المقالة المصدر متاحة حاليًا باللغة الإنجليزية.
Privacy Policy
Last updated: July 20, 2026.
This policy explains what Mint Shelf collects, how we use and disclose it, and the choices available to you.
1. Information we collect
- Account information, including your phone number, email address, authentication records, and public profile details.
- Marketplace activity, including searches, listings, collections, follows, bids, offers, purchases, orders, and reviews.
- Seller information, including business details, team membership, Stripe Connect status, shipping origins, and fulfillment records.
- Transaction and fulfillment information, including payment status, refunds, disputes, shipping addresses, and tracking information.
- Communications, including private messages, comments, support requests, feedback, and survey responses.
- Device and network information needed for delivery and security, including IP address, device type, browser, operating system, app version, and approximate location. Cloudflare processes network addresses at the service edge. We disable PostHog IP and GeoIP enrichment for analytics events.
- Product telemetry, including interactions, navigation, searches, performance, sanitized errors, reliability outcomes, and session recordings. Cloudflare separately handles operational Worker logs and traces.
- Scout information, including prompts, responses, uploads, tool activity, model details, token usage, cost, and timing.
- SMS consent records, including opt-in status and related preference changes.
2. How we use information
- Operate accounts, authentication, recovery, preferences, and notifications.
- Provide marketplace, seller, payment, shipping, and support features.
- Process payments, payouts, refunds, and disputes through Stripe.
- Prevent fraud, enforce our terms, secure the service, and investigate incidents.
- Measure product usage, improve search and marketplace quality, and understand business outcomes.
- Diagnose errors, performance issues, failed requests, and unreliable workflows.
- Improve Scout prompts, tools, quality, cost, and reliability.
- Meet legal, financial, tax, recordkeeping, and compliance obligations.
3. Service providers and disclosures
We disclose information to service providers that operate Mint Shelf:
- Stripe processes payments, Stripe Connect onboarding, payouts, refunds, and disputes.
- Twilio delivers verification codes and opted-in marketplace text messages.
- PlanetScale, Cloudflare, and Better Auth provide database, storage, delivery, security, email, and authentication services.
- OpenAI and Google provide Scout AI model services and process prompts, responses, tool context, and permitted uploads needed to provide Scout.
- Google and Apple provide optional account sign-in.
- Shippo provides return shipping rates, labels, and tracking and receives the addresses and package details needed to do so.
- PostHog provides product analytics, heatmaps, replay, sanitized error monitoring, application reliability telemetry, flags, surveys, groups, warehouse data, and Scout AI observability.
We may also disclose information when legally required, to protect people or the service, or during a business transaction.
We do not sell personal information or share it with advertising networks or for cross-context behavioral advertising.
We do not sell, rent, or disclose SMS opt-in consent or phone numbers for third-party marketing. Text-message originator consent is not shared with third parties.
4. Marketplace visibility
Public profiles, businesses, listings, collections, events, comments, and public-intended images can be visible to other users.
Sellers receive information needed to fulfill orders, including shipping, contact, and transaction details.
Businesses may receive aggregate buyer reputation information for marketplace decisions. Private messages are not included in that aggregate information.
5. PostHog analytics and session replay
PostHog can collect interactions, navigation, searches, page activity, touch activity, performance, sanitized errors, surveys, feature-flag use, and group activity.
For visitors Cloudflare identifies as being in the United States, basic analytics starts on by default. Basic analytics remains off until permission is given for visitors in the EEA, United Kingdom, unknown locations, and other locations we have not reviewed. A visitor’s country is used to choose this policy and is not stored in the privacy-preference record. Signed-in basic analytics can be linked to the Mint Shelf account. We do not use telemetry for advertising or cross-context behavioral advertising.
Session replays require your explicit permission everywhere. Input text is masked, and Scout, authentication, checkout, messages, and sensitive account areas are blocked from replay.
We mask passwords, one-time codes, credentials, payments, addresses, tracking numbers, contact entry, and designated sensitive regions.
Network replay records sanitized metadata only. It excludes request and response bodies, headers, cookies, authorization data, sensitive query values, and console logs.
