Privacy Policy
Last updated 2026-08-16T00:00:00.000Z · Shelf Cloud Services OÜ
Shelf Cloud holds an account email, a billing record from Stripe, the public key and configuration you give a machine, and service logs. It does not sell personal data, does not run analytics on the marketing site, and does not look inside your machine.
1. Who we are
Shelf Cloud Services OÜ, registry code [registrikood], [registered address], Estonia, is the controller of the personal data described in this policy.
Contact: [privacy@ email]
We have not appointed a Data Protection Officer; we are not required to under Article 37 GDPR. Data protection enquiries go to the address above.
Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, Tallinn — or the authority in your own country of residence or work.
2. What this policy covers, and what it does not
This policy covers data we hold about you as our customer or as a visitor to our website: your account, billing, support correspondence, and service telemetry. For that data, we decide why and how it is processed, so we are the controller.
It does not cover data inside your instance. What you run and store on a Shelf instance is yours. For that data, you are the controller and we are your processor, acting only on your instructions. Those obligations live in the Data Processing Addendum, not here.
We do not inspect, scan, index, analyse or mine the contents of customer instances.
3. What we collect and why
Account data:
We do not receive or store full card numbers. Payment details go directly to Stripe.
Service data:
Website data:
We do not use advertising cookies, tracking pixels, session recording, or third-party analytics that profile you. If that changes, we will ask for consent first and update this policy before doing so.
Quoting data:
Our pricing is dynamic. When you request a price we log the shape requested, the price shown, and whether it was accepted. Where you are logged in, this is linked to your account.
We do not use this to price differently for you personally. Prices depend on the shape requested, market conditions and our available capacity — not on who is asking.
4. Who we share it with
We do not sell personal data, and we do not share it for advertising or profiling.
5. Where your data is
Account data is stored within the EEA. Instance data is stored in Germany.
Where a recipient processes data outside the EEA — currently only Stripe's US operations — the transfer is made under an adequacy decision or the EU Standard Contractual Clauses (2021/914).
6. How long we keep it
Retention periods are in the tables above. Two general rules:
• Accounting records: 7 years. Estonian law requires it; we cannot delete these on request.
• Everything else: deleted when the purpose ends, or at the stated period, whichever is sooner.
On termination, instance storage is retained for 7 days so you can request a copy, then securely wiped. See DPA §11.
7. Your rights
Under the GDPR you may:
• Access the data we hold about you
• Rectify inaccurate data
• Erase data, where we have no overriding obligation to keep it
• Restrict processing while a dispute is resolved
• Port data you gave us, in a machine-readable format
• Object to processing based on legitimate interests — including our quoting logs
• Withdraw consent, where we relied on it (we currently rely on consent for nothing)
• Complain to a supervisory authority
Write to [privacy@ email]. We respond within one month, extendable by two months for complex requests, and we will tell you if we need the extension. There is no charge unless a request is manifestly unfounded or excessive.
Practical limit worth knowing: if your request concerns data inside a Shelf instance belonging to one of our customers, we must forward it to that customer rather than act on it. They control that data; we cannot search it.
8. Security
Technical and organisational measures are described in our Security Overview and in DPA Annex II. In short: TLS everywhere, encryption at rest, KVM isolation between tenants, SSH keys only, MFA on administrative accounts, logged administrative access.
Two things we state plainly rather than bury:
1. Encryption at rest is not zero-knowledge. We hold the keys and are technically capable of accessing instance storage. Encrypt within your instance if you need a stronger boundary.
2. We do not back up customer instances. Backups are your responsibility.
9. Automated decision-making
Our pricing engine automatically decides what price to show, and may decline to quote. This is not a decision producing legal or similarly significant effects about you under Article 22 — it is a decision about market conditions and our inventory, applied uniformly to everyone requesting the same shape at the same moment.
We do not profile customers, and we do not price by identity.
10. Children
Our services are sold to businesses only and are not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes
We will post material changes here at least 30 days before they take effect, and email account holders. The version and effective date are at the top of this page. Superseded versions are available on request.
12. Complaints
Tell us first — [privacy@ email] — and we will try to resolve it. You may complain to the Estonian Data Protection Inspectorate or your local supervisory authority at any time, whether or not you contact us first.
Contact
Questions about this document go to the support page at /support.