Legal

Privacy Policy

Archived version: September 22, 2026

This is an archived version. Read the latest privacy policy.

September 22 update. We have clarified connected-account data, Google data-use limits, and how to disconnect or request deletion. These disclosures do not authorize new uses of existing customer data. Stronger data-use protections apply immediately. Updated terms for existing customers take effect October 6, 2026; they apply immediately to new customers.

Previous version: April 30, 2026

1. Overview

This Privacy Policy explains how One2Many LLC, an Oklahoma limited liability company (“One2Many,” “we,” or “us”), collects, uses, shares, and protects information in connection with ResellMaxx (the “Service”). Capitalized terms not defined here have the meaning given in our Terms of Service.

For Customer Data uploaded into a tenant by a paying customer, we act as a data processor or service provider on behalf of that customer; the customer is the controller. For account-level data (e.g., billing contact, login credentials) and our own marketing site, we act as the controller.

2. Data We Collect

Account & billing. Name, business name, email, authentication information held by our login provider, phone (optional), Stripe customer ID, subscription plan, billing history. Card data is handled by Stripe; we do not receive full card numbers.

Customer Data uploaded by you. Inventory records (including IMEIs, serial numbers, models, conditions, costs, sale prices), buyer and supplier contacts, invoices, ad-account metrics, IMEI-check results, chatbot conversations, and other content you load into your tenant.

Connected accounts. We receive the account identity, authorization tokens and reporting data described below when you choose to connect an account.

Marketplace alerts. For FBM Sniper and similar features, we collect the keywords, radius, and city/region you configure, and the public listing results returned for those queries.

Usage & device data. IP address, browser type, device type, pages and features used, timestamps, error logs, and similar telemetry generated when you use the Service.

Communications. Emails, support tickets, and survey responses you send us.

3. Connected Advertising and Messaging Accounts

Optional connections. Connecting Google or Meta is optional. This policy also covers invited users of our review environment. Google Ads reporting is limited to invited test users while Google OAuth verification is pending. Direct Meta Messenger/Instagram connections are being tested in the review environment and are not generally available in the production app. A feature accesses an account only after you authorize its connection.

Google Ads reporting. We receive your Google email address and stable account identifier; accessible advertising and manager account identifiers, names, currency, time zone and account status; the account you select; and campaign identifiers, names, status and channel type. We import daily spend, impressions, clicks, conversions and conversion value to show reporting for your workspace. We store the refresh token needed to keep that connection working, encrypted before storage, plus connection and sync records. We do not receive your Google password or read your Gmail, Drive files or contacts through this connection.

Meta Ads reporting. We receive your app-scoped Facebook user identifier, display name, accessible ad account details, authorization token, and campaign, ad set and ad details and performance metrics. These include spend, impressions, clicks, reach, frequency, leads, conversions and conversion value where provided by Meta. We use them to display attribution and performance reports for your workspace. Stored advertising tokens are encrypted.

Reporting access. The advertising reporting integrations do not create, edit, pause or delete campaigns or change budgets. Google offers one Ads permission covering reads and writes; our current Google integration uses it only to read reporting. It does not create conversion actions or upload conversions through the Google Ads API. Any future campaign-management feature requires separate notice and your authorization before it acts.

Connected messaging. Where you choose to connect a Facebook Page or Instagram professional account in the review environment, we process account identifiers and names, granted permissions, encrypted Page tokens, participant display names, message content and attachments, message identifiers, delivery state, and webhook records. These support your inbox and replies you enable. Where you connect GoHighLevel in the production app, contacts, messages, attachments, tags and booking information pass between ResellMaxx and your own GoHighLevel account. Messaging is separate from an advertising reporting connection.

4. Google User Data and Limited Use

ResellMaxx’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. The restrictions in this section apply to Google data and information derived from it, and take priority over any broader wording elsewhere in this policy or our terms.

We use Google-connected account data only to provide or improve the reporting and account-connection features you can see in ResellMaxx. We do not sell it, use it to advertise ResellMaxx or other products to you, use it for personalized advertising or retargeting, provide it to data brokers, or use it for credit or lending decisions. We do not use it to train generalized AI or machine-learning models, and the current Google Ads reporting integration does not send it to our AI providers.

We transfer Google data only as permitted by Google’s policy: to deliver or improve the appropriate user-facing features with your consent, for security purposes, to comply with law, or in a merger, acquisition or sale of assets after obtaining your explicit prior consent. Hosting and database providers process it to operate the connection and reports. We do not send Google Ads reporting data to Meta or other advertising platforms.

Human access to Google data is limited to the exceptions permitted by Google’s policy: your affirmative agreement to inspect specific data for support; a security need such as investigating a bug or abuse; a legal requirement; or aggregated data used for permitted internal operations. General administrator access does not authorize staff to browse your Google data for unrelated purposes. These limits bind our personnel, contractors and successors.

5. AI Processing

When you enable the assistant, Anthropic processes conversation content, relevant shop instructions and profile information, conversation summaries, tool results and customer images needed to respond. A shop may supply its own Anthropic credential, in which case use is governed by that shop’s agreement with Anthropic. OpenAI processes search phrases for knowledge-base matching. Google Cloud Vision processes images submitted through the staff IMEI scanner. These features are distinct from Google Ads reporting.

We do not sell your messages or use Customer Data to train a model of our own. Provider retention and training practices depend on the applicable provider agreement and account settings; we do not promise that all providers have zero retention. Google Ads data is subject to the stricter restrictions above and is not sent to these AI services by the reporting integration.

