Data Flow Chart
An overview of Shelf's data management architecture, illustrating how user data moves from initial platform interaction through secure database storage.

At Shelf, we prioritize the security and efficiency of our data management system. This page describes how data moves through the Shelf hosted service (app.shelf.nu and the Shelf Companion mobile app), from the moment a user interacts with it to where the information is stored.
Key Components
- Client -- A web browser, or the Shelf Companion mobile app for iPhone and Android.
- Web App (Remix) -- The main application, hosted on Fly.io's SOC 2 Type 2 compliant servers.
- Supabase -- The database (PostgreSQL), sign-in accounts and file storage.
- Stripe -- Manages all payment and subscription-related processes.
- Sentry -- The error logging and monitoring system.
- Microsoft Clarity -- Usage analytics: page-usage recordings and heatmaps of the web application.
- SSO & SCIM -- Enables seamless integration with Microsoft or Google authentication systems.
- Cloudflare -- The edge network in front of app.shelf.nu. All traffic passes through it.
- Resend (sending through Amazon SES) -- Delivers sign-in codes, invitations and notifications.
Where Your Data Is
- Database, sign-in accounts and files: Supabase, in AWS region eu-central-1 (Frankfurt, Germany).
- Application servers: Fly.io, in Amsterdam, the Netherlands.
- Email delivery: Resend, sending through Amazon SES in the United States.
How Data Moves
Using Shelf in a browser. Browser → Cloudflare → Shelf application (Amsterdam) → database (Frankfurt). Pages are built on the server, so the browser never queries the database directly. Images are loaded from Supabase Storage over HTTPS.
Signing in. With an email address, a password or a one-time code sent by email, both handled by Supabase Auth. With single sign-on, the browser is redirected to your identity provider, which returns a SAML assertion to Supabase Auth, and Shelf then opens the session.
Shelf Companion. The mobile app signs in through Supabase Auth and sends all data through the Shelf API on app.shelf.nu, with the same permission checks as the web application.
Scanning a QR label. A signed-in workspace member who scans a label goes to the asset page. Anyone else sees no asset data: only a page to sign in or to send a message to the workspace owner. Each scan is recorded with its time and browser details; location is recorded only if the scanning device allows it.
Email. Invitations, booking notifications and sign-in codes are delivered through Resend. The provider receives the recipient address and the message content.
Third-Party Services
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All account and workspace data | EU: Frankfurt, Germany |
| Fly.io | Application servers | Requests while they are processed | EU: Amsterdam, Netherlands |
| Cloudflare | Edge network, page-view analytics | All traffic passes through | Global edge |
| Resend (Amazon SES) | Email delivery | Recipient address, message content | United States |
| Stripe | Billing | Billing contact, subscription details | Provider-hosted |
| Sentry | Error monitoring | Error details, user and workspace identifiers. In reports from the web app and its servers, email addresses are masked to their domain | United States |
| Microsoft Clarity | Usage analytics | Page-usage recordings and heatmaps | Provider-hosted |
| Crisp | Support chat | Name, email and messages of users who open chat | Provider-hosted |
| PostHog | Product analytics | Sign-up, upgrade and cancellation events, internal user ID | Provider-hosted |
| MapTiler | Map display | Map image requests from the browser | Provider-hosted |
| OpenStreetMap Nominatim | Address lookup | Location address text | Provider-hosted |
Card details are entered on Stripe's own pages and never reach Shelf.
Before an error report, performance trace or log line leaves the web app (in the browser or on Shelf's servers) for Sentry, the email addresses in it are masked: jane.doe@acme.com is sent as [email]@acme.com. The domain is kept so a failing sign-in or mail setup can be traced to the right workspace.
Security Measures
- All HTTP requests are secured using SSL/TLS 128-bit encryption with TLS 1.3 protocol.
- The PostgreSQL database is encrypted with AES-256, ensuring top-tier data protection.
- Workspace data is separated in the application: every database query is scoped to the workspace, and an automated code check flags any query that is not.
- Permissions are checked on the server for every page and action, on the web and in the mobile app.
Conclusion
This architecture provides a seamless, secure, and scalable solution for all your asset management needs. By leveraging industry-leading technologies and following best practices in data security, Shelf ensures valuable information remains protected and accessible.
For questions about data flow or security measures, contact the support team.
Ready to try Shelf?
Put what you're learning into practice. Free plan available — no credit card required.