Este artículo fuente está disponible actualmente en inglés.
Privacy Policy
Effective: July 31, 2026.
This Privacy Policy explains how Mint Shelf, Inc., doing business as Mint Shelf (Mint Shelf, we, us, or our), collects, uses, discloses, and protects personal information when you use mintshelf.com or a Mint Shelf application, marketplace, website, communication, or service that links to this policy (collectively, the Services).
This policy applies to buyers, sellers, business team members, account holders, visitors, and people who communicate with us. It does not apply to a third party’s independent service or privacy practices.
1. Personal information we collect
The information we collect depends on how you use the Services.
Account and profile information
We collect information such as your name, email address, phone number, birth date, profile photo, biography, country, language, authentication method, account identifiers, preferences, and account security and verification records. If you use a passkey, the credential’s public key and related technical information are stored; Mint Shelf does not receive the biometric used locally by your device to unlock it.
Business and seller information
We collect business names, descriptions, logos, contact methods, locations, operating hours, team memberships, roles, permissions, shipping origins, return destinations, fulfillment settings, and seller onboarding and verification status.
Stripe collects seller identity, business, bank-account, tax, and verification information through Stripe Connect. Mint Shelf receives connected-account identifiers, status, requirements, and other information needed to operate the marketplace. We may also collect or receive seller identity, contact, tax, certification, and transaction information required for marketplace transparency, fraud prevention, tax reporting, or legal compliance.
If a business seeks sales-tax exemption for inventory purchased for resale, we collect its completed resale-certificate document, legal purchaser name and address, taxpayer or permit number, business type, descriptions of merchandise normally sold and items intended for resale, signer name, signature and date confirmations, submission and review history, and per-purchase resale elections and attestations. We also create document hashes, extracted-field results, confidence and anomaly indicators, official-registry results, masked permit displays, approval status, reason codes, certificate-use records, tax calculations, and adjustment or refund records. Taxpayer numbers are encrypted, and certificate documents are stored as private files rather than public marketplace media.
Marketplace and transaction information
We collect searches, follows, listings, drafts, collections, events, bids, offers, purchases, order items, prices, fees, payment status, refunds, returns, evidence, disputes, reviews, buyer-reputation events, appeals, fulfillment choices, pickup records, shipping addresses, parcel information, labels, carriers, tracking, and delivery status.
Payment card details are collected directly by Stripe. Mint Shelf receives payment-method identifiers, type and limited display information, authorization and charge status, and related transaction records; we do not store full payment card numbers or security codes.
Content and communications
We collect content you submit, publish, upload, or send, including listing text and media, comments, reviews, messages where available, support requests, reports, feedback, and survey responses. Communications may include sender and recipient information, time, delivery status, and message content.
Scout and AI information
When you use Scout, we collect prompts, responses, transcripts, uploaded images, camera frames you deliberately share, audio, video, documents, spreadsheets and other files, tool inputs and results, proposed and approved actions, public-source research, model and token information, timing, cost, feedback, and reliability outcomes.
Scout Live uses microphone audio when you start a voice session. Its camera preview does not mean Scout continuously receives video: a camera image is sent for processing when you deliberately ask Scout to look or otherwise invoke the camera-sharing function.
Device, network, and usage information
We and our providers collect IP address, browser, device type, operating system, app version, language, time zone, referring page, cookie or local-storage identifiers, authentication-session information, push token, request and response metadata, crash and error information, security events, and interactions with the Services. We may infer an approximate country or region from an IP address to apply regional privacy rules, prevent fraud, and operate the Services. We do not collect precise GPS location through the current Services.
With your optional choices described below, product telemetry may include navigation, searches, clicks, touch activity, performance, heatmaps, surveys, feature use, sanitized errors, and session recordings.
Device permissions and media
If you choose a feature that needs them, the Services may request access to your camera, microphone, photo library, files, or notifications. We collect only the media, file, audio, camera frame, or push token involved in the feature you use. You can manage device permissions in your operating-system or browser settings, though disabling a permission may prevent the related feature from working.
Consent and preference records
We collect privacy choices, SMS and notification opt-ins and opt-outs, the policy version, preference changes, timestamps, and related evidence needed to honor and demonstrate your choices.
