1. Introduction
TrackYourShelves ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our inventory-management and business-operations platform, including our website, our web application at trackyourshelves.com, our native mobile apps for iOS and Android, and any other products or channels we make available.
2. Information We Collect
Personal Information
We collect information you provide directly, including:
- Name and contact information (email, phone number)
- Address information (for residential accounts)
- Company information (for commercial accounts)
- Account credentials
- Payment information (processed securely by our third-party payment processors, such as Stripe)
Inventory Data
We collect and store inventory data you enter, including:
- Item names, descriptions, and categories
- Quantities, locations, and values
- Photos and documents you upload
- Purchase dates and warranty information
Automatically Collected Information
- Device information and browser type
- IP address and location data
- Usage patterns and preferences
- Cookies and similar technologies
Mobile App Information
When you use the TrackYourShelves mobile app for iOS or Android, we additionally collect or request access to:
- Camera access: used only when you scan a barcode to look up or add an inventory item, or when you photograph a warranty receipt. Camera frames are processed on-device; we do not upload raw video.
- Photo library access: used only when you choose to attach a photo to an inventory item, warranty, wishlist entry, or family member avatar.
- Push-notification permission: used to send reminders for expiring items, warranty expirations, maintenance tasks, medication refills, lending returns, and appointments. You can opt out in the app's Settings or in your device's notification settings.
- Push notification device token: a device-specific identifier (issued by Apple or Google) that we store only to deliver your notifications. It is not used for advertising or cross-app tracking. Revoked automatically on sign-out.
- Diagnostic and crash data: when the app hits an error we collect the error message, stack trace, route, app version, OS version, device class (e.g. iPhone 15 Pro), and a small breadcrumb trail of recent in-app actions, to help us fix bugs. We do not include inventory contents or message text in diagnostic payloads.
- Biometric authentication: if you enable Face ID, Touch ID, or Android fingerprint unlock, biometric data never leaves your device. We only receive a yes/no unlock signal from the OS.
The mobile app contains no advertising software, no cross-app tracking, and no analytics tools that share your data with anyone else.
TYS Booking app
TYS Booking is a separate app for the staff of businesses that run their bookings on TrackYourShelves. There is no sign-up in it: a business turns on a staff member's access and gives them a code to sign in with, and the business can sign that phone out at any time. The bookings, customers and events the app shows belong to that business, which decides what is in them; we process them on its behalf.
- Your name and your phone's name: the name the business gave you, shown on its check-in log so it can see who admitted whom, and your phone's device name (for example “Sam's iPhone”), so the business can tell which phone to sign out.
- Camera access: used only while the ticket scanner is open, to read the code on a ticket. The picture is read on the phone and is never stored or sent to us.
- What is kept on the phone: your sign-in, in the phone's secure storage; the day's schedule and the events list, so they still show without a signal; and any changes made offline, until they can be sent. Signing out deletes all of it from the phone, and so does the business signing the phone out, the next time the app connects.
- What the app never uses: your location, contacts, photos or microphone, or any advertising identifier. It contains no advertising, no analytics and no crash-reporting tools.
Your access is removed by the business that gave it to you. To have your details taken out of a business's records, ask that business, or contact us (section 13).
2a. Sensitive Health Information
TrackYourShelves lets you record household medical information: family member profiles, allergies, medical conditions, medications, dosages, appointments, emergency contacts, insurance details, and an optional mental-health journal. Because this information is sensitive, it is handled differently from the rest of your account data.
We are not a HIPAA covered entity
The Health Insurance Portability and Accountability Act (HIPAA) regulates how healthcare providers, health plans, and their business associates handle protected health information. TrackYourShelves is a consumer software product: you record your own household information for your own reference. We are not a HIPAA covered entity, we are not acting as a business associate to any healthcare provider, and the health information you enter is not covered by HIPAA. The terms "HIPAA-compliant" or "HIPAA-certified" do not apply to our Service.
What that practically means: HIPAA protects information collected by your doctor about you; it does not regulate notes you keep about yourself in a personal app. We voluntarily apply security practices comparable to the HIPAA Security Rule's technical safeguards (described below), but that is a design choice rather than a regulatory status.
Field-level encryption
Sensitive fields in the medical module get a second, separate layer of encryption before they are stored, on top of the encryption already applied to everything else. Specifically:
- Family profiles: allergies, medical conditions, emergency contact, insurance provider/policy/group/phone, primary doctor and doctor phone, and free-text notes.
- Pets: microchip ID, veterinarian, vet phone and address, insurance, free-text notes, allergies, medical conditions.
- Medications: dosage, dosage unit, frequency, route, prescription number, prescriber and prescriber phone, pharmacy and pharmacy phone, purpose, side effects, instructions, and notes.
