Customer success
About us

Privacy Notice

Last updated 2026-08-16T00:00:00.000Z · Shelf Cloud Services OÜ

The short statement of what personal data Shelf Cloud holds about you, why, for how long, and the rights you have over it. The full Privacy Policy carries the detail.

1. Who we are

Shelf Cloud Services OÜ, registry code [registrikood], [registered address], Estonia, is the controller of the personal data described in this policy.

Contact: [privacy@ email]

We have not appointed a Data Protection Officer; we are not required to under Article 37 GDPR. Data protection enquiries go to the address above.

Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, Tallinn — or the authority in your own country of residence or work.

2. What we collect and why

Account data:

We do not receive or store full card numbers. Payment details go directly to Stripe.

Service data:

Website data:

We do not use advertising cookies, tracking pixels, session recording, or third-party analytics that profile you. If that changes, we will ask for consent first and update this policy before doing so.

Quoting data:

Our pricing is dynamic. When you request a price we log the shape requested, the price shown, and whether it was accepted. Where you are logged in, this is linked to your account.

We do not use this to price differently for you personally. Prices depend on the shape requested, market conditions and our available capacity — not on who is asking.

3. Where your data is

Account data is stored within the EEA. Instance data is stored in Germany.

Where a recipient processes data outside the EEA — currently only Stripe's US operations — the transfer is made under an adequacy decision or the EU Standard Contractual Clauses (2021/914).

4. How long we keep it

Retention periods are in the tables above. Two general rules:

• Accounting records: 7 years. Estonian law requires it; we cannot delete these on request.

• Everything else: deleted when the purpose ends, or at the stated period, whichever is sooner.

On termination, instance storage is retained for 7 days so you can request a copy, then securely wiped. See DPA §11.

5. Your rights

Under the GDPR you may:

• Access the data we hold about you

• Rectify inaccurate data

• Erase data, where we have no overriding obligation to keep it

• Restrict processing while a dispute is resolved

• Port data you gave us, in a machine-readable format

• Object to processing based on legitimate interests — including our quoting logs

• Withdraw consent, where we relied on it (we currently rely on consent for nothing)

• Complain to a supervisory authority

Write to [privacy@ email]. We respond within one month, extendable by two months for complex requests, and we will tell you if we need the extension. There is no charge unless a request is manifestly unfounded or excessive.

Practical limit worth knowing: if your request concerns data inside a Shelf instance belonging to one of our customers, we must forward it to that customer rather than act on it. They control that data; we cannot search it.

Contact

Questions about this document go to the support page at /support.