This policy explains how Shelvly handles personal data for shared pantry and home food stock management. It is designed to support GDPR-style privacy rights and may be updated as the service evolves.
Shelvly is a pantry and home food stock management app for households, families, and caregivers. Data Controller: Newlux Multiservice LDA. Address: Tete City, Tete 2301, Mozambique. Contact: support@shelvly.app.
2. What data we collect
We collect only the data needed to create accounts, keep pantries in sync, support shared access, and keep the service safe.
Account data: email address, full name, and avatar URL if provided through Google login.
Authentication data: user id, session information, login provider, and Supabase Auth state.
Preferences: language, theme, onboarding or guide preferences, install/home-screen preference, and cookie preference choices.
Activity data: actions such as item, shopping list, task, recipe, invite, member, or pantry changes visible to relevant pantry members.
Technical data: device/browser details, IP address, request logs, or deployment logs if collected by hosting or infrastructure providers.
Cookies, localStorage, sessionStorage, and similar technologies used for auth, preferences, and app functionality.
3. Why we use data
We use data for clear service purposes and avoid using pantry content for unrelated purposes without a lawful basis.
Create and manage user accounts.
Provide pantry, shopping list, tasks, recipes, expiry, and restocking features.
Save and sync user content and uploaded images across devices.
Enable shared pantry access, member roles, and invitations.
Keep users signed in and protect authenticated routes.
Improve security, prevent abuse, and investigate service issues.
Provide support and respond to privacy requests.
Maintain, improve, and comply with legal obligations for the service.
4. Legal bases under GDPR
Where GDPR applies, Shelvly relies on appropriate legal bases depending on the purpose of processing.
Contract: to provide the Shelvly service users request.
Consent: for optional cookies or marketing where consent is needed.
Legitimate interests: security, fraud prevention, debugging, and service improvement that does not override user rights.
Legal obligation: where applicable, such as responding to valid legal requests or keeping required records.
5. How shared pantry data works
Shelvly is collaborative. If a pantry is shared, other members or viewers may see pantry items, notes, expiry dates, and activity depending on their role.
Pantry owners should invite only the correct people and review roles carefully.
Members and viewers may see pantry content and activity depending on access level.
Users should avoid entering highly sensitive personal information in pantry names, item names, descriptions, or notes.
6. Third-party service providers and processors
We use verified service providers to deliver Shelvly: Supabase for authentication, database, storage, and related backend services; Vercel for hosting, deployment, web analytics, and performance insights; and Resend for transactional email. These providers may process data only to deliver the service, subject to their agreements and applicable safeguards.
Supabase: authentication, database, storage/session management, and related backend services.
Vercel: hosting, deployment, edge/network delivery, technical logs, Web Analytics, and Speed Insights.
Google: OAuth login only if a user chooses Continue with Google; Google may provide name, email, and avatar.
Email/password login: users provide email and password credentials; passwords are handled by Supabase Auth and are not displayed in the Shelvly UI.
Email delivery providers may be used for invites, password emails, or account messages when configured for the service.
7. Analytics and performance measurement
We use Vercel Web Analytics to understand how visitors use Shelvly, such as which pages are viewed and how the website is used. Vercel Web Analytics is designed to provide aggregated usage insights without using third-party cookies.
We may also use Vercel Speed Insights to measure website performance, including Core Web Vitals and technical performance information such as route, browser, device type, country-level location, network type, and performance metrics.
We may collect privacy-safe product interaction events, such as when users create a pantry, add an item, use the shopping list, or interact with the web app installation prompt. These events do not include pantry item names, shopping list contents, invite emails, private notes, or uploaded images.
We use this information to improve Shelvly, fix issues, understand product usage, and improve performance.
We do not use these tools to collect pantry names, pantry item names, shopping list contents or item names, invite email addresses, private notes, household or member private content, uploaded images, or exact user identity in analytics events.
Service provider: Vercel Inc. For privacy or data protection requests, contact us at support@shelvly.app.
8. International data transfers
Data may be processed by providers with infrastructure outside the user’s country. We avoid overpromising where provider locations can change.
Providers may process or store data in regions outside Portugal, Mozambique, the EU, or the user’s country.
Where GDPR applies, transfers should rely on appropriate safeguards such as standard contractual clauses or equivalent provider safeguards where available.
We will update this policy if data hosting or important provider arrangements materially change.
9. Data retention
We keep data for as long as needed to provide the service, support security, meet legal obligations, or complete deletion workflows.
Account data is retained while the account is active unless deletion is requested and completed.
Pantry data is retained while the user account, pantry, or shared pantry membership exists.
Backup copies may remain for a limited period after deletion as part of our security, recovery, and service-continuity processes. They are not used for ordinary product access and are removed or overwritten according to the retention practices of our service providers.
Invites and activity logs may be retained for security, audit, and abuse prevention unless deleted according to the final retention policy.
10. User rights
Where GDPR-style rights apply, users can request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Portuguese users may complain to CNPD, the Portuguese supervisory authority.
Access a copy of personal data we process.
Rectify inaccurate or incomplete data.
Request deletion of account and pantry data where available and lawful.
Restrict processing in certain circumstances.
Object to processing based on legitimate interests.
Request portability of data in a commonly used format where technically feasible.
Withdraw consent for optional processing without affecting previous lawful processing.
Complain to a supervisory authority, including CNPD for Portugal.
11. Children
Shelvly is not intended for children under 16 unless use is allowed with appropriate guardian consent under applicable law. If we learn that a child has used the service without the required consent, we will take appropriate steps.
12. Security
We design Shelvly with practical security measures, but no online service can guarantee absolute security.
Supabase Auth supports account login and session management.
Protected routes limit access to authenticated areas.
Access controls and roles help separate pantry owners, members, and viewers.
Row-level security is used in Supabase to restrict database access.
HTTPS encrypted transport protects data in transit.
Users should protect their accounts and report suspicious access.
13. Changes to this policy
This policy may be updated as the service evolves, including when important product features, analytics, payments, or providers change.
14. Contact
For privacy or data protection requests, contact us at support@shelvly.app. Data Controller: Newlux Multiservice LDA. Address: Tete City, Tete 2301, Mozambique.