Back
ShelfLoop

Connecting readers, building community.

Privacy Notice

Effective June 18, 2026

How ShelfLoop collects, uses, stores, and protects your personal data.

Who We Are

ShelfLoop is a community book sharing and exchange platform. Users can list, discover, borrow, buy, give away, wishlist, waitlist, and review books.

What Data We Collect
The table below summarizes common data categories, examples, and purposes.

Account data

Examples

  • Name
  • Email address
  • Login method and authentication provider
  • Account creation and login timestamps

Why we collect it

  • Create and secure your account
  • Identify you inside the platform
  • Send important service communications

Profile data

Examples

  • Phone number if provided
  • Profile photo or avatar if provided
  • Bio and reading interests if provided
  • Area, building, city, state, PIN/postal code, society, or locality if provided

Why we collect it

  • Help nearby users coordinate exchanges
  • Build community trust
  • Improve book discovery and filtering

Address and location-related data

Examples

  • Address fields
  • Approximate latitude/longitude if captured
  • Society, locality, or place information

Why we collect it

  • Show nearby books
  • Calculate approximate distance
  • Support location-based filtering using approximate location or address information provided by you

Book listing data

Examples

  • Book title, author, ISBN, category, genre, condition, language
  • Class, year, month, volume, price or rent
  • Cover image

Why we collect it

  • Publish book listings
  • Enable search, discovery, requests, and exchange workflows

Exchange and transaction data

Examples

  • Borrow, sale, or giveaway requests
  • Request status and due dates
  • Pickup and return OTP verification timestamps
  • Extension requests and completion status
  • Expected/final amount or bill details where applicable

Why we collect it

  • Manage book exchanges
  • Generate transaction records
  • Support dispute resolution and audit history

Ratings, reviews, and trust data

Examples

  • Ratings submitted by users
  • Review comments
  • Trust or reputation summaries
  • Badges, leaderboard, and referral counts where applicable

Why we collect it

  • Build trust and improve community safety
  • Show user reputation and contribution history

Communications and notifications

Examples

  • In-app messages
  • Notification preferences
  • Email delivery events
  • Transactional email logs

Why we collect it

  • Enable coordination between users
  • Send OTPs, reminders, request updates, wishlist/waitlist alerts, and service notifications

Verification data

Examples

  • Email verification status
  • Government ID type/number if you choose to provide it or if this feature is enabled
  • Corporate ID or other verification details if you choose to provide them or if this feature is enabled

Why we collect it

  • Prevent misuse
  • Improve trust and safety

Technical and security data

Examples

  • Device/session data
  • Browser or device type
  • IP-derived approximate location if used
  • Last active time
  • Authentication and session logs

Why we collect it

  • Secure accounts
  • Detect misuse
  • Maintain active session history
  • Troubleshoot technical issues

Support and admin data

Examples

  • Support tickets and messages
  • Admin review notes if any
  • Audit logs of admin actions

Why we collect it

  • Respond to user issues
  • Maintain platform safety
  • Support compliance and accountability
Google Login and Google User Data

If you sign in with Google, ShelfLoop may receive basic Google account information such as your name, email address, profile image, and Google account identifier, depending on the permissions you grant.

This data is used only to create or log in to your ShelfLoop account, display profile information, and secure the account. ShelfLoop does not sell Google user data, does not use Google user data for advertising, and does not transfer Google user data to third parties except as necessary to provide the app, comply with law, prevent abuse, or with your consent.

ShelfLoop's use and transfer of Google user data should comply with the Google API Services User Data Policy, including Limited Use requirements. If Google permissions are limited to basic profile/email authentication, the app does not access Gmail, Google Drive, Google Calendar, or other Google content unless separately implemented and disclosed.

How We Use Data
  • Account creation and login
  • Email verification
  • Trust and safety
  • Book discovery and search
  • Nearby distance calculation
  • Request, approval, and OTP workflows
  • Borrow, sale, and giveaway completion
  • Waitlist and wishlist matching
  • Ratings and reviews
  • Notifications and reminders
  • Admin support and misuse prevention
  • Legal or compliance obligations
  • Improving the platform
Legal Basis / Lawful Use

Depending on where you live and which laws apply, ShelfLoop may rely on consent, service necessity, legitimate interests, and legal obligations to process personal data.

