legal

Privacy Policy

Last updated: 4 August 2026

Who we are (data controller)

Wrenlist is operated by WRENLIST LTD, a company registered in England and Wales (company number 17381266), with its registered office at 66 Paul Street, London, England, EC2A 4NA, trading as Wrenlist. WRENLIST LTD is the data controller for personal data processed through the Wrenlist service. From 4 August 2026, WRENLIST LTD is the operator and controller; before that date, Wrenlist was operated by Dominic Cushnan trading as Wrenlist, who was the controller for personal data processed up to that date.

Contact: admin@wrenlist.com

ICO registration: WRENLIST LTD is registered with the UK Information Commissioner's Office as a data controller, registration reference ZC213724.

We process your personal data in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018. For users in the European Economic Area, we apply the same standards under the EU General Data Protection Regulation. For California residents, see the "California privacy rights (CCPA/CPRA)" section below.

What personal data we collect

Account Registration: Name, email address, password (hashed), authentication method (Google Sign-In or email).

Usage Data: Your inventory items, listing details, photos, pricing, platform connections, and sales history.

Photos: Item photos you upload or take with your device camera, including photos taken for a Forage appraisal ("should I buy this?") and photos you attach to a conversation with Wren.

Voice recordings: If you use the microphone button in the Wren assistant, the recording is sent for transcription and the resulting text is kept as part of your conversation. We do not keep the audio itself. The microphone is only ever active while a recording you started is running.

Push notification token: If you allow notifications in the iPhone app, Apple issues a device token which we store so we can send you alerts (for example when something sells). It identifies the installation, not you personally, and is deleted when you sign out or delete your account.

Marketplace Credentials: When you connect marketplace accounts (eBay, Vinted, Etsy, Shopify, Depop, Facebook Marketplace), we store OAuth tokens securely where an OAuth flow exists (eBay, Shopify). For marketplaces without a public OAuth flow (Vinted, Depop, Facebook Marketplace), you sign in to the marketplace yourself — in the Wrenlist browser extension on your computer, or in the Wrenlist iPhone app — and we use only that existing logged-in session, on your own device. We never ask for, see, or store marketplace passwords.

Instagram: If you choose to connect Instagram so Wrenlist can post your items, we store an encrypted access token for your account plus your Instagram username, account ID and account type. See "Instagram posting" below for exactly what we do with it and how to disconnect.

Technical Data: IP address, browser type, device information, access logs (for security purposes only), and diagnostic logs from the browser extension and iPhone app so we can debug a failed publish without needing your device in hand.

Referral Payout Details: If you earn a reward under our referral programme, we collect the payout details you give us at that point — your PayPal email address, or UK bank sort code and account number — solely to pay you. They are used for that payment (lawful basis: contract), kept only as long as needed for payment and accounting records, and never used for marketing or shared beyond our payment provider.

Lawful basis for processing

Under UK GDPR Article 6, we process your personal data for the following lawful bases:

  • Contract: Processing necessary to provide Wrenlist services (inventory storage, listing management, marketplace integrations).
  • Legitimate Interests: Security monitoring, fraud prevention, platform maintenance, service improvements, and creating the anonymised dataset used to improve our AI features (see "AI features and anonymised training data" below).
  • Consent: Marketing communications (you can opt out at any time).

How we use your data

To Provide Services: Store your inventory, manage listings, connect to marketplaces, provide customer support.

For Security: Prevent fraud, detect unauthorised access, maintain account security.

For Improvement: Analyse usage patterns to improve Wrenlist (anonymised data only).

For Communication: Send service updates, account notifications, and (with consent) marketing emails.

Marketplace connections

When you connect marketplace accounts (eBay, Vinted, Etsy, Shopify, Depop, Facebook Marketplace), we store your OAuth access tokens encrypted at rest (AES-256-CBC). Refresh tokens are stored securely. We only access the permissions you explicitly grant during OAuth authorisation. We do not store your marketplace username or password. Instagram is connected the same way but is not a marketplace — it is covered separately under "Instagram posting" below.

