Back to home
TrackYourShelves

Trust Center

How we protect the customer, stock and money records your business runs on: where we stand on the law, what keeps your data safe, and who else touches it.

Last updated October 6, 2026

Where we stand legally

  • Privacy law (GDPR and CCPA)

    You can download everything we hold on your business, or delete the whole account, without asking us. Deleting gives you 30 days to change your mind: sign back in and choose to keep your account. After that it is erased, apart from records the law requires us to keep.

  • Card security (PCI)

    Card numbers never reach us. Our payment processor handles them, so there is nothing here to steal and the rules that apply to you stay as light as they can be.

  • Marketing email law (CAN-SPAM)

    A promotional email cannot leave the system without a working unsubscribe link and a real postal address on it. We block the send rather than trust whoever wrote it.

  • Deleted means deleted

    Erased data is gone from our backups within 180 days, and we check that every night.

  • A data processing agreement

    Our Data Processing Agreement is part of our terms for every business, so there is nothing to sign. If your organization needs a countersigned copy, we will send one.

  • Where your data is kept

    We store it in the United States. Every company that handles it is named on our subprocessor page, with where it is located.

What protects your business

Getting into your account

A stolen password on its own should not be enough to get into your business.

  • Turn on two-step sign-in and we ask for a code from your phone every time
  • Backup codes, so losing the phone does not lock you out for good
  • Passwords are stored scrambled, so nobody here can read yours, including us

Your business is separate from everyone else's

Other businesses on the platform cannot see your records, and your staff see only what you have given them.

  • Every request is tied to your business before it can read or write anything
  • Staff accounts can only reach their employer's records, never anyone else's
  • If you use both the home and business sides, the two stay separate from each other

Your data is encrypted

Scrambled while it is stored and while it travels, so it is unreadable to anyone who gets hold of it.

  • Encrypted on its way between your browser and us
  • Encrypted where it is stored
  • The most sensitive information gets a second layer on top
  • Backups are encrypted too

Card payments

We never see or keep card numbers, yours or your customers'.

  • Cards go straight to our payment processor and are swapped for a token
  • A break-in here could not expose card numbers, because they are not here
  • Payments and refunds are recorded once, so a hiccup cannot double-charge anyone

A record of who did what

When something changes, you can find out who changed it and when, without calling support.

  • Money, permission and admin changes are each recorded separately
  • Anyone looking at personal records leaves a trace
  • Refunds and account changes show up for the owner to review

Attacks and abuse

Someone trying to guess their way in, or hammering the system, gets stopped before it reaches your data.

  • Repeated sign-in attempts are slowed and then blocked
  • Private files people upload are checked for viruses, and an infected one is deleted
  • Unusual behavior raises an alert a person reviews

The website itself

Your browser is told to refuse anything we did not put there, so a bad advert or injected script has nothing to stand on.

  • Connections are forced onto the secure version of the site
  • The camera, microphone and location are switched off unless something genuinely needs them

What our own staff can see

The question people ask least and wonder about most. Nobody here can take over your account.

  • Our staff cannot sign in as you
  • Support helps you from their own account, never from inside yours
  • When someone here looks at personal records, it leaves a trace

Your data

Where it is kept
On managed servers in the United States, encrypted, reachable only over a secure connection. Files you upload are stored the same way.
Backups
Encrypted, and erased data leaves them within 180 days. Private files also have a locked copy that nobody, us included, can change or delete early.
Closing your account
You get 30 days to change your mind: sign back in and choose to keep your account. After that your files, any custom web address and your support conversations are erased, apart from records the law requires us to keep.
Taking your data with you
Download everything at any time from your settings. You do not need to ask us.

Erased data is gone from our backups within 180 days, and we check that every night.

Who else touches your data

See the full list

Every outside company that handles your data is named, with what it does for us, what information reaches it, and where it is located. The list is updated whenever a provider is added or dropped.

Certifications

Where we stand on formal certifications, so you do not have to ask.

  • SOC 2 Type II

    Not yet certified. It is a yearly outside audit we will take on as we grow. Several of the companies underneath us already hold it, and they are listed on our subprocessor page.

  • ISO 27001

    Not yet certified.

  • HIPAA

    We are not set up to handle protected health information and do not sign BAAs. Please do not put patient records into the platform.

Documents

Privacy Policy

What we collect, why, and what you can ask us to do about it.

Terms of Service

The agreement covering your use of the platform.

Data Processing Agreement

How we handle personal data on your behalf, part of the terms for every business.

Subprocessors

Every outside company that touches your data, and what reaches each one.

Security contact

Our security contact details, published where researchers look for them.

Questions, or something to report

Found a security problem? Email security@trackyourshelves.com. It goes to the engineers, not a general support queue. We reply within 72 hours and keep you posted until it is fixed.

Reviewing us for your company and need more detail than this page gives? Ask at the same address and we will answer properly. We keep the specifics off a public page on purpose.

For privacy questions or to request your records, see our Privacy Policy.