2. Where personal information comes from
We collect personal information:
- directly from you when you create an account, use the marketplace, upload content, contact us, or change a preference;
- automatically from your browser, device, and use of the Services;
- from buyers, sellers, business administrators, team members, and other users involved in a transaction or report;
- from providers such as Stripe, Shippo, carriers, sign-in providers, communications providers, analytics providers, and app platforms; and
- from public sources when Scout or our safety, verification, or support processes use public information.
3. How we use personal information
We use personal information to:
- create, authenticate, secure, and administer accounts, business workspaces, roles, and preferences;
- provide profiles, listings, search, bids, offers, purchases, orders, reviews, notifications, Scout, and other requested features;
- process payments, seller onboarding, payouts, fees, refunds, returns, disputes, shipping, pickup, and customer support;
- communicate about authentication, transactions, safety, service changes, support, and messages you choose to receive;
- personalize and improve marketplace results and user experience;
- detect, investigate, and prevent fraud, unsafe goods, abuse, security incidents, prohibited conduct, and violations of our Terms;
- verify sellers, maintain marketplace integrity, calculate reputation or risk signals, and resolve reports and appeals;
- comply with tax, accounting, product-safety, marketplace-transparency, legal-process, recordkeeping, and other legal obligations;
- establish, exercise, or defend legal claims and protect users, the public, Mint Shelf, and our providers;
- measure, debug, and improve the Services when permitted by the applicable privacy controls; and
- create aggregated or de-identified information that we do not use to identify you.
4. How we disclose personal information
We disclose personal information only as described in this policy or with your direction.
Marketplace participants and the public
Public profiles, public business and location details, team affiliations you choose to make public, listings, collections, events, comments, reviews, and public-intended media can be seen by other users and visitors.
Buyers and sellers receive information reasonably needed to complete and support a transaction. For example, sellers may receive a buyer’s name, shipping address, contact information, order and payment status, return information, and fulfillment instructions. Buyers receive seller, listing, fulfillment, tracking, pickup, contact, return, and transaction information. Authorized business team members can access information based on their roles and location permissions.
Businesses may receive aggregate or relevant buyer-reputation and transaction-integrity information. We do not include private Scout conversations or unrelated private communications in public reputation information.
We may disclose verified seller identity and contact information to buyers and provide a reporting mechanism when required by marketplace-transparency law.
Providers that operate the Services
We disclose information to providers that process it for the following purposes:
- Stripe provides payment processing, seller onboarding and verification, connected accounts, payouts, refunds, disputes, fraud tools, Stripe Tax calculation and transaction records, and tax or financial reporting.
- Cloudflare provides network delivery, security, Workers and containers, object storage, email delivery, operational logs, and related infrastructure.
- PlanetScale provides the hosted application database.
- Twilio and telecommunications carriers deliver requested verification codes and opted-in text messages and process phone numbers, message content, routing, consent, delivery, and usage records.
- Shippo and shipping carriers provide rates, labels, tracking, and return shipping and process names, addresses, contact details, and package and shipment information.
- OpenAI provides the models and agent runtime used by Scout and limited structured analysis of resale-certificate documents. For certificate review, Mint Shelf sends only content needed to extract and compare certificate fields, disables provider-side application storage where supported, and retains the structured result rather than the prompt payload. OpenAI states that it does not use API inputs or outputs to train its models by default.
- PostHog provides consent-gated product analytics, heatmaps, session replay, surveys, sanitized error and reliability monitoring, and optional Scout diagnostics, as well as approved aggregate or privacy-filtered warehouse reporting.
- Expo provides push-notification delivery and processes push tokens and notification content.
- Google and Apple provide optional account sign-in and process the information needed to authenticate you.
Better Auth is software Mint Shelf operates as part of its authentication system; it is not a separate hosted recipient of your personal information merely because we use its software.
ClamAV is security software Mint Shelf operates inside its Cloudflare environment to scan uploaded resale-certificate files before private storage; it is not a separate hosted recipient of those documents.
