Skip to main content
Shelf Talker
Shelf Talker
Wineries Breweries Distilleries Retailers Distributors Pricing Blog
Join Waitlist
  • Wineries
  • Breweries
  • Distilleries
  • Retailers
  • Distributors
  • Pricing
  • Blog
  • What is a Shelf Talker?
Shelf Talker
  • Interpretation and Definitions
  • Interpretation
  • Definitions
  • Acknowledgment
  • Related Agreements
  • Where the Service is Offered
  • Collecting and Using Your Personal Data
  • Types of Data Collected
  • Use of Your Personal Data
  • Legal Bases for Processing (EEA / UK Residents)
  • Sharing of Your Personal Data
  • Personal Information Table
  • Your Privacy Rights
  • Updating and Deleting Your Personal Information
  • Deleting Your Account and Your Data
  • Cookies and Similar Technologies
  • Retention of Your Personal Data
  • Transfer of Your Personal Data
  • Disclosure of Your Personal Data
  • Business Transactions
  • Law enforcement
  • Other legal requirements
  • Data Security
  • Breach Notification
  • Detailed Information on the Processing of Your Personal Data
  • Analytics
  • Payments and Subscription Management
  • Hosting
  • Email Delivery
  • Customer Support
  • Sign-In Providers
  • Importing Images
  • Email Marketing
  • Children's Privacy
  • Links to Other Websites
  • Changes to this Privacy Policy
  • Governing Law
  • Disputes Resolution
  • United States Legal Compliance
  • Severability
  • Waiver
  • Translation Interpretation
  • Accessibility
  • Contact Us

Shelf Talker LLC Privacy Policy

Effective Date: August 16, 2026 | Last Updated: August 16, 2026 | Version: 1.0

Please read this Privacy Policy carefully so You understand how We handle Your information.

This Privacy Policy describes Our policies and procedures on the collection, use, and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

The Company uses Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

"Account" means a unique account created for You to access our Service or parts of our Service.

"Agreement" means this Privacy Policy, to be used in conjunction with our Subscription Agreement, User Agreement, and License Agreement, that form the entire agreement between You and the Company regarding the use of the Service.

"Application" means the software program provided by the Company that is downloaded by You on any electronic device, named Shelf Talker.

"Company" (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to Shelf Talker LLC, a Michigan Limited Liability Company.

"Cookies" are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.

"Device" means any device that can access the Service such as a computer, smartphone, or a digital tablet.

"Personal Data" / "Personal Information" both refer to any data that identifies, relates to, describes, or could be reasonably linked with a particular consumer, household, or business.

"Sale" refers to the exchange of personal information for monetary or other valuable consideration (e.g., selling a mailing list or data broker activities).

"Sensitive Personal Information" refers to specific types of consumer data that warrant heightened legal protection against identity theft or unauthorized disclosure.

"Service" refers to the mobile application software program, Shelf Talker, designed to be downloaded, installed, and operated on handheld wireless communication devices such as smartphones or tablets and all the content, services, or features the user can access within the software application and the shelftalkerapp.com Website.

"Service Provider" means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service, or to assist the Company in analyzing how the Service is used.

"Share" refers specifically to disclosing personal information to a third party for cross-context behavioral advertising (interest-based advertising or retargeting), regardless of whether money changes hands.

"Usage Data" refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

"You" means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

Acknowledgment

This is an Agreement that acknowledges the use of data as related to this Service and the conditions that operate between You and the Company. This Agreement sets out the rights and obligations of all users regarding the use of the Service.

You must be at least 18 years of age to use the Service.

Your access to and use of the Service is conditioned on Your acknowledgement that you have read this Privacy Policy. This Agreement applies to all visitors, users, and others who access or use the Service.

By accessing or using the Service, You acknowledge that you have read this Privacy Policy. If You disagree with any part of this Agreement, then You may not access the Service.

When checking the "acknowledgement box", You confirm You have read and are consenting to all terms of this Agreement. By continuing to use the Mobile App and Service, You are acknowledging that you have read the most updated Agreement, even if You have not clicked an acknowledgement box for the most recent version if non-material changes were made.

Related Agreements

Your access to and use of the Service is also conditioned on Your acceptance of and compliance with the following, which together with this Privacy Policy form the Service Terms:

  • User Agreement – describes Our policies and procedures on the rules, user rights, obligations, and restrictions when You use the Service or Website.
  • License Agreement – describes Our policies and procedures on the capacity, use, and allowance of Your interaction with, ownership in, and ability to navigate the Service or Website.
  • Subscription Agreement – describes Our policies, procedures, and terms governing the subscription levels, pricing, free trials, billing, automatic renewal, price changes, cancellation, and refunds.

Please read each of them carefully before using Our Service.

Where the Service is Offered

The Service is offered in the United States only. We do not offer, market, or sell the Service outside the United States, and the Mobile App is listed only on the United States App Store and Google Play storefronts. If You are located outside the United States, the Service is not offered to You and You should not create an Account.

We expect to extend the Service to other countries over time. Until We do, any protection described in this Policy that arises under the law of another country – including the European Union, the United Kingdom, Switzerland, Canada, Australia, and New Zealand – is offered voluntarily, and does not indicate that We offer the Service in that country. We would rather give every user those protections than withhold them from anyone the law happens to cover.

