Legal
Privacy policy
Effective September 3, 2026
Summary in plain English
Pull Different is the operations platform behind your sports-card business. We collect the data your shop generates — inventory, orders, customers, financials — so the platform can do its job. We do not sell that data, we do not share it with advertisers, and we do not use one tenant's data to power another tenant's experience.
Who we are
Pull Different Technologies (“we”, “us”) operates the Pull Different platform at pulldifferent.io. Reach us at hello@pulldifferent.io for any privacy question.
What we collect
- Account data — email, name, role, password (hashed), authentication factors.
- Operational data your shop creates — inventory, orders, customers, vendors, purchase orders, returns, stream schedules, financial records.
- Integration data — credentials and webhook secrets for the third-party services you choose to connect.
- Usage telemetry — pages visited, API calls, timestamps, error logs. Used to keep the platform reliable.
- Billing data — plan, invoices, payment status. Card details are handled by our PCI-compliant payment processor; we never see or store them.
How we use it
- Run the features you signed up for.
- Sync data to/from the third-party channels you connect.
- Send transactional email — receipts, security alerts, support replies.
- Aggregate, anonymized analytics so we can prioritize what to build next. Never tied back to your business.
- Comply with tax, fraud, and legal obligations when we have to.
Who sees your data
Your tenant's data is visible to: (1) members of your tenant (per the roles you grant them), (2) a small number of Pull Different Technologies staff who need it to operate the platform or help you with support, and (3) the third-party services you explicitly connect.
We do not sell data. We do not use one tenant's data to improve another tenant's experience.
Our role
For your account data — your name, email, role, billing details — we are the data controller. For the operational data you load into your tenant, including your own customers' personal data, you are the controller and we are your processor: we handle it on your instructions and to run the Service, not for our own purposes.
Service providers (subprocessors)
We rely on a small number of vetted providers to run the platform. Each is bound by confidentiality and data-protection obligations, and we share only the data needed for them to perform their function.
- Vercel — application hosting and content delivery.
- Supabase — database, authentication, and file storage.
- Stripe — subscription billing and payment processing.
- Anthropic — the AI features you choose to use (drafted emails, pricing assistance, in-app help). Content sent for these features is not used to train models.
- Email delivery — Resend, or the provider you connect yourself (SendGrid, Postmark).
- Cloudflare — bot protection on public forms.
- Sentry — error monitoring, where enabled. Credentials and cookies are stripped before an error report leaves our systems.
Providers you connect yourself — your Shopify, eBay, QuickBooks, ShipStation, and similar accounts — receive data at your direction and under their own privacy policies.
How we protect it
Data is encrypted in transit (TLS) and at rest. Tenant isolation is enforced at the database level by row-level security, so one tenant's queries cannot reach another's rows. Access by our staff is limited to those who need it, and administrative actions are recorded in an audit log you can review in-app.
No system is perfectly secure. If we become aware of a breach affecting your data, we'll notify you without undue delay and, where required, within the timeframe the law sets.
Cookies + tracking
We use cookies that are strictly necessary to run the Service — keeping you signed in and keeping your session secure. We do not use advertising cookies, and we do not sell or share personal information for cross-context behavioral advertising as those terms are defined under US state privacy laws.
Where your data is processed
The Service is hosted in the United States, and our providers may process data there and in other countries where they operate. If you're in the EEA or UK, we rely on appropriate safeguards — including Standard Contractual Clauses — for those transfers.
Children
The Service is for businesses and is not directed at anyone under 18. We don't knowingly collect personal data from children. If you believe a child's data has reached us, email us and we'll delete it.
Data retention
We retain operational data for as long as your tenant is active, and we keep it after cancellation rather than deleting it on a schedule. That way your account and its history can be restored if you come back, and the records stay available for tax, accounting, and audit purposes.
Where the law gives you a right to have personal data erased, we honor it — see Your rights below. Records we're legally required to keep, such as invoices and audit logs, are retained for up to 7 years regardless.
Your rights
Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of the personal data we hold about you, and to object to processing or withdraw consent. Email hello@pulldifferent.io and we'll respond within 30 days. We won't discriminate against you for exercising these rights.
California residents: we do not sell your personal information and have not done so in the preceding 12 months. The categories we collect, why, and who we share them with are described above.
If you're a customer of one of our tenants — a shop that uses Pull Different — that shop controls your data, not us. Send your request to them; if it reaches us first, we'll pass it along.
If you're in the EEA or UK and think we've mishandled your data, you can complain to your local supervisory authority.
Changes to this policy
We'll update this page when something material changes and email active account holders when a change materially affects your rights. Continued use of the platform after a change means you accept the updated policy.