Shelflo
Privacy Policy
Last updated: 30 August 2026
Shelflo is an offline-first retail app. Products, customers, sales, invoices, stock, and related shop records live in a local SQLite database on your device. You can use the app fully without an account, and local-only use does not upload shop data. An optional account with a paid subscription can sync those records to Ofa Suite servers. This policy explains what stays on the device, what an account involves, which processors we use, how long data is kept, and how to delete it.
Who we are
Shelflo is operated by Ofa Suite, an independent one-person software company registered in the Netherlands. The site is ofasuite.com. Questions about this policy can be sent to info@ofasuite.com.
For account data (your email, password hash, subscription status) Ofa Suite is the data controller. For the shop records you choose to sync - including your own customers' details - you are the controller and Ofa Suite acts as a processor on your behalf.
What the app stores on your device
Shop data you enter - products, customers, sales, invoices, stock, settings, and related records - is stored in SQLite on the device. The core app remains fully usable offline without an account. If you never sign in, that shop data is not uploaded to Ofa Suite.
Optional account
An account is optional. Creating one uses an email address and a password. The password is hashed with argon2id on the sync server; it is not stored in plain text. Sign-in is only possible after the email address has been confirmed.
Confirmation, password-reset, and account-deletion messages are sent through Resend from ofasuite.com, as Shelflo <noreply@ofasuite.com>.
Cloud sync
Cloud sync is paid and entitlement-gated. It runs only while the subscription status is Active. When Active, shop and business records you create can sync to https://shelflo-sync.ofasuite.com (Hetzner VPS, PostgreSQL). The app does not contact the sync server anonymously; every request is tied to a signed-in account.
What the server stores
Besides the account email and password hash, the server can store:
- A device_id and invoice series_tag per device that signed in.
- Refresh-token hashes and hashed one-time email tokens (confirmation, reset, deletion).
- IP-derived rate-limit counters for the sign-in, reset, and deletion endpoints.
- Stripe customer and subscription IDs and the subscription status.
- Your synced shop records and an append-only row_history of prior synced versions, used to resolve conflicts between devices.
Synced shop records can include your customers' names, emails, phone numbers, and addresses, and financial records (sales, invoices, payments, and related shop data). Only sync what you are entitled to share with a processor.
A customer record you delete locally can still exist in server history until the cloud account is deleted.
Payments
Payments for cloud sync go through Stripe hosted Checkout and the Stripe Customer Portal. Card data is collected by Stripe, not inside the Shelflo app. Stripe also receives the account email when a Stripe Customer is created. When you delete your account we delete that Stripe Customer; Stripe still keeps the invoice and payment records it is legally required to retain, under its own privacy policy.
Camera
The camera is used on the device only to read barcodes and QR codes. Shelflo does not store camera frames and does not upload them.
Notifications
Reminders and alerts are local operating-system notifications created by the app. They are not a marketing push channel.
Exports, backups, and sharing
Exports, backups, and shares go only to the destination you pick. Once a file leaves Shelflo, that destination, app, or service controls the copy.
Legal basis
- Performance of a contract (GDPR art. 6(1)(b)): creating and running your account, syncing your records, and billing the subscription.
- Legitimate interest (art. 6(1)(f)): rate limiting and abuse prevention on the authentication endpoints, and keeping the service secure.
- Legal obligation (art. 6(1)(c)): retaining payment records through Stripe as required by tax and accounting law.
Shelflo does not use your data for advertising or profiling and does not sell it.
Processors and where data goes
We use the following processors in connection with Shelflo:
- Hetzner (Germany, EU) hosts the sync service database and these pages.
- Cloudflare proxies HTTPS traffic for ofasuite.com and shelflo-sync.ofasuite.com (and therefore sees request metadata such as IP addresses) and stores the nightly database backups (R2).
- Resend delivers transactional email (confirmation, password reset, account deletion).
- Stripe handles subscription payments and receives the account email.
Cloudflare, Resend, and Stripe are US-headquartered companies. Where data leaves the EU they rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses. Shop data synced to the service is stored in the EU.
Retention
- Account and synced records: kept until you delete the account.
- Refresh tokens: valid for 30 days; access tokens expire after 15 minutes.
- Email links: confirmation links expire after 24 hours, password-reset and deletion links after 60 minutes; each is single-use and stored only as a hash.
- Rate-limit counters: per 60-second window, removed as windows roll over.
- Server backups: the sync database is backed up nightly to object storage (Cloudflare R2, encrypted at rest) and each backup is deleted after 30 days, so a deleted account can remain in backups for up to 30 days. Backups are used only for disaster recovery.
- Stripe records: the Customer is deleted with the account; invoice and payment records stay at Stripe for as long as tax and accounting law requires.
Deleting your account and data
Local shop data can be removed with in-app delete actions. Uninstalling the app removes the local database on Android and iOS. On Desktop, data folders may remain after uninstall. Exports, backups, and files you already saved or shared elsewhere may remain at those destinations.
To delete your Shelflo cloud account you have two options:
- In the app: Settings → Account → Delete account, while signed in. You confirm with your password.
- On the web, for example after uninstalling: open shelflo-sync.ofasuite.com/auth/delete-account, enter the account email, and confirm through the link we send to that address.
Either path cancels the Stripe subscription and deletes the Stripe Customer, then removes the account, its sign-in tokens, device registrations, all synced records and their history from the sync server. Shop data on your own devices is not touched. Deletion cannot be undone.
If you cannot use either path, email info@ofasuite.com from the address on the account.
Your rights
Under the GDPR you can ask to access, correct, export, or erase the personal data we hold about you, to restrict or object to its processing, and to withdraw consent where processing is based on it. Account deletion above covers erasure; the app's CSV export and database backup cover portability of your shop records. For anything else, email info@ofasuite.com. You can also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
Children
Shelflo is a business tool and is not directed at children under 16. We do not knowingly create accounts for them.
Tax and legal
Shelflo helps you record sales, stock, invoices, and related figures. It is not tax, accounting, or legal advice and does not guarantee compliance. You are responsible for your records and local requirements.
Changes to this policy
If Shelflo's data handling changes, this page and the "last updated" date above will be revised. Material changes will be reflected here.
Contact
Questions or requests about privacy: info@ofasuite.com.