Instagram

Wrenlist can post your items to your own Instagram account, show you how those posts did, and help you answer the people who reply to them. All of it is optional, off by default, and nothing happens until you connect an account yourself.

What we store. When you connect, Instagram issues us an access token for your account. We store that token encrypted at rest (AES-256-GCM), along with your Instagram username, account ID and account type. We never see, ask for, or store your Instagram password. The token lasts 60 days; we renew it automatically while your connection is active, and you can end it at any time.

What we do with it. We read your username and account type to confirm the account is able to publish — Instagram permits this only from Business and Creator accounts, so we check at the point you connect rather than failing later. And we publish the posts you create in Wrenlist, only when you press Post now or when a post you scheduled falls due. We never post without an action you took, and never post to any account other than the one you connected.

How your posts performed. If Instagram grants us access to it, we collect the figures Instagram reports for your own posts — how many people saw one, and how many liked, saved or shared it — so you can tell which items are worth promoting. These are counts about a post, not information about the people who saw it. We never collect figures for anyone else's posts.

Comments, if you switch them on. You can ask Wrenlist to help with the comments people leave on your own posts. When you do, we store the comment, the commenter's Instagram username and when it was left, so we can spot the ones asking whether an item is still available and answer from your real stock. Replying is off until you turn it on, and you choose between Wrenlist drafting a reply for you to send, or answering that one question automatically. We only ever read comments on your own posts — never anyone else's.

Direct messages, if you connect them. You can ask Wrenlist to help with the messages people send your account. When you do, we store those messages, the sender's Instagram username and when they were sent, so we can draft a reply for you. We never send a message on our own — every message goes out because you pressed send.

Other people's information, and your part in it. Comments and messages are written by other people, so switching these on means we hold a little of their personal data on your behalf: what they wrote, their Instagram username, and when. We use it for nothing except showing it to you and drafting your reply — never to build a profile, never for advertising, never for training AI models, and never shared with anyone else. It is deleted when you disconnect Instagram, when you delete your Wrenlist account, or if Instagram asks us to erase it.

What we never do. We never read your feed, your followers, or anyone else's posts, comments or messages. We never message anyone who has not messaged you first — Instagram does not permit it and neither do we.

Photos, and one thing worth knowing. Instagram publishes a post by fetching the images from a web address rather than receiving them from us. So when you post an item, we place a copy of that item's photos — converted to the format Instagram requires — at a randomised address in our storage that is reachable by anyone holding the link. The address is an unguessable hash and is never listed or shared, but unlike the rest of your photos it is not behind your login, because Instagram's servers have to be able to read it. The copy is removed when you delete the post or your account. This applies only to photos in posts you choose to publish; every other photo in your account stays private to you.

What we keep afterwards. A record of each post — its caption, which photos it used, when it went out, and the link to it on Instagram — so you can see your own posting history. It is deleted with your account.

Disconnecting. You can disconnect on the Social page in Wrenlist at any time. We delete the stored token immediately, cancel anything still scheduled, and delete the comments and messages we were holding for you. Posts already published stay on Instagram — they are yours, and you delete them there if you want them gone. You can also revoke our access from Instagram's side under Settings → Apps and websites (instagram.com/accounts/manage_access). Deleting your Wrenlist account removes the token and your posting history.

Wrenlist browser extension

Wrenlist publishes an optional Chrome browser extension — Wrenlist — Marketplace Sync — which acts as the automation layer for marketplaces that do not offer a public OAuth flow. Installing the extension is optional; you can use Wrenlist without it, but publish, update, and delist on Vinted, Depop, Etsy, Shopify and Facebook Marketplace require it.

