Legal · Version 2026-08-29-draft-v1
Privacy Policy
Draft for counsel review — not effective until formally approved and published.
This Policy describes how the company operating ShelfHarbor will collect, use, disclose, retain, and protect information when providing the ShelfHarbor business service.
1. Information we collect
- Account information: name, work email, organization, role, login and account status.
- METRC connection information: encrypted username and password, connection status, facility selection, authentication timestamps, and error information.
- Authorized inventory data: processor products, downstream retailer identities, quantities, package counts, report timestamps, historical snapshots, and analytics derived from those records.
- Billing information: plan, billing contact, customer and recurring-payment identifiers, invoice and payment status. Payment providers receive bank or card details directly; ShelfHarbor does not store full bank-account, routing, or card numbers.
- Technical and audit information: IP address, browser or device information, request logs, security events, policy acceptance, authorization records, and support communications.
2. Sources
We receive information from you and your authorized users, customer-authorized METRC access, payment providers, service operations, support interactions, and official licensing datasets used to match facilities.
3. How we use information
We use information to authenticate users; isolate customer workspaces; retrieve and organize authorized inventory; provide current inventory and Growth forecasts; process subscriptions; support customers; detect fraud and security incidents; maintain audit records; improve reliability; comply with law; and enforce agreements.
4. How we disclose information
We disclose information only as needed to operate the service, follow your instructions, complete a transaction, protect rights and security, or comply with law. Service providers are expected to process information under contractual and confidentiality restrictions.
5. Service providers
Expected providers include Supabase for authentication and database services, Vercel for application hosting, Browserbase for isolated browser sessions, and Intuit QuickBooks for billing and payments. The final policy will identify the operating entity and current subprocessor list before launch.
6. No sale or cross-customer sharing
We do not sell personal information or customer inventory data. We do not use one customer’s identifiable inventory information to provide another customer access to that information. We do not use personal information for cross-context behavioral advertising.
7. Retention and deletion
During the pilot, account and inventory data will be retained while the subscription is active and for a limited wind-down period after termination. METRC credentials will be deleted or rendered inaccessible after disconnection or termination subject to operational backup cycles. Billing, authorization, security, and legal records may be retained longer where reasonably necessary or legally required. Counsel-approved production retention periods will be published before launch.
8. Security
We use tenant-level database controls, encryption in transit, encryption of stored METRC credentials, separate persistent browser contexts, limited administrative access, audit logging, and operational monitoring. No security measure guarantees absolute protection. Customers should use dedicated least-privilege METRC users and revoke them promptly when access is no longer needed.
9. Your choices and rights
Authorized account administrators may update account details, disconnect METRC, cancel subscriptions, and request access, correction, export, or deletion by contacting us. Some information may be retained when required for security, billing, dispute, or legal purposes. Additional state-law rights will be honored where applicable.
10. Business transfers and legal requirements
Information may transfer as part of a financing, merger, acquisition, reorganization, or sale, subject to appropriate safeguards. We may disclose information when reasonably necessary to comply with law, legal process, or valid government requests, or to protect the service, customers, or others.
11. Children and geography
ShelfHarbor is a business service and is not directed to children. The initial service is operated for United States businesses and data may be processed in the United States.
12. Changes and contact
We will publish changes with a revised version and provide additional notice where appropriate. Privacy questions and requests may be sent to privacy@shelfharbor.com.