Privacy policy
Last updated 25 September 2026
This policy explains what information ShelfSignal collects, why, and what we do with it. It covers the website at shelfsignal.io, including the store check, and the reporting service we provide to brands that hire us.
Who we are
ShelfSignal is a product of, and operated by:
byAkbar, Inc., a Delaware corporation, doing business as ShelfSignal132 C S Kendall Ave Apt C, Kalamazoo, MI 49006
abdul@shelfsignal.io
Questions about this policy or your data go to the address above.
Website visitors and the store check
The address you check
When you enter a website address, our server fetches that site's public pages the way an AI assistant would: robots.txt, llms.txt, the sitemap, product pages, and a public product list if the store publishes one. We don't log in anywhere or read anything that isn't public. We don't keep the addresses you check in our own database, but each check (the store address, its score, and the store platform) is recorded in Google Analytics, described below. A result may be reused for up to five minutes so that a repeat check of the same site is faster.
Analytics and cookies
We use Google Analytics to understand how the site is used: pages viewed, how visitors arrived, approximate location (country and city), device and browser, the stores checked with their scores, and clicks on our contact options. Google Analytics sets first-party cookies (such as _ga) to recognise returning visitors. Google processes this data as our service provider under its own terms and privacy policy.
You can opt out by blocking cookies in your browser or by installing Google's Google Analytics opt-out add-on. We don't use advertising trackers or sell visitor data, and there are no accounts.
Fonts
Your browser loads our typefaces from Google Fonts, so Google receives your IP address when a page loads.
Server logs
Our hosting provider, Vercel, keeps standard request logs (IP address, browser type, and the page requested, including the address you checked) for a short period, for security and to keep the site running.
If you email us, we keep the message and your address to reply and to keep a record of our conversation.
Data we handle for client brands
When a brand hires us for weekly reporting, it authorizes read-only access to the data below. We access only what the brand authorizes, and only for that brand.
From Amazon (Selling Partner API)
- Search Query Performance report: weekly search-funnel figures for the brand's own ASINs: how often shoppers searching a term saw, clicked, added to cart, or bought the brand's products, against the total for that term.
- Search Terms report: the most-clicked products for search terms, filtered to the brand's category and named competitors.
These reports are aggregated and contain no information about individual buyers. We request only Amazon's Brand Analytics role. We don't request any restricted role, and we can't see buyer names, addresses, contact details, or individual orders on Amazon. We never make changes to a brand's Amazon account.
Our commitments for Amazon data. We access Amazon Selling Partner API data (Brand Analytics reports) only after the brand authorizes us in Seller Central. We use it only to produce that brand's own reports. We store it encrypted. We delete it when the brand asks us to, or when the brand revokes our access, and in any case within 30 days of either.
From Shopify (Admin API, read-only)
Order ID and number, order date, order total and currency, the products, SKUs, and quantities on each order, the sales channel, and where the visit came from (referring website, landing page, and UTM tags). We don't request customer names, email addresses, phone numbers, or postal addresses.
From the brand directly
Product lists, the competitors to track, and a log of listing changes, so we can measure whether each change worked.
AI visibility check
To estimate whether AI assistants recommend a brand, we send shopper-style questions built from search terms (for example, "best barista oat milk") to Anthropic's API. These questions contain no personal information and no client sales data.
How we use data
- Only to produce reports and dashboards for the brand that authorized access.
- We never sell data, share one client's data with another client, use it for advertising, or use it to train AI models.
- Amazon information is used only as Amazon's Acceptable Use Policy and Data Protection Policy allow, and only to provide our service to the seller who authorized it.
Who processes data for us
| Provider | What for |
|---|---|
| Vercel | Hosting this website and the store check |
| Amazon Web Services | Storing downloaded report files |
| Our managed Postgres provider | The database behind client reports |
| Instant Dashboards | Showing each client its own dashboard |
| Anthropic | The AI visibility check (search terms only) |
| Email, web fonts, and website analytics (Google Analytics) |
These providers may process data in the United States and other countries. Each is bound by its own security and privacy commitments.
How we protect data
- Data is encrypted in transit (TLS) and at rest.
- Access is limited to the people who produce the reports, each using multi-factor authentication.
- Access tokens for Amazon and Shopify are stored as encrypted secrets, never in code, and are revoked when an engagement ends.
- Each client's dashboard login can read only that client's reports.
- If we detect a security incident affecting client data, we notify the affected clients without undue delay. Incidents involving Amazon information are also reported to Amazon within the time its policies require.
How long we keep data
- Client data is kept while the engagement is active.
- It is deleted within 30 days after the engagement ends or the brand revokes our access, or sooner if the brand asks.
- Emails are kept as long as needed for our correspondence and records.
Your choices
- Amazon: revoke our access at any time in Seller Central under Apps and Services, then Manage Your Apps.
- Shopify: uninstall our app from your Shopify admin.
- Access or deletion: email us to see what we hold about you or your brand, or to have it deleted. We reply within 30 days.
Children
ShelfSignal is a business service and isn't directed at children.
Changes
If we change this policy, we update the date at the top. Material changes are emailed to active clients before they take effect.