Privacy Policy
Effective July 15, 2026
ShelfPilot is operated by Innobio Solutions LLC (“ShelfPilot,” “we,” “us,” or “our”). ShelfPilot provides commerce analytics, reporting, monitoring, and business intelligence tools for merchants and other business users.
This Privacy Policy explains how we collect, use, disclose, store, and delete information in connection with shelfpilot.io, the ShelfPilot application, and related services (collectively, the “Service”). It applies to business users of the Service, people who communicate with us, and visitors to our website.
ShelfPilot is designed to connect to business accounts that you choose to authorize. These may include Shopify, Amazon Selling Partner, Meta, Google Analytics 4, Google Ads, Klaviyo, and other services we make available from time to time (each a “Connected Platform”). We may combine data from multiple Connected Platforms to provide unified dashboards, cross-channel analysis, reports, alerts, recommendations, and other user-facing features.
1. Our role and your authorization
When you connect a Connected Platform, you direct ShelfPilot to access and process information available through the permissions you grant. You represent that you are authorized to connect the applicable business, store, marketplace, advertising, analytics, or marketing account.
Depending on the data and applicable law, ShelfPilot may act as a processor or service provider processing data on behalf of a merchant or business customer. The merchant or business customer remains responsible for its own privacy notices, legal bases, consents, and instructions relating to personal information it controls.
2. Information we collect
Account and authentication information
When you create or use an account, we receive account information such as your name, email address, account identifiers, and authentication-related information. Clerk provides authentication and session management for the Service. We maintain information needed to associate your ShelfPilot account with your organization, permissions, and Connected Platforms.
Connected Platform authorization and credentials
When you connect a platform using OAuth or another supported authorization method, we receive authorization information such as access tokens, refresh tokens, account identifiers, store identifiers, marketplace identifiers, property identifiers, and the permissions or scopes associated with the connection. We use these credentials to access the accounts you authorize and to keep enabled features synchronized.
Sensitive connector credentials are protected using technical safeguards, including encryption at rest and access controls. We do not ask for or store your Connected Platform password when the platform provides an OAuth or comparable authorization flow.
Connected Platform data
The categories of information available to ShelfPilot depend on the Connected Platform, the permissions approved by that platform, the permissions you grant, and the features you enable. The following describes our principal integrations as of the effective date of this Policy.
Shopify.We may access store and merchant identifiers, product and catalog information, orders, refunds, transactions or sales information, inventory, fulfillment, shipping and operational information, and related analytics. Shopify treats certain order- and customer-related resources as protected customer data. ShelfPilot accesses protected customer data only to the extent authorized by Shopify and needed for enabled Service features. We do not use Shopify customer contact information to independently market ShelfPilot to a merchant’s customers.
Amazon Selling Partner. We may access seller and marketplace identifiers and data made available through approved Selling Partner API roles and operations, which may include product listings, catalog information, inventory, orders, fulfillment, sales, operational reporting, and brand analytics. We process Amazon information only for authorized Service features and subject to applicable Amazon agreements, the Selling Partner API Acceptable Use Policy, and the Amazon Data Protection Policy.
Meta. When you connect Meta, ShelfPilot uses Facebook Login for Business or another Meta-approved authorization flow. Depending on the permissions presented in the authorization flow and the features you enable, we may receive basic profile information used to identify the connecting user; ad account and Business Manager asset identifiers; the list of Pages or business assets you are authorized to access; and advertising or Page performance information such as campaigns, ad sets, ads, impressions, reach, clicks, spend, conversions, engagement, followers, and related insights. For example, permissions may include public_profile, ads_read, business_management, pages_show_list, and pages_read_engagement where approved and necessary.
Google Analytics 4. When you connect Google Analytics 4, we use Google OAuth and read-only Google Analytics access to identify the Analytics accounts or properties you authorize and retrieve reporting data. This may include property and account identifiers and metrics or dimensions relating to sessions, users, acquisition, traffic sources, engagement, events, conversions or key events, e-commerce performance, and other Google Analytics reporting information available through the authorized APIs. ShelfPilot does not receive your Google password through this connection.
Google Ads. When you connect Google Ads, we use Google OAuth and read-only Google Ads API access to identify the Google Ads accounts you authorize and retrieve advertising performance data. This may include customer and ad-account identifiers and campaign, ad group, ad, and keyword reporting such as impressions, clicks, cost or spend, conversions, conversion value, and return on ad spend (ROAS). Google Ads provides a single OAuth scope (https://www.googleapis.com/auth/adwords); ShelfPilot reads reporting data only and does not create, edit, pause, or delete campaigns or manage budgets or bids. Advertising performance shown in ShelfPilot is synchronized periodically and may be delayed relative to Google Ads by more than 24 hours. ShelfPilot does not receive your Google password through this connection.
