Privacy Policy
Last updated: 4 May 2026
1. Who We Are
Sorted ("we", "us", "our") is operated by Green Soles, a UK-based business located at Lancing, West Sussex. We provide an AI-powered listing tool for preloved clothing resellers at sortedapp.ai.
Contact us: For data protection enquiries, email alex.greenhalgh@live.co.uk
2. What Data We Collect
We collect and process the following personal data:
- Account information: Email address, username, password (hashed)
- Usage data: Listing count, batch history, subscription tier
- Uploaded content: Photos of clothing items (temporarily stored for processing)
- API credentials: Your OpenAI API key (encrypted at rest)
- Payment information: Processed by Stripe (we do not store card details)
- Technical data: IP address, browser type, device information (via hosting logs)
3. Why We Collect Your Data (Legal Basis)
We process your data under the following legal bases:
- Contract performance: To deliver the Sorted service (AI analysis, CSV generation, billing)
- Legitimate interests: Service improvement, security, fraud prevention
- Legal obligation: Tax compliance, responding to legal requests
- Consent: Marketing emails (you can opt out anytime)
4. How We Use Your Data
- Process your photos with OpenAI GPT-4o Vision to generate listing details
- Generate eBay-ready CSV files
- Email you completed listings and account notifications
- Manage your subscription and billing (via Stripe)
- Display your username on the leaderboard (optional, can be changed)
- Provide customer support
- Improve our AI models and service features
5. Who We Share Your Data With
We share your data with these trusted third-party services:
- OpenAI (USA): Processes your photos for AI analysis
- Stripe (USA/EU): Payment processing and subscription management
- Vercel (USA): Hosting and serverless infrastructure
- Cloudflare (USA/EU): DNS, CDN, and photo storage (R2)
- Turso (EU): Database hosting (EU AWS region)
- Railway (USA): Background job processing
- Resend (USA): Transactional emails
All third parties are GDPR-compliant and have data processing agreements in place. Data transferred to the USA is covered by Standard Contractual Clauses (SCCs).
6. How Long We Keep Your Data
- Photos: Deleted from R2 storage 30 days after upload (unless you delete sooner)
- Listing data: Kept while your account is active, deleted 90 days after account closure
- Account info: Kept while your account is active
- Billing records: Kept for 7 years (UK tax law requirement)
- Logs: Retained for 90 days for security and debugging
7. Your Rights (GDPR)
Under UK/EU data protection law, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Delete your account and all associated data (via Settings → Delete Account)
- Data portability: Export your listings as CSV/JSON
- Restrict processing: Limit how we use your data
- Object: Stop certain types of processing (e.g., marketing)
- Withdraw consent: Unsubscribe from emails anytime
To exercise your rights, email alex.greenhalgh@live.co.uk. We'll respond within 30 days.
8. Data Security
We protect your data with:
- HTTPS encryption for all data in transit
- Encrypted storage for API keys and sensitive data
- Password hashing (bcrypt)
- Access controls and authentication (JWT tokens)
- Regular security audits of third-party services
No security system is 100% secure. If we detect a data breach, we'll notify you within 72 hours as required by GDPR.
9. Cookies
We use minimal cookies:
- Essential: Authentication token (expires after 30 days)
- Analytics: We don't currently use tracking cookies
You can disable cookies in your browser, but this may affect login functionality.
10. Children's Privacy
Sorted is a business tool intended for users aged 18 and over. We do not knowingly collect data from children. If we discover we've collected data from a minor, we'll delete it immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. For significant changes, we'll email you at your registered email address.
12. Complaints
If you're unhappy with how we handle your data, you have the right to complain to the UK Information Commissioner's Office (ICO).
Questions? Email alex.greenhalgh@live.co.uk