We may also check resale-certificate information against the Texas Comptroller’s official taxpayer or permit records and receive matching name, address, permit-status, and verification information. A certificate with a mismatch, ambiguous result, anomaly, or unavailable registry check may be routed to a Mint Shelf administrator for review.
Legal, safety, and business reasons
We may disclose information when we reasonably believe it is necessary to comply with law or legal process; respond to lawful government requests; enforce our agreements; investigate fraud, security, safety, or rights violations; protect people, property, or the Services; obtain professional advice; or establish, exercise, or defend legal claims.
We may disclose information in connection with financing, due diligence, a merger, acquisition, reorganization, bankruptcy, sale of assets, or similar business transaction, subject to appropriate confidentiality and legal requirements.
5. No sale or targeted-advertising sharing
Mint Shelf does not sell personal information for money. We do not disclose personal information to third-party advertising networks or share it for cross-context behavioral or targeted advertising. We do not use third-party advertising trackers.
We use sensitive personal information, such as account credentials and payment or identity-verification information, only as reasonably necessary to provide, secure, and administer the Services, comply with law, and prevent fraud. We do not use sensitive personal information to infer characteristics about you.
We do not sell or rent SMS opt-in data or phone numbers, and we do not disclose text-message originator consent to third parties for their own marketing. We disclose messaging data to Twilio, carriers, and other providers only as needed to deliver, secure, and comply with rules governing the messaging service.
6. Product analytics, session replay, and Scout diagnostics
Mint Shelf provides separate choices for Product analytics, Session replays, and Scout improvement. These optional purposes remain off until you allow them. You can allow all, decline optional processing, or customize the choices in Privacy choices or Settings. Surveys follow the Product analytics choice. Withdrawing a choice stops new collection for that purpose but does not require deletion of information lawfully processed before withdrawal.
We honor Global Privacy Control and Do Not Track signals by keeping these optional purposes off on the browser sending the signal. A browser signal can override a previously enabled account preference on that browser.
Product analytics
If enabled, PostHog may collect interactions, navigation, searches, page activity, touch activity, performance, heatmaps, surveys, feature use, group activity, and sanitized error information. Signed-in analytics may be associated with your account. We disable PostHog IP and GeoIP enrichment for analytics events and do not use this information for advertising.
Session replay
Session replay requires a separate affirmative choice. A replay can show ordinary interface text, public-intended images, interactions, non-sensitive searches, public drafts, and structured inputs so we can understand how the product behaved.
We use masking and blocking controls designed to exclude passwords, one-time codes, credentials, payment fields and screens, addresses, tracking numbers, contact entry, private messages, Scout screens, system pickers, and designated sensitive regions. Authentication, checkout, purchase, and account pages can otherwise show ordinary interface content outside blocked regions. Because no masking system is infallible, do not enter sensitive information in a field that does not request it.
Replay network records contain sanitized metadata, not request or response bodies, headers, cookies, authorization data, sensitive query values, or console logs. Session replays are retained for 30 days under the current configuration.
Scout processing and optional diagnostics
Sending information to OpenAI as needed for Scout to answer a request is part of providing Scout and is not controlled by the optional Scout improvement choice.
Content-free Scout reliability measurements may include model, token, cost, timing, and outcome fields without prompts, responses, transcripts, media, credentials, or user identity. If you separately enable Scout improvement, Mint Shelf may send Scout prompts and responses, tool inputs and outputs, and diagnostic and model-usage data to PostHog to improve Scout. That content may include personal information you entered or that appeared in tool results. Product analytics or replay permission does not enable Scout content diagnostics.
We filter credentials, signed URLs, binary attachments, raw media, and base64 data where possible before sending optional Scout diagnostics to PostHog. Declining or withdrawing Scout improvement does not prevent ordinary Scout use.
Operational reliability and reporting
Sanitized server reliability events without user identifiers or content may continue when optional telemetry is off. Cloudflare also processes operational network and Worker logs under its service controls.
PostHog may read approved aggregate or privacy-filtered database views through restricted, read-only connections and may receive approved Stripe-derived transaction and operational records through those views for reconciliation and financial reporting. This reporting can continue after optional usage tracking is disabled because it is separate from behavioral analytics.
