Free audit

Transparency

How ShopAtlas uses the Etsy API

ShopAtlas is built on Etsy's official Open API v3, under Etsy's API Terms of Use. This page explains exactly what each of the five permissions we request is used for - in the same plain language we'd want as sellers ourselves. One principle governs all of it: a seller's data is used for that seller alone. It is never mined, aggregated into research products, sold, or shared - and the seller can export or delete it at any time.

Legacy Etsy email permission

email_r

Existing Etsy consent grants may still name this permission. ShopAtlas identity now comes from Google or an email sign-in code, and Etsy OAuth is used only to connect your shop. We have asked Etsy to confirm the procedure for removing this unused permission from future consent requests.

What it's never used for: Not used for ShopAtlas sign-in, integrations or marketing, and never sent to an integration destination.

Your shop's profile and stats

shops_r

Reads your shop's profile and stats - so the audit is about your shop, matched exactly, not a lookalike.

What it's never used for: We never read other sellers' private data. Each seller sees only their own shop.

All of your listings, including expired and inactive ones

listings_r

Takes the daily snapshot of all of your listings - titles, descriptions, tags, prices, quantities, states, and photos - including the expired and inactive listings a visitor to your shop page can never see. This is what finds the dead weight and builds your version history.

What it's never used for: Never used to read any shop but your own.

Your order history

transactions_r

Reads your order history so your audit and your timeline are built from real orders, not estimates. We record what your own shop shows you, and never widen it.

What it's never used for: Never used to read another seller's orders. Ship-to name and address, when Etsy includes them on a receipt, stay in your Record, encrypted. Buyer email is a separate Etsy grant we do not have — we do not render or promise it. Integration and public surfaces never receive ship-to.

Apply the edits you approve

listings_w

Updates a listing's title, tags, or description when - and only when - you have reviewed the exact before-and-after diff and clicked confirm. The same permission powers one-click restore: putting a listing back to a previous version you choose.

What it's never used for: Never used autonomously. No scheduled edits, no bulk rewrites, no AI acting alone, no changes of any kind without an explicit per-change confirmation from the seller.

Seller-authorised integrations

A seller may authorise a destination they own or control to ask one narrow question about their own shop: whether an exact Etsy receipt is paid, not cancelled or refunded, and contains a listing the seller configured as eligible. A cache miss reads that one receipt only. It never searches buyers or orders, starts a whole-shop sync, or writes to Etsy.

The answer contains receipt and listing identifiers, quantities, status and timestamps, but no buyer name, username, member ID, email, postal address, payment detail or free text. Credentials are server-side, scoped to one shop, hashed at rest, rate-limited and revocable. The destination owns its end-user sign-in, redemption and entitlement records.

A seller may separately publish a curated feed containing only active listings and public fields they selected. The feed contains no order history, revenue, sales count, buyer data or sales-derived ranking, and its calls to action send shoppers to Etsy for the current price and purchase.

The permission we never request: deleting listings

listings_d

We never ask for delete permission. ShopAtlas cannot delete anything in your shop, ever. Etsy has a separate permission for deleting listings; we deliberately don't request it, so that guarantee is enforced by Etsy, not by our good behaviour.

Why we request write access at all

ShopAtlas's core promise is that any change to a listing is reversible. Without write access, a seller who wants to bring back last month's better-performing title would have to copy each field out of ShopAtlas and paste it into Shop Manager by hand - slow, error-prone, and the moment mistakes happen. With write access, a restore is a single reviewed, confirmed, exactly-as-stored update.

The same applies to improvements. When a seller decides to fix an underperforming listing - a clearer title, more accurate tags, a fuller description - ShopAtlas lets them draft the change, see the precise diff, and apply it in one confirmed step, with the previous version kept. It is functionally the same edit the seller could make in Shop Manager; ShopAtlas adds the record, the measurement, and the undo.

Every write is seller-initiated, previewed, individually confirmed, logged in the seller's own history, and reversible. There is no automation mode, and we do not build one.

Why this is good for the marketplace

Everything ShopAtlas measures points sellers toward the same outcome Etsy's own guidance encourages: accurate titles, honest and complete tags, clear descriptions, and well-maintained listings. When sellers can see which improvements actually helped, they make more of them - and make them confidently instead of fearfully.

Better-kept listings mean buyers find what they're actually searching for, fewer disappointing clicks, and more completed sales. Sellers grow, buyers have a better experience, and the marketplace gets healthier. That is the whole thesis of the product.

The term “Etsy” is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc. Questions about any of the above: hello@shopatlas.app.