Privacy Policy

Last updated: July 23, 2026

1. Who we are

Doc2Shelf (“we”, “us”) provides a software service that turns supplier product documents into draft marketplace listings and compliance-related content, and can publish those listings to e-commerce platforms you connect (“Service”), available at doc2shelf.com. Doc2Shelf is the controller of the personal data described in this policy. For any privacy matter, contact us at info@doc2shelf.com.

2. Data we collect

  • Account data — email address, name, and optional avatar, provided when you register (directly or via Google sign-in). Authentication is handled by our hosting provider’s identity service; we never see or store your password.
  • Documents and content — the supplier PDFs you upload, the product data extracted from them, and the listings, declarations, translations, and images generated or attached in your workspace.
  • Store connections — when you connect a Shopify, WooCommerce, or eBay store, we store the platform’s shop identifier and the OAuth access tokens needed to publish on your behalf. Tokens are encrypted at rest.
  • Billing data — your subscription plan, billing period, and payment references. Card payments are processed by Stripe; Shopify-billed subscriptions are processed by Shopify. We never receive or store card numbers.
  • Usage and technical data — monthly usage counters (documents processed, AI generations, published listings), server logs, IP addresses used for rate limiting and abuse prevention, and error reports.

3. How we use your data

We process personal data to:

  • Provide the Service: store your documents, run extraction and generation, and publish listings to stores you connected (performance of contract).
  • Bill your subscription and prevent fraud and abuse (performance of contract; legitimate interest).
  • Keep the Service secure, rate-limited, and reliable, and debug errors (legitimate interest).
  • Communicate with you about your account, critical technical matters, and changes to the Service (performance of contract).

We do not sell personal data and we do not use it for third-party advertising.

4. AI processing of your documents

To extract product data and draft listings, declarations, and translations, the content of the documents you upload is processed by third-party large-language-model providers (currently Google’s Gemini API) acting as our processors. Under the API terms we rely on, submitted content is not used to train the provider’s models. Only document and product content is sent for generation — not your account credentials or billing data.

AI outputs are automated drafts. As set out in our Terms of Service, you are responsible for reviewing them before use.

5. Who we share data with

We share data only with the processors needed to run the Service:

  • Cloud hosting, database, storage, and authentication (Supabase).
  • Payment processing (Stripe) and, for Shopify-billed subscriptions, Shopify.
  • E-commerce platforms you explicitly connect (Shopify, WooCommerce, eBay) — we send them the listing content you choose to publish.
  • AI generation (Google Gemini API) and, when you use image search, image search providers (Google Programmable Search, Serper).
  • Error monitoring (Sentry).

Some providers process data outside the EU/EEA. Where they do, transfers are covered by the European Commission’s Standard Contractual Clauses or an adequacy decision.

6. Shopify merchants and their customers

When you use Doc2Shelf as a Shopify app, we access only product, publication, location, and inventory data of your store. We do not request or receive your customers’ personal data or order data. We honor Shopify’s mandatory privacy webhooks: on a shop-data erasure request, all data connected to that shop is deleted, and customer-data requests are answered with the (empty) set of customer data we hold.

7. Retention and deletion

We keep your data for as long as your account exists. You can export your data and delete your account directly in the app; deletion cancels billing references, purges your uploaded files and generated content, and removes your identity record. Residual copies in encrypted backups expire on the backup rotation schedule. Some billing records are retained where tax or accounting law requires it.

8. Your rights

Under the GDPR (and similar laws elsewhere), you have the right to access, rectify, export, restrict, object to the processing of, and erase your personal data, and the right to lodge a complaint with your supervisory authority. The in-app export and account-deletion functions cover the most common requests; for anything else, email info@doc2shelf.com.

9. Security

All traffic is encrypted in transit (TLS with HSTS). Store-connection tokens are encrypted at rest, database access is restricted with row-level security, and payment card data never touches our systems. No internet service can guarantee absolute security, but we design for least privilege and defense in depth.

10. Cookies and local storage

The app uses browser local storage strictly for essential purposes: keeping you signed in and remembering interface preferences (such as language). We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics scripts on your browser.

11. Children

The Service is a business tool and is not directed at children under 16. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy as the Service evolves. Material changes are announced in the app or by email before they take effect. The date above always reflects the latest revision.