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information We collect includes, but is not limited to:

  • Identifiers and Customer Records: email address; first name and last name; profile photo depending on your login method
  • Commercial information: subscription data and transaction data (see the Subscription Agreement for more information)
  • Internet activity: Usage Data and cookies (see below for more information)
  • Geolocation: general, not precise - including approximate location derived from IP by website analytics, and the State and Country entered voluntarily by You as the user
  • Professional: company or business name associated with the Account
  • Sensitive Personal Information: Account log-in credentials (password stored hashed). Specifically not collected: precise geolocation, racial or ethnic origin, religious beliefs, union membership, health, sex life or orientation, genetic data, or biometric data for unique identification.

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.

We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.

Use of Your Personal Data

The Company may use Personal Data for the following purposes:

  • To provide and maintain Our Service, including to monitor the usage of Our Service.
  • To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
  • For the performance of a contract: the development, compliance, and undertaking of the purchase contract for the products, items, or services You have purchased or of any other contract with Us through the Service.
  • To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
  • For marketing communications: We may send You marketing emails about new features, promotions, and educational content related to the Service. For more information, see the Email Marketing section within the Detailed Information on the Processing of Your Personal Data heading found below.
  • To manage Your requests: To attend and manage Your requests to Us.
  • For business transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.
  • To analyze Our Service : We may use Your information to monitor Our Service, such as data analysis, identifying usage trends, determining the effectiveness of Our promotional campaigns. and to evaluate and improve Our Service, products, services, marketing, and Your experience.

If a new purpose for using Your personal data should arise, We are committed to obtaining Your consent for any new purpose before that new purpose goes into effect.

Legal Bases for Processing (EEA / UK Residents)

For each purpose, We rely on one of the following lawful bases under GDPR Art. 6 / UK GDPR Art. 6:

PurposeLawful Basis
Provide and maintain the ServiceArt. 6(1)(b) — performance of a contract
Manage Your AccountArt. 6(1)(b) — performance of a contract
Process paymentsArt. 6(1)(b) — performance of a contract
Customer supportArt. 6(1)(b) — performance of a contract
Marketing emails to existing users (soft opt-in)Art. 6(1)(f) — legitimate interests + opt-out
Marketing emails to new prospectsArt. 6(1)(a) — consent
Cookies / similar tech (non-essential)Art. 6(1)(a) — consent (via cookie banner)
Security, fraud prevention, abuse monitoringArt. 6(1)(f) — legitimate interests
Analytics & service improvementArt. 6(1)(f) — legitimate interests
Compliance with legal obligationsArt. 6(1)(c)
Business transfers / due diligenceArt. 6(1)(f) — legitimate interests

Footnotes for the table:

  • Where We rely on legitimate interests, We have balanced those interests against Your rights and freedoms. You may object to processing based on legitimate interests at any time by contacting privacy@shelftalkerapp.com.

Sharing of Your Personal Data

The Company does not sell, rent, or share Your personal information with third-parties except as required by law or to provide Our Services (such as with trusted service providers who assist Us in operating the Service). The Company will never sell, rent, or share Your personal information with a third party for money, advertising, or other valuable consideration.

We may share Your personal information in the following situations:

  • With Service Providers: to monitor and analyze the use of Our Service, for payment processing, or to contact You.
  • For business transfers: in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
  • With other members of Your Team: if You belong to a Pro + Team Subscription, Your name and email address are visible to other members of Your Team, and content You place in the Team's shared library - including Product Sheets or Designs shared with the Team and the Team's Brand Kits - is visible to and usable by them.
  • With Your consent: for any other purpose with Your consent.

Personal Information Table

For more information regarding the type of personal information, how We obtain it, why we gather that information, and the external entities or categories of organization We disclose that information to, see the Personal Information Table below:

Category of Personal InformationCategories of SourcesBusiness / Commercial PurposeCategories of Recipients (Third Parties)
Identifiers & Customer Records (CCPA § 1798.140(v)(1)(A)–(B)) — email; first & last name; profile photo; internal Account ID; authentication tokens; single-sign-on Account IDs (Google sub, Microsoft object ID, Apple sub)Directly from You at registration; from Your sign-in provider when You use Google / Microsoft / Apple (name, email, photo); generated by Us (Account ID, tokens)Create, authenticate, and secure Your Account; display Your profile; Account recovery; show Your name and email to Your TeamHosting & database (Microsoft Azure, US); Stripe (email + name on the billing customer); Resend (email and name, to send Account and transactional emails); Jira Service Management / Atlassian (email and name when You contact support); other members of Your Team. With Sign in with Apple, Apple may relay a private proxy email instead of Your real address.
Commercial Information (§ 1798.140(v)(1)(D)) — subscription plan, status & platform; Stripe customer and subscription IDs; Apple and Google transaction IDs; Team Seat counts; billing dates & subscription-event history; Designs-saved count & storage used. We do not store card numbers.Generated when You purchase or manage a subscription; webhooks from Stripe (web) and RevenueCat (in-app); usage counts measured by UsProcess and manage Your subscription; gate paid features; enforce storage quotas; internal revenue reportingStripe (web payments — also receives Your card data directly, which We never see); Apple App Store and Google Play (in-app purchases); RevenueCat (in-app-purchase tracking, keyed to Your internal Account ID); hosting & database
Internet or Other Electronic Network Activity (§ 1798.140(v)(1)(F)) — usage data; IP address; device and browser type and identifiers; pages viewed and session data; sign-in timestamps (last login/active); server logs; website analytics eventsCollected automatically from Your device or browser when You use the Website or AppOperate and secure the Service; detect and prevent fraud and abuse (e.g., login rate-limiting); measure and improve the Service; website conversion analyticsGoogle Analytics via Firebase — website only (device and browser identifiers, approximate IP-derived location, events); Apple App Store and Google Play (store-level performance metrics). The mobile app uses no analytics SDK; server logs remain internal.
Geolocation Data — general, not precise (§ 1798.140(v)(1)(G)) — business country and U.S. state (free-text country if "Other"); approximate location derived from IP by website analyticsSelected by You in Your profile (country and state); derived from IP by website analytics. We do not collect precise/GPS location.Currency and pricing localization; regional and tax compliance; website analyticsHosting and database; inferred currency passed to Stripe; approximate location to Google Analytics (website)
Professional or Employment-Related Information (§ 1798.140(v)(1)(I)) — business or company name; Team name; Your role within a Team (owner/admin/member)Entered by You (business name, Team name); set when You create or are invited to a TeamBusiness context; Team collaboration and role-based accessHosting and database; business name on the Stripe billing record; other members of Your Team
Sensitive Personal Information (§ 1798.140(ae)) — Account log-in credentials: password (stored hashed) and authentication,refresh, and handoff tokens (encrypted). We do NOT collect precise geolocation, racial or ethnic origin, religion, union membership, health, sex life or orientation, genetic, or biometric data.Password set by You; tokens generated by UsAuthenticate You and secure Your session; used only as necessary to perform the Service (no Sensitive Personal Information is used to infer characteristics — § 1798.121)Hosting and database only — not shared

