Permissions Requested
Templifier requests only the specific Etsy API permissions needed to provide its features. Here is every scope we request and exactly why:
How the Connection Works
Click "Connect Etsy Shop" in Studio
You initiate the connection from within Templifier's Studio or from this page. You must be signed in to Templifier first.
Etsy's OAuth page opens
You are redirected to etsy.com โ Templifier never sees your Etsy password or login credentials. Etsy shows you exactly which permissions are being requested.
You approve (or decline) the permissions
You see every permission being requested and choose to approve or decline. No data is accessed until you approve. You can approve all or decline entirely.
Etsy sends an authorisation code to our proxy
Etsy redirects to tf-proxy.ashutoshpatney1.workers.dev/etsy/callback. The Cloudflare Worker exchanges the code for an access token โ never in your browser.
Token stored securely, shop synced
Your Etsy access token is stored encrypted in your Supabase account. Templifier then pulls your shop listings and you see your Shop Dashboard.
You control all actions
Templifier never modifies your Etsy listings without your explicit instruction. Every write action (update tag, push listing) requires you to click a button. Nothing is automatic.
๐ Security & Data Handling
- Your Etsy OAuth access token is stored encrypted in Supabase โ never in your browser or in plain text on any server.
- Templifier uses PKCE (Proof Key for Code Exchange) for the OAuth flow โ the most secure OAuth 2.0 method available.
- API calls to Etsy are proxied through our Cloudflare Worker โ your token is never exposed to browser-side JavaScript.
- Templifier accesses your Etsy data only when you initiate a specific action within the Studio.
- We do not store copies of your Etsy listing data on our servers โ data is fetched fresh on each session and kept in your browser only.
- To revoke access: go to Etsy โ Account โ Security โ Apps with Access and remove Templifier. Your token in our system is automatically invalidated.
Frequently Asked Questions
No. Templifier does not take any action on your Etsy shop automatically. Every write action (creating or updating a listing) requires your explicit instruction โ you click a "Push to Etsy" or "Update listing" button. There is no background automation.
Yes. You can disconnect in two ways: (1) from Templifier's Settings โ Connected Accounts โ Disconnect Etsy, or (2) directly from Etsy at etsy.com โ Account โ Security โ Apps with Access. Either method immediately revokes Templifier's access to your shop.
No. Templifier does not request and cannot access your Etsy Payments balance, bank account details, payout history, or any financial account information. The permissions we request are limited to listings, shop info, transactions (order count only), and profile.
We recommend against using Templifier on shared or public computers. Your Templifier session (via Supabase auth) is what controls Etsy access โ anyone who accesses your Templifier account can potentially act on your Etsy shop through Templifier. Sign out of Templifier when using shared devices.
No. Connecting Etsy to Templifier is a standard API integration that does not interact with Etsy's Star Seller metrics. Etsy's Star Seller programme measures your shop's response rate, dispatch rate, and reviews โ Templifier does not interact with or modify any of these.