Privacy & Data Protection
Privacy Policy
Privacy Commitment
At Shelf Labs, we are committed to protecting your privacy and handling your data with transparency and care. This Privacy Policy explains how we collect, use, store, and protect your information when you use ShelfGRC.
Last updated: 27 September 2026
1. Introduction
This Privacy Policy applies to ShelfGRC, a cloud-based software-as-a-service (SaaS) platform provided by Shelf Labs. We are committed to compliance with applicable data protection laws, including:
- Australian Privacy Principles (APPs) under the Privacy Act 1988
- General Data Protection Regulation (GDPR) for EU users
- California Consumer Privacy Act (CCPA) for California residents
2. Information We Collect
2.1 Information You Provide Directly
When you use ShelfGRC, you may provide us with the following information:
- Account Information: Name, email address, job title, organization name, phone number
- Billing Information: Payment card details, billing address (processed securely through third-party payment processors)
- Customer Data: Risk assessments, control documentation, evidence files, compliance records, incident reports, and other GRC-related content you upload or create
- Communications: Messages, feedback, and support requests you send to us
2.2 Information Collected Automatically
When you access and use ShelfGRC, we automatically collect:
- Usage Data: Actions taken within the platform, recorded in our server logs and audit trail
- Device Information: IP address, browser type and version, operating system, device identifiers
- Log Data: Access times, error logs, performance metrics
- Cookies and Similar Technologies: Session cookies and one preference cookie (see Section 8)
2.3 Information from Third Parties
We may receive information from:
- Payment Processors: Transaction confirmation and billing information
- Server Logs: Request logs held by our hosting provider, used for security and reliability, not for profiling
We do not currently offer third-party sign-in (e.g., Google or Microsoft); account access is by email and password, optionally with multi-factor authentication.
2.4 Third-Party Incident Reporters
ShelfGRC customers may publish a public incident-report form to let people outside their organisation (e.g., a member of the public, a contractor, or a customer of theirs) submit a report. That form collects a title, severity, date of occurrence, affected systems, an impact description, and a description of the incident, plus a name and email address, both optional. A submitted report is stored as part of the customer organisation's data, governed by this Privacy Policy and that organisation's own practices, and is sent to that organisation's owners and to the people it designates to handle these reports. If you provide an email address, we also send you a confirmation email with your report reference. IP address and browser user agent are not stored with the report (our hosting provider's request logs are covered separately — see Section 2.3).
3. How We Use Your Information
3.1 Service Provision
We use your information to:
- Provide, maintain, and improve ShelfGRC
- Process your account registration and authentication
- Enable core features including risk management, compliance tracking, and evidence storage
- Suggest data-import field mappings and draft report narrative for your review (see our AI Usage Policy)
- Provide customer support and respond to inquiries
- Process payments and manage subscriptions
3.2 AI and Machine Learning
We use your Customer Data to power AI features, including:
- Answering your questions about your own data through the chat assistant
- Suggesting column-to-field mappings when you import a spreadsheet
- Drafting narrative text for reports, for your review
Important: We do not use your Customer Data to train AI models that serve other customers. Your data remains isolated within your tenant. See our AI Usage Policy for more details.
3.3 Communication
We may use your contact information to:
- Send service-related notifications and updates
- Respond to your support requests
- Send important security or legal notices
- Provide product updates and feature announcements (you may opt out)
3.4 Analytics and Improvement
We analyse server logs and support requests to:
- Understand how users interact with ShelfGRC
- Identify and fix bugs and performance issues
- Develop new features and improvements
- Monitor service availability and security
3.5 Legal Compliance
We may use your information to:
- Comply with legal obligations and regulatory requirements
- Enforce our Terms and Conditions
- Protect our rights, property, and safety
- Prevent fraud, abuse, and security threats
4. Data Storage and Security
4.1 Data Storage
Your data is stored securely using Supabase, a cloud database platform built on PostgreSQL, with redundancy and backup systems.
Data Residency: Customer Data — including the vector embeddings we generate to power AI features — is stored in the Supabase database region you select during account setup: Australia (Sydney) by default, or European Union (Frankfurt), Asia (Tokyo), United States (N. Virginia), or India (Mumbai). Selecting an enabled region moves your data there automatically during onboarding; Australia, the European Union, and Asia are enabled today, while United States and India are provisioned but not yet enabled, so a customer who selects one of those is served from Australia until it is enabled. Your account identity (login credentials, sessions, and multi-factor authentication), billing records, and tenant registration are always stored in Australia, regardless of your data region. ShelfGRC's application servers, hosted by Vercel, run in Australia for every customer. The lightweight request-routing layer that sits in front of those servers (authentication checks and session handling) runs on Vercel's global edge network, which may process your request in a location other than Australia before handing it to our Australian application servers. AI embeddings are computed by Amazon Bedrock in the same region as your data; AI assistant responses are generated using Anthropic's API in the United States, and prompts to it may include relevant Customer Data regardless of your data region. We will update this policy and notify affected customers before any further change to where data is stored or processed.
4.2 Security Measures
We implement industry-standard security measures to protect your data, including:
- Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Role-based access control (RBAC) and multi-tenant data isolation
- Authentication: Secure authentication with support for multi-factor authentication (MFA)
- Monitoring: Continuous security monitoring and audit logging
- Vulnerability Management: Regular security assessments and penetration testing
- Incident Response: Documented incident response procedures
4.3 Data Retention
We retain your data as follows:
- Active Accounts: Customer Data is retained for as long as your organisation's account is active, including if your subscription is cancelled or lapses — cancelling a subscription does not, by itself, delete or schedule deletion of your organisation's data
- Deleted Organisations: An owner may delete the organisation from Settings. Its data — including AI chat transcripts with our assistant, which are stored as part of the organisation's data — becomes inaccessible immediately and is recoverable by contacting support for 30 days, after which it is permanently purged from our production systems
- Audit Logs: Retained for 7 years to comply with regulatory requirements; a record of who did what and when is kept even after an organisation's other data is purged
- Billing Records: Retained for 7 years for tax and accounting purposes
You may request early deletion of your data by contacting us at privacy@shelflabs.com.
