Privacy Policy
Effective October 8, 2026
ShelfCount is an inventory and food-cost platform for cafés and restaurants, operated by Mentrup Group LLC, doing business as Insider Management (“we”, “us”). This policy explains what information we collect when you use ShelfCount, why we collect it, and the choices you have. The short version: we collect what the product needs to work, we don’t sell your data, we don’t use it for advertising, and nothing third-party loads on our marketing site until you say yes.
Information we collect
Account information. Your name, email address, and a password (stored only as a cryptographic hash — we never see or store the password itself).
Business information. Your organization’s name, business address, and logo if you upload one.
Operational data you enter. Inventory items, recipes, counts, storage locations, vendors, purchase orders, par levels, waste logs, and similar records you and your team create while using the product.
Point-of-sale data. If you connect a POS system (Square, Toast, or Clover), we sync your catalog and sales data using read-only access so we can calculate food costs. We store the access tokens needed to keep that connection alive, and you can disconnect at any time from your settings.
Receipts and invoices. Vendor receipts and invoices you upload, photograph, or forward to us, along with the text we extract from them.
Email from a receipt inbox you connect. If you give ShelfCount the credentials to a mailbox so vendor invoices arrive automatically, we read messages in that mailbox and store what we find: the attachments, and the raw message body itself (that is where many vendors put the invoice). Those credentials are encrypted, they belong to your organization alone, and you can remove them at any time from your settings. Stored messages and attachments are kept until your organization is deleted — see “Data retention” below — because they are the source record behind every receipt in your history. Only connect a mailbox you have the right to let us read.
Billing information. Payments are processed by Stripe. We never see or store your full card number — Stripe handles it and gives us only what we need to manage your subscription (such as the card’s last four digits and your billing status).
Log and device data. Our web server records standard access logs — IP address, browser user agent, and the URL requested — which we use to keep the service secure and to debug problems. We keep these for up to 30 days and then they are discarded. Separately, each time you sign in we store a session record holding the IP address and browser you signed in from, so you and we can tell a legitimate login from a suspicious one; that record is deleted when the session expires.
How we use your information
- To provide the product: counts, recipe costing, purchase orders, COGS reporting, and everything else you signed up for.
- To read your receipts: we use automated text recognition and AI to extract line items from receipt images and PDFs (see the next section).
- To send transactional email: password resets, purchase orders you send to vendors, and alerts you’ve turned on.
- To respond when you contact us for support.
- To keep the service secure and prevent abuse.
We do not sell your personal information, and we do not use your data for advertising.
AI processing of receipts
When you upload a receipt, we may send its text or image to Anthropic (the company behind the Claude AI models) to extract line items — vendor, product names, quantities, and prices. This happens under commercial API terms that prohibit Anthropic from training its models on your data. Extracted results are always presented for your review before anything is saved to your inventory; nothing is committed automatically.
Analytics and product usage
On our marketing website (the pages you can see before signing in), we use Microsoft Clarity and Google Analytics to understand which pages actually help people. Neither one loads — no script, no request, no cookie — until you click OK in the privacy notice at the bottom of the page. If your browser sends Global Privacy Control or Do Not Track, we honor it: the notice is never shown and neither tool ever loads. To withdraw consent later, clear this site’s cookies or turn on Global Privacy Control in your browser. Neither tool runs on the affiliate portal, and neither runs inside the signed-in product.
Inside the signed-in product, we use PostHog for usage analytics — which screens and features get used — and, mainly during your first setup and trial, masked session replay to see where the onboarding steps confuse people. Replay is masked by default: everything you type is hidden, and all on-screen text is hidden unless it’s our own structural chrome (menus, buttons, headings). We never unmask table data — item names, costs, vendor details, or staff emails stay hidden. We do not record clicks automatically, and PostHog is configured not to store your IP address or derive a location from it. Demo accounts and our own internal platform-admin account are excluded entirely. Use of the signed-in product is covered by our Terms of Service; if you’d rather not be included, email us and we’ll turn it off for your organization.
Error monitoring. We use Sentry to collect crash and error reports so we can fix bugs. Error reports are sent from our servers and do not carry your name, email, or IP address.
Our own analytics. Independently of all of the above, we record which pages get visited using a first-party cookie (sc_aid) and our own servers — no third party is involved, and we do not store your IP address or user agent with those events. We keep them for 365 days.
Email opens and clicks. Emails we send about your account (trial and onboarding emails, inventory alerts you’ve turned on) include a small tracking image and links that pass through our own server, so we can tell whether an email was opened or a link was clicked, how many times, and from which mail app. Purchase orders you send to vendors carry the same image, so you can later see whether the vendor opened the order. No third party is involved, we do not store the IP address, and password-reset, verification and team-invite emails are never tracked. These records are deleted with your organization’s data.
Do Not Track and Global Privacy Control
We honor browser privacy signals. If your browser or an extension sends Global Privacy Control (the Sec-GPC signal) or a Do Not Track header, ShelfCount treats it as a decision to decline: no third-party analytics or session-replay tool is loaded on our marketing site, and we do not ask you again. We are telling you this plainly because California’s Online Privacy Protection Act (Bus. & Prof. Code §22575(b)(5)) requires us to say how we respond to those signals.
