Privacy policy
What we read, what we keep, and how to remove it
Effective September 2, 2026
Shelfwyze is software for food and beverage brands. It answers where a brand should sell next and helps them pursue it. To do that it reads data the brand chooses to connect. This page says exactly what that is, what we store, who else touches it, and how to make us delete it. If anything here is unclear, write to privacy@shelfwyze.com.
Your account
When you sign up we store your email address and a hashed password, handled by our authentication provider. We use your email to sign you in, to send password resets, and to contact you about the service. We do not send marketing email unless you ask for it.
Your brand profile
Details you type in — products, costs, wholesale prices, certifications, capacity, retailers you already sell to — are stored under your account and shown back to you, and to buyers only where you choose to share a pitch kit. We label these as brand-provided everywhere they appear, because they are.
Shopify
If you connect a Shopify store, we read orders and products through Shopify's API using the read-only permissions you grant. From orders we calculate aggregate figures: revenue, order counts, average order value, repeat rate, and how many customers are in each state or region. We store those aggregates. We do not store customer names, email addresses, phone numbers, street addresses or individual orders — there is no table in our database for them. Your Shopify access token is encrypted before it is stored. Disconnecting in Shopify or in Shelfwyze ends our access.
Who processes your data
We run on a small number of service providers, each processing data only to provide the service:
- Supabase — database and authentication.
- Vercel — hosting.
- Anthropic — the AI model that reads retailers' own public pages for our retailer research, and reads product images submitted to our consumer directory. Under our agreement with Anthropic, data sent to the model is not used to train its models.
- Resend — transactional email such as password resets.
- Cloudflare Turnstile — bot checks on public forms.
- Shopify — the platform you connect, under its own terms.
We do not sell personal data and we do not show advertising.
What is public
Two things can be public, and only if you turn them on. A shared pitch kit is reachable by anyone with its link and shows the figures and evidence you chose to include. A verified badge, embedded on your own site, shows that your store is connected and synced; it never shows revenue.
Retention and deletion
Connected-platform data is kept while the connection is active and deleted when you disconnect. Your account and brand profile are kept until you ask us to delete them; email privacy@shelfwyze.com from your account address and we will delete everything within 30 days. Encrypted backups expire on their own schedule shortly after.
Local Food Finds
We also operate Local Food Finds, a consumer directory of small food brands, at /directory. It has no accounts. If you subscribe to its notifications we store the email address you give us and the filters you chose, and every email carries an unsubscribe link. Product submissions are public by design.
Changes
If we change what we read or keep, we update this page and the date at the top, and we tell account holders by email when the change affects data we already hold.