Klaviyo. When you connect Klaviyo, we may access account and integration identifiers and marketing data available through the permissions you authorize. Depending on enabled features, this may include campaign, flow, message, list or segment, event, audience, and performance data. Where a feature requires profile-level or event-level information, ShelfPilot may process that information only to the extent authorized and necessary to provide the feature.
Other integrations. We may add additional Connected Platforms and features over time. The authorization screen, in-product disclosure, or other notice associated with a new connection or feature will describe the permissions requested where required. We will not use newly accessed platform data for a materially different purpose without providing disclosures or obtaining consent where required.
Service usage, device, and log information
We may collect technical and usage information such as IP address, browser and device information, timestamps, authentication events, pages or features used, sync status, API errors, security events, and diagnostic information. We use this information to operate, secure, troubleshoot, and improve the Service.
Payment information
Subscription payments may be processed by Stripe, Shopify Billing, or another payment provider identified at checkout. ShelfPilot generally does not receive or store full payment card numbers. Payment providers process payment information under their own terms and privacy notices.
Cookies and similar technologies
We use cookies and similar technologies that are necessary for authentication, sessions, security, preferences, and OAuth authorization flows. For example, Clerk may set session cookies, and ShelfPilot may use short-lived cookies or state values to protect connection handshakes against unauthorized requests. We may add product analytics or similar measurement tools in the future and will update our disclosures where required.
Communications and support
If you contact us, request support, participate in onboarding, or otherwise communicate with us, we collect the information you provide and related correspondence.
3. How we use information
We use information to:
- provide, operate, maintain, and secure the Service;
- connect to and synchronize the business accounts you authorize;
- combine data across Connected Platforms for user-facing cross-channel analytics and reporting;
- generate dashboards, business briefings, reports, alerts, forecasts, recommendations, and other insights;
- personalize enabled features and maintain continuity in your organization’s business context;
- troubleshoot connections, detect abuse or security incidents, and maintain reliability;
- provide customer support and communicate about accounts, billing, security, or Service changes;
- develop and improve user-facing features, accuracy, reliability, and performance, subject to applicable platform-specific restrictions;
- enforce our Terms of Service and comply with legal obligations; and
- protect ShelfPilot, our customers, Connected Platforms, and others.
4. Artificial intelligence and automated processing
ShelfPilot may use artificial intelligence, machine learning, rules-based systems, and other automated methods to generate reports, summaries, forecasts, recommendations, classifications, or other outputs. To provide these user-facing features, we may send a service provider the minimum information reasonably needed to process a request or generate an output. That information may include business metrics, summaries, prompts, or other Connected Platform data necessary for the enabled feature.
We currently use Anthropic for certain AI-powered features. We may use or replace service providers that perform similar infrastructure or AI-processing functions, subject to applicable contractual, legal, and Connected Platform requirements.
We do not sell Connected Platform data. Unless a customer expressly opts in and the use is permitted by applicable law and the applicable Connected Platform’s terms, we do not intentionally use merchant-identifiable Connected Platform data to train generalized third-party AI models.
We may create and use aggregated or de-identified information to operate, evaluate, secure, and improve the Service, develop user-facing features, and understand Service performance, but only where the information cannot reasonably identify a customer, individual, store, or connected account and the use is permitted by applicable law and Connected Platform requirements.
5. Google API data
ShelfPilot uses Google API data — from both Google Analytics and the Google Ads API — to provide and improve visible, user-facing ShelfPilot features such as Google Analytics property selection, Google Ads account selection, traffic, engagement, and advertising performance reporting, cross-channel analysis, business briefings, and recommendations. We may combine Google Analytics and Google Ads reporting data with data from other Connected Platforms when you enable cross-channel features.
ShelfPilot’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google API user data, use it for advertising or ad targeting, or use it to determine creditworthiness or for lending. We do not use Google API user data to train generalized artificial intelligence or machine learning models. Human access to Google API user data is limited to circumstances permitted by Google’s policies, such as with the user’s affirmative agreement, for security or troubleshooting where necessary, to comply with law, or for permitted aggregated internal operations.
6. Meta Platform data
We process Meta Platform data only as described in this Policy and for the ShelfPilot features associated with the permissions you grant. We use Meta data to identify and connect authorized business assets and to provide advertising, Page, performance, cross-channel analytics, reporting, and recommendation features.
We do not sell Meta Platform data or use it to advertise unrelated products or services based on a merchant’s connected Meta data. You can disconnect Meta in ShelfPilot. Disconnecting causes ShelfPilot to stop using the connection and remove the associated connector credentials from active use. You may also remove ShelfPilot through your Facebook or Meta settings to revoke authorization through Meta.
To request deletion of Meta data associated with your ShelfPilot account, email privacy@shelfpilot.ioand identify the ShelfPilot account or email address associated with the request. You may use the subject line “Meta Data Deletion.” We will verify and process the request as required by applicable law and Meta’s Platform Terms. For step-by-step instructions, see our Data Deletion Instructions.
