1. Information We Collect
When you register a merchant account or interact with the ShelfOne POS platform, we collect information required to operate your retail workspace, process billing transactions, and maintain compliance:
- Account & Owner Credentials: Full name, business email address, verified phone/mobile number, and Firebase authentication credentials.
- Retail Shop & Entity Profile: Registered store name, business category, GSTIN (GST Identification Number), street address, city, state, postal PIN code, and storefront custom URL preferences.
- POS & Transactional Data: Product catalog items, SKU prices, stock inventory logs, customer purchase records, invoice totals, and payment method indicators (Cash, UPI, Card, Khata).
- Technical & Device Logs: IP address, browser type, operating system details, time zones, session tokens, and Cloudflare CDN access logs for DDoS prevention.
2. How We Use Your Data
We utilize the collected information strictly for operational, compliance, and product enhancement purposes:
- To provision your personalized POS dashboard, product catalog, and online store URL.
- To generate GST-compliant invoices, sales reports, and inventory stock alerts.
- To dispatch transactional email receipts, welcome announcements, and billing updates via Resend API.
- To facilitate customer Khata ledger tracking and balance due calculations.
- To protect our infrastructure against fraudulent access, unauthorized API calls, and cyber threats.
3. Data Security & Encryption
We enforce industry-standard security measures to safeguard your business and customer information against unauthorized access, loss, or alteration:
All API communications between your browser and our Cloudflare Workers edge nodes are encrypted using TLS 1.3 / HTTPS SSL protocols.
Store databases are hosted on NeonDB PostgreSQL with AES-256 encryption at rest, automated point-in-time backups, and strict row-level authorization.
4. Third-Party Service Providers
ShelfOne integrates with trusted infrastructure partners to deliver real-time POS services:
- Firebase Authentication (Google Cloud): Handles secure user sign-in, OAuth verification, and JWT token issuance.
- Cloudflare Workers & Edge CDN: Executes backend API routes, static asset caching, and global edge firewall protection.
- Resend API: Dispatches transactional email invoices, receipt copies, and account notifications.
- NeonDB PostgreSQL: Serverless cloud database provider storing merchant catalogs and order ledgers.
We never sell, rent, or monetize your retail store data or customer lists to third-party advertisers.
5. User Rights & Data Deletion
As a ShelfOne merchant, you retain full ownership of your data rights:
- Data Export: You can export your sales ledgers, SKU inventory, and customer databases to CSV format at any time from the Reports tab.
- Account & Store Deletion: You can request permanent shop profile and database purging through Settings or by contacting SuperAdmin. Upon approval, all records are permanently deleted from primary databases.
- Correction & Updates: You can update your shop details, address, owner contact number, and GSTIN anytime in Dashboard Settings.
6. Contact & Privacy Officer
If you have any questions or privacy concerns regarding this Privacy Policy, please contact our Privacy Team: