flipzer← BACK HOME
★ CHROME EXTENSION

Privacy &
permissions.

LAST UPDATED · 5 SEPTEMBRE 2026

The French version of this document prevails.

This document describes in detail how the Chrome extension Flipzer — Vinted Reseller Assistant processes your data, which permissions it uses and why. It supplements our general privacy policy and complies with the Chrome Web Store Limited Use Policy and the GDPR.

01

Sole purpose of the extension

Flipzer — Vinted Reseller Assistant is a productivity tool for sellers and resellers on the Vinted marketplace. Its sole purpose is:

Help Vinted sellers manage their listings, track their sales, relist items and analyse market trends, from a unified dashboard.

All extension features serve this sole purpose. The extension performs no other function (no altered browsing, no ad injection, no third-party collection).

02

Limited Use Policy compliance

In compliance with the Chrome Web Store User Data Policy and in particular the Limited Use Policy, we commit to:

  • Using data processed by the extension solely to provide user-visible features.
  • Never transferring data to third parties, except: (i) to provide the service, (ii) to comply with a legal obligation, or (iii) with your explicit consent.
  • Not using data for advertising, commercial profiling or resale purposes.
  • Not allowing humans to access processed data, except: (i) with your explicit consent, (ii) for security or support operations, (iii) to comply with a legal obligation, or (iv) for anonymised and aggregated statistical data.
03

Data processed by the extension

The extension processes only the data strictly necessary for its operation. Full list:

Session token (authentication)

  • Flipzer session token (Bearer) — stored locally in chrome.storage.local to authenticate the extension with the flipzer.club server. This is a session token, NOT a password, and it can be revoked at any time by logging out.

Personally identifiable information

  • Vinted user ID (numeric) and public Vinted username — read from your active Vinted session to identify your own account. No data from other Vinted users is collected.

Website content (your own listings)

  • Titles, descriptions, prices, identifiers and photo URLs of your own Vinted listings, for backup and relisting purposes.
  • Public status of items you monitor (available / sold / reserved), for niches you have created in the dashboard.

User activity

  • Automation preferences (sync intervals, active Vinted profiles), stored locally and sent to flipzer.club only to synchronise your settings across devices.

Sourcing (reverse image search, optional)

  • When you use the sourcing feature, the submitted image is sent to a third-party reverse image search service to retrieve supplier results. No personal data is attached to this request.
04

Data we do NOT collect

For the avoidance of doubt, the extension never collects:

  • Your Vinted password — Flipzer uses only your active browser session, exactly as you do when using Vinted normally.
  • Your payment credentials (card, IBAN, PayPal, etc.).
  • Your Vinted message content is retained only when you enable “cloud message backup”. When Auto Mode is active, the latest relevant message is processed temporarily by Flipzer to select a reply and is not added to logs or the decision registry.
  • Your postal addresses, phone numbers, or shipping information.
  • Personal data of other Vinted users, beyond the public buyer username included in your order metadata (see section 14).
  • Your web browsing history outside the domains listed below.
  • Your health data, GPS location or identity documents (ID card, etc.).
  • Your raw Vinted cookies (local read only, never transmitted to flipzer.club).
05

Cookies and browser session

The extension uses the cookies permission solely to:

  • Detect your logged-in Vinted account — by reading the user identifier contained in the Vinted session cookie, present in your browser when you are logged in to Vinted.
  • Connect your Flipzer session to the extension — by reading the Flipzer session cookie when you are signed in to the dashboard.

Vinted session cookies remain entirely in your browser. No raw cookie, no Vinted authentication token is transmitted to our servers. Only the numeric identifier of your account (publicly visible on your Vinted profile) is used server-side to associate your listings with your Flipzer account.

For this automatic sign-in, the Flipzer session cookie is sent over HTTPS only to flipzer.club for validation. The returned session token is stored in the extension to authenticate its requests to Flipzer. Vinted cookies are not sent to Flipzer.

