Shelfgrade

Legal

Privacy Policy

Last updated: August 31, 2026

What we collect

Your email address (for sign-in and team membership), the product feed files you upload, the domains you ask us to audit, and the audit results we generate. If you use citation monitoring, we also store the monitored domain, the queries you configure, and the check results. Payments are handled by Stripe; we store a payment session reference, never card details.

What we do with it

Feed data is used to run your audit and generate your artefacts — nothing else. We fetch your store's public pages (robots.txt, product pages) the same way search crawlers do. Uploaded feed content is deleted from the processing queue once your audit completes; audit results and generated artefacts are retained so you and your team can reopen them.

What we don't do

We don't sell data, we don't use your feed or results to train anything, and we don't share your data with third parties beyond the processors below.

Processors

Stripe (payments), Resend (sign-in and invite emails), and our hosting/database provider. If you use citation monitoring, your configured queries are sent to the monitored surfaces' official APIs (OpenAI, Perplexity, Google) to run the checks — the query text only, never your feed data or account details. Each processor receives only what it needs for its function.

Cookies

One essential cookie: your sign-in session (httpOnly, expires after 90 days or on sign-out). No advertising, tracking, or third-party cookies, and no cross-site anything.

Sharing you control

Report links are shareable by design: anyone with a report URL can view that report (they're unguessable and marked noindex). Workspace members see the workspace's audits and allowance. Owners can revoke member access at any time, effective immediately.

Deletion

Email support@shelfgrade.ai to delete your account, workspace, or any audit data and we'll do it. Removing a workspace member immediately ends their access.