What the extension reads. Only on marketplace domains you have connected in Wrenlist (*.vinted.*, *.ebay.*, www.etsy.com, admin.shopify.com, *.myshopify.com, *.depop.com, *.facebook.com, upload.facebook.com) and on your own Wrenlist dashboard (*.wrenlist.com). The extension reads the session cookie of marketplaces that require it (Vinted, Depop, Facebook Marketplace) so it can make authenticated requests on your behalf. It never reads, stores, or transmits cookies, messages, profile data, news feed, or any other data outside the marketplace API calls required to publish, update, or delist your own listings.

What the extension sends where. Your listing data goes to the marketplace APIs you are already signed into. Publish/delist job status is reported back to your own Wrenlist dashboard at app.wrenlist.com. No listing or session data is sent to any third party.

What the extension stores locally. Your Wrenlist bearer token (so it can talk to your Wrenlist dashboard), your extension preferences, and a short-lived diagnostic log for troubleshooting. No marketplace credentials are stored.

Remote code. The extension does not fetch or execute any remote JavaScript. All logic ships inside the published bundle on the Chrome Web Store.

Data we do not do. We do not sell, rent, or share any data the extension reads with third parties. We do not use the extension for advertising, profiling, or creditworthiness decisions. We do not use it to collect data unrelated to publishing and delisting your own listings.

Wrenlist for iPhone

Wrenlist publishes an optional iPhone app. It does the same job as the browser extension — publishing to marketplaces that have no public OAuth flow — plus the point-of-purchase AI features (Forage) and the Wren assistant. Using it is optional; your account works the same either way.

How marketplace sign-in works. Inside the app's Connect tab, each marketplace is its own web view showing that marketplace's real website. You sign in there, directly with them, exactly as you would in Safari. Wrenlist never sees the login form's contents and never stores a marketplace password. When you publish an item, the request is made from that signed-in session on your own phone — which is why your listings look like you posted them, because you did.

Camera. Used to photograph items and to scan barcodes and ISBNs. Only when you open the camera yourself.

Microphone. Used only for the push-to-talk button in the Wren assistant. It records while a recording you started is running, transcribes it, and puts the text in the message box for you to read and edit before sending. It is never active in the background, and we do not keep the audio.

Notifications. If you allow them, Apple issues a device token we store to send alerts — when an item sells, or when something needs your attention. You can turn each type off in the app's settings, or all of them in iOS Settings.

No tracking, and no third-party SDKs. The app contains no analytics, advertising or attribution software of any kind — it is entirely our own code talking to our own servers. We do not use the advertising identifier (IDFA) and do not track you across other companies' apps or websites, which is why the app never shows an App Tracking Transparency prompt.

Remote code. As with the extension, the app fetches and executes no remote code. Everything it runs ships inside the reviewed build on the App Store.

Deleting your account. You can delete your Wrenlist account from within the app (Settings → Delete my account). It is the same permanent deletion described under "Data retention" below. Note that it removes your Wrenlist account — your listings on Vinted, eBay and elsewhere stay live and must be taken down on those marketplaces.

Data storage and security

Storage: Your data is stored in Supabase (PostgreSQL database hosted on AWS) with row-level security (RLS) enabled. All data is stored in EU data centres, ensuring compliance with UK GDPR.

Encryption: All connections use HTTPS/TLS encryption in transit. Sensitive fields (OAuth tokens, payment information) are encrypted at rest.

Access Control: Only you can access your data. Database queries are filtered by your user ID (auth.uid()).

Data retention

While Your Account is Active: Your data is retained as long as your Wrenlist account is active.

After Deletion: If you delete your account, all personal data (name, email, photos, descriptions, marketplace tokens) is permanently deleted immediately. Backup copies are securely destroyed within 90 days.

Anonymised Data Retention: When you delete your account, we retain a fully anonymised record of your product and sales data (category, brand, condition, pricing, sell-through timing) for service improvement and aggregate analytics. This data contains no user identifiers, photos, descriptions, or any information that could identify you. Under UK GDPR Recital 26, anonymised data is not personal data and is exempt from data subject rights. If you object to this retention, contact admin@wrenlist.com before deleting your account.