Private source maps may be sent to PostHog during an approved Product release so authorized maintainers can resolve sanitized error locations. Source maps are not published with the website or Worker.
6. Scout AI observability
Content-free Scout reliability and usage measurements can include model, token, cost, timing, and outcome fields. They do not include prompts, responses, transcripts, media, credentials, or user identity.
Scout’s required processing to answer a request is separate from optional Scout improvement diagnostics. Optional detailed Scout traces require the Scout improvement choice, which we may ask for when you first use Scout. Declining does not prevent normal Scout operation. Product analytics or session replay permission does not enable raw Scout content, and Scout screens are blocked from replay. We remove credentials, signed URLs, binary content, raw media, and base64 data before sending permitted Scout diagnostics.
7. Warehouse and Stripe data
PostHog reads only approved aggregate or privacy-filtered database views through restricted, read-only connections. We do not use warehouse access to reconstruct journeys for people who opted out or to expose Scout conversations.
PostHog also imports approved Stripe-derived transaction and operational records through our database warehouse for reconciliation and trusted financial reporting.
Approved aggregate database and Stripe ingestion can continue after usage tracking is disabled. Source retention and transaction obligations still apply.
8. Your privacy controls
Use Privacy choices or Settings to allow all or customize three purposes: Product analytics, Session replays, and Scout improvement. Surveys follow Product analytics, and submitting a survey response is voluntary.
In United States default-on mode, dismissing the notice does not record consent and leaves only basic analytics active. Elsewhere, optional processing remains off until you choose. You can change or withdraw a choice at any time, and session replay or Scout diagnostics stop when their permission is withdrawn.
We honor Global Privacy Control and Do Not Track on each browser. These signals override an enabled account preference on that browser.
Web preferences use the mintshelf.privacy-preferences.v2 local-storage record across Mint Shelf web routes so choices take effect immediately. Signed-in choices synchronize to Mint Shelf’s PlanetScale Postgres database, which keeps nullable per-purpose decisions and append-only consent records. Regional defaults and dismissing a notice are not recorded as consent. The public Site can send anonymous analytics under the same rules and does not become a signed-in identity authority.
Sanitized server reliability events may also continue without user identifiers or content. This includes content-free scheduled-job outcomes that PostHog can use for missed-run monitoring. Cloudflare retains operational Worker logs and traces under its service controls.
9. Your choices and requests
- Access and update profile and preference information in Settings.
- Opt out of text messages by replying STOP.
- Request access, correction, export, or deletion by contacting privacy@mintshelf.com.
- Delete your account through the available account controls or by contacting us.
- Appeal a denied privacy request by replying to our decision.
We may need to verify your identity before completing a request. Applicable law may provide additional rights based on where you live.
10. Cookies and local storage
Mint Shelf uses cookies and local storage for authentication, session persistence, security, product preferences, and analytics permitted by the effective regional policy and your choices. PostHog capture and persistence start disabled while those rules are resolved.
We do not use third-party advertising trackers.
11. Retention and deletion
We retain session replays for 30 days. We retain PostHog events and permitted Scout diagnostics only as long as needed for the purposes described in this policy; their retention varies by telemetry product and service configuration.
Access to raw replay, Scout AI, warehouse, and private-content products is limited to authorized personnel who need it for their work.
Account deletion enqueues deletion of the related PostHog person, events, and recordings.
Some order, warehouse, Stripe, fraud, tax, financial, and transaction records may remain when required by law or legitimate operational obligations.
12. Security
We use administrative, technical, and organizational safeguards designed to protect information in transit and at rest.
Payment card data is sent directly to Stripe. We monitor for unauthorized access and will provide notices when required by law.
No service can guarantee absolute security. Contact security@mintshelf.com if you believe you found a security issue.
13. Children
Mint Shelf is not intended for anyone under 18. We do not knowingly collect personal information from children.
Contact us if you believe a child provided information so we can investigate and delete it when appropriate.
14. United States processing
Mint Shelf and the providers listed above may process and store information in the United States.
15. Changes to this policy
We may update this policy as Mint Shelf and its providers change. We will update the date above and provide notice for material changes.
16. Contact
Contact privacy@mintshelf.com for privacy requests. Contact support@mintshelf.com for general help.