Who we share data with
We share data only with the service providers that run the product, and only what each needs to do its job:
- Hetzner Online GmbH — cloud hosting for the application and database.
- Stripe — subscription billing.
- Anthropic — receipt line extraction, as described above.
- Google Workspace — sending transactional email.
- Google — Google Analytics on our marketing site, and only if you consented to it.
- Microsoft — Clarity on our marketing site, and only if you consented to it.
- PostHog — product analytics and masked session replay inside the signed-in product.
- Sentry — error and crash reports.
- Square, Toast, or Clover — only if you connect them, and only to pull your own data into ShelfCount.
- Shiftpad — our companion staff-scheduling app at schedule.getshelfcount.com. If your organization connects scheduling, we send it your name, email address, and organization identifiers, plus your password hash so the same password signs you into both apps. Nothing is sent unless scheduling is connected.
We may also disclose information if the law requires it, or to protect the rights and safety of our users and business.
Data retention
We keep your data while your account is active. If your subscription lapses or you cancel, your account is paused and your data stays put for 12 months from the date of cancellation — resubscribe in that window and everything is right where you left it. After 12 months we permanently delete your data, and we’ll email you before that happens. If you want your data deleted sooner, email us and we’ll remove it, including from backups as they cycle out (our backups are kept on a rolling schedule off the main server).
Some categories have their own, shorter clocks:
- Server access logs (IP, user agent, URL): up to 30 days.
- Sign-in session records (IP, user agent): deleted when the session expires.
- Our own page-view analytics events: 365 days.
- Receipts, receipt emails, and their attachments: kept for the life of your organization, because they are the source record behind your purchase history.
- Clarity, Google Analytics, PostHog and Sentry keep what they collect under their own retention settings, and delete it sooner on request — see “Your rights” below.
Security
All traffic to ShelfCount is encrypted in transit (HTTPS). Passwords are hashed, POS and mailbox credentials are stored encrypted, access to POS data is limited to read-only scopes where the provider offers them, and access within your organization is controlled by the roles you assign your team.
Your rights
You can access and update most of your data directly in the product. You can also email us to request a copy of your data or ask us to delete it.
California residents
We are a small business and most likely fall below the thresholds that make the California Consumer Privacy Act (as amended by the CPRA) apply to us. We honor its core requests anyway: you can ask us what personal information we hold about you, ask for a copy of it, ask us to correct it, and ask us to delete it. We will not treat you differently for asking. Email us at the address below and a human will handle it.
We do not sell personal information, and we do not share it for cross-context behavioral advertising — the CPRA meanings of “sell” and “share.” There is no advertising network in ShelfCount, no ad pixel, and no audience or remarketing list built from your visit.
Shine the Light. California Civil Code §1798.83 lets California residents ask, once a year and free of charge, what personal information a business disclosed to third parties for their own direct marketing. We don’t disclose personal information for that purpose, but you’re welcome to ask us to confirm it in writing.
Cookies
Here is every cookie ShelfCount can set, and why. Most are set only in a specific situation — signing in, arriving via a referral link — and never otherwise.
| Cookie | What it’s for | How long it lasts |
|---|---|---|
| better-auth.session_token | Keeps you signed in. Named __Secure-better-auth.session_token over HTTPS. Set only after you log in. | Until the session expires or you sign out |
| sc_aid | A first-party, signed, random id so we can tell one visit apart from another in our own analytics. It is not shared with anyone and carries no personal information. | 365 days |
| sc_consent | Remembers whether you accepted or declined the analytics tools on our marketing site. Without it we ask again. | 365 days |
| shelfcount_aff | Records which affiliate referred you, so they get credited if you subscribe. Set only if you arrive through a referral link. | 60 days |
| shelfcount_aff_session | Keeps an affiliate signed in to the affiliate portal. Set only for affiliates. | 30 days |
| sc_upgrade | Carries your details across from our scheduling app when you upgrade into ShelfCount, so you don't retype them. | 30 minutes |
| Microsoft Clarity and Google Analytics cookies | Set by those tools on our marketing site, and only after you click OK in the privacy notice. Clarity also sets Microsoft's MUID identifier (via clarity.ms and bing.com), which Microsoft uses across its own services. If your browser sends Global Privacy Control or Do Not Track none of these are set. | Set by the tool; see their policies |
We set no advertising cookies of our own, and nothing we control is used to follow you around other websites. Google Analytics and Microsoft Clarity are run by companies that also sell advertising; their cookies are set on our marketing site only, and only after you click OK.
Children
ShelfCount is a business tool and isn’t directed at children. We don’t knowingly collect information from anyone under 16.
Changes to this policy
If we make meaningful changes to this policy, we’ll update the effective date above and, for significant changes, notify you by email or in the product.
Contact
Questions about this policy or your data? Email hello@getshelfcount.com and a human will get back to you.