Footnotes for the table:

  • "Hosting & database" refers to Microsoft Azure (United States), where the Service is hosted.
  • The third parties listed are service providers that process data on Our behalf under contract. We do not sell, rent, or share Your personal information for money or for cross-context behavioral advertising.
  • Sign in with Apple may relay a private proxy email address instead of Your real address; if You choose this, We never receive Your real email.
  • Feedback You submit may be displayed publicly together with a display name only if You give explicit consent.
  • Card and bank details are handled directly by Stripe, Apple, or Google; the Company never receives or stores them.

Your Privacy Rights

Depending on where You reside, applicable law gives You rights regarding the personal information We collect about You. We honor the rights described below regardless of jurisdiction; where Your local law provides additional or stronger rights, We will honor those to the extent required by law. We will not discriminate against You for exercising any of these rights.

Rights Available to All Users

  • Access: request a copy of the personal information We hold about You.
  • Correction: request that We correct inaccurate or incomplete personal information.
  • Deletion: request that We delete personal information We hold about You. We may retain limited information to comply with legal obligations, resolve disputes, prevent fraud and abuse, complete a transaction You requested, and enforce our agreements; where We do, We will explain why.
  • Portability: receive Your personal information in a structured, commonly used, machine-readable format.
  • Opt-out of marketing: at any time, by clicking the unsubscribe link in any marketing email or contacting privacy@shelftalkerapp.com.
  • Withdraw consent: where We rely on Your consent, You may withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Additional Rights for California Residents (CCPA / CPRA)

  • Right to Know (Cal. Civ. Code § 1798.100, § 1798.110, § 1798.115): categories and specific pieces of personal information collected, categories of sources, business or commercial purposes, and categories of third parties to whom We disclose, sell, or share Your personal information.
  • Right to Delete (§ 1798.105): subject to enumerated statutory exceptions.
  • Right to Correct (§ 1798.106).
  • Right to Opt-Out of Sale or Sharing (§ 1798.120): We do not sell or share Your personal information as those terms are defined under the CCPA. We nonetheless honor the Global Privacy Control (GPC) signal as an opt-out of sale and sharing should our practices ever change. You may also use the "Do Not Sell or Share My Personal Information Information" link at the footer of every page of the Website.
  • Right to Limit Use of Sensitive Personal Information (§ 1798.121).
  • Right to Non-Discrimination (§ 1798.125).
  • Authorized Agents (§ 1798.135(c)).
  • Before fulfilling certain requests We will verify Your identity (CCPA Regs §§ 7060–7063).
  • "Shine the Light" (Cal. Civ. Code § 1798.83): California residents may request a list of third parties to whom We have disclosed personal information for those third parties' direct marketing purposes in the prior calendar year. We do not share personal information for third-party direct marketing.

Additional Rights for EEA / UK Residents (GDPR / UK GDPR)

  • Articles 15–22: access, rectification, erasure, restriction of processing, portability, objection (including to direct marketing), and right not to be subject to a solely automated decision producing legal or similarly significant effects.
  • Right to withdraw consent at any time (Art. 7(3)) where We rely on consent.
  • Right to lodge a complaint with Your supervisory authority — find Yours via the European Data Protection Board or, in the UK, the Information Commissioner's Office.
  • Representative (Art 27): none is appointed, because the Service is not offered in the EEA or the UK - see "Where the Service is Offered" above. Should We begin offering the Service in those territories, We will appoint representatives and name them here before doing so.
  • The lawful basis for each purpose is described in the "Legal Bases for Processing" section above; where We rely on legitimate interests under Art. 6(1)(f), We have conducted a balancing test and will provide details upon request.

Additional Rights for Canadian Residents (PIPEDA & Quebec Law 25)

  • Access (PIPEDA Principle 4.9), challenge accuracy (4.9.5), withdraw consent (4.3.8).
  • Quebec residents: right to be informed of automated decision-making (Quebec Law 25 art. 12.1), right to data portability (art. 27), right to deindexation / cessation of dissemination (art. 28.1).
  • Quebec Privacy Officer: privacy@shelftalkerapp.com.

