Current as of January 21, 2025

Privacy Policy

Learn how Shelf.nu protects your personal data and respects your privacy. Review our privacy policy to understand how we collect, use, and safeguard your information.

Introduction

At Shelf.nu, we respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, process, and store your personal data, and your rights regarding that data.

As an asset management platform, we maintain a careful balance between data privacy and essential business record-keeping.

Data Controller

The data controller for Shelf.nu is Shelf Asset Management, Inc. The company is responsible for ensuring that your personal data is processed in accordance with this privacy policy and applicable laws.

Data Collection

We collect several types of personal data, including:

  • Names
  • Email addresses
  • Profile Pictures
  • Team Member Names
  • Asset custody records
  • Equipment check-out / check-in history
  • Booking records
  • Asset modification logs

Purpose of Data Collection

We collect this data to:

  • Identify you as a user and grant access to our cloud product
  • Communicate with you and provide customer support
  • Display your profile picture next to your name on our platform
  • Associate team members with your account
  • Maintain accurate business records of asset custody and usage
  • Enable organizations to track their equipment effectively
  • Provide audit trails for asset management
  • Support legitimate business documentation needs

Legal Basis for Processing

Our data processing is based on:

  • Contractual necessity (providing asset management services)
  • Legitimate business purposes (maintaining asset records)
  • Legal obligations (supporting audit and accounting requirements)
  • User consent (for optional features like profile pictures)

Data Processor

We use Supabase as our database provider, which processes and stores your personal data on our behalf. Supabase has implemented adequate security measures to protect your personal data and prevent unauthorised access, disclosure, modification, or destruction.

Shelf has carefully reviewed Supabase's Data Processing Addendum and is satisfactory for our use case.

Data Retention

For active accounts, we retain your personal data for as long as necessary to fulfill the purposes outlined in this privacy policy. For deleted accounts:

  • Essential business records (asset custody, check-out history, booking records) are retained to meet business and audit requirements
  • Personal profile data is deleted upon account closure
  • Transaction logs necessary for asset tracking are maintained as required by law and legitimate business needs

Data Security

We take appropriate technical and organizational measures to ensure that your personal data is secure and protected from unauthorized access, disclosure, modification, or destruction. Our security measures include:

  • EU-based hosting (Frankfurt)
  • TLS 1.3 encryption for data in transit
  • AES-256 encryption for stored data
  • Strict access controls

Our data processor, Supabase, also implements robust security measures to protect your data.

Your Rights and Practical Implementation

You have certain rights regarding your personal data, including the right to:

  • Access your data through your profile and activity history
  • Correct your personal information
  • Delete optional personal data (profile pictures, optional fields)
  • Object to data processing where applicable

Please note that certain data, such as asset custody records and equipment check-out history, must be maintained for legitimate business purposes and cannot be deleted as they constitute essential business records.

European Users and GDPR

For our European users, we align with GDPR requirements while maintaining necessary business records. While we respect data privacy rights including the "right to be forgotten," it's important to understand that much of our data processing falls under legitimate business and legal requirements that override erasure rights under GDPR Article 17, specifically:

Asset custody records, check-out histories, and booking logs must be maintained to:
 - Comply with legal obligations (accounting, auditing)
 - Establish chain of custody for legal claims if needed
 - Document proper asset handling and business operations

We process and store this data in the EU (Frankfurt). Personal data not essential for business records (like profile pictures or optional information) can be deleted upon request.

Contact Information

If you have any questions or concerns about our data handling practices, please contact our Data Protection Officer, Carlos Virreira, at carlos@shelf.nu.

Changes to this Privacy Policy

We reserve the right to modify this privacy policy at any time. When we make changes, we will notify you by posting the revised privacy policy on this webpage. Your continued use of our products and services after the effective date of the change constitutes your consent to the revised privacy policy.