Back to home
ShelfHelp

Privacy Policy

Last updated: 28 August 2026

Short version: ShelfHelp collects what it needs to run your dashboard and nothing else. Your data isn’t sold, rented, or handed to advertisers — there’s no version of this business where that makes sense.

What gets collected

Your account: name, email address, and a password stored only as a one-way hash — the actual password is never saved and can’t be recovered, only reset. If you add a passkey, what’s stored is a public key; the private half never leaves your device.

Your stores: which platforms you sell on. Once store connection is available, this will also include the access credentials you choose to grant, stored encrypted.

Store data: once a store is connected — orders, products, costs and similar records pulled from it, so the numbers can be built. Nothing is pulled from a store you haven’t connected.

Technical: a session cookie to keep you signed in, plus ordinary server logs (IP address, browser, what was requested) kept briefly for security and debugging. No advertising or tracking cookies, and no analytics that follow you elsewhere.

What it’s used for

Running the service: building your dashboard, flagging broken products, making the changes you click, taking payment, and emailing you about your own account. That’s the whole list. Nothing is changed in your store unless you trigger it.

You won’t get marketing email you didn’t ask for. Account email — confirmation, password resets, notices about your plan — comes with having an account and can’t be turned off while the account exists.

Who else touches it

Running a service means using other companies. These are the only ones handling your data, each for one job:

  • Vercel — hosts the site and runs the code.
  • Neon — the database where your account and store data live.
  • Stripe — payments. Card details go directly to Stripe; I never see or store them.
  • Resend — sends account emails.
  • The platforms you connect — Shopify, Etsy and others, which you authorise yourself.

Beyond that, nothing is shared — no selling, no renting, no data brokers. The one exception is if the law actually requires it.

How it’s kept

Everything travels over HTTPS. Passwords are hashed, any store credentials are encrypted, and access is limited to what’s needed to run the service. No system is perfectly secure and anyone who tells you otherwise is selling something — but if there’s ever a breach affecting your data, you’ll be told promptly and plainly.

How long it’s kept

Account and store data are kept while your account is open. Close it and the data is deleted within 30 days, apart from records that have to be kept for tax or accounting — invoices, essentially. Server logs are cleared out within about 30 days. You can disconnect a store at any time from that platform’s own settings, and ask me to delete the stored credentials.

Your rights

Email me and you can get a copy of what’s held about you, have it corrected, have it deleted, or have your account closed. No hoops — it’s your data. Depending on where you live you may have further rights under laws like the GDPR or CCPA; those apply regardless of what this page says.

Children

ShelfHelp is for people running a store and isn’t intended for anyone under 16. If a younger person’s data ends up here, tell me and I’ll delete it.

Changes and contact

If this policy changes in a way that matters, account holders get an email before it takes effect. Questions, or a request about your data: noah@shelfhelp.net.