Legal

Privacy policy

Last updated: 29 September 2026

In short:

  • This website uses no cookies, no analytics and no ads, and loads nothing from third parties.
  • The app stores what it needs to work in your store: its settings, a copy of the public catalog and anonymous usage counters.
  • We don't collect personal data about your store's customers.
  • We don't sell data or share it with advertisers.

1. Who is responsible

Owner[Full name or company name]
Tax ID[NIF / CIF]
Address[Full postal address]
Contact[email protected]

In this policy, “InShelf”, “we” and “the app” refer to the owner and their InShelf – 3D Bookshelf Display app for Shopify. The Spanish version of this policy is the reference text.

2. Data processed by this website

The inshelf.app website is informational. It has no forms, asks for no sign-up and sets no cookies. The fonts and the demo's 3D engine are served from the same domain, so your browser doesn't connect to third parties when you visit it.

3. Data processed by the Shopify app

When a store installs InShelf, we store:

4. Data about store customers

InShelf doesn't collect personal data about store customers and doesn't request access to Shopify's protected customer data. Shopify adds the logged-in customer's ID to some requests; the app ignores it and never stores it. The cart uses the store's own tools: we don't see or store its contents. The bookshelf sets no cookies; it only saves the colors extracted from book covers in the browser's localStorage (key inshelf:colors:v1) so it loads faster next time. It contains no personal data.

If you're a customer of a store that uses InShelf, that store is responsible for your data. For any question, contact the store; it can contact us if needed.

5. Why we use data and on what legal basis

PurposeLegal basis (GDPR)
Providing the app: syncing the catalog, showing the bookshelf, applying the plan and designPerformance of the contract with the store (Art. 6(1)(b))
Billing through Shopify and managing the free trialPerformance of the contract and legal obligations (Art. 6(1)(b) and 6(1)(c))
Showing aggregated statistics to the storePerformance of the contract (Art. 6(1)(b))
Answering emails and providing supportLegitimate interest in handling your request (Art. 6(1)(f))
Technical server logs of the websiteLegitimate interest in the website's security (Art. 6(1)(f))

For the store's catalog, we act on the store's instructions. We don't use data for profiling, we make no automated decisions and we don't share it with anyone unless required by law.

6. Providers that help us

Some of these providers may process data outside the European Economic Area. When they do, they use the safeguards required by the GDPR, such as the EU-U.S. Data Privacy Framework or the European Commission's standard contractual clauses.

7. How long we keep data

8. Security

All traffic is encrypted with HTTPS. We verify the signature of the webhooks Shopify sends and of the requests that come through the store's app proxy. Access to the database is restricted.

9. Your rights

You can ask us to access, correct, delete or export your data, or to restrict or object to its use. Write to [email protected] saying which right you want to exercise; we'll reply within one month.

If you think we haven't handled your data properly, you can complain to the Spanish Data Protection Agency (aepd.es) or the authority in your country.

If you live in California (CCPA/CPRA), you have the right to know what personal information we collect and to ask us to delete it. We don't sell or share personal information.

10. Changes to this policy

If what we do with data changes, we'll update this page and its date. If the change is significant, we'll also announce it inside the app.