Legal

Privacy Policy

How SnapShelf ("we", "us") collects, uses, stores, and protects personal data when merchants and visitors use SnapShelf in India.

Last updated

1. Overview & scope

This Privacy Policy applies to SnapShelf at snapshelf.org and related applications operated by SnapShelf from India.

We process personal data to provide the live shelf, merchant dashboard, QR storefront, and offer workflow. This policy should be read with our Terms of Service.

Merchant accounts are intended for shop operators and authorised staff. Public storefronts may be viewed without creating an account.

2. Merchant data vs buyer data

  • Merchant / staff data: account email, authentication identifiers, shop profile, staff linkage, dashboard activity, billing contact details, and content you upload.
  • Buyer / visitor data: name, phone number, offer amount, optional message, listing viewed, timestamps, and technical session data when interacting with a storefront.
  • We act as a data fiduciary / controller for Platform account and operational data. Merchants remain responsible for how they use buyer information offline after an offer is received.

3. Personal data we collect

  • Account & identity data: email address and authentication tokens via Supabase Auth.
  • Shop & listing data: store name, slug, optional location fields, photos, video, prices, grades, descriptions, and inventory status.
  • Offer & communication data: offer amounts, buyer name, phone number, interest level, notification delivery metadata.
  • WhatsApp data (if enabled): phone numbers and message delivery status needed for WhatsApp Business API alerts.
  • Device & technical data: browser type, IP address, device identifiers, push notification tokens (with permission), cookies or local storage needed for session operation, and security logs.

4. Purposes & legal bases

  • Provide, maintain, and improve the Platform (contract / service necessity).
  • Send in-app, push, email, or WhatsApp alerts you enable (consent or legitimate use for service communications).
  • Prevent fraud, abuse, and security incidents (legitimate interests and legal compliance).
  • Comply with law, respond to lawful requests, and enforce our Terms (legal obligation).
  • Generate aggregated, non-identifying analytics to improve reliability (legitimate interests).

5. When we share personal data

We do not sell your personal data.

  • Infrastructure and communication processors (e.g. Supabase, Vercel, Firebase for push, Meta for WhatsApp) process data on our behalf under contractual safeguards.
  • Public storefronts display listing media and shop branding you choose to publish. Private merchant account emails are not shown on public pages.
  • Merchants receive buyer offer details submitted through their storefront.
  • We may disclose information if required by law, court order, or government authority, or to protect rights, safety, and integrity of the Platform.

6. Retention

  • Active merchant account data is retained while your subscription or account remains active and as needed to provide the service.
  • Offer and notification records may be retained for merchant history, dispute resolution, and audit purposes, typically up to 24 months unless a longer period is required by law or an open complaint.
  • Security logs are retained for a limited period appropriate to incident investigation.
  • When you request account deletion, we will delete or anonymise personal data within a reasonable period, subject to legal retention obligations and backup cycles.

7. Security

We use reasonable technical and organisational measures including encrypted transport (HTTPS), access controls, and server-side validation. No method of transmission or storage is completely secure.

8. Your rights & choices

  • Merchants can update shop and listing information in the dashboard.
  • Push and WhatsApp alerts are optional and depend on device or channel permissions.
  • You may request access, correction, updating, or erasure of your personal data by emailing privacy@snapshelf.org.
  • You may withdraw consent for optional communications by disabling notifications or contacting us.
  • If you are unsatisfied with our response, you may escalate to our Grievance Officer (see below).

9. Grievance redressal (India)

In accordance with applicable Indian digital and data protection requirements, you may contact our Grievance Officer for complaints relating to this Policy or our handling of personal data:

Email: grievance@snapshelf.org

We aim to acknowledge grievances promptly and respond within 30 days, subject to complexity and legal requirements.

For postal correspondence, email legal@snapshelf.org and we will share our mailing address on request.

10. Children

SnapShelf is a business platform for shops and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe a minor has submitted data, contact privacy@snapshelf.org.

11. Cookies & similar technologies

  • We use essential cookies or local storage needed for authentication, session continuity, and security.
  • We may use analytics or performance logs to understand reliability and usage trends.
  • You can control browser cookies through your device settings; disabling essential cookies may affect login or dashboard functionality.

12. Cross-border processing

SnapShelf is operated from India. Your data may be processed in India and, where we use cloud providers, in other countries where those providers host infrastructure. We take reasonable steps to ensure appropriate safeguards for such processing.

13. Changes & contact

We may update this Policy from time to time. Material changes will be reflected in the "Last updated" date and, where appropriate, notified through the Platform.

Privacy questions or data requests: privacy@snapshelf.org

Grievance Officer: grievance@snapshelf.org

Questions? Contact us