Legal Obligations: If required by law (e.g., tax or fraud investigations), we may retain data longer to comply with UK legal requirements.

AI features and anonymised training data

Wrenlist's AI features (photo identification, pricing suggestions, category matching) are improved using data from how the service is actually used. Two distinct kinds of data are involved, and they are handled differently.

1. Anonymised sales records. When an item sells, a nightly process copies a stripped-down record into a separate, anonymised dataset. That record contains: category, brand, condition, size, colour, cost, asking price, sold price, sourcing and sale dates, days-to-sell, and which marketplace it sold on. It contains no user ID, no item ID, no photos, no descriptions, no SKUs, and no notes. Duplicate prevention uses a one-way salted hash, which cannot be reversed to identify you or your item. These records cannot be linked back to your account.

2. AI interaction logs. When you use an AI feature, we keep a per-account record of the inputs (the item photo and title you submitted, the asking price on a Forage appraisal, the text of your conversation with Wren, or the transcript of a voice message) and the outcome (whether you accepted, rejected, or corrected the suggestion). We use these logs to audit accuracy and improve the AI's prompts and examples. Unlike the anonymised sales records, these logs are personal data: they are keyed to your account, only visible to you and Wrenlist, and are permanently deleted when you delete your account.

Photos submitted to AI features are kept, on purpose. We want to be straight about this: photos you send to photo identification, Forage or the Wren assistant are not deleted after a set period. They are kept for as long as your account exists, because they are the dataset we measure the AI against — an appraisal we cannot re-run is an appraisal we cannot learn from. They remain private to your account, are never published, and go when your account goes. If you would rather a particular photo did not stay, delete the find or the conversation it belongs to, or email us.

Lawful basis. The act of creating anonymised records from your data is processing of personal data; we rely on legitimate interests (UK GDPR / EU GDPR Article 6(1)(f)) — improving the AI features all users rely on, using the minimum data needed, with identifiers removed at the earliest step. We have completed a legitimate interest assessment for this processing, available on request from admin@wrenlist.com. Once data is anonymised, it is no longer personal data under UK GDPR Recital 26. If we ever wanted to use identifiable content for AI training — we do not today — we would ask for your consent first.

Retention. Anonymised sales records are retained indefinitely — they are the dataset the AI features are built on. AI interaction logs are retained while your account is active and deleted with it.

What deletion does and does not undo. Deleting your account permanently removes all personal data: your photos, descriptions, listings, marketplace tokens, and AI interaction logs. Two things are not undone, and we want to be transparent about both: (1) sales records that were already anonymised before deletion remain in the anonymised dataset — they contain nothing that identifies you and cannot be traced back to you; (2) AI models already trained or tuned using anonymised data cannot selectively "unlearn" an individual contribution. Neither contains your personal data.

No sale of personal data. We never sell personal data. We may publish or commercialise aggregate, anonymised market statistics (for example, average sold prices by category). These contain no personal data.

Your choice. If you object to your data being included in future anonymisation snapshots or training runs, email admin@wrenlist.com and we will exclude your account going forward.

California privacy rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you rights to know, delete, correct, and port the personal information we hold about you, and to opt out of the sale or sharing of personal information.

We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes requiring a right to limit.

Deidentified data commitment: where we maintain deidentified data (the anonymised sales records described above), we maintain and use it only in deidentified form and commit not to attempt to re-identify it, as the CCPA requires.

To exercise any CCPA right, email admin@wrenlist.com with "California Privacy Request" in the subject line. We will verify your request and respond within 45 days. We will not discriminate against you for exercising these rights.

Cookies and tracking

Essential Cookies Only: We use cookies solely for authentication and session management (e.g., storing your session token).

