Privacy Policy
Last updated: October 3, 2026
1. Who we are
xShelf is a store platform for X creators, used through a Chrome extension and this website (xshelf.app). This policy covers the extension, the website, and the Lite subscription offered on it. The data controller is:
Operator: xShelf, China. Contact for all privacy matters: xshelfapp@gmail.com.
This policy explains, in plain language, what data xShelf processes and what it deliberately does not.
2. Data we collect
2.1 Extension: the page you are viewing.
While you browse x.com, the xShelf extension reads exactly one piece of information from the page you are currently viewing: the X username (handle) of the profile on screen. It sends that username to the xShelf server to check whether this creator has an xShelf store, so the store can be shown to you. Nothing else is read from the page — not the content of posts, images, or videos you view.
2.2 Your X identity (only if you sign in).
Signing in uses X's official OAuth authorization with a read-only scope. We receive only your public identity: username, display name, profile image, X user ID, and X Premium status (used to gate member features). xShelf will never post, like, follow, or send messages on your behalf — the authorization does not allow it. X's access and refresh tokens are stored on our server only; they never appear in the extension or in your browser's storage.
2.3 Store and creator content.
If you open a store, we store the content you publish there (your public store and product content). This is public, because that is the point of a store.
2.4 Claims, check-ins, and notifications.
When you use features such as claiming products, daily check-ins, or reminding a creator, we record the basic facts needed to provide each feature (for example, that a claim or a check-in happened). Sharing an item from your backpack opens X's own share window and is not recorded on our servers.
2.5 Payment and subscription data.
Purchases are processed by Waffo (Waffo Pancake), acting as merchant of record. Waffo collects your payment details on its own PCI-DSS compliant checkout; card numbers never reach xShelf's servers. We receive only the data needed to run your subscription: your account identifier, the subscribed plan, the subscription status, and transaction identifiers (for activation, renewals, cancellation, and refunds). If you email us, we process the content of your email to answer it.
3. How we use data
- To resolve which store to show while you browse x.com (the viewed username)
- To run your account, your store, and product claiming/verification
- To activate, renew, and cancel your subscription (via Waffo)
- To keep the service secure and prevent abuse
Legal bases (GDPR): performance of a contract for account and subscription data; legitimate interest for security and abuse prevention; consent where X's OAuth authorization requires it. We do not use your data for profiling or automated decision-making.
4. Cookies and local storage
This website sets no analytics, advertising, or tracking cookies and loads no external scripts. It currently runs no analytics at all. The only browser storage we use on the website is your sign-in token, kept in your browser's local storage (30 days, or until you sign out — signing out also revokes it on the server). In the extension, the token is kept in the extension's session storage on your device, which the browser clears when the browser restarts. Your language preference is stored locally in your browser only. Tokens are sent with requests to the xShelf API and to no one else.
5. Data sharing
We do not sell your personal data and do not share it for advertising.
- Waffo (Waffo Pancake) — payment processing as merchant of record (PCI-DSS). Waffo processes your payment data under its own privacy policy.
- Cloudflare — our hosting provider (application, database, and object storage), purely to run the service.
- X (Twitter) — OAuth sign-in itself, and content you choose to post on X yourself.
- Legal requests — only where we are legally required, to the extent required.
6. Security
All traffic is encrypted in transit (TLS). Sign-in uses X's read-only OAuth; xShelf never sees your X password. Session tokens are random, server-revocable, and stored hashed on our server. Payment card data never touches our servers. No system is perfectly secure, but we limit what we hold precisely so there is little to lose.
7. Data retention
Store-resolution requests are kept transiently in cache for performance (minutes, not months) and are not used to build profiles. Account and store data is kept while your account exists. After you cancel a subscription, your account simply continues on the free plan; transaction records are retained as long as required for accounting and tax purposes. You can ask for deletion of your account and data at any time (Section 8) — we delete it within 30 days of your request, except data we must keep by law.
8. Your rights
Depending on where you live (including GDPR in the EU/EEA and CCPA/CPRA in California), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Export your data in a portable format
- Object to or restrict processing
- Not be discriminated against for exercising these rights (CCPA)
To exercise any right, email xshelfapp@gmail.com from a message that lets us identify your account (your X handle). We respond within 30 days. You also have the right to complain to your local data protection authority.
9. Marketing
We do not send marketing emails or messages, and we do not share your data with advertisers. If this ever changes, we will ask for your consent first and update this policy.
10. International data transfers
xShelf runs on Cloudflare's global network, so data may be processed in countries other than yours. Where personal data is transferred out of the EU/EEA or the UK, we rely on recognized safeguards (such as standard contractual clauses) offered by our infrastructure providers.
11. Children
xShelf is not directed at anyone under 18, and our Terms of Service require account holders to be at least 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
12. Third-party links
Stores may link to X posts or external pages shared by creators. Those destinations are not controlled by us and are governed by their own privacy policies; we are not responsible for their content or practices.
13. Changes to this policy
If this policy changes meaningfully, the updated date above will change and significant changes will be announced on this page before they take effect.
14. Contact
Questions or requests (including data access or deletion): xshelfapp@gmail.com.