Legal

Privacy policy

The shelf.fit website works without user accounts, without advertising networks and without tracking cookies. This policy describes the small amount of data that nevertheless arises when you visit this website, and the legal basis on which it is processed. It covers the website only; the shelf.fit app has its own privacy policy (section 12).

This is a translation for convenience. shelf.fit is operated from Germany, and the German version of this page is the legally binding one.

1. Controller

The controller for data processing on this website within the meaning of the GDPR is:

Ali Hwayyiz
Eichborndamm 96
13403 Berlin
Deutschland

me@shelf.fit

2. Your rights

At any time, you have the following rights regarding personal data concerning you:

  • Access to the data processed (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59-61, 10555 Berlin (www.datenschutz-berlin.de). You may equally contact the authority where you live. An informal message to the email address above is sufficient to exercise any of your rights.

3. Hosting

This website runs on a server provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Hetzner's data centre in Nuremberg. The website, its application programming interface (API) and its database all run together on this server; no data is transferred to countries outside the European Union, and no third-party content delivery network (CDN) sits in front of it. Hetzner provides the server and processes the data stored on it on our behalf under a data processing agreement pursuant to Art. 28 GDPR. The legal basis is our legitimate interest in operating this website securely and reliably (Art. 6(1)(f) GDPR).

4. Server log files

When you visit this website, your browser automatically sends information to our server: your IP address, the date and time of the request, the address requested, the referrer, and your browser and operating system identifiers. This data is technically necessary to deliver the page. We do not keep access logs. Technical error logs of the server, which may in individual cases contain an IP address, are used solely for operational security and to prevent abuse, are not combined with other data sources and are deleted automatically after one day at the latest. The legal basis is Art. 6(1)(f) GDPR.

5. Product database

The product data on this website is held in a MongoDB database that we operate ourselves on our server in Nuremberg (section 3). It stores product information — names, nutrition values, categories and availability. Visitors' personal data is stored in this database only if you write to us through the contact form; see section 10 for that. The database cannot be reached from the internet, and apart from Hetzner as the provider of the server no other service provider is involved. The database is backed up daily on the same server; each backup is deleted after 14 days.

6. “My Shelf” — storage on your device

When you save a product to “My Shelf”, that selection is stored exclusively in your browser's local storage. The data is never transmitted to us or to any third party and does not leave your device. Because this is a function you have expressly requested, the storage is strictly necessary and exempt from consent under § 25 (2) no. 2 TDDDG. You can delete it at any time by clearing this site's data in your browser.

7. No cookies, no advertising networks, no accounts

This website sets no cookies, embeds no advertising networks, performs no profiling and requires no registration. Nothing is sold through this website either: there is no checkout here, and no payment data is collected. That is why you will not find a consent banner here: there is nothing to obtain consent for. Should this change in future — through affiliate programmes with conversion tracking, for example — this policy will be updated beforehand and consent will be obtained before any such processing takes place.

8. Fonts, images and external content

All fonts and product images are served from our own server. In particular, Google Fonts and comparable services are not loaded dynamically, so no connection is made to third-party servers and no IP address is transmitted to them when the page loads. We embed no external content such as maps, videos or social media widgets.

9. Links to Instagram, the App Store and Google Play

We link to our Instagram profile using a plain hyperlink only. It is not an embedded widget: as long as you do not click the link, no data is transmitted to Meta. Once you do, the privacy policy of Meta Platforms Ireland Ltd. applies.

The same applies to the links to Apple's App Store and to Google Play, where the shelf.fit app is offered: they are plain hyperlinks. As long as you do not click one, no data is transmitted to Apple or Google. Once you do, the privacy policy of the respective provider applies.

10. Contacting us by email and through the contact form

If you write to us by email, we process what you send solely to deal with your enquiry and any follow-up questions. The contact form collects exactly two things: your email address, so that we can reply, and your message. No name is requested, and your IP address is neither stored nor kept in hashed form. The message is stored in our database (section 5) and deleted automatically no later than 180 days after it arrives; the database performs that deletion itself rather than waiting to be asked. The legal basis is our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR), or Art. 6(1)(b) GDPR for contract-related enquiries. The form sets no cookies and embeds no captcha or other third-party service. Please do not send health data or other special categories of personal data under Art. 9 GDPR through the form — there is no reason and no legal basis for such data here.

11. Encryption

This website is served exclusively over encrypted HTTPS/TLS. Requests made over unencrypted HTTP are redirected automatically to the encrypted address.

12. The shelf.fit app

This policy applies to the shelf.fit website only. The shelf.fit app for iOS and Android is a separate service with its own data processing, for the Shelf Scanner and the paid Premium features for example. That processing is described in the app's own privacy policy, which you will find in the app. “My Shelf” on this website (section 6) stays in your browser and is not transferred to the app.

13. Changes to this policy

We update this privacy policy whenever the processing described here changes — for instance when a further service provider is added. The version published here is the applicable one; the date at the foot of the page indicates when it was last reviewed.

Last updated: September 30, 2026