Additional Rights for Australian Residents (Privacy Act 1988 / APPs)

  • Access (APP 12) and correction (APP 13).
  • Right to deal with Us anonymously or pseudonymously where lawful and practicable (APP 2).
  • Right to complain about Our handling of personal information — internally via privacy@shelftalkerapp.com, or to the Office of the Australian Information Commissioner.

Additional Rights for New Zealand Residents (Privacy Act 2020 / IPPs)

  • Access (IPP 6) and correction (IPP 7).
  • Right to complain to the Office of the Privacy Commissioner.

How to Exercise Your Rights

Email privacy@shelftalkerapp.com with the subject line "Privacy Rights Request" and include the email associated with Your Account and the right You wish to exercise. We will respond within 45 days (CCPA) / 30 days (GDPR, PIPEDA, Australia, New Zealand); where reasonably necessary, We may extend by an additional 45 days with notice to You. You may also submit requests through the Profile page within the Mobile App.

How We Verify Your Requests

To protect Your information, We will verify Your identity before We act on a request to know, delete, or correct Your personal information. We do not require verification to opt out of the sale or sharing of personal information or to limit the use of Sensitive Personal Information. We have established and documented a reasonable method for verifying identity, and We will use information already in Our possession to verify You wherever feasible.

  • If You have an Account: We verify You through Your existing Shelf Talker login. You may be asked to sign in again (re-authenticate) before We disclose, delete, or correct Your information. If We detect suspicious or potentially fraudulent activity on an Account, We may decline the request and require additional verification.
  • If You do not have an Account (or contact Us by email): for a request to know the categories of personal information We hold, We will ask You to provide information that We can match to at least two reliable data points in Our records. For a request to know the specific pieces of personal information We hold, We will ask You to match at least three data points and to provide a signed declaration, under penalty of perjury, that You are the consumer whose information is the subject of the request. For deletion and correction requests, the level of verification We require depends on the sensitivity of the information and the risk of harm.
  • Authorized agents: You may use an authorized agent to submit a request. We may require the agent to provide proof that You gave them signed permission, and We may require You to verify Your own identity directly with Us or to confirm directly that You authorized the agent. We will not require this where the agent holds a valid power of attorney, and We will never require You to provide a power of attorney in order to use an authorized agent.

Any information We ask for solely to verify Your identity is used only for verification and fraud prevention and is deleted afterward. We do not charge a fee to verify Your request. If We cannot verify Your identity to the degree of certainty the law requires, We will not be able to fulfill the request, and We will explain why in Our response.

Updating and Deleting Your Personal Information

You may access and update Your personal information at any time through the Profile page within the Mobile Application or by contacting Our team at privacy@shelftalkerapp.com. Our support team can also be reached through the contact us button located on the Profile page within the Mobile Application.

We collect only the necessary and essential personal information needed to operate and maintain the Service. The only required personal data collected is Your first and last name and the email address associated with the Account. To delete this information will require You to delete Your Account. You may delete Your Account through the Profile page within the Mobile Application or by contacting Our support team at support@shelftalkerapp.com. Our support team can also be reached through the contact us button located on the Profile page within the Mobile Application.

The Company also collects a limited amount of non-essential personal information that allows Us to greatly improve the Service. This non-essential information is:

  • Country and State: to monitor the laws and regulations of that region so We can provide Designs within Our Service that meet those requirements.
  • Company associated with the Account: so We can recognize the businesses supporting Us and reduce the amount of Shelf Talker marketing those businesses are subjected to.

You may opt out of or delete non-essential information at any time through the Profile page within the Mobile Application or by contacting Our support team at privacy@shelftalkerapp.com.

The Company will notify You through the email attached to the user Account, and by a notification within the Mobile Application, at least 30 days prior to any changes in the personal information collected or to this Policy.

There is no discrimination in a Subscriber's ability to use Our Service based on the essential and non-essential personal information collected. Our Company has no financial incentive to collect your personal information.

Deleting Your Account and Your Data

You may delete Your Account, and the personal data associated with it, at any time. You can do this yourself from the Profile page of the Mobile Application, under "Danger sone" -> "Delete Account". You may also request deletion without using the app - including if You have uninstalled it - by following the instructions at shelftalkerapp.com/delete-account or by emailing support@shelftalkerapp.com.

Deletion covers Your profile, Your saved Designs and their generated files, Your folders and favorites, Your Brand Kits, Your Product Sheets, Your uploaded images, and Your share Collections.

When deletion is confirmed, Your Account is deactivated immediately and Your data is held for a 90-day grace period before it is permanently erased, so that an accidental deletion can be undone. You may ask Us to erase Your data immediately instead of waiting out that period.

Please note that deleting Your Account does not cancel a paid Subscription. Subscriptions purchased through the Apple App Store or Google Play must be cancelled in those stores; Subscriptions purchased on Our Website can be cancelled on the Website or by contacting Us.

After erasure We retain only those records We are legally required to keep, principally billing and transaction records held to satisfy tax and accounting obligations, together with a record of the deletion request itself.

Cookies and Similar Technologies

What We Use

  • Strictly necessary cookies and storage — required to operate the Service (e.g., authentication, security). Always on.
  • Analytics cookies — measure usage to improve the Service (e.g., Google Analytics). Set only after You consent.

We do not use advertising or cross-context behavioral advertising cookies, and We do not use functional or preference cookies.

