Privacy Policy

Last updated: 5 August 2026

This policy explains what information DKH collects, why we collect it, how we protect it, and the choices you have. It covers both the information you give us directly and the information we access on your behalf through the Etsy Open API.

1. Who we are

DKH (“DKH”, “we”, “us”) provides an order management tool for Etsy sellers. For the purposes of the GDPR we act as a data processor for the order and buyer data we handle on behalf of our customers (the sellers), and as a data controller for the account data of the sellers themselves.

Contact: support@dkh.io.vn

2. Information you give us

  • Account details: name, email address, password hash, company name, country.
  • Billing details: plan selection and invoice history (card data is held by our payment processor, never by us).
  • Support content: messages, attachments and ticket history you send us.

3. Information we access through the Etsy API

When you connect a shop, you authorise DKH through Etsy's own OAuth screen. We then access only the data covered by the scopes you approved. For Etsy this means:

  • Shop profile (shops_r) — shop id, shop name, currency and URL, used to label the connection in your dashboard.
  • Listings (listings_r) — title, SKU, price, quantity and image, used to show your catalog and match order lines to products.
  • Receipts / orders (transactions_r) — order id, buyer name, buyer email where provided, shipping address, line items, personalization text, totals and payment state, used to create the order records you manage in DKH.
  • Tracking upload (transactions_w) — we write the tracking number and shipped status back to Etsy when you record a shipment.

Those four scopes are the complete list. We do not request email_r, listings_w or shops_w. We do not read messages between you and your buyers, and we do not access financial or banking information held by Etsy.

We never contact your buyers. DKH sends no email, SMS or other message to Etsy members. Uploading a tracking number is the only action that has any buyer-visible effect, and the resulting notification is sent by Etsy, not by us.

4. How we use the information

  • To provide the service: importing your orders and listings, running your workflow rules, and uploading tracking numbers back to Etsy.
  • To secure the service: authentication, fraud prevention, abuse detection and audit logging.
  • To support you: answering tickets and diagnosing sync problems.
  • To improve the service: aggregated, non-identifying usage statistics.

We do not sell personal data. We do not use buyer data for advertising, profiling or any purpose unrelated to fulfilling the seller's orders. We do not share buyer data with other sellers on the platform.

5. Legal bases (GDPR)

  • Contract — processing needed to deliver the service you signed up for.
  • Legitimate interests — securing the platform and improving reliability.
  • Consent — optional product emails, which you can withdraw at any time.
  • Legal obligation — retaining invoices for tax purposes.

6. Sub-processors and sharing

We share data only with the providers needed to run the service:

  • Cloud hosting and managed database providers (EU and US regions).
  • Payment processor, for subscription billing.
  • Transactional email provider, for emails to you about your own account. Never to your buyers.

Each sub-processor is bound by a data processing agreement. We will notify customers before adding a new sub-processor that handles buyer data.

7. Retention

  • OAuth tokens are deleted immediately when you disconnect a shop or revoke access from your Etsy account.
  • Order and shipment records are kept while your account is active, so you can search your own history.
  • When you delete your account, all shops, orders, shipments and buyer data are permanently erased within 30 days.
  • Audit logs are retained for 12 months; invoices for 7 years where tax law requires it.

8. Your rights and data deletion

You can access, correct, export or delete your data at any time from Dashboard → Settings, or by emailing support@dkh.io.vn. Specifically:

  • Disconnect a shop — stops all syncing and deletes the stored tokens for that shop.
  • Export — download your orders and shipments as CSV.
  • Delete account — erases your account and every record attached to it.

Buyers whose data appears in a seller's DKH account may contact us and we will route the request to the relevant seller (the controller) and assist with fulfilling it. EU and UK residents also have the right to lodge a complaint with their supervisory authority.

9. Security

Data is encrypted in transit (TLS 1.2+) and at rest. OAuth tokens are stored encrypted and are never exposed in the interface or the API. Access to production systems is limited to named engineers with multi-factor authentication. See our Security Policy for the full description.

10. Cookies

We use a single essential cookie to keep you signed in. We do not use advertising or cross-site tracking cookies. Optional analytics are aggregated and cannot identify an individual buyer.

11. Children

DKH is a business tool and is not directed at anyone under 16.

12. Changes

We will post any change on this page and update the date above. Material changes affecting how buyer data is handled will also be emailed to account owners at least 14 days before they take effect.

13. Trademarks

The term “Etsy” is a trademark of Etsy, Inc. This Application uses Etsy’s API, but is not endorsed or certified by Etsy.

Privacy Policy · DKH