Privacy Policy
What ShelfStep collects, why, who else touches it, and what you can do about it. Short version: your workspace data is yours, we don’t sell it, and we only share it with the services needed to run the product.
What we collect
Account: your name and email (from Google sign-in or the email you register with), and the workspace you belong to.
Workspace content: whatever you enter — products, launch plans, formulas, costs, samples, contacts, notes, files, listings, orders, outreach messages and replies.
Usage: anonymous page views and product events (for example “launch created”, “tool used”) so we can see what’s working. No personal content is included in these events.
Billing: if you upgrade, Stripe collects your payment details. We never see your full card number; we store your Stripe customer id and subscription status.
How we use it
To run the service for your workspace, generate AI guidance you ask for, send emails you ask us to send, deliver the daily briefing to workspace admins, bill paid plans, and improve the product. We do not sell personal data or use your workspace content to train AI models.
Who else processes it
These providers process data on our behalf, only as needed to deliver the feature:
- Supabase — database, authentication and file storage (US East).
- Vercel — hosting and anonymous web analytics.
- Anthropic — AI features; receives the workspace content relevant to your request.
- Resend — sends outreach, briefing and account emails, and receives replies to outreach.
- Stripe — payments and subscription management.
- USDA FoodData Central — public ingredient nutrition lookups (ingredient names only).
- Tavily — web search for vendor finding (your search query only).
What other people can see
Members of your workspace see your workspace. Marketplace listings you publish are visible to all ShelfStep workspaces, along with your workspace name and the contact email on the listing. Share links you create show a read-only launch summary to anyone with the link until you stop sharing it. Emails you send from ShelfStep go to the recipient you chose.
Cookies
We use a sign-in session cookie, a cookie that remembers you are in the demo workspace, and small browser-storage flags for things like dismissed tips. No advertising cookies.
Retention
Workspace data stays as long as the workspace exists. Deleted records are removed from the live database immediately and from backups on their normal rotation. If you ask us to delete your workspace we do so within 30 days, keeping only what billing law requires.
Your rights
You can view and edit most of your data inside the app. Email us to export your workspace, correct something you can’t change yourself, or delete your account. If you are in a region with specific privacy rights (for example the EU/UK or California) we honor access, correction, deletion and portability requests.
Security
Data is encrypted in transit and at rest by our providers. Every workspace’s data is scoped to that workspace at the application layer. Sign-in is handled by Supabase Auth (Google or email). No system is perfectly secure; tell us right away if you think something is wrong.
Children
ShelfStep is for adults running food businesses and is not directed at children under 13.
Changes and contact
If this policy changes materially we will note it here and, for significant changes, email workspace admins. Questions or requests: marcoksoe@gmail.com. See also the Terms of Service.