Legal

Privacy Policy

This policy explains what information Refit collects, why we collect it, and how it is handled across our platform and marketplace integrations.

Last updated · 31 July 2026

Scope

This policy applies to refitplatform.com and the Refit platform, including any web applications, mobile applications and marketplace integrations operated by Refit. It covers information handled through our current website today, and information handled through the Refit platform.

Introduction

Refit ("Refit", "we", "us") is building listing intelligence software for professional resale businesses. Today, refitplatform.com is primarily an informational website. This policy describes how we handle information collected through that website, and how information is handled across the Refit platform and its marketplace integrations.

Information We Collect — Current Website

  • Contact and partner enquiry submissions, including the message content you send us.
  • Names, email addresses, company names, roles and other business details you provide voluntarily.
  • Basic analytics and technical website data, such as pages viewed, browser type, device information and IP address.

Information Collected Through the Refit Platform

The following categories apply when you create an account or connect a marketplace.

  • Account information: name, work email, company name and role.
  • Product photographs and listing content you upload or generate.
  • Structured product attributes such as brand, category, material, colour, size and condition.
  • Marketplace account identifiers returned when a marketplace is connected.
  • OAuth access and refresh tokens scoped to the permissions granted.
  • Usage and operational data, including feature usage and technical logs.

How We Use Information

Information collected through the website is used to respond to enquiries, operate and secure the site, and understand aggregate usage. Information is used:

  • To provide the platform: extracting structured product data, enhancing photographs and preparing publication-ready listings.
  • To validate listings against the requirements and policies of connected marketplaces.
  • To publish, update or retrieve listings on a user's behalf when authorised to do so.
  • To operate, secure, debug and improve the service.
  • To meet legal, accounting and regulatory obligations.

We do not sell personal information, and we will not use customer listing content to build products for unrelated third parties.

Marketplace Account Connections (OAuth)

When users connect a marketplace account, Refit uses that marketplace's official OAuth authorisation flow. Users authenticate directly with the marketplace — Refit never asks for, receives or stores marketplace passwords.

  • When authorised, Refit receives an access token (and, where applicable, a refresh token) scoped to the permissions approved.
  • Tokens are encrypted at rest and used only to perform actions the user has requested, such as validating, publishing or updating listings.
  • Refit requests the minimum scopes required for the features in use.
  • Access is revocable at any time from within Refit or from the marketplace account settings, where supported. Revocation stops further marketplace requests.

Cookies and Analytics

Our website uses strictly necessary cookies and privacy-conscious analytics to understand aggregate usage. Strictly necessary cookies are also used to keep users signed in and to maintain session security. Analytics data is used in aggregate and is not sold. You can control or block non-essential cookies through your browser settings.

Third-Party Services

Refit relies on a small number of vetted service providers, including cloud hosting and database infrastructure, image processing and machine learning services, transactional email delivery, and product analytics. These providers process data only on our instructions and under contractual confidentiality and security obligations. Connected marketplaces will be independent controllers of the data they receive; their own privacy policies apply to activity on their platforms.

Data Storage and Security

Data is stored on reputable cloud infrastructure. Traffic to and from Refit is encrypted in transit using HTTPS/TLS, and sensitive stored data — including OAuth tokens — is encrypted at rest. Internal access to production data is restricted to the personnel who need it to operate and support the service. We retain information for as long as it is needed for the purpose it was collected, and thereafter only where required for legal or legitimate business purposes. No system can be guaranteed to be completely secure, but we work continuously to protect the data entrusted to us.

User Rights

  • Access a copy of the personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of your information and your account and associated data, subject to legal retention requirements.
  • Export your listing and product data.
  • Withdraw marketplace authorisations at any time.
  • Object to or restrict certain processing, and lodge a complaint with your local data protection authority.

To exercise any of these rights, contact us using the details below.

Contact Information

Questions about this policy or how we handle data can be sent to privacy@refitplatform.com. Refit is built in Perth, Australia.

Last Updated

This Privacy Policy was last updated on 31 July 2026.