- Medical appointments: location, reason, notes, and follow-up notes.
- Mental-health journal: the free-text fields (reflection, what helped, tomorrow's focus) on each entry.
Encryption keys are derived per-household using a unique salt stored on each owner's account plus a master secret held outside the database. An attacker with database read access alone cannot decrypt your medical information without also compromising the master secret and running a key-derivation step for each user. We do not have a way to read your encrypted medical fields if the master secret is destroyed; please retain your account password so we can authenticate you for exports and deletions.
Mental-health information
The optional mental-health journal is the most sensitive surface of the Service. Entries are stored only in your own account (they are not visible to other household members), they are encrypted as described above, and they are excluded from analytics, machine-learning model training, and any product summary or report that we make available to staff. We do not infer clinical conditions from your entries, and TrackYourShelves does not provide medical advice. If you are in crisis, please contact a qualified professional or, in the United States, dial or text 988.
Household sharing model
When you add a household member to a residential home, that member can see medical records associated with the household by default (e.g., a shared medication list). Personal medications and appointments marked "personal" remain private to their creator. Mental-health entries are always single-user. You can review and adjust who has access from the Family page in the residential dashboard.
Defense-in-depth on medical surfaces
- Medical pages are never cached, never pass on where you came from, and cannot run outside code at all (stricter than the rest of the Service).
- The mobile medical screen requires a separate biometric (Face ID, Touch ID, or fingerprint) confirmation each time it is opened, on top of the regular app unlock.
- Bulk medical exports are limited to one request per hour per household, can only be initiated by the home owner, and are recorded in an access log.
- Denied attempts (a household member trying to bulk-export or bulk-delete, a failed confirmation phrase) are logged so suspicious activity is visible.
- Push notifications about medical events (refill reminders, appointment reminders) include only the minimum information needed (e.g., the medication name and date), never dosage, prescriber, or notes.
Your control over health data
While the home product is paused, email privacy@trackyourshelves.com and we will export or delete your medical data. When it is running, you can delete any individual medical record at any time from inside the app. You can also use the "Delete all medical data" option in your account settings to wipe medications, appointments, family profiles, pets, mental-health entries, the access log, or your consent record in one action (with a confirmation phrase to prevent accidental deletion). Exporting gives you a complete, readable copy of your medical data for your own backup or to take elsewhere.
3. How We Use Your Information
We use your information to:
- Provide and maintain the Service
- Process transactions and send related information
- Send administrative messages and updates
- Respond to your inquiries and provide support
- Improve and personalize your experience
- Analyze usage patterns to enhance the Service
- Detect and prevent fraud or security issues
- Comply with legal obligations
3a. The AI Assistant (Tracky)
Tracky is an optional in-app assistant. It answers questions about the product and, where your workspace allows it, looks up and drafts records on your behalf.
Not in use at the moment. Tracky is switched off for every workspace, so nothing from your account is sent to OpenAI. The points below apply if we switch it back on.
- What is sent: the message you type and the records needed to answer it — for example the inventory item or customer you asked about. It is processed by OpenAI as our processor, in the United States.
- What it can reach: only data inside your own workspace, and only what your own permissions already allow. The assistant applies the same per-module permissions as the rest of the product.
- Accuracy: AI output can be wrong. Check anything that affects money, stock counts or a customer before you rely on it. The assistant does not make decisions about you, and it cannot change your account, your plan, or anyone's permissions.
- Consent and switching it off: each person accepts the assistant terms before their first message, and a workspace owner can switch the assistant off for the whole workspace. Turning it off stops future processing; conversations already stored remain until you delete them or they age out (see section 6).
- Review: conversations may be reviewed by our team to investigate a fault or a safety report. Access is restricted and logged.
3b. TeamChat
TeamChat is the chat a business uses with its own team. When a business uses it:
- What is kept: the messages, reactions, pins, polls and files people send; who is in each conversation; each person's status; when they last signed in; and counts of use, such as messages a day and file space, which we use to run the service and keep its cost in check. Messages are held on the chat service we run on Cloudflare, in a store for that business alone, not in our main database. Files are in the business's own file storage.
- Who sees it: the people in each conversation, and the people the business allows to manage TeamChat. Our staff have no tool for reading messages. We provide them only if the business asks us in writing or the law requires it, and we record when we do.
- How long: as long as the business chooses in its TeamChat settings. When a business deletes its account, its TeamChat is deleted with it. When a person's own account is deleted, their name is taken off the business's conversations (they show as “Former member”), and their messages stay as the business's record unless the business deletes them.
- Notifications: when you are away, the bell in TrackYourShelves tells you about direct messages and mentions. It says who and where, never what the message says. TeamChat does not send email.
