How SmashOrder protects connected shop operations
SmashOrder is designed around explicit seller authorisation, separate organisation boundaries and the minimum access needed for operational work.
Official shop authorisation
Each shop owner or authorised operator connects through Etsy's official OAuth consent flow. SmashOrder does not request or store Etsy passwords and does not use browser scraping or simulated shop logins.
Separate seller workspaces
Every self-registered seller begins with an isolated organisation. Orders, product records, logistics details and team memberships are scoped to that organisation.
Role-based access
Administrators control team membership and fixed roles. Buyer delivery information is reserved for fulfilment needs, while finance access can be provided without exposing full delivery details.
Human-confirmed actions
SmashOrder prepares listing and shipment information for review. Publication and tracking submission require an explicit action by an authorised user.
Revocation, retention and deletion
A shop connection can be revoked and account holders may request deletion through the documented process. Read the Privacy Policy and Data Deletion instructions for more information.
Report a concern
If you believe an account or shop connection is being misused, contact SmashOrder support. Support enquiries are reviewed within 24 hours.