Legal
Privacy Policy
Archived version: September 22, 2026
This is an archived version. Read the latest privacy policy.
Previous version: April 30, 2026
1. Overview
This Privacy Policy explains how One2Many LLC, an Oklahoma limited liability company (“One2Many,” “we,” or “us”), collects, uses, shares, and protects information in connection with ResellMaxx (the “Service”). Capitalized terms not defined here have the meaning given in our Terms of Service.
For Customer Data uploaded into a tenant by a paying customer, we act as a data processor or service provider on behalf of that customer; the customer is the controller. For account-level data (e.g., billing contact, login credentials) and our own marketing site, we act as the controller.
2. Data We Collect
Account & billing. Name, business name, email, authentication information held by our login provider, phone (optional), Stripe customer ID, subscription plan, billing history. Card data is handled by Stripe; we do not receive full card numbers.
Customer Data uploaded by you. Inventory records (including IMEIs, serial numbers, models, conditions, costs, sale prices), buyer and supplier contacts, invoices, ad-account metrics, IMEI-check results, chatbot conversations, and other content you load into your tenant.
Connected accounts. We receive the account identity, authorization tokens and reporting data described below when you choose to connect an account.
Marketplace alerts. For FBM Sniper and similar features, we collect the keywords, radius, and city/region you configure, and the public listing results returned for those queries.
Usage & device data. IP address, browser type, device type, pages and features used, timestamps, error logs, and similar telemetry generated when you use the Service.
Communications. Emails, support tickets, and survey responses you send us.
3. Connected Advertising and Messaging Accounts
Optional connections. Connecting Google or Meta is optional. This policy also covers invited users of our review environment. Google Ads reporting is limited to invited test users while Google OAuth verification is pending. Direct Meta Messenger/Instagram connections are being tested in the review environment and are not generally available in the production app. A feature accesses an account only after you authorize its connection.
Google Ads reporting. We receive your Google email address and stable account identifier; accessible advertising and manager account identifiers, names, currency, time zone and account status; the account you select; and campaign identifiers, names, status and channel type. We import daily spend, impressions, clicks, conversions and conversion value to show reporting for your workspace. We store the refresh token needed to keep that connection working, encrypted before storage, plus connection and sync records. We do not receive your Google password or read your Gmail, Drive files or contacts through this connection.
Meta Ads reporting. We receive your app-scoped Facebook user identifier, display name, accessible ad account details, authorization token, and campaign, ad set and ad details and performance metrics. These include spend, impressions, clicks, reach, frequency, leads, conversions and conversion value where provided by Meta. We use them to display attribution and performance reports for your workspace. Stored advertising tokens are encrypted.
Reporting access. The advertising reporting integrations do not create, edit, pause or delete campaigns or change budgets. Google offers one Ads permission covering reads and writes; our current Google integration uses it only to read reporting. It does not create conversion actions or upload conversions through the Google Ads API. Any future campaign-management feature requires separate notice and your authorization before it acts.
Connected messaging. Where you choose to connect a Facebook Page or Instagram professional account in the review environment, we process account identifiers and names, granted permissions, encrypted Page tokens, participant display names, message content and attachments, message identifiers, delivery state, and webhook records. These support your inbox and replies you enable. Where you connect GoHighLevel in the production app, contacts, messages, attachments, tags and booking information pass between ResellMaxx and your own GoHighLevel account. Messaging is separate from an advertising reporting connection.
4. Google User Data and Limited Use
ResellMaxx’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. The restrictions in this section apply to Google data and information derived from it, and take priority over any broader wording elsewhere in this policy or our terms.
We use Google-connected account data only to provide or improve the reporting and account-connection features you can see in ResellMaxx. We do not sell it, use it to advertise ResellMaxx or other products to you, use it for personalized advertising or retargeting, provide it to data brokers, or use it for credit or lending decisions. We do not use it to train generalized AI or machine-learning models, and the current Google Ads reporting integration does not send it to our AI providers.
We transfer Google data only as permitted by Google’s policy: to deliver or improve the appropriate user-facing features with your consent, for security purposes, to comply with law, or in a merger, acquisition or sale of assets after obtaining your explicit prior consent. Hosting and database providers process it to operate the connection and reports. We do not send Google Ads reporting data to Meta or other advertising platforms.
Human access to Google data is limited to the exceptions permitted by Google’s policy: your affirmative agreement to inspect specific data for support; a security need such as investigating a bug or abuse; a legal requirement; or aggregated data used for permitted internal operations. General administrator access does not authorize staff to browse your Google data for unrelated purposes. These limits bind our personnel, contractors and successors.