Your Choices

  • Cookie banner: the first time You visit shelftalkerapp.com We display a cookie banner, from any region, that lets You accept all or reject analytics cookies. We set no non-essential cookies before You give consent (UK PECR Reg. 6; EU ePrivacy Art. 5(3)).
  • Change Your mind: use the "Cookie references" link in the footer of every page at any time. Selecting "Reject" turns analytics off and removes its cookies.
  • Browser controls: You can clear or disable cookies in Your browser settings.
  • Global Privacy Control (GPC): We honor GPC signals as a valid opt-out of "sale" or "share" for California consumers (CCPA Regs § 7025). A GPC signal applies to the browser or device from which it is sent; where You are logged in to Your Account, We will also apply Your opt-out to that Account.
  • Do Not Track (DNT): because there is no industry-standard response to browser DNT signals, We do not respond to them. We instead offer meaningful choice through our cookie banner and by honoring the Global Privacy Control (GPC) signal as described above. (CalOPPA disclosure under Cal. Bus. & Prof. Code § 22575(b)(5).)

Cookies in Use

A complete list of cookies in use, including provider, purpose, and duration, is available in the table below:

Cookie / TechnologyProviderPurposeDurationCategory
_gaGoogle Analytics (via Firebase)Distinguishes unique visitors to measure website traffic and usage on shelftalkerapp.com.2 yearsAnalytics (non-essential)
_ga_<stream-id>Google Analytics (via Firebase)Persists Google Analytics 4 session state.2 yearsAnalytics (non-essential)
.AspNetCore.ExternalSchemeShelf Talker (ShelfTalker API)Temporarily holds sign-in state during Google, Microsoft, or Apple OAuth sign-in. Deleted immediately after sign-in completes.Session (transient)Strictly necessary
__stripe_midStripeFraud prevention during checkout. Set on checkout.stripe.com when you start a subscription (Shelf Talker redirects to Stripe-hosted checkout).1 yearStrictly necessary
__stripe_sidStripeFraud prevention during a checkout session. Set on checkout.stripe.com.30 minutesStrictly necessary
shelfTalkerSite.accessToken, shelfTalkerSite.refreshTokenShelf Talker (first-party)Keeps you signed in to the web portal. Stored in browser local storage, not a cookie.Until sign-out / clearedStrictly necessary (local storage)
shelfTalkerSite.postLoginRedirect, shelfTalkerShare.accessToken.*Shelf Talker (first-party)Holds navigation state during login and temporary access to password-protected share links. Stored in browser session storage.Session (cleared when the browser tab closes)Strictly necessary (session storage)
shelfTalker.accessToken, shelfTalker.refreshTokenShelf Talker (first-party)Keeps you signed in within the mobile app. Stored in the app's web-view local storage.Until sign-out or clearedStrictly necessary (app local storage)

Footnotes for the table:

  • Google Fonts and Cloudflare cdnjs (Font Awesome icons) are loaded as static resources and set no cookies.
  • Apple App Store and Google Play Store analytics (described in the "Analytics" section of the Privacy Policy) are store-level metrics tied to device identifiers; they are not browser cookies and are therefore not listed above.
  • The mobile app uses no analytics SDK and sets no cookies. RevenueCat (in-app purchases) stores data in the device's native secure storage (keychain), not cookies.

Retention of Your Personal Data

The Company will retain Your Personal Data for as long as You hold an active Account with the Mobile Application. You may delete Your Account at any time, as described under "Deleting Your Account and Your Data" above; deletion starts a 90-day grace period, after which the data is permanently erased.

If Your Subscription ends without Your Account being deleted, the clocks in the table below begin from the end of the Subscription.

We will retain and use Your Personal Data to the extent necessary to comply with Our legal obligations (for example, if We are required to retain Your data to comply with applicable laws), resolve disputes, and enforce Our legal agreements and policies.

The Company will also retain Usage Data for internal analysis purposes, strengthen the security or to improve the functionality of Our Service, or where We are legally obligated to retain this data for longer time periods.

See the following retention table for Our retention times:

Data typeRetention
Account information90 days after the Subscription ends, or 90 days after a deletion request
Product Sheets, Designs and Brand Kits90 days after the Subscription ends
Estate deletion requestsErased within 30 days of verification
Billing records7 years (US tax recordkeeping; Anonymised when written)
Support tickets3 years
Marketing preferences and unsubscribe recordsIndefinitely (legal obligation)
Server logs90 days
Backups30 days rolling

Footnotes for the table:

  • Residual copies may remain in encrypted backups for up to 30 days, after which they are permanently overwritten.

Transfer of Your Personal Data

Shelf Talker LLC is based in the United States. When You use the Service, Your personal information is processed in the United States and may be transferred to and processed by service providers in other countries that may have data protection laws different from those in Your country.

For transfers from the EEA, UK, or Switzerland to the United States or other countries (i.e., countries not subject to an adequacy decision), We rely on:

  • Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) and the UK International Data Transfer Addendum, where required;
  • The EU–U.S. Data Privacy Framework, EU–U.S. DPF UK Extension, and Swiss–U.S. DPF for transfers to certified U.S. service providers (where applicable);
  • Where neither applies, Your explicit consent under GDPR Art. 49(1)(a), after We have informed You of the possible risks of such transfers in the absence of an adequacy decision and appropriate safeguards.

For transfers from Canada, Australia, and New Zealand: We take reasonable steps to ensure recipients are bound by privacy obligations comparable to those required under PIPEDA, the Australian Privacy Principles (esp. APP 8.1), and the New Zealand Privacy Act (esp. IPP 12), respectively.

