shelf. coffee
Legal

Privacy Policy

Last updated 2026-05-20

This Policy describes how shelf.coffee handles your personal data under Brazil's General Data Protection Law (LGPD, Law 13.709/2018) and the EU General Data Protection Regulation (GDPR), where applicable.

1. Controller

The controller of your data is shelf.coffee ("Controller"), a service operated from Brazil. Contact: privacy@shelf.coffee.

2. Data we collect

3. Why we collect (legal basis)

4. Sharing

We share data only with processors essential to operating the Service:

We do not sell your data nor share it for third-party marketing.

5. Cookies and similar technologies

6. Retention

7. Your rights

Under LGPD Art. 18 (and GDPR equivalents), you may request:

To exercise any right: privacy@shelf.coffee. We respond within 15 business days.

8. Security

We adopt reasonable technical controls: enforced HTTPS, password hashing (delegated to OAuth), Row Level Security in the database, server-side secrets (API keys) isolated from the client, HMAC verification with replay protection on payment webhooks. No system is 100% secure — in case of an incident involving personal data, we will notify the relevant authority (ANPD in Brazil) and affected data subjects per LGPD requirements.

9. International transfer

Some processors (Supabase, Cloudflare, Paddle, Google) process data in servers outside Brazil. We ensure these processors offer adequate protection levels via standard contractual clauses and recognized certifications.

10. Children

The Service is not directed to children under 13. We do not knowingly collect data from children. Legal guardians who identify a child has provided data should contact us for removal.

11. Changes

This Policy may be updated. We will notify material changes via the Service interface. The date at the top indicates the current version.

12. Data Protection Officer (DPO)

The channel for data protection matters is privacy@shelf.coffee. Contact: privacy@shelf.coffee.