Privacy Policy
Last updated: 2026.09.03
This Privacy Policy describes how itemlogs.com ("we", "us"), handles data in connection with registering and hosting an itemlogs inventory through itemlogs.com. It also sets out the basic terms of use in sections 6 and 7 below (license, warranty, and liability), rather than as a separate agreement.
1. What we access
During registration, you generate a Vercel personal access token (at vercel.com/account/tokens) and paste it in. This token is not scoped to a single project — Vercel requires Full-Account or All-Projects access to create a brand-new project in the first place (a token can't be scoped to a project that doesn't exist yet), and Vercel doesn't support narrowing a token's scope down after the fact either. So, technically, this token could reach any project in your Vercel account.
In practice, our code only ever touches the one project created for your itemlogs inventory: creating it, attaching Blob storage and a Supabase database to it, setting its AUTH_SECRET environment variable, and triggering redeploys of it (for example, after a bug fix). We do not read, list, or modify any other project in your account.
2. What we store
We store: your chosen domain, a hashed password, the generated AUTH_SECRET for your deployment, your Vercel team ID (if you registered under a team rather than your personal account), and the access token described above. This is stored in our own database and is not shared with third parties except as needed to operate the service (for example, Vercel and Supabase, which you are independently interacting with to host your inventory).
If you use the contact form on the Contact page, we also store the name, email address, and message you submit there, so we can read and reply to it. These submissions aren't emailed anywhere — they're only readable from a password-protected page we control, and are not shared with third parties.
3. What we don't do
We do not sell your data. We do not access the contents of your itemlogs inventory's own database (items, sales, images, etc.) — that data lives in the Supabase project provisioned for your inventory during registration, separate from itemlogs.com's own database.
4. Your controls
You can revoke access at any time by deleting the access token at vercel.com/account/tokens. Revoking it does not delete your itemlogs inventory — it only removes our ability to push further environment variable updates or trigger redeploys for you.
5. Contact
Questions about this policy can be sent via the contact form on the Contact page, or by emailingshininglogs@gmail.com.
6. License, warranty, and liability
We grant you a limited, non-exclusive, non-transferable license to use itemlogs.com's registration and hosting service solely to set up and operate an itemlogs inventory you registered through it.
The service is provided "as is", without warranty of any kind, express or implied — we do not guarantee uninterrupted or error-free operation. To the maximum extent permitted by law, we are not liable for any indirect, incidental, or consequential damages arising from its use.
We may discontinue the service at our discretion; this does not delete an itemlogs inventory you've already deployed, since it runs on infrastructure (Vercel, Supabase, Blob) under your own account, independent of itemlogs.com.