5. AI Processing
When you enable the assistant, Anthropic processes conversation content, relevant shop instructions and profile information, conversation summaries, tool results and customer images needed to respond. A shop may supply its own Anthropic credential, in which case use is governed by that shop’s agreement with Anthropic. OpenAI processes search phrases for knowledge-base matching. Google Cloud Vision processes images submitted through the staff IMEI scanner. These features are distinct from Google Ads reporting.
We do not sell your messages or use Customer Data to train a model of our own. Provider retention and training practices depend on the applicable provider agreement and account settings; we do not promise that all providers have zero retention. Google Ads data is subject to the stricter restrictions above and is not sent to these AI services by the reporting integration.
6. How We Use Data
- Provide, operate, secure, and improve the Service.
- Authenticate users and isolate tenants.
- Process payments, send invoices, and manage subscriptions.
- Generate attribution, KPI, and inventory reports requested by the tenant.
- Detect, investigate, and prevent fraud, abuse, and security incidents (including IMEI-related risk signals).
- Send transactional, account, and (with appropriate basis) product-update communications.
- Comply with legal obligations and enforce our Terms of Service.
- Produce internal counts about Service usage and reliability. We do not publish or sell benchmarks, market reports or indexes derived from Customer Data, or use one workspace’s data to serve or price another workspace.
7. Legal Bases (GDPR)
Where the EU/UK GDPR applies, we rely on: (a) contract, to provide the Service you signed up for; (b) legitimate interests, to secure, improve, and market the Service in a way that is balanced against your rights and the Google data-use restrictions above; (c) legal obligation, for tax, accounting, and compliance; and (d) consent, where required (e.g., for certain marketing communications or non-essential cookies).
10. Retention, Disconnection and Deletion
We keep Customer Data, including imported advertising reports, while your account is active unless it is deleted. Advertising reports do not currently have an automatic fixed-age deletion schedule. After account closure, retention is limited to restoration, disputes, security and legal obligations; request deletion if you do not want optional retained history kept. We do not promise a fixed number of days that our systems do not enforce.
Disconnecting Google. In an environment where the connection is enabled, use Settings → Integrations → Google Ads → Disconnect. This asks Google to revoke access and deletes our stored credential and discovered-account list. You may also remove ResellMaxx through your Google Account connections. Disconnecting stops further access but retains reports already imported. It does not stop campaigns or advertising charges.
Deleting Google data without closing your workspace. Email one2many@courtmcgee.biz and request deletion of your Google connection and imported Google Ads data. After verifying your authority, we will remove the connection, stored credentials, account list, imported Google campaign and performance records, and associated sync records. Your unrelated inventory, invoices and other workspace records are not part of that request. Any legally required retention will be explained and limited to that purpose.
Meta requests. You can remove ResellMaxx through Facebook’s Apps and websites settings. Use Facebook’s data-deletion request option where available, or email us to request removal of your Meta connection and imported advertising or messaging data. In-product controls may differ between production and the review environment. We verify requests and distinguish platform-sourced data from your independently collected business records; we will explain any records retained and why.
Exports, account deletion and backups. Email the same address for an export or workspace deletion. The product does not provide a complete self-service workspace export or deletion control. Requests are handled after identity and authority checks, within applicable legal timeframes. Billing records may be retained as required by law. Deleted records may remain in provider backups until those backups expire; any restoration must reapply completed deletions. We can explain applicable retention and backup limits when handling your request.
11. Security
We use industry-standard administrative, technical, and physical safeguards, including encryption in transit, hashed credentials, encrypted stored integration tokens, row-level security to enforce tenant isolation, least-privilege access, and audit logging. No system is 100% secure; you are responsible for safeguarding your credentials and the data you upload. We will notify affected customers and, where required, regulators of a confirmed personal-data breach without undue delay.
12. Your Rights
Depending on where you live, you may have rights to: access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent. To exercise these rights, email one2many@courtmcgee.biz. We will verify your request and respond within the timeframe required by applicable law. If you are an end user whose data was uploaded by a tenant, please direct your request to that tenant; we will assist them as the processor.
13. California Residents (CCPA/CPRA)
California residents have the right to know what personal information we collect, to delete it, to correct inaccurate information, and to limit the use of sensitive personal information, subject to exceptions. We do not sell or “share” personal information for cross-context behavioral advertising. You will not be discriminated against for exercising these rights. To submit a request, email one2many@courtmcgee.biz.
14. International Transfers
The Service is operated from the United States. If you access it from outside the U.S., you understand that your data will be transferred to and processed in the U.S. and other countries where our service providers operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses.
15. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
16. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the latest version. For material changes, we will provide additional notice (e.g., email or in-app banner) before they take effect.
17. Contact
Privacy questions or requests? Contact us at one2many@courtmcgee.biz.
One2Many LLC, Oklahoma, U.S.A.
See also our Terms of Service.