  • Consent: optional profile fields, notification preferences, optional verification data, optional location details, and marketing or promotional emails if enabled.
  • Contract or service necessity: account creation, book requests, OTPs, exchanges, bills, and service notifications.
  • Legitimate interests and platform safety: fraud prevention, abuse detection, support, audit logs, and community trust.
  • Legal obligation: lawful requests, dispute handling, or other requirements under applicable law.
Data Sharing

ShelfLoop does not sell personal data or share it for third-party advertising.

Limited data may be shared with:

  • Other users, only where needed for book exchange coordination, public profile or trust details, listings, ratings, and messages.
  • Service providers such as Supabase for backend, authentication, and storage, and Resend for transactional emails.
  • Google, when you use Google login, as part of the authentication flow.
  • Admins or moderators for support, safety, and platform operations.
  • Authorities if legally required.
What Other Users Can See

Depending on your privacy settings and workflow, other users may see:

  • Display name or private-user label
  • Profile photo or avatar if provided
  • Book listings
  • Approximate area, society, or locality if shown by the app
  • Ratings, reputation, badges, and reviews if published
  • Request-related coordination details once an exchange is active
  • Messages you send in the platform

Private details such as full email, phone, exact address, or government ID should not be shown to other users unless a specific feature clearly discloses it.

Data Retention
  • Account and profile data is retained while your account is active.
  • Exchange and transaction records may be retained for service history, audit, dispute handling, billing, and legal purposes.
  • Messages, support tickets, and admin logs may be retained for safety and support.
  • Email logs may be retained for delivery tracking and audit.
  • Deleted or deactivated accounts may still have some data retained where required for legal, security, fraud prevention, audit, or completed transaction history.
  • You can request deletion or correction by contacting support@shelfloop.com.
User Rights and Choices
  • Request access to or a copy of your data.
  • Correct or update profile data.
  • Request deletion of your account or personal data.
  • Withdraw consent for optional processing where applicable.
  • Change notification preferences and disable marketing or promotional emails if enabled.
  • Manage public/private profile settings where available.
  • Raise grievances regarding personal data processing.
  • Where GDPR applies, you may have rights to access, rectify, erase, restrict, object, and portability.
Children / Minors

ShelfLoop may be used by families and students. Where a user is a minor, the platform is intended to be used under parent or guardian supervision. Minors should not provide personal data without parent or guardian consent.

Parents or guardians can contact support@shelfloop.com to request review, correction, or deletion of a minor's data. ShelfLoop should not collect unnecessary data from children. A minimum age can be defined later by the platform owner.

Security Practices

ShelfLoop aims to follow security practices aligned with common information security principles, including access control, auditability, least privilege, and data minimization.

  • The app uses authentication, role-based access, database security policies, and access controls.
  • Sensitive workflows such as pickup and return use OTP verification.
  • Admin activity may be logged for accountability.
  • Access to production data should be limited to authorized admins.
  • No system is 100% secure. Users should protect their login credentials.
International Transfers

ShelfLoop may use cloud service providers whose systems may process or store data in different regions. Where required, transfers will be handled according to applicable law and service provider safeguards.

Cookies and Similar Technologies

The app may use cookies, local storage, or session storage for login sessions, preferences, security, and app functionality. If analytics or advertising cookies are added later, this notice should be updated.

Data Breach / Contact

In case of a security incident affecting personal data, ShelfLoop will take reasonable steps to investigate, mitigate, and notify affected users or authorities where legally required.

Updates to This Notice

This notice may be updated from time to time. Users should review this page periodically.

Effective date: June 18, 2026

Last updated: June 18, 2026

Related Terms

Also see our Terms of Use.

Contact

Data Protection / Privacy Contact: support@shelfloop.com

Website: shelfloop.com