06

Chrome permissions — justification

Each permission requested by the extension addresses a specific technical need:

  • storage — store your Flipzer session token and preferences locally.
  • unlimitedStorage — retain sync logs and listing backups when the network connection is unavailable.
  • alarms — schedule periodic sync cycles (checking your listings every 30 minutes).
  • downloads — download PDF shipping labels issued by Vinted, on your explicit request, and images of your own listings during a backup.
  • tabs — detect whether you have a Vinted tab open (required to run sync code in the correct context), and open a Vinted tab on your request when relisting.
  • cookies — identify your logged-in Vinted account (see section 05).
  • scripting — execute code in your open Vinted tabs to read your logged-in account identifier and to orchestrate relisting, on your request.
  • declarativeNetRequestWithHostAccess — adjust request headers when calling the third-party image search service to comply with its CORS constraints.

The extension is limited to the following domains (host_permissions) — it never runs on other sites:

  • vinted.fr, .be, .es, .it, .de, .nl, .pl, .pt, .co.uk, .com, .net — to interact with your Vinted account.
  • flipzer.club, www.flipzer.club — to communicate with the Flipzer dashboard and API.
  • fatkun.net — for reverse image search (sourcing).
  • localhost:3000 — used only in the Flipzer team development environment.
07

Storage and hosting

Processed data is stored in two locations:

  • Locally in your browser (chrome.storage.local) — session token, preferences, recent logs, authentication cache. This data is purged when you uninstall the extension.
  • On our servers — your saved Vinted listings, your monitored niches, your statistics. Data is hosted in the European Union in an encrypted-at-rest PostgreSQL database on a dedicated server operated by Flipzer.
08

Sharing with third parties

We do not share any data for commercial purposes. The only technical third parties through which information transits are:

  • Stripe (Stripe Payments Europe, Ltd., payment provider) — to manage your subscription. Only your billing information transits, never the details of your Vinted usage.
  • Third-party image search service — only if you use the sourcing feature. Submitted images are not associated with your identity.
  • Discord (optional) — only if you link your Discord account to access our community.

We never sell or rent your data. No third-party advertising is served by the extension.

09

Independent service

Flipzer is an independent service. Flipzer is not affiliated with, endorsed by, or sponsored by Vinted UAB or any of its subsidiaries. The name "Vinted" appears in this document solely for descriptive purposes, to indicate the platform with which our tool interoperates.

10

Data retention

Your data is retained for as long as your account is active. If you uninstall the extension, locally stored data is automatically deleted by your browser. If you delete your Flipzer account, associated data is erased within 30 days, subject to legal obligations (including invoice retention for 10 years under commercial law).

11

Your rights

Under the GDPR, you have the right of access, rectification, erasure, restriction, portability and objection regarding your personal data. To exercise these rights, write to us at contact@flipzer.club. You may also lodge a complaint with your national data protection authority.

12

Security

All communications between the extension and our servers are encrypted via HTTPS. Flipzer account passwords are kept only as an irreversible hash (never in plain text, never backed up in plain text). Our regular server backups cover application data only, not your credentials. Data at rest is encrypted. Server access is restricted to the Flipzer team and is logged. While no method can guarantee absolute security, we are committed to maintaining industry standards.

13

Contact and updates

For any questions about this policy or the Flipzer extension, contact us at contact@flipzer.club.

This policy may be updated. The last update date appears at the top of the document. Any material change will be notified via the extension or by email.

See also our general privacy policy and our terms of service.

14

Cloud sync (orders, scheduler, messages)

So you can consult your data from any device (including your phone), the extension may sync some data to our servers, encrypted in transit (TLS) and accessible only by you:

  • Orders (transaction metadata: reference, status, item title, buyer, price) and repost scheduler configuration — synced automatically, kept while your account is active.
  • Your Vinted message content — ONLY if you explicitly enable the “Save my messages to the cloud” option (off by default, in the Messages tab). Retained for at most 90 days after the last sync; disabling it immediately deletes the stored copy.

None of this data is shared with third parties or used for advertising.

← GENERAL POLICYTERMS OF SERVICE →
© Flipzer 2026 · INDEPENDENT SERVICE · NOT AFFILIATED WITH VINTED UAB