No Third-Party Analytics: We do not use Google Analytics, Facebook Pixel, or any third-party tracking services. The iPhone app contains no third-party SDKs at all and does not use the advertising identifier (IDFA).

No Marketing Cookies: We do not use cookies to track your behaviour for marketing purposes.

Consent: By using Wrenlist, you consent to essential cookies. You can disable cookies in your browser settings, but this may affect functionality.

Your data rights under UK GDPR

You have the following rights under UK GDPR Articles 15–20:

  • Right of Access (Article 15): Request a copy of your personal data. We will provide this within 30 days.
  • Right to Rectification (Article 16): Correct inaccurate data. You can update account details directly in settings.
  • Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten"). We will delete all data within 30 days.
  • Right to Data Portability (Article 20): Request your data in a portable, standard format (CSV/JSON). We will provide this within 30 days.
  • Right to Restrict Processing (Article 18): Request we limit how we process your data.
  • Right to Object (Article 21): Object to processing for marketing purposes.

Sharing your data

We do not sell your data to third parties. Your data is only shared with:

  • Marketplace Platforms: When you connect marketplace accounts (eBay, Vinted, Etsy, etc.), they receive the inventory and listing data you choose to publish. This is necessary to provide the service.
  • Meta Platforms (Instagram): If you connect Instagram, Meta receives the posts you choose to publish — the caption you approved and the photos in that post — and fetches those photos from the web address described under "Instagram posting". Meta processes this as an independent controller under their own terms and privacy policy, not as our processor.
  • Antique-centre owners (if you are a booth-renting dealer): When you accept an invitation to join an antique centre on Wrenlist, you are agreeing to share a defined slice of your data with that centre's owner. See "Wrenlist Emporium — centre and dealer data sharing" below for the exact list.
  • Service Providers: AWS (hosting), Supabase (database), Vercel (application hosting), Google and Apple (authentication), Apple (push notifications to the iPhone app), Resend (transactional email), Stripe (subscription payments). All have UK GDPR data processing agreements in place.
  • AI providers: OpenAI and Anthropic process the content you send to an AI feature — item photos, listing text, voice recordings, and your conversations with Wren. They act as our processors, are contractually barred from using your content to train their models, and are covered by the transfer safeguards described under "International data transfers" below.
  • Legal Requirement: If required by law, law enforcement, or court order — but not without checking first. See "Requests from the police, courts and other authorities" below.

Wrenlist Emporium — centre and dealer data sharing

Wrenlist Emporium lets a UK antique-centre owner operate a multi-dealer till on Wrenlist. The relationship between centre owner and booth-renting dealer involves a defined slice of personal and trading data flowing both ways. This section explains who sees what, and why.

When you accept an invitation to join a centre as a dealer:

  • The centre owner becomes a joint data controller with Wrenlist for the till and settlement data generated by sales at their centre. Wrenlist processes the data on shared infrastructure; the centre owner uses it to run their business.
  • The lawful basis is contract (the booth-rental agreement between you and the centre) combined with legitimate interests (the centre needs to settle commission, the dealer needs to be paid, both need an auditable record).
  • You can leave at any time by suspending or declining the membership; no new data is shared after that point.

What the centre owner can see:

  • Your email address and display name (so they can invite, contact, and pay you).
  • Your booth-tagged sales rung up at their till: item title, optional cashier-typed description, sale price, payment method, optional photo, time of sale.
  • Your booth stock currently listed at the centre (item title and price only, drawn from finds you have linked to your booth stash).
  • Aggregated settlement totals (gross, commission, rent if any, amount owed) per period.

What the centre owner cannot see:

  • Your wider Wrenlist account: sales on other marketplaces, finds not linked to this centre's booth, your sourcing log, your cost or profit figures, or your bank details.
  • Other centres' data if you rent at more than one venue.
  • The contents of messages or notes you write that aren't explicitly stamped on a sale row.

What you (the dealer) can see about the centre: centre name, address, payout cadence, commission %, and your own per-period settlement breakdown.