4. Information Sharing
We do not sell your personal information. We may share information with:
- Service Providers: Third parties that help us operate the Service (payment processors, hosting providers, email services)
- AI assistant (OpenAI): Not in use at the moment (see section 3a). If your workspace uses Tracky, our in-app assistant, the text of your request and the records needed to answer it are sent to OpenAI acting as our processor. Nothing is sent for a workspace that has the assistant switched off, or for a person who has not accepted the assistant terms. OpenAI does not use API data sent by us to train their models. See section 3a for what this covers and how to turn it off.
- Support tickets (Discord): When you raise a support ticket, the conversation is relayed into a private Discord server that only our support team can read, so we can answer you from one place. By default what is sent is the messages themselves and a reference code; your name, email address, phone number, plan and any amounts are not. An administrator can configure a specific staff-only channel to receive that detail as well, and that setting is what governs it. We also send operational alerts there (errors, payment events, feedback) under the same rule. If you ask us to delete your account, the Discord conversation is deleted too, not archived.
- Live chat (tawk.to): Not in use at the moment: our pages do not load it. If you start a chat with our support team, the conversation is handled by tawk.to acting as our processor. When you are signed in we pass them your name, email address, company name, plan, which side of the product you are using (residential or commercial), the page you were on, and your store and website addresses and whether they are live, so support can help without asking you to repeat it. We do not pass your account identifier, anything belonging to your own customers, or any of your workspace contents. Anonymous visitors are not identified to tawk.to at all.
- Business Transfers: In connection with mergers, acquisitions, or asset sales
- Legal Requirements: When required by law or to protect our rights
- With Your Consent: When you explicitly authorize sharing
4a. Business and Customer Data (Commercial Accounts)
If you use the commercial side of the Service, you may enter or generate data about your own business and your own customers, vendors, and staff, for example customer and vendor contact records, orders, quotes, invoices, payments and payouts, point-of-sale and storefront transactions, and portal activity ("Business Data").
For Business Data, you are the controller (or equivalent "business") and TrackYourShelves acts as your service provider / processor: we process Business Data on your behalf and under your instructions in order to provide the Service, and we do not sell it or use it for our own advertising. You are responsible for having a lawful basis to collect and share Business Data with us, for providing any privacy notices and obtaining any consents your own customers are owed, and for honoring their privacy rights. Where a payment is involved, the applicable payment processor may act as its own controller of the payment data it handles under its own policies. If you enable a third-party feature (such as a tax-calculation provider), the data needed for that feature is shared with that provider under its terms.
5. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption of all data while it travels between your device and us
- Encryption of all data where it is stored
- Passwords stored scrambled and never in readable form, so nobody can read yours
- Sign-in sessions that are limited in scope and expire
- Biometric-unlock option on mobile (data stays on-device)
- Rate-limited authentication and abuse detection
- Regular security review and patching of the software we build on
- Access controls and audit logging for staff actions
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
Breach notification
If we become aware of a breach of security that results in the unauthorized disclosure of your personal information, we will notify you without undue delay, consistent with applicable law, through the email address on your account or another prominent means.
Responsible disclosure
If you believe you have found a security vulnerability, please email security@trackyourshelves.com with a description and proof-of-concept. We will acknowledge receipt within 72 hours and work with you in good faith on remediation. Please do not publicly disclose vulnerabilities until we have had reasonable time to respond.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Specific retention windows:
- AI assistant conversations: kept for six (6) months from your last activity in that conversation, then deleted automatically. You can delete a conversation yourself at any time, and closing your account removes them with everything else. Your assistant messages are included in the data export you can request under section 7.
- Account profile data: when you close your account, it is deactivated immediately (sign-in disabled, sessions revoked) and queued for anonymization thirty (30) days later. You, your workspace admin, or TYS may cancel the closure within that window. After anonymization, the personally-identifying fields on your profile (name, email, phone, profile photo, linked Discord identity) are permanently wiped from live systems; backups roll out within a further 30 days. If you own the workspace, closing your account deletes the whole workspace instead, including your team members' logins. Business records you created (orders, invoices, audit log entries) remain on your workspace's books with a “[Deleted User]” placeholder so the team's books and audit trail stay intact — this is required by U.S. tax and accounting rules for retained business records, and the placeholder qualifies as “deidentified” under CCPA § 1798.140.
- Payment records: retained for 7 years to comply with U.S. tax and accounting obligations.
- Support tickets: retained for 3 years to help us improve service quality and for dispute resolution.
- Crash / diagnostic logs: retained for 90 days then purged.
- Push notification tokens: switched off when you sign out of a device or uninstall the mobile app.