You may request a copy of the safeguards in place by contacting privacy@shelftalkerapp.com.

The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place.

Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

For users located in California, We will provide notice and an opportunity to opt-out before Your Personal Data is transferred, and the receiving entity is bound to honor prior Privacy Policy terms (CCPA § 1798.140(ad)(2)(C)).

Law enforcement

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency). The Company is committed to challenging overbroad requests for Your Personal Data.

Other legal requirements

The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:

  • comply with a legal obligation;
  • protect and defend the rights or property of the Company;
  • prevent or investigate possible wrongdoing in connection with the Service;
  • protect the personal safety of Users of the Service or the public;
  • protect against legal liability.

Where We are legally permitted to do so, the Company will inform You within 30 days of disclosing Your Personal Data for legal purposes.

Data Security

The security of Your Personal Data is important to Us. We implement administrative, technical, and physical safeguards designed to protect Your personal information against unauthorized access, disclosure, alteration, and loss. These include encryption in transit (TLS 1.2+), encryption at rest, role-based access controls, vendor security review, and periodic security testing.

No internet transmission or storage method is 100% secure. While We use commercially reasonable measures, We cannot guarantee absolute security.

Breach Notification

If a security incident affects Your personal information and applicable law requires notification, We will notify You and the relevant authority as required by:

  • Cal. Civ. Code § 1798.82 and other US state breach notification laws — without unreasonable delay;
  • GDPR Arts. 33–34 — to the supervisory authority within 72 hours, and to affected individuals where high risk;
  • PIPEDA s. 10.1 — as soon as feasible where there is a real risk of significant harm;
  • Privacy Act 1988 (AU), Notifiable Data Breaches scheme — within 30 days of becoming aware;
  • NZ Privacy Act 2020 ss. 112–114 — as soon as practicable for notifiable privacy breaches.

Detailed Information on the Processing of Your Personal Data

The Service Providers We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.

Analytics

We may use third-party service providers to monitor and analyze the use of Our Service. We do not process or export data collected from these third-party services providers beyond Our internal monitor and analyses reports.

The third-party service providers We use may be, but not limited to:

  • Google Analytics (website only, via Firebase)
  • Purpose: measures website traffic, user behaviour, and conversion events to improve product experience.
  • Data shared: device and browser identifiers; approximate location (IP-derived); pages visited and session data; referral source and campaign data; and events and conversions data.
  • Privacy policy link: Google Privacy Policy
  • Opt-out: reject analytics in Our cookie banner or via "Cookie Preferences"; also Google Ad Settings Browser add-on opt-out; enable IP anonymisation in implementation.
  • International transfer mechanism: EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs).
  • Apple App Store analytics
  • Purpose: tracks App Store impressions, downloads, crashes, and in-app purchases to understand app performance.
  • Data shared: resettable device identifier; App Store impressions and page views; downloads, updates and re-downloads; in-app purchases; crash and diagnostic data if You have opted in.
  • Privacy policy link: Apple Privacy Policy
  • Opt-out: iOS: Settings -> Privacy & Security -> Analytics & Improvements -> untick Share iPhone Analytics. App Store personalisation: Settings -> Apple ID -> Privacy -> Personalised Recommendations.
  • International transfer mechanism: Standard Contractual Clauses (SCCs); Apple's Binding Corporate Rules (BCRs) for intra-group transfers.
  • Google Play Store analytics
  • Purpose: store listing performance data (impressions, installs, ratings) and Android Vitals crash and ANR reports to developers via Play Console
  • Data shared: Android advertising ID (GAID); store listing impressions and installs; ratings and reviews signals; crash rates and ANR data (Android Vitals); and country-level install distribution.
  • Privacy policy link: Google Privacy Policy
  • Opt-out: Android: Settings -> Google -> Ads -> Delete advertising ID. Or: opt out of ads personalization in the same menu.
  • International transfer mechanism: EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs).

Payments and Subscription Management

  • Stripe (Website purchases)
  • Purpose: processes payments and uses transaction data for fraud detection, financial reporting, and improving payment performance.
  • Data shared: payment and bank details (provided by You directly to Stripe - We never receive them); billing name; email address; IP address and device fingerprint; transaction history and amounts; fraud signals and risk scores.
  • Privacy policy link: Stripe Privacy Policy
  • Opt-out: transaction data is necessary to take payment and cannot be opted out of while a Website Subscription is active. See the Stripe Privacy Centre - end-user rights.
  • International transfer mechanism: EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs); UK IDTA addendum.
  • RevenueCat (in-app purchases)
  • Purpose: Manages validates in-app purchase and tracks subscription state and entitlement across platforms, so the app can unlock paid features based on active subscription status.
  • Data shared: internal Account ID (passed as app_user_id); purchase and subscription events (e.g. purchase, renewal, cancellation, expiry); App Store and Google Play transaction identifiers; app version and platform metadata.
  • Privacy policy link: RevenueCat Privacy Policy
  • Opt-out: purchase and entitlement data is necessary to provide subscription-based features and cannot be opted out of while a subscription is active. To request deletion of RevenueCat-held data, submit a request to privacy@revenuecat.com referencing Your internal Account ID.
  • International transfer mechanism: Standard Contractual Clauses (SCCs).
  • Apple App Store and Google Play also process Your purchase directly as the merchant of record for in-app purchases, under their own privacy policies.

