Privacy Policy

Automation Alchemists — Return Label Converter & CP Bot

Last updated: 18 July 2026

1. Introduction & Scope

This Privacy Policy explains how the Return Label Converter web application and the CP Bot Chrome extension (“we”, “our”, “the Service”) collect, use, store, and protect your data. The Service is developed and operated by Automation Alchemists.

The Service comprises two products that share a single Supabase backend and user account system:

  • Return Label Converter— A web application for creating premium, clean eBay AU return labels from Amazon AU return QR codes, barcodes, or printable labels.
  • CP Bot (CopyPaste Bot)— A Manifest V3 Chrome extension for Australian eBay-to-Amazon dropship order fulfilment. It copies buyer addresses from eBay AU Seller Hub and fills Amazon AU checkout forms.

By using either product, you agree to the practices described in this policy.

2. Data We Collect

All data is associated with your authenticated user account. The following tables detail what each product collects.

2a. Return Label Converter

CategoryData FieldsStorage Location
Uploaded ImagesReturn label, QR code, or barcode images uploaded for conversionSupabase storage bucket (label-uploads, per-user folder, private)
Generated LabelsConverted/rendered label output images (PNG, JPG, or PDF)Generated client-side; not stored server-side
Label HistoryTemplate ID, item name, quantity, order reference, uploaded code image URLSupabase database (label_history table, per-user, row-level security)

2b. CP Bot Chrome Extension

CategoryData FieldsStorage Location
AuthenticationEmail address, Supabase session tokensSupabase Auth, browser cookies, Chrome extension storage
eBay AU Order DataOrder IDs, buyer names, street addresses (street lines, suburb, state, postcode, country), phone numbers (when present on the order), item titles, quantities, source URLsChrome session storage, Supabase cloud clipboard (auto-expires after 5 minutes)
Amazon AU DataOrder references, ASINs, Amazon account emailSupabase fulfillment logs
Fulfillment LogseBay order ID, Amazon order reference, buyer name, postcode, item title, quantity, fulfilment status, address validation warnings, Amazon accountSupabase database (cp_bot_fulfillments table, per-user, row-level security)
Activity & Event LogsEvent type (e.g. paste success, checkout error, scan), eBay order ID, extension version, event detail metadataSupabase database (cp_bot_activity_log table, per-user, row-level security)
Gift Message SettingsGift enabled flag, message text, sender nameChrome local storage, Supabase settings (cp_bot_settings table)
User SettingsAutomation toggles (enabled, auto-select address, auto-mark ordered)Chrome local storage, Supabase settings (cp_bot_settings table)

3. How We Use Your Data

Return Label Converter

  • Label conversion: Processing uploaded return label images (QR codes, barcodes, printable labels) and rendering clean, eBay-suitable return labels for download.
  • History: Recording which labels you have converted so you can re-access or re-download them.

CP Bot

  • Order fulfilment: Copying buyer shipping addresses from eBay AU order pages and filling them into Amazon AU checkout/address forms.
  • Cross-device sync:Temporarily storing addresses in a cloud clipboard so you can copy on one device and paste on another (entries auto-expire after 5 minutes).
  • Fulfillment tracking: Logging which eBay orders have been fulfilled and their corresponding Amazon order references.
  • Activity monitoring: Recording automation events (successes, failures, errors) so you can review your fulfilment history and diagnose issues.
  • Authentication: Verifying your identity and securing access to your data.

4. Data Storage & Security

  • Server-side data is stored in Supabase (hosted on AWS infrastructure). All data is transmitted over HTTPS (TLS encryption in transit).
  • Row Level Security (RLS) is enforced on every database table — each user can only read, update, or delete their own rows.
  • The extension never stores or transmits the Supabase service-role key. Only the public anon key is used, scoped by RLS policies.
  • Local extension data (settings, cached orders) is stored in chrome.storage.local and chrome.storage.session, accessible only to the extension.
  • Uploaded label images are stored in a private Supabase storage bucket with per-user folder isolation enforced by RLS.

5. Data Retention & Deletion

  • Cloud clipboard entriesauto-expire and are deleted after 5 minutes.
  • Fulfillment logs and activity logsare retained indefinitely for your records. You can request deletion at any time (see Section 8).
  • Label history and uploaded images are retained until you delete them from your account or request account deletion.
  • Account deletion: If you delete your Supabase account, all associated data (fulfillments, activity logs, settings, label history, uploaded images) is automatically cascade-deleted.

6. Third-Party Services

The Service integrates with the following third-party providers:

  • Supabase — Authentication, database, and file storage. See Supabase Privacy Policy.
  • Vercel — Web application hosting, analytics, and performance monitoring (via Vercel Analytics and SpeedInsights). See Vercel Privacy Policy.

We do not sell, trade, or share your data with any other third parties.

7. Chrome Extension Permissions

The CP Bot extension requests the following permissions. Each is required for the functionality described:

PermissionPurpose
ebay.com.auInject content scripts on eBay AU Seller Hub order pages to read buyer shipping addresses for cross-platform fulfillment.
amazon.com.auInject content scripts on Amazon AU checkout and address pages to autofill scraped buyer addresses into shipping forms, and detect the active Amazon account.
Web app domainBridge authentication between the hosted web application and the extension via the AuthBridge handshake.
activeTabRequired for programmatic script injection on the currently active tab during order scanning.
storagePersist user settings, automation state, and cached order data locally within the extension.
scriptingProgrammatically inject content scripts into eBay order detail tabs during batch address scanning.
tabsOpen eBay order detail pages in background tabs for batch scanning and detect Amazon sign-out navigation.
webNavigationDetect Amazon AU sign-out navigation events to update the Amazon account status indicator.

8. Your Rights

You have the right to:

  • Access all data associated with your account via the CP Bot Admin dashboard and your Account page.
  • Delete individual fulfillment records, activity logs, label history entries, and uploaded images at any time.
  • Exportyour data by contacting us (see Section 10).
  • Delete your account entirely, which will cascade-delete all associated data across both products.
  • Uninstall the CP Bot extension at any time. Local extension storage is automatically cleared on uninstall. Server-side data remains until account deletion.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last updated” date. Continued use of the Service after changes constitutes acceptance of the revised policy.

10. Contact

If you have questions about this Privacy Policy or want to exercise your data rights, please contact us at:

dsclub.au@gmail.com