7. Cookies, local storage, and similar technology
Mint Shelf uses cookies, local storage, secure device storage, and similar technology for authentication, security, session continuity, language and display settings, privacy choices, and other product preferences. We use PostHog storage only when permitted by your effective choices.
On the web, privacy choices use the mintshelf.privacy-preferences.v2 local-storage record across Mint Shelf routes so they take effect promptly. Signed-in choices synchronize with the Mint Shelf account and are recorded with the applicable policy version and time. Declining optional processing is recorded so we can honor the choice.
Browser or device controls can clear or block storage, but doing so may sign you out, reset local preferences, or affect functionality.
8. Retention
We retain personal information for the shortest period reasonably necessary for the purposes described in this policy, taking into account the type and sensitivity of the information, the Services you use, legal and contractual obligations, fraud and safety needs, dispute and limitation periods, and whether the information is needed to complete a transaction.
In general:
- account and profile information is retained while the account is active and for a reasonable period afterward;
- listings, orders, payments, payouts, returns, shipping, disputes, tax, accounting, safety, consent, and compliance records may be retained after account deletion to meet legal and legitimate operational obligations;
- an accepted resale certificate and its submission, verification, audit, and use records are retained for at least four years after the certificate’s final use, and longer when required by a tax hold, audit, dispute, or other legal obligation;
- public content may remain until deleted or the account is closed, subject to transaction records, legal preservation, and copies made by others;
- Scout threads, uploads, tool records, and generated artifacts are retained while needed to provide the feature and according to account deletion and provider processes;
- optional PostHog analytics and Scout diagnostics are retained according to the relevant PostHog product configuration; and
- session replays are retained for 30 days under the current configuration.
When information is no longer needed, we delete, de-identify, or aggregate it, subject to backup cycles and legal exceptions. Account deletion starts deletion workflows for associated PostHog persons, events, and recordings. Providers may retain information as independently required by law, payment-network rules, telecommunications rules, fraud-prevention needs, or their own role as a controller.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit, protected storage, scoped credentials, security logging, and review of sensitive access. Payment card data is submitted directly to Stripe. Private Scout uploads are stored separately from public marketplace media and are provided through controlled access.
No system is completely secure. You are responsible for protecting your account and devices. Contact security@mintshelf.com if you believe personal information or the Services may have been compromised.
10. Your privacy choices and rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- know whether we process your personal information and access it;
- request a portable copy of information you provided;
- correct inaccurate personal information;
- delete personal information;
- opt out of sale, targeted-advertising sharing, or certain profiling;
- withdraw consent for optional processing;
- appeal a decision on a privacy request; and
- receive equal service and not be discriminated against for exercising a privacy right.
Mint Shelf does not currently sell personal information, use it for targeted advertising, or use personal information for legally significant profiling of consumers. You can manage account information and privacy purposes in Settings, use account-deletion controls where available, reply STOP to opt out of text messages, or email privacy@mintshelf.com.
Describe your request and the account or email it concerns. We may ask for information reasonably necessary to verify your identity and authority. An authorized agent may submit a request where law allows, but we may require proof of authorization and direct identity verification. If we deny a request, you may appeal by replying to the decision. You may also contact your state attorney general or other privacy regulator where applicable.
Some information cannot be deleted or disclosed because of another person’s rights, security, legal privilege, transaction and tax obligations, fraud prevention, or another legal exception. We will explain the applicable reason when required.
11. Children
The Services are not directed to anyone under 18, and people under 18 may not create an account or use the marketplace. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact privacy@mintshelf.com so we can investigate and take appropriate action.
12. United States service and international access
The Services are operated in the United States and are intended for United States users and transactions. Mint Shelf and the providers described above may process and store information in the United States and other places where they operate. If you access the Services from another country, your information may be transferred to a jurisdiction with different data-protection laws.
13. Changes to this policy
We may update this policy as the Services, providers, and law change. We will post the updated policy with a new effective date. If a change materially affects how we use personal information, we will provide reasonable notice through the Services, email, or another appropriate channel and obtain consent where required.
14. Contact
Mint Shelf is responsible for the personal information described in this policy. For privacy questions or requests, contact privacy@mintshelf.com. For general support, contact support@mintshelf.com.