Last updated: 28 August 2026
Short version: ShelfHelp collects what it needs to run your dashboard and nothing else. Your data isn’t sold, rented, or handed to advertisers — there’s no version of this business where that makes sense.
Your account: name, email address, and a password stored only as a one-way hash — the actual password is never saved and can’t be recovered, only reset. If you add a passkey, what’s stored is a public key; the private half never leaves your device.
Your stores: which platforms you sell on. Once store connection is available, this will also include the access credentials you choose to grant, stored encrypted.
Store data: once a store is connected — orders, products, costs and similar records pulled from it, so the numbers can be built. Nothing is pulled from a store you haven’t connected.
Technical: a session cookie to keep you signed in, plus ordinary server logs (IP address, browser, what was requested) kept briefly for security and debugging. No advertising or tracking cookies, and no analytics that follow you elsewhere.
Running the service: building your dashboard, flagging broken products, making the changes you click, taking payment, and emailing you about your own account. That’s the whole list. Nothing is changed in your store unless you trigger it.
You won’t get marketing email you didn’t ask for. Account email — confirmation, password resets, notices about your plan — comes with having an account and can’t be turned off while the account exists.
Running a service means using other companies. These are the only ones handling your data, each for one job:
Beyond that, nothing is shared — no selling, no renting, no data brokers. The one exception is if the law actually requires it.
Everything travels over HTTPS. Passwords are hashed, any store credentials are encrypted, and access is limited to what’s needed to run the service. No system is perfectly secure and anyone who tells you otherwise is selling something — but if there’s ever a breach affecting your data, you’ll be told promptly and plainly.
Account and store data are kept while your account is open. Close it and the data is deleted within 30 days, apart from records that have to be kept for tax or accounting — invoices, essentially. Server logs are cleared out within about 30 days. You can disconnect a store at any time from that platform’s own settings, and ask me to delete the stored credentials.
Email me and you can get a copy of what’s held about you, have it corrected, have it deleted, or have your account closed. No hoops — it’s your data. Depending on where you live you may have further rights under laws like the GDPR or CCPA; those apply regardless of what this page says.
ShelfHelp is for people running a store and isn’t intended for anyone under 16. If a younger person’s data ends up here, tell me and I’ll delete it.
If this policy changes in a way that matters, account holders get an email before it takes effect. Questions, or a request about your data: noah@shelfhelp.net.