← Resell Pro MCP

MCP Privacy Notice

Draft for publication · Last updated 11 September 2026

Scope and controller

This notice covers a Resell Pro account used to connect the Resell Pro Model Context Protocol (MCP) research service. It does not replace the separate browser extension privacy policy.

The controller identified for this service is Souk Group Inc. Its business contact address is 169 Madison Ave, New York, NY 10016-5101, United States. You can also contact us at hello@resellpro.com.

Information we process

  • Account and sign-in information: your email address, name when available, email-verification status, account identifier, and sign-in or session information needed to run a Resell Pro account. The current sign-in flow uses Google OAuth when you choose to continue with Google.
  • Connection information: the MCP client id and name, approved scopes, connection creation, use and revocation times, and a hashed refresh token with its expiry. A dynamically registered confidential client can also have its redirect URIs and a hashed client secret stored.
  • MCP request telemetry: the connected account pseudonym, MCP client id, requested tool names, response status, and validated bounded tool arguments. Those arguments can include a brand query or keywords, country, period, and sort choice. Invalid arguments are recorded as invalid without the rejected argument values.
  • Website and technical information: standard request, device and security information, plus product-usage analytics where configured. Website analytics can include pseudonymous identifiers, page or interaction information, and account sign-in attribution.

The MCP service does not receive the text of your full conversation from a connected assistant. Text that is placed in an accepted MCP tool argument, such as a keyword query, is processed and logged as described above. The service returns Resell Pro market analytics and bounded lists of observed-sold items, including titles, prices, observation dates, and available photos and links. It does not request Vinted credentials, private Vinted messages, or payment details.

How we use it

We use this information to create and secure your account, show the OAuth approval screen, issue and revoke MCP access, provide bounded market-research responses, prevent abuse, diagnose reliability issues, and understand how the MCP service is used.

Recipients

Our code routes the information above through the following service providers or recipients for the stated purposes:

  • Cloudflare: serves the web application and MCP endpoint, including request handling and security controls.
  • Convex: stores account and MCP OAuth records used to operate the connection.
  • Google: handles authentication when you choose Google sign-in.
  • PostHog: receives the product-usage events and MCP telemetry described above when analytics is configured.
  • Resend: may receive your email address and name for account or email communications when that integration is enabled.
  • Your selected MCP client: receives the OAuth claims you authorize and the tool responses it requests. If an email scope is granted, the UserInfo endpoint can return your email address, verification status, and name when available.

Your controls

You choose whether to approve or decline an MCP connection. After approval, sign in to Resell Pro and open Settings to see connected apps and revoke one. Revocation stops refresh-token use immediately; an already-issued access token can remain usable for up to one hour. A client can also use the OAuth revocation endpoint when it supports it.

Revoking a connection is an access control, not a deletion request. For account or privacy questions, contact hello@resellpro.com.

Token expiry is not data retention

The implementation gives authorization codes a 60-second expiry, access tokens a one-hour expiry, and rotating refresh tokens a 30-day expiry. These are authentication lifetimes. They do not specify how long account records, OAuth connection records, analytics events, server logs, backups, or provider records are retained.

This draft does not state retention or deletion periods for those records. The final notice will state them before it takes effect.

Questions

Contact hello@resellpro.com and include “MCP privacy” in the subject line.