FirstShelf.AI ("we," "us," or "our") is committed to protecting your privacy and ensuring transparency about how we collect, use, and safeguard your personal information. This Privacy Policy explains our data practices when you use our Generative Engine Optimization (GEO) platform and services (collectively, the "Service").
By using the Service, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree with our practices, please do not use the Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
Email address: Required for account creation, authentication, and communications
Password: Securely hashed and stored (for email/password authentication)
Name: If provided during registration or via Google OAuth
Profile picture: If provided via Google OAuth
Google account ID: If you authenticate using Google OAuth
2.2 Product Listing Data
To provide our GEO optimisation services, we collect the product information you submit:
Product titles: The titles of your e-commerce listings
Product descriptions: Full text descriptions you provide for analysis
Product tags/keywords: Tags associated with your listings
Product images: Images you upload for visual analysis
Platform information: Which e-commerce platform your listing is on
Product category: The type of product you're selling
2.3 Usage Data
We automatically collect information about how you use the Service:
Audit and optimisation history: Records of analyses and optimisations performed
Feature usage counts: Number of audits, optimisations, and image generations used
Session information: Login timestamps and session duration
Device information: Browser type, operating system, and device type
IP address: For security, fraud prevention, and approximate location
2.4 Payment Information
We do not directly collect or store payment card details. All payment processing is handled by our third-party payment processor, LemonSqueezy. We receive:
Subscription status and tier
Billing cycle dates
Transaction IDs for reference
Customer ID from the payment processor
Payment and transaction records are retained for a minimum of 7 years for legal, accounting, and tax compliance purposes, even after account deletion. Please refer to our Terms of Service — Billing & Refund Policy for details on subscription charges.
3. How We Use Your Information
3.1 Provide and Improve the Service
Analyse your product listings using AI to generate GEO scores and recommendations
Generate optimised titles, descriptions, and tags for your products
Analyse uploaded images for text-image alignment and visual quality
Generate AI-optimised product images (Pro and Premium tiers)
Store your audit history for future reference
Track and enforce usage limits based on your subscription tier
3.2 Account Management
Authenticate your identity and maintain account security
Analyse aggregate usage patterns to improve our algorithms
Identify and fix technical issues
Develop new features based on user needs
3.4 Legal and Security
Prevent fraud, abuse, and unauthorised access
Comply with legal obligations
Enforce our Terms of Service
4. AI Processing and Data Handling
4.1 How AI Analyses Your Data
When you submit product listings for analysis or optimisation, your content is processed by AI systems to generate scores, insights, and recommendations. This includes:
Text analysis for semantic density, structure quality, and entity detection
Image analysis for visual signal quality and text-image alignment
Content generation for optimised titles, descriptions, and tags
Image generation using AI models (for applicable tiers)
4.2 Third-Party AI Providers
We use third-party AI model providers to power our analysis and generation features. When your content is sent to these providers for processing:
Your data is transmitted securely using encryption
We use API-based integrations that process but do not retain your data beyond the request
AI providers are bound by their own privacy policies and data processing agreements
4.3 What We Don't Do
We do not train AI models on your specific product data
We do not share your product listings with other users
We do not use your content for advertising purposes
4.4 Private experimental response research
Where an account uses an experimental model-response feature, FirstShelf stores the response only to show that account its configured controlled sample and to operate the experiment. Access is limited to the account owner and authorised service processes through access controls. These private samples do not prove external AI-shopping visibility, recommendation, ranking, traffic, or sales outcomes.
Raw model answers, excerpts, and detailed parsed response content are redacted after 90 days under the retention process described below. Please do not submit unnecessary personal, sensitive, or third-party information to an experimental prompt.
5. Data Storage and Security
5.1 Where We Store Your Data
Your data is stored using the following services:
Supabase: Cloud-hosted PostgreSQL database for account data, listings, audits, and optimisations
Supabase Storage: Secure cloud storage for uploaded and generated images
5.2 Security Measures
We implement industry-standard security measures to protect your data:
Encryption in transit: All data transmitted between your browser and our servers uses TLS/HTTPS encryption
Encryption at rest: Database and storage data is encrypted at rest
Secure authentication: Passwords are hashed using secure algorithms; OAuth tokens are handled securely
Access controls: Row-level security ensures users can only access their own data
Signed URLs: Private images use time-limited signed URLs (10-minute expiration)
5.3 Data Retention
Account data: Retained while your account is active and for a reasonable period after deletion
Audit history: Retained for your reference; you may request deletion
Uploaded images: Stored as long as needed for the Service; deleted upon request
Generated images: Retained in your account unless you delete them
Operational usage logs: Retained for security and service reliability purposes, typically for 90 days
Marketing measurement: Raw funnel events are retained for up to 13 months. Older events are deleted after only non-identifying daily groups with at least five events may be retained. Consent-linked attribution records are deleted after 24 months of inactivity.
