Privacy Policy
Version 2.0.0-draft · Effective July 11, 2026
Data processors
| Processor | Purpose | Data categories |
|---|---|---|
| Clerk | Authentication and account identity | Name, email address, profile image, sign-in credentials |
| Stripe | One-time payment processing, receipts, refunds, and dispute handling | Billing name/email, payment method metadata, purchase and transaction history |
| PostHog | Product analytics (understanding feature usage) | App usage events, device/browser metadata, approximate location from IP |
| Convex | Application database and backend functions | Marker collection, organization preferences, saved palettes, lifetime purchase grant status |
| Vercel | Application hosting and performance monitoring | Request logs, performance/analytics metadata |
1. Overview
This Privacy Policy explains what personal data ColorShelf collects, why, and the rights you have over it, including rights under Brazil's Lei Geral de Proteção de Dados (LGPD).
If you use ColorShelf as a signed-out guest, your marker collection, organization, and palette data stay in your browser's local storage and are never sent to our servers. The sections below describing app-data processing apply once you create an account.
2. Data we collect
Account and profile data: your name, email address, and profile image, managed through Clerk when you create an account.
App data: the marker sets you mark as owned, your organization grid preferences, and any palettes and tags you save, stored in our Convex database under your account.
Purchase data: if you buy Pro, Stripe processes the one-time payment and stores transaction, receipt, refund, and dispute history. ColorShelf does not store your card details; Convex stores only the identifiers and grant state needed to recognize lifetime access.
Usage data: product analytics events (e.g. which features you use) collected via PostHog, along with standard technical data such as device type, browser, and approximate location derived from IP address.
Legal acceptance records: the version and timestamp of the Terms of Service and Privacy Policy you have accepted.
3. Why we process your data and our legal basis
To provide the service you requested (contract performance): storing your collection, organization, and palette data so it syncs across devices.
To process the one-time Pro purchase (contract performance / legal obligation): transaction data is processed by Stripe to fulfill lifetime access, handle refunds or disputes, and meet financial record-keeping obligations.
To understand and improve the product (legitimate interest): product analytics help us see which features are useful; you can opt out at any time from your Account page.
To comply with the law (legal obligation): for example, retaining certain billing records for the period required by tax and financial regulations.
4. Who we share data with
We share data with the service providers (processors) listed below, each of which processes data only to provide their respective service to us, not for their own independent purposes.
5. How long we keep your data
App data (collection, organization, palettes) is kept for as long as your account exists, and deleted when you delete your account.
Billing records are retained for the period required by applicable financial and tax regulations, even after account deletion, as disclosed in the Data Subject Rights section below.
Analytics events are retained according to PostHog's standard retention period and are not linked to your account once you opt out of analytics.
6. Your rights (LGPD data subject rights)
Access and portability: you can download a copy of your ColorShelf app data (marker collection, organization preferences, palettes, lifetime grant state, and legal acceptance history) at any time from the Account page's Privacy & Data section. Detailed Stripe transaction history remains available from Stripe and is not duplicated in the app export.
Correction: you can update your profile name directly from the Account page; other app data can be corrected by editing it within the product.
Deletion: you can request deletion of your account and associated app data from the Account page's Privacy & Data section. We delete your Convex lifetime grant, other app data, and account identity. There is no recurring subscription to cancel. Stripe transaction records are retained as required by law even after deletion because they document a completed financial transaction.
Objection to analytics: you can opt out of product analytics at any time from the Account page.
To exercise a right not covered by the self-service tools above, contact us using the details in the Contact section.
7. Cookies and analytics
ColorShelf uses PostHog for first-party product analytics — understanding which features people use, not advertising or cross-site tracking. This may use cookies or similar local storage to recognize your session.
You can opt out of analytics collection at any time from your Account page's Privacy & Data section; this does not affect core product functionality.
8. International data transfers
Our service providers may process data outside Brazil. Where this occurs, we rely on the safeguards each provider offers for international transfers.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we make substantive changes, we will update the version and effective date above, and signed-in users will be asked to review and accept the updated policy before continuing to use authenticated features.
10. Contact
For privacy questions or to exercise a data subject right not covered by self-service tools, contact us at privacy@colorshelf.example.com. (Replace with the team's actual contact address before this document leaves draft status.)