7. Shopify data and privacy requests
ShelfPilot implements Shopify’s mandatory privacy compliance webhooks, including customers/data_request, customers/redact, and shop/redact. We respond to verified Shopify requests and complete applicable access or deletion actions within the time required by Shopify, except where retention is legally required.
Shopify data is used to provide merchant-authorized analytics, reporting, operational monitoring, and related Service features. Platform-specific data restrictions and approved protected-customer-data access limits apply even where this Policy describes a broader category of potential business information.
8. Amazon information
ShelfPilot processes Amazon information only for approved and merchant-authorized Service use cases and subject to Amazon’s applicable Selling Partner API policies and agreements. Amazon-specific restrictions override any broader statement in this Policy where those restrictions apply.
We apply platform-specific retention limits to Amazon information. Where applicable under Amazon’s current Data Protection Policy requirements, Amazon personally identifiable information is deleted within 30 days after order delivery, and Amazon non-PII information is not stored for longer than 18 months unless a longer period is legally required. We may retain security logs for periods required by Amazon, provided those logs are handled in accordance with applicable requirements.
9. How we disclose information
We may disclose information in the following circumstances:
Service providers. We use vendors that provide authentication, hosting, databases, infrastructure, payments, communications, security, customer support, and AI or data-processing services. Current providers include Clerk, Supabase, Vercel, Anthropic, and Stripe. These providers receive information only as reasonably necessary for the functions they perform and subject to applicable agreements and platform-specific restrictions.
Connected Platforms and customer-directed integrations. We exchange information with Connected Platforms as needed to authenticate connections, retrieve authorized data, maintain integrations, and provide features you enable. We may also disclose information when you direct us to connect, export, or send data to another service.
Legal, compliance, and safety. We may disclose information where we reasonably believe disclosure is required by law, legal process, or a valid governmental request, or is necessary to investigate fraud, abuse, or security incidents; enforce agreements; or protect rights, safety, and property.
Corporate transactions. Information may be disclosed in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and Connected Platform restrictions.
With your consent. We may disclose information for another purpose when you direct us or provide consent.
We do not sell personal information or Connected Platform data. We do not use Connected Platform data for cross-context behavioral advertising.
We may add, replace, or remove service providers as our infrastructure evolves. Where a change materially affects our handling of personal information or Connected Platform data, we will update this Policy or provide another notice as appropriate.
10. Data retention and deletion
We retain account information, connector credentials, and synchronized business information for as long as reasonably necessary to provide the Service, maintain an active connection, support the purposes described in this Policy, comply with legal obligations, resolve disputes, or enforce agreements. Shorter Connected Platform retention requirements override this general retention period.
When you disconnect a Connected Platform, we stop using the active connection and remove or disable the associated connector credentials from active use. Synced data may be deleted immediately or through scheduled deletion processes, subject to applicable platform requirements, legal obligations, dispute or security needs, and limited backup retention.
When you delete your ShelfPilot account or submit a verified deletion request, we delete or de-identify applicable account and Service data unless we are required or permitted to retain certain information. Deleted information may remain for a limited period in encrypted or access-controlled backups, disaster-recovery systems, and rotating security logs. We do not restore deleted information except for legitimate recovery, security, or legal purposes.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information. These safeguards include encrypted network transmission, protection of sensitive connector credentials at rest, access controls, authentication controls, logging and monitoring, and security and incident-response practices appropriate to the Service and applicable Connected Platform requirements.
No method of transmission, storage, or security is completely secure. We cannot guarantee absolute security.
12. International data transfers
ShelfPilot is operated from the United States. We and our service providers may process information in the United States and other countries where we or they operate. Where required by applicable law, we rely on appropriate transfer mechanisms or contractual safeguards.
13. Your rights and choices
Depending on where you live and the nature of the information, you may have rights to request access to, correction of, deletion of, or a copy of personal information, or to object to or restrict certain processing. You may also withdraw an authorization for future access by disconnecting a Connected Platform or revoking ShelfPilot’s access through the Connected Platform.
To make a privacy or deletion request, email privacy@shelfpilot.io. We may ask for information reasonably necessary to verify the request and your authority over the relevant ShelfPilot account or connected business account. For step-by-step instructions, see our Data Deletion Instructions.
If ShelfPilot processes personal information on behalf of a merchant or business customer, we may direct a request to that customer or assist the customer in responding, as appropriate.
14. Children’s privacy
The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children through the Service.
15. Changes to this Policy
We may update this Privacy Policy as the Service, our integrations, or legal and platform requirements evolve. We will update the effective date when we revise the Policy. If a change materially alters how we use information, we will provide additional notice or obtain consent where required.
16. Contact us
ShelfPilot is operated by Innobio Solutions LLC in the United States.
Privacy questions and requests: privacy@shelfpilot.io
General support: hello@shelfpilot.io