Privacy policy
What Ract reads, keeps and sends
Ract turns your Whatnot live sales into tray assignments and printed labels. To do that it has to read your sales, and on card shows it looks at your stream. This page says exactly what, where it goes, and what it never touches. Last updated 5 September 2026.
Who we are
Ract is operated by Olive Tree Trading Ltd, trading as Ract.io, Unit 68 Basepoint, Shearway Business Park, Folkestone, Kent, England, CT19 4RH. For anything on this page, write to support@ract.io. We are the data controller for your account; for your buyers’ details you are the controller and we act on your instructions (see “Your buyers”).
The Ract Capture extension
The extension runs only on whatnot.com and on ract.io. On Whatnot it reads the sale events your own signed-in tab already receives — who bought, what, for how much, and the order id — and hands them to your Ract tab in the same browser. It reads those events from the page’s own network traffic; it does not sign in for you, never sees or stores your password, and never sends a message, places a bid, or changes a listing.When you scan a parcel in Shipping, the extension looks that order up on Whatnot using your own signed-in session and fetches the courier label Whatnot issued for it, so it can be printed. Those requests go to Whatnot and to the hosts Whatnot serves labels from, and nowhere else.On a card show it captures still frames from the video element on your own stream and passes them to your Ract tab for card identification (see below). Frames are handed over the moment they are taken and are not kept by the extension.While a show runs, the extension keeps a recording of the sale events in memory, so that if capture drops you can check afterwards which sales were missed. That recording never leaves your computer unless you download it and choose to import it into Ract, and it is gone when Chrome quits. It contains sale events only — never video frames.The extension has no server of its own and uploads nothing anywhere. It needs the permissions it asks for to see your Whatnot tab, to talk to your Ract tab, and to fetch a courier label — and for nothing else.
What we store on our servers
Your account: the email address you sign in with. Sign-in is by emailed link; there is no password.Your shows and sales: for each sale, the buyer’s Whatnot username and id, the product name, the price, Whatnot’s order id, when it sold, the tray Ract assigned it to, and on card shows the card it was identified as. Whether a parcel has shipped. The settings you choose — your label sign-off, VAT, printer, credit preferences.Your credits: a ledger of what you have been granted, bought and spent. Billing is invoiced by hand, so we hold no card or bank details.We do not store: your Whatnot password or session; your buyers’ names and postal addresses (a courier label is fetched into your browser and printed there — it is never uploaded to us); video frames from your stream; anything about your buyers beyond the sale itself.
Card identification
On a show with card identification turned on, frames of your stream are sent from your browser to Ract’s identification service, which asks two providers to name the card: Ximilar, a catalogue match, and Google’s Gemini, a model that describes the image. The frames are used for that purpose only, are not kept by Ract, and are never written to logs. Only the answer — the card’s name, set and number, and which provider gave it — is stored, against the sale. Each provider handles the image under its own terms. Frames of a live stream may show you and anyone else on camera; identification is off unless you turn it on for a show.
Your buyers
The people who buy from you are your customers, not ours. We process what Whatnot tells your tab about each sale — a username, a product, a price, an order id — because that is what it takes to put the right item in the right parcel, and for no other purpose. We do not contact your buyers, build profiles of them, or share their details with anyone. A buyer who wants to know what a seller holds about them should ask the seller.
Who else handles data
Vercel hosts the application. Supabase hosts the database and sends the sign-in emails — the database is in the EU. Ximilar and Google process stream frames for card identification, as above. Sentry receives error reports when it is enabled; those are stripped of label and buyer content before they leave the browser. QZ Tray and Zebra Browser Print, if you use them, run on your own computer and are sent only labels to print. We sell nothing to anyone and use no advertising or analytics services.
Cookies and local storage
One cookie, to keep you signed in. No advertising, tracking or analytics cookies. Your browser also holds a local copy of your recent shows so a show keeps running if the connection drops; that copy lives only in that browser and is trimmed as shows age.
How long we keep it
Your shows, sales and ledger are kept for as long as your account is open, because they are your sales history and your credit statement. Ask us to close your account and we delete it and everything under it. Local copies on your own devices are yours to clear.
Your rights
You can ask for a copy of what we hold about you, have it corrected, or have your account and its data deleted, by writing to support@ract.io. We answer within a month. If you are in the UK or EU you also have the right to complain to your data protection authority; in the UK that is the ICO.
Security
Everything travels over HTTPS. Each seller can read and write only their own rows in the database — that is enforced by the database, not by the app. The key that can bypass that rule exists only on the server, and is used for exactly one job: keeping the credit ledger.
Chrome Web Store
Ract Capture’s use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Changes
If what Ract does with data changes, this page changes first and the date at the top moves. Wording is tidied without a date change.
Ract is not affiliated with, endorsed by, or connected to Whatnot. Install the extension · Home