← Back to CandleSmart
Privacy Policy
Also see our Terms of Service.
Last updated: July 2026
CandleSmart ("we", "us", or "our") is a candle-making productivity application operated by an individual developer. This Privacy Policy describes how we access, use, store, and protect your data when you use our application at candlesm.art (the "App").
Information We Collect
Account information: When you create an account, we collect your email address and a unique user identifier provided by Firebase Authentication. We do not collect or store your password — authentication is handled by Firebase.
Google user data (when you connect Google Sheets):
- Your Google email address — used solely to confirm your identity and link the connection to your account.
- Google Sheets data — we create and write to Google Sheets that you own, containing your CandleSmart inventory, budget, and candle recipe data that you choose to export.
- Google Drive file access — we create spreadsheet files in your Google Drive that you have authorised. We access only the specific files created by this application.
Etsy data (when you connect your Etsy shop):
- Shop name and ID — to identify your shop for listing creation.
- Listing management permissions — to create draft listings on your behalf.
Shopify data (when you connect your Shopify store):
- Store name — to identify your store for product creation.
- Product management permissions — to create draft products and upload images on your behalf.
TikTok data (when you connect your TikTok account):
- Display name and avatar — to show your connected TikTok identity in the app.
- Video upload permissions — to post short videos of your candle recipes and batch progress to your TikTok account on your behalf.
- We access only the minimum data required: your TikTok display name, avatar, and the ability to upload videos. We do not access your DMs, friends list, browsing history, or any other TikTok data.
Application data: We store your candle recipes, fragrance library, inventory, batch records, burn tests, budget transactions, stickers, settings, bookmarks, and profile information in Firebase Firestore, tied to your user account.
How We Use Your Data
- Your data is used exclusively to provide the application's functionality: recipe management, inventory tracking, cost calculations, Google Sheets export, and marketplace integrations.
- Google and TikTok OAuth tokens are used solely to create and manage spreadsheets in your Google Drive and to upload videos to TikTok, respectively, when you choose to use these features.
- Etsy and Shopify OAuth tokens are used solely to create draft listings/products on your connected marketplace when you choose to post.
- We use your email address for account identification and to send notifications you have opted into (e.g., batch curing reminders).
Data Sharing and Disclosure
- We do not sell your data to any third party.
- We do not share your data with third parties for advertising, marketing, data brokerage, or any purpose other than providing the application's features.
- We do not use your data for targeted advertising, personalised ads, retargeted ads, or interest-based advertising.
- We do not transfer your data to data brokers, information resellers, or for credit-worthiness assessments.
- We do not use your data to train AI or machine learning models.
- Community features (e.g., wick pool, recipe feed) display data you voluntarily choose to share publicly. You control what is published.
- We may disclose data only if required by law or to protect the rights and safety of our users.
Data Protection and Security
- All data is stored in Firebase (Google Cloud) and encrypted at rest using AES-256.
- All communications between your browser and our servers use TLS 1.2+ encryption.
- OAuth tokens are stored in Firestore and are never transmitted to or accessible by third parties.
- User data is isolated per account via Firebase Security Rules — no user can access another user's data.
- Image uploads are scanned for inappropriate content before being stored.
- We follow industry-standard security practices and regularly review our data handling procedures.
Data Retention and Deletion
- Your data is retained for as long as your account exists and you use the application.
- When you disconnect a marketplace, Google, or TikTok integration, OAuth tokens are immediately deleted from our system. Google tokens are also revoked via Google's token revocation endpoint.
- You may delete your account at any time from Settings → Account. Account deletion permanently removes all your data, including recipes, inventory, transactions, stickers, OAuth tokens, and profile information.
- Account deletion data is purged within 30 days of the deletion request.
- Community data you have voluntarily published (e.g., wick test results) may persist in anonymised form after account deletion.
- We do not retain data longer than necessary for the purposes described in this policy.
Google User Data Specific Disclosures
CandleSmart's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Scopes requested: We request only the minimum scopes necessary:
spreadsheets (create and read/write Google Sheets), drive.file (create and manage files created by CandleSmart in your Google Drive), and userinfo.email (read your Google email address for account identification).
- Data access: When you connect your Google account, we access your email address for identification and create a "CandleSmart Exports" folder in your Google Drive (if it does not already exist). We create and write spreadsheets containing your exported inventory, budget, and sales data to this folder.
- Data use: Google user data is used only to provide and improve user-facing features (creating and writing to spreadsheets you own). It is not used for any other purpose.
- Data transfer: Google user data is not transferred to any third party. We do not sell, rent, or share your Google data with anyone.
- Data protection: OAuth tokens are stored securely server-side in Firebase Firestore with AES-256 encryption at rest. Access is restricted to authenticated Cloud Functions only.
- Data deletion: Google OAuth tokens are deleted immediately when you disconnect your Google account or delete your CandleSmart account. Google tokens are also revoked via Google's token revocation endpoint to ensure access is terminated.
- Authentication: When you sign in with Google, we receive your Google email address and profile identifier through Firebase Authentication. This is used solely for account creation and authentication.
TikTok User Data Specific Disclosures
CandleSmart's use of TikTok user data complies with TikTok's Developer Terms of Service and Developer Policy.
- We request only the minimum scopes necessary:
user.info.basic (display name and avatar) and video.upload (to upload videos on your behalf).
- TikTok user data is used only to provide and improve user-facing features (showing your connected account and uploading videos you initiate).
- TikTok user data is not used for any purpose other than the application's TikTok integration features.
- TikTok user data is not transferred to any third party.
- TikTok OAuth tokens are stored securely in Firebase Firestore and are deleted when you disconnect TikTok or delete your account.
- We do not access your DMs, friends list, browsing history, or any data beyond the scopes you authorize.
Community and Public Data
- When you publish a recipe to the community feed, your display name and recipe data become visible to all users.
- Burn test results and cure data you contribute to community pools are anonymised and used to improve wick recommendations for all users.
- Your public profile (display name, avatar, bio, published recipes) is visible to other users.
- You may make your profile private at any time from Settings → Privacy.
Children's Privacy
CandleSmart is not intended for use by children under 13. We do not knowingly collect data from children under 13. If we become aware that a child under 13 has provided us with data, we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notification. The "Last updated" date at the top indicates when this policy was last revised.
Contact
If you have questions about this Privacy Policy or our data practices, use the Contact Admin button in Settings to reach us, or email us directly.
The term 'Etsy' is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.
The term 'Shopify' is a trademark of Shopify Inc. This application uses the Shopify API but is not endorsed or certified by Shopify Inc.
Google and Google Sheets are trademarks of Google LLC. This application uses the Google Sheets API but is not endorsed or certified by Google LLC.
TikTok is a trademark of TikTok Ltd. This application uses the TikTok API but is not endorsed or certified by TikTok Ltd.