Experimental model responses: Raw model answers, response excerpts, and detailed parsed response data from private controlled research are retained for up to 90 days, then redacted. Derived selection, rank, and confidence measurements may remain with the related account record.
Payment records: Retained for a minimum of 7 years for legal and accounting compliance
5.4 Optional marketing measurement
FirstShelf records server-owned product events, such as an accepted audit job or a verified payment, to operate and understand the Service. These events do not include a listing draft, image payload, URL query string, or free-form browser data.
Anonymous marketing attribution is optional and off by default. When enabled, FirstShelf may store a random browser identifier, a page path without query parameters, a referrer without query parameters, and recognised UTM values. After that same browser signs in, FirstShelf may use the consented identifier to associate its first and last non-direct touch with that account. We intentionally do not use this feature for cross-device attribution or automated decisions about you.
Marketing measurement preference
We process this information only as permitted by applicable law. If you have questions about the lawful basis that applies to you or want to exercise a privacy right, contact us using the details in this policy.
6. Third-Party Services
We share data with the following third-party service providers who process data on our behalf:
Service
Purpose
Data Shared
Supabase
Database, authentication, file storage
All account and listing data
LemonSqueezy
Payment processing, subscription management
Email, subscription status, payment details
AI Model Providers
Text analysis, content generation, image generation
Listing content submitted for analysis
Resend
Transactional email delivery
Email address, email content
Google
OAuth authentication (optional)
Authentication tokens, basic profile info
Each third-party provider is bound by their own privacy policy and applicable data protection laws. We select providers who demonstrate commitment to data security and privacy.
7. Cookies and Tracking
7.1 Essential Cookies
We use essential cookies that are necessary for the Service to function:
Authentication cookies: To maintain your logged-in session
Security cookies: To prevent cross-site request forgery (CSRF) attacks
Preference cookies: To remember your settings and preferences
7.2 What We Don't Use
We do not use third-party advertising cookies
We do not use cross-site tracking cookies
We do not sell data to advertisers or data brokers
8. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal data:
8.1 Access and Portability
You have the right to access the personal data we hold about you and to receive a copy in a portable format. You can view your audit history and account information directly in the dashboard.
8.2 Correction
You have the right to correct inaccurate personal data. You can update your account information through your account settings.
8.3 Deletion
You have the right to request deletion of your personal data. To delete your account and associated data, contact us at Email us. Note that some data may be retained for legal or legitimate business purposes (see Section 5.3).
8.4 Restriction and Objection
You may have the right to restrict or object to certain processing of your data. Contact us to discuss your specific situation.
8.5 Withdraw Consent
Where processing is based on consent, you may withdraw consent at any time. This will not affect the lawfulness of processing before withdrawal.
8.6 Lodge a Complaint
If you believe your privacy rights have been violated, you have the right to lodge a complaint with your local data protection authority.
9. GDPR Compliance (EEA Users)
If you are located in the European Economic Area (EEA), the following additional provisions apply:
9.1 Legal Basis for Processing
We process your personal data based on the following legal bases:
Contract performance: Processing necessary to provide the Service you requested
Legitimate interests: Processing for fraud prevention, security, and service improvement
Consent: Where you have given explicit consent (e.g., for marketing communications)
Legal obligation: Processing required by law
9.2 International Data Transfers
Your data may be transferred to and processed in countries outside the EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, such as:
Standard Contractual Clauses approved by the European Commission
Adequacy decisions for countries with adequate data protection
Binding corporate rules where applicable
9.3 Data Protection Enquiries
For GDPR-related inquiries, contact us at Email us.
10. CCPA Compliance (California Users)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Right to Know: Request disclosure of personal information collected, used, and disclosed
Right to Delete: Request deletion of your personal information
Right to Opt-Out: We do not sell personal information, so this right does not apply
Right to Non-Discrimination: We will not discriminate against you for exercising your rights
To exercise your CCPA rights, contact us at Email us.
11. Children's Privacy
The Service is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at Email us.
12. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
Notify affected users without undue delay (within 72 hours where required by law)
Provide information about the nature of the breach and data involved
Describe the measures taken to address the breach
Recommend steps you can take to protect yourself
Report to relevant supervisory authorities as required by law
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes:
We will update the "Last updated" date at the top of this policy
We will notify you via email or through a notice on the Service for significant changes
Your continued use of the Service after changes constitutes acceptance of the updated policy
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at Email us.
We aim to respond to all inquiries within 30 days.