Hosting

  • Microsoft Azure (United States)
  • Purpose: host the Service, its database, and uploaded image storage.
  • Data shared: all Personal Data described in this Policy, as the underlying infrastructure.
  • Privacy policy link: Microsoft Privacy Statement
  • International transfer mechanism: Standard Contractual Clauses (SCCs); EU-U.S. Data Privacy Framework.

Email Delivery

  • Resend
  • Purpose: delivers transactional and Account-related emails on Our behalf, including Account verification, password reset, renewal and retention notices, and product notifications.
  • Data shared: email address; display name.
  • Privacy policy link: Resend Privacy Policy
  • Opt-out: transactional emails (e.g. Account security notices) are necessary for the Service and cannot be opted out of while an Account is active. Marketing email can be unsubscribed from at any time. To request deletion of data held by Resend, contact privacy@resend.com.
  • International transfer mechanism: Standard Contractual Clauses (SCCs).

Customer Support

  • Jira Service Management / Atlassian
  • Purpose: powers the in-app and email-based customer support ticketing system; support agents use this data solely to respond to and resolve Your submitted requests.
  • Data shared: email address; display name; and the content of any support requests or attachments You submit.
  • Privacy policy link: Atlassian Privacy Policy
  • Opt-out: data is submitted voluntarily when You contact support. To request deletion of a support record, raise a data subject request via Atlassian's Privacy Request Portal or contact privacy@atlassian.com.
  • International transfer mechanism: EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs).

Sign-In Providers

You may sign in with an email address and password, which shares no data with a third party, or with one of the following providers.

  • Sign in with Apple
  • Purpose: authenticates You without exposing Your Apple ID, and can relay a private proxy email so the app never receives Your real address.
  • Data shared: stable, app-scoped user identifier; name (user-controlled, first sign-in only); real or relay email address (Your choice); short-lived authentication tokens.
  • Privacy policy link: Apple Privacy Policy
  • Opt-out: iOS/macOS: Settings -> [your name] -> Password & Security -> Apps Using Apple ID -> revoke access per app Revoking disconnects the app; Apple stops forwarding relay emails immediately.
  • International transfer mechanism: Standard Contractual Clauses (SCCs); Apple Binding Corporate Rules (BCRs) for intra-group transfers.
  • Google Sign-In
  • Purpose: authenticates You via Your Google Account and shares a minimal profile with the app; may also enable Google One Tap and cross-device session continuity.
  • Data shared: stable Google Account ID (sub claim); name and profile picture; email address; OAuth 2.0 access and ID tokens; IP address and device or browser information; and sign-in event metadata (timestamp, locale).
  • Privacy policy link: Google Privacy Policy
  • Scopes requested: openid, email, and profile only. We do not receive or store Your calendar, contacts, or other Google data.
  • Opt-out: Google Account -> Data & Privacy -> Third-party apps Revoke per-app access; does not delete data already held by the third-party app.
  • International transfer mechanism: EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs).
  • Microsoft Sign-In
  • Purpose: authenticates You via Your Microsoft or work/school account (Microsoft Entra ID).
  • Data shared: stable Microsoft object ID and tenant ID; display name and email address; OAuth 2.0/OpenID Connect tokens; IP address and device information. We request nothing further.
  • Privacy policy link: Microsoft Privacy Statement
  • Opt-out: Microsoft Account -> Privacy -> Apps & services Work/school accounts: admin or user revokes consent in Entra ID portal (My Apps). Personal accounts: revoke via the link.
  • International transfer mechanism: EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs); UK IDTA addendum; Microsoft's EU Data Boundary for enterprise customers.

Sign-in with Apple is the most privacy-protective of the three: its app-scoped identifier means Apple issues a different identifier for each app, so providers cannot cross-reference Your across services. Google and Microsoft use a single stable account ID, which allows for cross reference among services.

Importing Images

When You add an image to the app's Image Library, a Brand Kit, or a Design, You may import it from Your device or from one of the following sources. In every case access is read-only and limited to the specific items You select; We do not browse, index, or retain anything beyond the images You choose to import.

  • Google Drive Import
  • Data shared: the image files You select and their metadata (filename, file size, and MIME type); an OAuth 2.0 access token scoped to the files You pick; Your Google Account ID (to authenticate the Drive session).
  • Scope requested: drive.file - access is limited to files You explicitly select, not Your whole Drive.
  • Opt-out: Google Account -> Data & Privacy -> Third-party apps Revoke per-app access to remove Drive authorisation; does not affect files already imported.
  • International transfer mechanism: EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs).
  • Google Photos Import
  • Data shared: the photos You select and their metadata (filename, capture date, and MIME type); an OAuth 2.0 access token scoped to the Photos Picker; Google Account ID (to authenticate the Photos session).
  • Scope requested: photospicker.mediaitems.readonly - selection-scoped, so We receive only the items You pick.
  • Opt-out: Google Account -> Data & Privacy -> Third-party apps Revoke per-app access to remove Photos authorisation; does not affect images already imported.
  • International transfer mechanism: EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs).
  • Your device's photo library and files
  • Data shared: the image files You select. Selection happens in Your operating system's own picker, so the app receives only the items You choose and requires no standing access to Your library.
  • Opt-out: revoke photo access for the app in Your device's privacy settings.
  • International transfer mechanism: not applicable — selection happens on the device; the image is then uploaded to Our hosting as described above.

Email Marketing

We may send You marketing emails about new features, promotions, and educational content related to the Service. You may opt-out of receiving any, or all, of these communications at any time by following the unsubscribe link provided in any email or notification We send or by contacting Us at privacy@shelftalkerapp.com.

