Skip to content
ShelfTonight

ShelfTonight · /privacy

Privacy Policy

What we collect and why.

Last updated August 28, 2026

Who this is for

This policy explains what ShelfTonight collects when you visit shelftonight.com, pay as a guest, create a buyer account, or open a shop.

Accounts

Shop owners: name of the shop, shop_code (slug of the name), store location (street, city, state, ZIP, country — that city is the public town, and that street is ship-from and pickup), email, password hash, phone, fulfillment choices, Stripe Connect account id, and what you type on the desk.

Buyer accounts (optional): email, password hash, name if you give one, a saved ship-to if you save one, and orders we attach to you. Guest checkout does not create an account unless you ask us to save it afterward. Guests can look up a paid order at /orders with the checkout email and the order id; we only show the receipt when both match.

Photos

Shops upload photos of inventory. Those photos become public on that shop’s /s/{shop_code} page when an item is listed. Staff bots (Sort, Name, Card, Tag, Price) draft names and flags from notes and sticker OCR. There is no OpenAI / Grok / vision API in the website. We do not use shop photos as a stock library for other shops.

Payments via Stripe

Checkout runs on Stripe. Stripe processes the card, Apple Pay, or PayPal. We store order amounts, Stripe session or payment ids, and the contact you typed (name, email, phone, ship-to). We do not store full card numbers on ShelfTonight’s servers.

Logs and hits.jsonl

Every live search, including logged-out search, can append a line to hits.jsonl for that shop and for the site. Item views and checkout starts can append to activity logs. These are server files used to run and debug the product, not a public people-search.

Emails

When a buyer pays, we email the shop immediately (from hello@shelftonight.com) and send the buyer a receipt — we do not wait for a human to approve those. We also remind the shop at 48 hours if they have not sent a ship-to order or marked pickup ready, and we alert them again if they still have not. Daily sales notes and magic-link sign-in mail also go out when we can send. Support, refunds, and other Notify lines can stay drafts until a human sends them. We do not sell your email list.

Cookies

We use essential cookies to keep a shop owner signed in (st_owner), a founder ops session (st_admin), and, if you create a buyer account, to keep you signed in (st_buyer). Better Auth may set its own session cookie for the owner desk. These are needed for login. We do not use advertising cookies or a third-party analytics pixel. Because we do not use non-essential tracking cookies, there is no separate cookie-banner product here.

How long, and your choices

Orders, photos, and logs stay as long as the shop and this product need them to show a catalog, a packing slip, or a refund history. You can ask us to close a buyer account or a shop by writing support@shelftonight.com. We may keep records we need for payments, fraud, or the law.

Contact

Privacy questions: support@shelftonight.com. hello@shelftonight.com is the same inbox. We are ShelfTonight, operating shelftonight.com.