Public micro-site: if the centre publishes a public page on /e/[slug], your booth-linked items may appear in the live stock grid with your booth code and first name. You can opt down to booth-code-only or fully anonymous attribution at any time by emailing the centre owner or contacting admin@wrenlist.com.

Retention: sales rows and settlement statements are retained for at least 7 years after the financial year they relate to, to meet HMRC record-keeping requirements for both parties. Deleting your account anonymises personal identifiers on your sales but does not delete the sale row itself, so the centre's books remain auditable.

Disputes between you and the centre (e.g. a sale you don't recognise) are between the two of you in the first instance. Wrenlist surfaces a dispute flag on the relevant settlement and preserves the audit trail; we are not a party to the commercial relationship and do not arbitrate.

Requests from the police, courts and other authorities

Occasionally a public authority — the police, a court, HMRC, a regulator — asks a company for data about someone. It has never happened to Wrenlist. This is what would happen if it did.

We check it is lawful before we do anything. Who is asking, under what specific legal power, and whether they have the authority to compel a UK company at all. A request with no stated legal basis goes back for one. A voluntary request is treated as a request, not an instruction — we say no unless there is an independent lawful reason to say yes.

We challenge what looks wrong. If a request appears unlawful, overbroad or defective, we object in writing, ask for it to be narrowed or properly issued, and take legal advice where the point is arguable. We comply once it is right — not because resisting is inconvenient.

We give the least we can. Only the fields actually asked for, over the narrowest date range, with other people's data excluded. Never a whole-account export because it was easier to produce.

We write down every one. What was asked, by whom, under what power, what we decided and why, and exactly what we handed over — kept for six years, whether or not we disclosed anything.

We tell you. If your data is requested, we will tell you what was asked for and what we gave — unless a legal prohibition stops us, in which case we tell you as soon as it lifts.

Wrenlist is a small company, not a legal department: this is a written procedure one person follows, with a solicitor when it warrants one. It is deliberately modest and it is genuinely followed.

International data transfers

Storage stays in the EU. Your account, inventory, photos and sales history are stored in the EU (Ireland) on AWS servers, via Supabase.

The app itself runs in the UK. The servers that answer Wrenlist's requests — loading your finds, saving an edit, publishing a listing — run in London, next to that Irish database. Both are inside the UK and EU.

AI processing happens in the United States. Our AI features cannot run on stored data alone — when you use one, the relevant content leaves the EU and is sent to our AI providers in the US for processing:

  • OpenAI — item photos and titles (identification, pricing, Forage appraisals) and voice recordings you make in chat (transcription).
  • Anthropic — the text of your conversations with Wren, and item details the assistant needs to answer you.

These transfers rely on the safeguards required by UK GDPR Chapter 5 — the providers' data processing agreements, which incorporate the UK International Data Transfer Addendum and EU Standard Contractual Clauses. Under our API agreements with both providers, your content is not used to train their models.

So the AI features are the transfer — if you would rather nothing of yours left the UK and EU, the practical answer is not to use them (photo identification, pricing suggestions, Forage, and the Wren assistant). Everything else — inventory, listings, crossposting, sales tracking — runs without them and without leaving.

Marketplaces are their own story: when you publish a listing to eBay, Vinted, Etsy, Depop or Facebook, that listing goes to them, wherever they operate, under their own terms. That is the point of publishing it.

Data protection impact assessment

We conduct regular security reviews and data protection assessments to ensure compliance with UK GDPR.

Contact and your rights

To exercise any of your data rights, contact us at admin@wrenlist.com with "Data Request" in the subject line. We will respond within 30 days.

If you are unsatisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): www.ico.org.uk.

Changes to this policy

We may update this privacy policy at any time. Material changes will be notified via email. Continued use of Wrenlist after changes constitute acceptance.

Contact

For privacy questions or data requests, email admin@wrenlist.com.