6. How We Use Data

  • Provide, operate, secure, and improve the Service.
  • Authenticate users and isolate tenants.
  • Process payments, send invoices, and manage subscriptions.
  • Generate attribution, KPI, and inventory reports requested by the tenant.
  • Detect, investigate, and prevent fraud, abuse, and security incidents (including IMEI-related risk signals).
  • Send transactional, account, and (with appropriate basis) product-update communications.
  • Comply with legal obligations and enforce our Terms of Service.
  • Produce internal counts about Service usage and reliability. We do not publish or sell benchmarks, market reports or indexes derived from Customer Data, or use one workspace’s data to serve or price another workspace.

8. How We Share Data

We do not sell Customer Data or supply it to data brokers. Vercel hosts the application, and Supabase supplies database, authentication and file storage. They process the data needed to run the Service, including connected-account records. Stripe processes billing and payment information. Resend processes transactional email. Sentry receives diagnostic error reports. AI processing is described above; GoHighLevel, Google and Meta receive only the information needed for the features you authorize.

Access by One2Many personnel is limited to operating, securing, supporting and repairing the Service and complying with law. Workspace support sessions record the administrator, workspace, reason and time. Google data remains subject to the narrower human-access limits in the Google User Data section.

We may disclose information when required by law or necessary for security. A successor in a business transfer must honor these data-use restrictions. Google data may be transferred in such a transaction only after the explicit prior consent described above. General sharing provisions do not override Google’s Limited Use requirements.

9. Cookies, Analytics and Conversion Tracking

The ResellMaxx application uses authentication and security cookies. Vercel Web Analytics and Speed Insights measure page use and performance. The advertising reporting connection does not itself install an advertising pixel or track visitors on your behalf.

Shop storefronts are separate from the ResellMaxx application. A shop may configure Google Analytics, Google Tag Manager, Google Ads conversion tags, a Meta pixel or Microsoft Clarity. Those services receive information from their browser tags where enabled. Storefront attribution can store campaign parameters and advertising click identifiers in a first-party cookie for 90 days. Those identifiers can relate to a person and should not be treated as anonymous.

Quote and purchase attribution may include event time, value, currency, page address, advertising click identifiers and hashed contact information. Hashing an email address or phone number does not make it anonymous. Where configured, Meta conversion events are sent from our servers and are separate from read-only reporting. Google conversions can be reported by configured browser tags or exported by a shop for its own upload; the current Google Ads OAuth integration does not upload them. Server-side processing is not necessarily stopped by blocking browser cookies.

The shop is responsible for its storefront privacy disclosures and lawful tracking choices. Consent controls depend on the storefront’s configuration and region; this policy does not promise that every optional tag is consent-gated in every region. You can manage cookies in your browser and contact the shop about tracking on its storefront. We process its customer records on its behalf.

10. Retention, Disconnection and Deletion

We keep Customer Data, including imported advertising reports, while your account is active unless it is deleted. Advertising reports do not currently have an automatic fixed-age deletion schedule. After account closure, retention is limited to restoration, disputes, security and legal obligations; request deletion if you do not want optional retained history kept. We do not promise a fixed number of days that our systems do not enforce.

Disconnecting Google. In an environment where the connection is enabled, use Settings → Integrations → Google Ads → Disconnect. This asks Google to revoke access and deletes our stored credential and discovered-account list. You may also remove ResellMaxx through your Google Account connections. Disconnecting stops further access but retains reports already imported. It does not stop campaigns or advertising charges.

Deleting Google data without closing your workspace. Email one2many@courtmcgee.biz and request deletion of your Google connection and imported Google Ads data. After verifying your authority, we will remove the connection, stored credentials, account list, imported Google campaign and performance records, and associated sync records. Your unrelated inventory, invoices and other workspace records are not part of that request. Any legally required retention will be explained and limited to that purpose.

Meta requests. You can remove ResellMaxx through Facebook’s Apps and websites settings. Use Facebook’s data-deletion request option where available, or email us to request removal of your Meta connection and imported advertising or messaging data. In-product controls may differ between production and the review environment. We verify requests and distinguish platform-sourced data from your independently collected business records; we will explain any records retained and why.

Exports, account deletion and backups. Email the same address for an export or workspace deletion. The product does not provide a complete self-service workspace export or deletion control. Requests are handled after identity and authority checks, within applicable legal timeframes. Billing records may be retained as required by law. Deleted records may remain in provider backups until those backups expire; any restoration must reapply completed deletions. We can explain applicable retention and backup limits when handling your request.

11. Security

We use industry-standard administrative, technical, and physical safeguards, including encryption in transit, hashed credentials, encrypted stored integration tokens, row-level security to enforce tenant isolation, least-privilege access, and audit logging. No system is 100% secure; you are responsible for safeguarding your credentials and the data you upload. We will notify affected customers and, where required, regulators of a confirmed personal-data breach without undue delay.

12. Your Rights

Depending on where you live, you may have rights to: access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent. To exercise these rights, email one2many@courtmcgee.biz. We will verify your request and respond within the timeframe required by applicable law. If you are an end user whose data was uploaded by a tenant, please direct your request to that tenant; we will assist them as the processor.

13. California Residents (CCPA/CPRA)

California residents have the right to know what personal information we collect, to delete it, to correct inaccurate information, and to limit the use of sensitive personal information, subject to exceptions. We do not sell or “share” personal information for cross-context behavioral advertising. You will not be discriminated against for exercising these rights. To submit a request, email one2many@courtmcgee.biz.

14. International Transfers

The Service is operated from the United States. If you access it from outside the U.S., you understand that your data will be transferred to and processed in the U.S. and other countries where our service providers operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses.

15. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

16. Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the latest version. For material changes, we will provide additional notice (e.g., email or in-app banner) before they take effect.

17. Contact

Privacy questions or requests? Contact us at one2many@courtmcgee.biz.

One2Many LLC, Oklahoma, U.S.A.

See also our Terms of Service.