer labels or usernames from before this practice; those leftovers are cleared on account closure, when a later finance sync overwrites stored transaction evidence, and when a provider sends a matching redaction or shop-redact notice.
Shipping. Seller ship-from or warehouse address on the Profile page is collected because listing preparation currently uses it (for example creating an eBay inventory location). Where a marketplace already maintains shipping policies or locations, Beams Vault stores and references those policy or location identifiers rather than copying the marketplace’s underlying customer addresses. Order payloads may include buyer shipping addresses; Beams Vault does not retain those addresses.
Inventory and business data. Item names, SKUs, categories, condition, quantities, locations, purchase costs, retail values, notes, listing descriptions, shipping weights and dimensions, package presets, image URLs and uploaded images, variants, barcodes, purchase lots, and sales records (quantities, proceeds, marketplace, order numbers, and optional buyer labels you enter). These are seller business records needed to operate the Service. They are not a marketplace-customer database.
AI usage (when enabled). Spreadsheet column headers and short sample cell values sent to Google Gemini for import column mapping. Inventory titles and descriptions are not currently sent to an LLM for listing-copy generation.
Support, security, and operations. Feedback messages and category; optional SMTP copies of feedback; support one-time access codes and expiry times when an administrator requests assisted access; financial-bundle consent records (including the confirmation sentence and, when captured, client IP); administrative entitlement flags; financial-audit snapshots of sale amounts, dates, SKUs, and optional seller-entered buyer labels; marketplace financial-transaction and payout evidence (amounts, fees, dates, order and payout identifiers, without buyer usernames); Etsy webhook routing fields (event type, shop id, receipt id, resource URL); Stripe webhook event ids and types; and standard technical logs such as IP address used for login/registration rate limiting, browser request metadata, and server logs that record shop, order, or event identifiers and error types rather than marketplace customer payloads. Images may be stored with a configured image repository (Synology/WebDAV or similar) rather than only in the application database. Operational database backups are unfiltered copies of the database as it existed at backup time, including leftover historical buyer labels until those rows are cleared and backups rotate. Beams Vault does not currently filter backups to exclude personal information.
We use this information to create and secure accounts; provide inventory, reporting, and marketplace features you request; authenticate to connected marketplaces and transmit listings or catalog data; process and reconcile subscriptions through Stripe; send service, support, and (if you opt in) optional product messages; generate accountant-facing reports you request; map import columns with AI when enabled; prevent abuse and debug reliability; and keep the seller business records needed to operate the Service.
We do not sell your personal information. We share information only as needed to operate the Service:
The Service does not currently include Google Analytics, Meta Pixel, or similar advertising trackers. We do not currently operate a marketing-cookie or targeted-advertising program in the application.
We use strictly necessary cookies to keep you signed in (session_token / session_id, currently set for up to 30 days) and a short-lived _auth0_state cookie during Auth0 login. These are used to operate the Service, not to sell advertising. Because we currently use only these operational cookies, the application does not display a marketing-cookie consent banner.
We use access controls, hashed password storage (bcrypt for local passwords), and authenticated encryption of marketplace tokens at rest with a dedicated key stored outside the database. No electronic transmission or storage is completely secure, and we do not claim that the Service is 100% secure. Notify us promptly through the feedback page or mike@mannersandmoonbeams.com if you suspect unauthorized access.
If a security incident involving personal information occurs, we will provide notices required by applicable law, including Florida law where it applies.
Beams Vault does not publish a numeric “delete after X days” schedule, and the Service does not currently auto-delete inactive accounts. Retention follows what the product actually stores, not a generic checklist.
Information Beams Vault controls and can delete. Profile and account fields, session tokens, the Auth0 user identifier stored on the Beams Vault record, encrypted marketplace credentials, and optional buyer labels on sales. You may permanently wipe inventory from Settings (this does not close the account). You may disconnect a marketplace connection, which stops Beams Vault’s access and removes stored tokens for that connection without deleting your inventory or your account at the marketplace. You may close your Beams Vault account from Settings; that deletes the personal and account data Beams Vault maintains, cancels an active Stripe subscription when a Stripe subscription identifier exists, and clears optional buyer labels on retained sales ledgers.
Information maintained by a third-party provider. Payment-card data at Stripe; authentication credentials and profile data at Auth0; listings, orders, customers, and accounts at eBay, Shopify, Etsy, Palmstreet, Whatnot, and similar marketplaces; and images held independently by a configured image repository. Closing a Beams Vault account or disconnecting an integration does not delete those provider-held records. Use the provider’s own tools if you want those records deleted.
Information that must legally or operationally be retained. Seller sales-ledger amounts, dates, SKUs, and item snapshots needed as Beams Vault business and accounting records; Stripe customer and subscription identifiers needed to match billing state; and operational database backups until they rotate. We do not retain extra categories of personal information merely to populate a retention schedule.
Provider-initiated deletion, redaction, uninstall, or authorization-revocation events cause Beams Vault to stop using the affected connection and to remove credentials and leftover buyer labels Beams Vault maintains for matching records. Those events do not mean Beams Vault deleted your account at the marketplace.
The following requirements apply without expanding collection:
You may review and update profile information on the Profile page and opt out of optional marketing there. You may disconnect supported marketplace connections in the relevant workspace. You may cancel a paid Stripe subscription as described in the Terms of Service. You may close your Beams Vault account from Settings as described above. Depending on your location, you may have additional rights to access, correct, delete, or obtain a copy of personal information Beams Vault controls, or to appeal a refusal. Submit verified requests to mike@mannersandmoonbeams.com. We will not discriminate against you for exercising privacy rights that apply to you. We cannot delete information we do not hold.
The Service is intended for adults 18 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us and we will delete it.
The Service is currently offered in the United States, and interactive signup and access are limited to that service territory as implemented in the application. Information may be processed where we or our service providers operate. If information is processed outside your location, it may be transferred to the United States.
We may update this Privacy Notice. Material changes will receive a new Last Updated date and version. We may notify you by posting the updated notice, through the Service, or by email. Where the Service records Privacy acknowledgement, we may require renewed acknowledgement.
Privacy questions and data requests: mike@mannersandmoonbeams.com or the in-app feedback page.