- Backups: kept for up to 30 days; deleted data leaves them within that window.
We may retain de-identified or aggregated data indefinitely for analytics, product improvement, and reporting.
7. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your personal information
- Export your data in a portable format (JSON / CSV)
- Opt out of certain data processing
- Withdraw consent for specific uses
- Lodge a complaint with a data-protection authority
To exercise these rights, contact us at privacy@trackyourshelves.com. We will verify your identity before responding and aim to respond within 30 days (or any shorter period required by law).
California residents (CCPA / CPRA)
If you are a California resident, you have the rights described in the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to know what categories of personal information we have collected about you, the sources, the purposes for collecting it, and with whom it is shared.
- Right to delete your personal information, subject to limited exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing of personal information for cross-context behavioural advertising. We do not sell or share your personal information for advertising purposes.
- Right to limit use of sensitive personal information. We only use sensitive personal information (such as account credentials) to provide the Service as you request.
- Right to non-discrimination for exercising any of the above.
To exercise California rights, email privacy@trackyourshelves.com with the subject "CCPA Request". You may designate an authorized agent to make a request on your behalf; we will verify both your identity and the agent's authority.
European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)
If you are in the EEA, the UK, or Switzerland, the General Data Protection Regulation (or the UK GDPR) applies to our processing of your personal data. Our legal bases for processing are:
- Performance of a contract: to create your account, provide the Service, and bill for paid plans.
- Legitimate interests: to secure the Service, prevent fraud, improve quality, and analyse aggregated usage.
- Consent: where required (e.g., marketing emails, push notifications, optional cookies). You may withdraw consent at any time.
- Legal obligation: to comply with tax, accounting, and law-enforcement obligations.
You have the right to access, rectify, erase, restrict, object to, or port your personal data, and the right to lodge a complaint with a supervisory authority. For requests, email privacy@trackyourshelves.com.
Data is stored on servers in the United States. The providers on our subprocessors page process it in the countries listed there.
Do-Not-Track signals
Our Service does not change its behaviour based on Do-Not-Track browser signals because we do not track users across third-party websites or services in the first place.
Automated decision-making
We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects on you.
8. Cookies and Local Storage
We use first-party cookies and browser local storage. No advertising cookies, no cross-site trackers, no fingerprinting libraries, no third-party profile pictures. Our live chat widget (tawk.to), which sets its own cookies when it runs, is switched off at the moment and does not load. Below is what we store, why, and for how long.
| What it is for | Category | Kept for |
|---|
| Signing you in and keeping you signed in as you move between pages | Strictly necessary | Your visit, or up to 30 days |
| Security: making sure a request really came from you | Strictly necessary | Your visit |
| Remembering which side of the product you are working in | Strictly necessary | Your visit |
| Remembering your choice about this cookie notice | Strictly necessary | Until you clear your browser storage |
| Your display preferences, such as theme and layout | Preferences | 1 year |
| Your language and region | Preferences | 1 year |
| Small conveniences saved on your own device only, such as which panels you left open (never sent to us) | Preferences | Until you clear it |
Payments
Our payment processors set their own cookies on their own hosted checkout and card-entry screens, and on in-person card readers. We do not control those cookies. For example, Stripe describes its cookies in its cookie policy.
Analytics, advertising, and Do-Not-Track
We do not run third-party analytics (Google Analytics, Mixpanel, Segment, PostHog, etc.) or advertising cookies on the Service. Outside scripts are blocked entirely on medical pages. Because we don't track you across other sites in the first place, Do-Not-Track browser signals have no additional behavior to change.
Controlling cookies
You can control cookies through your browser settings. Disabling the strictly-necessary cookies above will sign you out and prevent you from using the Service. Disabling preference cookies will reset your UI choices each session.
8a. Demo Workspaces
Public demo workspaces are currently switched off.
Demo workspaces are not intended for real medical data. Please do not enter actual prescriptions, medical conditions, or identifying details about household members into a demo.
9. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect information from children under 13. If we learn we have collected such information, we will delete it promptly.
10. International Transfers
Your information is stored in the United States and processed by the providers on our subprocessors page in the countries listed there.
11. Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of these sites. We encourage you to review their privacy policies.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or through the Service. Your continued use after changes constitutes acceptance.
13. Contact Us
TrackYourShelves L.L.C. is the data controller for information collected through the Service. If you have questions about this Privacy Policy or our practices, contact us at:
Privacy: privacy@trackyourshelves.com
Security: security@trackyourshelves.com
Support: support@trackyourshelves.com
Legal: legal@trackyourshelves.com
Mail: TrackYourShelves L.L.C., 8735 Dunwoody Place, Ste N, Atlanta, GA 30350, USA