  • Existing customers: We rely on the "soft opt-in" exception (GDPR Recital 47; UK PECR Reg. 22(3)). You will receive marketing emails about Shelf Talker products and services similar to those You have purchased or enquired about, unless You opt out. Every marketing email includes a one-click unsubscribe link.
  • Prospects and new users (EEA, UK, Canada, Australia, New Zealand): We obtain Your express consent before sending marketing emails. You may withdraw consent at any time via the unsubscribe link or by emailing privacy@shelftalkerapp.com.
  • Transactional emails (e.g., billing, account, security): We will send these even if You have opted out of marketing, because they are necessary to provide the Service.
  • CAN-SPAM (US): every email includes a physical postal address and a working unsubscribe mechanism honored within 10 business days.
  • CASL (Canada): all commercial electronic messages identify the sender, include unsubscribe, and are sent only with express or implied consent.
  • Spam Act 2003 (AU) and UEMA 2007 (NZ): consent, functional unsubscribe, and sender identification.

Children's Privacy

Our Service is intended solely for use by business professionals aged 18 or over. We do not knowingly permit anyone under the age of 18 to use the Service, and We do not knowingly collect Personal Data from children under the age of 18.

If We become aware that We have collected Personal Data from someone under the age of 18, We will delete it promptly. If You are a parent or guardian and believe a minor has provided Us with Personal Data, please contact Us at privacy@shelftalkerapp.com and we will delete it.

This also satisfies Our obligations under the US Children's Online Privacy Protection Act (COPPA), GDPR Art 8 (for EU users), and Age-Appropriate Design Code (for CA users), all of which concern children well below Our minimum age.

Links to Other Websites

Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third-party's site. We strongly advise You to review the Privacy Policy of every site You visit.

We do not embed third-party content that sets cookies before Your consent.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Changes to this Privacy Policy

We may update this Agreement from time to time. The "Effective Date" date at the top reflects the most recent revision. We will retain prior versions and link to them from the Mobile App's Profile page and the footer of the Shelf Talker website.

If We make material changes (e.g., changes that expand the categories of personal information We collect, the purposes for processing, the parties with whom We share Your information, or that materially affect Your rights or obligations), We will:

  1. provide at least 30 days' advance notice by email to the address associated with Your Account, by in-app notice, and on the Website;
  2. for consumers in the EEA, UK, Australia, Quebec, and other jurisdictions where mandatory consent is required for adverse changes, obtain Your affirmative re-acceptance (e.g., a click-through modal) before the change applies to You; and
  3. offer You a reasonable opportunity to cancel Your subscription without penalty if You do not accept the change.

For non-material, clarifying, or legally required changes, continued use of the Service after the "Effective Date" date constitutes acceptance, subject to applicable consumer-protection laws.

Links to the most recent version of this Policy, as well as the User Agreement, License Agreement, and Subscription Agreement documents can be found on the Profile page within the Mobile App and at the bottom of the Shelf Talker website, https://shelftalkerapp.com.

You are advised to review this Privacy Policy periodically for any changes.

Governing Law

This Agreement and Your use of the Service is governed by and construed in accordance with the internal laws of the State of Michigan without giving effect to any choice or conflict of law provision or rule. Your use of the Service may also be subject to other local, state, national, or international laws.

Any legal suit, action or proceeding arising out of or related to this Agreement and Your use of the Service shall be instituted exclusively in the federal courts of the United States or the courts of the State of Michigan in each case located in Kent County. You waive any and all objections to the exercise of jurisdiction over You by such courts and to venue in such courts.

Disputes Resolution

If You have any concern or dispute about the Service, You agree to first try to resolve the dispute informally by contacting the Company through the form provided on the profile page or at privacy@shelftalkerapp.com.

United States Legal Compliance

You represent and warrant that (i) You are not located in a country that is subject to the United States government embargo, or that has been designated by the United States government as a "terrorist supporting" country, including those referenced on the OFAC sanctioned countries list, and (ii) You are not listed on any United States government list of prohibited or restricted parties.

Severability

If any provision of this Agreement is held to be unenforceable or invalid, such provision will be changed and interpreted to accomplish the objectives of such provision to the greatest extent possible under applicable law and the remaining provisions will continue in full force and effect.

Waiver

Except as provided herein, the failure to exercise a right or to require performance of an obligation under this Agreement shall not affect a party's ability to exercise such right or require such performance at any time thereafter, nor shall the waiver of a breach constitute a waiver of any subsequent breach.

Translation Interpretation

This Agreement may have been translated if We have made it available to You on our Service.

You agree that the original English text shall prevail in the case of a dispute.

Accessibility

We are committed to making the Service accessible. We design and test the Mobile App and Website to conform substantially to the Web Content Accessibility Guidelines (WCAG) 2.2 Level AA. If You encounter accessibility barriers, please contact support@shelftalkerapp.com and We will make reasonable efforts to address the issue.

Contact Us

If You have any questions or concerns about this Privacy Policy, please contact Us at support@shelftalkerapp.com.

For legal or privacy related questions or concerns, please contact Steven Schaner at privacy@shelftalkerapp.com.

The Company can also be reached through the Contact Us button located on Your Profile Page within the Mobile Application.

Wineries Breweries Distilleries Retailers Distributors Pricing Blog What is a Shelf Talker?

© 2026 Shelf Talker. All rights reserved. Privacy Policy User Agreement License Agreement Subscription Agreement Cookie Preferences Do Not Sell or Share My Personal Information