SalesImporterby HMN Supplies LLC

Privacy Policy

Last updated September 2026

Who operates SalesImporter

SalesImporter is operated by HMN Supplies LLC. HMN Supplies LLC is the party responsible for the data described in this policy, and is who you are granting access to when you connect a marketplace account. You can reach us at info@salesimporter.com.

What SalesImporter does

SalesImporter is an accounting tool for ecommerce sellers. When you connect a marketplace (currently eBay, with Amazon planned), you authorize us — through that marketplace's own official login and consent screen, never a password you type into our app — to read your order, fee, and payout data so we can post it into a real double-entry ledger on your behalf.

What we collect and store

  • Account information you provide directly: name, email, company/business details.
  • Marketplace order, fee, refund, payout, and dispute records, as reported by the marketplace's own API — nothing we generate or infer beyond it.
  • Bank and credit card data, if you connect an account: transactions, balances, and the account name, mask and institution, retrieved through Plaid. We never see or store your bank login — Plaid handles that, and we receive only a token that lets us read the account you approved.
  • Files you upload: bank statements (OFX, QFX, CSV), QuickBooks Desktop exports, and receipts or documents you attach to a transaction. Attachments are stored as objects in Cloudflare R2 under keys we generate; statement and QuickBooks files are read for the transactions inside them.
  • Everything you record yourself — customers, vendors, items, invoices, bills, journal entries and the ledger those produce. This is the substance of your books.
  • Feedback you send us from inside the app: your message, plus the page you were on, your plan, your account status, when your data last synced, and your browser's user-agent string. The context is collected so a report like “this number looks wrong” can actually be investigated. It is sent to us by email as well as stored. Your transactions and figures are not attached — only what you type and that context.
  • Billing details: your Stripe customer and subscription identifiers, and what plan you are on. We never see or store your card number — payment details are entered on Stripe's own pages and held by Stripe.
  • If you join the launch list from our home page, the email address you gave us — held for that purpose until you unsubscribe.
  • The OAuth access credential (refresh token) each marketplace or bank issues once you approve the connection. This is encrypted at rest (AES-256-GCM) and is never displayed back to you or any other user after it's stored.

Who else processes your data

We use these providers to run the service. Each receives only what it needs for its part, and each is bound by its own confidentiality and security obligations.

  • VercelHosting, and the web analytics described below.
  • NeonThe database your books are stored in.
  • Cloudflare R2Storage for receipts and documents you attach to transactions.
  • PlaidBank and credit card connections. Plaid handles your bank login; we never receive it.
  • StripeSubscription payments. Stripe holds your card details; we do not.
  • ResendSending email: password resets, address verification, team invites, and notifications.
  • SentryError monitoring. When something breaks, it receives the error, the page it happened on, and technical details about the browser or server. We do not send it your books, and we do not use it to track what you do — though an error message can occasionally contain a fragment of the data that caused it.
  • MailerLiteThe launch notification list, if you joined it. It holds that email address and nothing else.
  • GoogleOnly if you choose to sign in with Google, in which case Google confirms your identity to us and we receive your name, email address and profile picture.

Cookies

We set one cookie that matters: the session cookie that keeps you signed in. It is necessary for the app to work at all — without it every page would ask you to log in again — and it is not used to track you anywhere else. We do not use advertising cookies, and nothing on this site follows you to another one.

How long we keep it

While your account exists, we keep your books — that is the point of them. If your subscription ends, your records are kept and remain readable and exportable for at least three years, because an accounting ledger is tax data and you may still be required to produce it.

You can delete data yourself from inside the app, and disconnecting a marketplace removes its stored credential and the transactions synced through it. You can ask us to delete your account and everything in it at any time by writing to info@salesimporter.com. Backups are overwritten on their own cycle, so a copy may persist there briefly after deletion.

Analytics

We use Vercel Web Analytics to count page views and see which pages people arrive on and where they came from. We use it to learn which of our help articles are worth writing more of — not to build a profile of you.

It sets no cookies and does not follow you across other websites. What it records is the page visited, the referring site, and coarse technical details such as country, device type and browser. It is not used on your books: nothing inside your account — no customer, transaction, or figure — is sent to it.

What we don't do

We don't sell your data. We don't share it with anyone beyond the marketplace and bank APIs we use to fetch it on your behalf, and the providers listed above that are required to run the service. We don't use your books to advertise to you, we don't train anything on them, and we don't look at one customer's figures to inform another's.

Revoking access

You can disconnect a marketplace at any time from the Import page inside SalesImporter, which deletes the stored credential and every transaction synced through it. You can also revoke SalesImporter's access directly from the marketplace's own account settings (for eBay: Account > Third Party Access) — that immediately invalidates the credential even if you don't disconnect it here first.

Disconnecting a bank works slightly differently. From the Banking page it deletes the stored credential and tells Plaid to revoke it, and you can also revoke access from your bank's own settings or through Plaid. Transactions already brought in and recorded in your ledger stay — they are part of your books by then, and removing them would change figures you may already have filed on. Delete those yourself if you want them gone, or ask us.

Contact

Questions about this policy, a request to access or delete your data, or anything else about how HMN Supplies LLC handles it, can be sent to info@salesimporter.com. If your company has several users, your own account administrator can also help with access to the books themselves.