5. Data Sharing and Disclosure
5.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information or Customer Data to third parties for marketing purposes.
5.2 Service Providers
We share data with trusted third-party service providers who assist us in operating ShelfGRC, including:
- Supabase: Database and backend infrastructure, in the region you choose (see Section 4.1)
- Vercel: Frontend hosting and content delivery — application servers in Australia, edge routing global (see Section 4.1)
- Payment Processors: Stripe (United States) for payment processing
- AI/LLM Providers: Anthropic (United States; chat assistant and report narrative) and Amazon Bedrock (in the same region as your data — see Section 4.1; search embeddings) — see our AI Usage Policy
- Klaviyo: (United States) Holds the email address of anyone who joins our waitlist, so we can tell them when they can sign up
- Resend: (United States) Transactional email delivery, including invitations, incident notifications, proposal escalation alerts, the weekly digest and record-alert emails (which may include the key, title, and owner name of the risk, control, or other record they concern), and account, billing, and trial emails
These service providers are contractually obligated to protect your data and use it only for the purposes we specify.
5.3 Legal Requirements
We may disclose your information if required by law or in response to:
- Valid legal process (subpoena, court order, warrant)
- Government or regulatory requests
- Protection of our legal rights or safety
- Investigation of fraud, security threats, or violations of our Terms
5.4 Business Transfers
If Shelf Labs is involved in a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change and provide options regarding your data.
6. Your Privacy Rights
6.1 Access and Portability
You have the right to access your personal information and Customer Data. You may export your data at any time through the ShelfGRC interface in standard formats (CSV, JSON).
6.2 Correction and Update
You may update your account information and Customer Data at any time through your account settings.
6.3 Deletion
You may request deletion of your personal information and Customer Data by:
- Having an organisation owner delete the organisation from Settings — this starts the 30-day recovery window described in Section 4.3; note that cancelling your subscription alone does not delete data
- Contacting us at contact@shelflabs.io for immediate deletion
Note: We may retain certain information as required by law or for legitimate business purposes (e.g., audit logs, billing records).
6.4 Opt-Out of Marketing
You may opt out of marketing communications by:
- Clicking "unsubscribe" in marketing emails
- Updating your communication preferences in account settings
- Contacting us at contact@shelflabs.io
Note: You cannot opt out of essential service communications (e.g., security alerts, billing notifications).
6.5 GDPR Rights (EU Users)
If you are located in the European Union, you have additional rights under GDPR:
- Right to Object: Object to processing of your personal data
- Right to Restrict: Request restriction of processing
- Right to Lodge a Complaint: File a complaint with your local data protection authority
6.6 CCPA Rights (California Residents)
If you are a California resident, you have rights under CCPA:
- Right to know what personal information we collect and how it's used
- Right to delete personal information
- Right to opt out of sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your rights
7. International Data Transfers
ShelfGRC's application is operated from Australia, and your Customer Data is stored in the region you choose during account setup (see Section 4.1 for available regions and current status). Regardless of your data region, some processing occurs elsewhere: AI-assisted features send relevant Customer Data to Anthropic's API in the United States, and your account identity, billing records, and tenant registration are always processed in Australia. Your data may therefore be transferred to and processed in Australia, the United States, or another country where our service providers operate.
For EU users, we ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements (DPAs) with service providers
- Compliance with GDPR requirements for international transfers
8. Cookies and Tracking Technologies
8.1 Cookies We Set
ShelfGRC sets only the cookies needed to keep you signed in and keep your session secure, plus one interface preference. We do not use analytics or advertising cookies.
- sb-<project>-auth-token (and numbered chunks): your Supabase sign-in session. Essential. Persists for up to 400 days unless you sign out.
- sg_last_activity: the time of your last request, used to sign you out after a period of inactivity. Essential. HttpOnly, cleared when the browser session ends.
- sg_last_tenant: which organisation you last worked in, used for the audit trail of organisation switches. Essential. HttpOnly, cleared when the browser session ends.
- sidebar_state: whether you collapsed the navigation sidebar. Preference. Persists for 7 days.
Your browser’s local storage also holds your light/dark theme choice, a mirror of the inactivity timestamp so all your open tabs sign out together, and an unsaved onboarding draft while you complete setup.
8.2 Managing Cookies
You can block or delete cookies through your browser settings. Because every cookie above except sidebar_state is required for sign-in, blocking them will prevent you from using ShelfGRC.
8.3 Profile Images
If you upload a profile picture, it is stored in a publicly readable location; anyone with the link can view it.
9. Third-Party Links and Services
ShelfGRC may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to third-party sites or services. We encourage you to review the privacy policies of any third-party services you use.
10. Children's Privacy
ShelfGRC is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will delete it promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification to your registered email address
- Displaying an in-app notification
Continued use of ShelfGRC after changes become effective constitutes acceptance of the updated Privacy Policy.
Current as at 24 September 2026
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Shelf Labs — Privacy Team
Email: contact@shelflabs.io
Website: www.shelflabs.io
For GDPR-related inquiries, you may also contact our Data Protection Officer at contact@shelflabs.io
Related Legal Documents