Privacy Policy
Last updated: March 7, 2026
Shelfware ("we", "us", "our") is a personal video game collection management service operated at shelfware.app. We built Shelfware because we're collectors too, and we believe your data should serve you — not advertisers, not data brokers, not anyone else.
This policy explains what we collect, why we collect it, and what we do (and don't do) with it.
What We Collect
Account Information
When you create an account, we collect your email address, username, and password (stored as a one-way hash — we never see or store your actual password). You may optionally provide a full name, date of birth, country, gender, avatar image, and preferred currency. All optional fields can be left blank.
Collection Data
The core of Shelfware is your collection. We store the games you catalog, including conditions (loose, complete in box, sealed), regions, acquisition costs you choose to enter, wishlist entries, platform preferences, and barcodes you scan. This data is yours — we just keep it organized for you.
Usage Data
We collect basic server logs (IP addresses, request timestamps, browser type) to keep the service running and to diagnose issues. We use Sentry for error reporting with a 10% sample rate — no personally identifiable information is sent to Sentry, only technical error details.
AI & Machine Learning
Shelfware uses AI and machine learning to make the service better for collectors:
- Barcode identification — When you scan a barcode, we may use AI services to identify the game. The barcode image and lookup request are logged.
- Recommendation scoring — Our self-hosted ML models analyze collection patterns to suggest games you might want. No collection data leaves our servers for this purpose.
- Game database matching — We use AI to match games across different data sources (IGDB, PriceCharting, TheGamesDB) to provide accurate metadata.
AI/ML service requests are logged with request and response payloads for quality improvement purposes. These logs are retained for 90 days and then automatically deleted. You can opt out of collaborative filtering (recommendations based on other collectors' patterns) in your profile settings.
Third-Party Services
We integrate with the following services to provide game data and keep the platform running. None of these services receive your personal information beyond what's strictly necessary:
-
IGDB — Game metadata, cover art, and platform information. No user data is shared with IGDB.
-
PriceCharting — Market pricing data for game values. We fetch pricing data in bulk; your collection details are never sent to PriceCharting.
-
TheGamesDB — Boxart images. No user data is shared.
-
Postmark — Transactional email delivery (password resets, email verification, account notifications). Postmark receives your email address only when we need to send you an email.
-
Sentry — Error reporting and performance monitoring. Sampled at 10%. No personally identifiable information is sent — only technical error details like stack traces and browser metadata.
What We Don't Do
Let's be clear about this:
- We do not display advertising of any kind.
- We do not sell, rent, or share your data with third parties for marketing purposes.
- We do not use social media tracking pixels or beacons.
- We do not engage in cross-site tracking.
- We do not use third-party cookies. The only cookies we use are strictly functional (session management and CSRF protection).
- We do not sell your collection data to price aggregators, resellers, or anyone else.
Data Retention
- Account and collection data is retained for as long as your account is active. If you request account deletion, your data enters a 30-day grace period during which you can cancel the deletion. After the grace period, your account and collection data are permanently deleted.
- AI/ML service logs (barcode lookups, recommendation requests) are retained for 90 days, then automatically purged.
- Audit logs are anonymized when your account is deleted — we retain the technical event data but remove all identifying information.
- Server logs (access logs, error logs) are retained for 30 days.
Your Rights & Controls
You have full control over your data:
- View and edit your profile information and collection data at any time through the app.
- Opt out of collaborative filtering in your profile settings. Your collection patterns won't be used to generate recommendations for others.
- Control your public profile visibility — choose whether your collection is visible to other users or kept private.
- Request account deletion from your profile settings. Deletion has a 30-day grace period during which you can change your mind. After that, all personal data is permanently removed.
- Export your data — contact us if you need a copy of your collection data in a portable format.
Security
We take the security of your data seriously:
- Passwords are hashed using industry-standard algorithms (bcrypt). We never store plaintext passwords.
- API authentication uses JWT tokens with appropriate expiration.
- Rate limiting is enforced on sensitive endpoints (login, registration, password reset, barcode scanning) to prevent abuse.
- All forms are protected against CSRF attacks.
- Mobile app tokens are stored in the device's encrypted secure storage.
- All connections use HTTPS/TLS encryption in transit.
Children's Privacy
Shelfware is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it promptly.
Changes to This Policy
We may update this privacy policy from time to time. If we make material changes, we'll notify you via the email address associated with your account at least 14 days before the changes take effect. The "last updated" date at the top of this page reflects the most recent revision.
Contact Us
Questions about this privacy policy or how we handle your data? Reach out at [email protected]. We're happy to help.