Introduction
This Privacy Policy ("Policy") governs the collection, use, processing, storage, and disclosure of information obtained by ShelfOptix, LLC, its subsidiaries, and its affiliates (collectively, "ShelfOptix," "we," "us," or "our") specifically through the provision of Services to the Client and grant of access to and use of the ShelfOptix proprietary online analytics dashboard, client portals, data visualization interfaces, and any associated applications, content, or materials made available through the portal (collectively, the "Dashboard"). This Policy is strictly limited to the Services, Dashboard, and Deliverables, and is distinct from the privacy policy governing the general ShelfOptix public-facing website. By accepting the Services and/or accessing, browsing, or utilizing the Dashboard, you ("User," "you," or "your") acknowledge that you have read, understood, and agreed to the practices described in this Policy.
Reference is made to the ShelfOptix Terms of Use, which is available at /terms-of-service.htm (the "Terms"; capitalized terms used but not otherwise defined herein shall have the meaning given to such terms in the Terms). The Services and Dashboard are intended solely for use by Users authorized by the commercial entities ("Clients") that may have entered into a Master Service Agreement, SOW, Pilot Agreement, or other written contract with ShelfOptix governing the provision of certain services as described therein (collectively with the Terms and this Policy, the "Service Agreements", and each, a "Service Agreement"). Each User's access is contingent upon the Client's standing with ShelfOptix. While the Service Agreements govern the broader business relationship, this Policy serves as the primary legal notice regarding the specific processing of Personal Data within the Services, Dashboard, and Deliverables.
In this Policy, "Personal Data" means information that identifies, relates to, describes, or is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular User, consumer, or household, including the categories of personal information defined under applicable data protection laws; provided that "Personal Data" excludes Robot Data, Derived Data, aggregated data, de-identified data, and any information that cannot reasonably be used to identify an individual or household.
Privacy of Minors
The Services, Dashboard and Deliverables are strictly a business-to-business commercial tool intended solely for use by authorized representatives of each Client. We do not knowingly collect, maintain, or process Personal Data from individuals under the age of eighteen (18). If we become aware that a User under the age of 18 has provided us with Personal Data, we will immediately delete such information and terminate the associated account. If you believe we might have any information from or about someone under the age of 18, please contact us immediately at the information provided below.
Information We Collect
To provide the Services, Dashboard, and/or Deliverables, maintain the security of our proprietary platform, and deliver the specific analytics required by the Service Agreements, ShelfOptix collects and processes the following forms of data: (1) Personal Data; (2) the operational and visual data captured by our robotics systems ("Robot Data"); and (3) the data developed by ShelfOptix in connection with the Services and as a result of the Robot Data.
A. Personal Data Provided Directly by Authorized Users
We collect Personal Data that you or the Client affirmatively provide.
- Account Registration and Authentication: We collect professional identifiers including your full name, business email address, professional title, and entity affiliation (e.g., the Client). We also manage secure authentication data, which may include hashed passwords or SSO tokens.
- Support and Communication Data: We collect the content and metadata of any support tickets, technical reports, or communications you send to ShelfOptix representatives.
B. Technical Usage Data and Telemetry Automatically Collected
When you interact with the Dashboard, our systems may automatically collect technical information regarding your device and behavior ("Usage Data").
- Device and Network Information: We collect IP addresses, browser type, operating system, device identifiers, and ISP information. We may also log approximate geolocation associated with your IP address.
- Interaction and Behavioral Metrics: We may track navigation within the Dashboard, including pages viewed, session duration, login/logout timestamps, and specific data queries or filters applied.
C. Robot Data and Robot-Captured Imagery
The Dashboard may display data collected by ShelfOptix, including without limitation data collected by its robotics systems deployed in physical retail environments.
- Incidental Capture and Anonymization: Robots may capture visual information from retail environments. ShelfOptix does not capture, collect, or store biometric identifiers, biometric templates, or face geometry scans of any individual.
D. Information Received from Third Parties
We may receive Personal Data from third-party sources, including identity verification services or data provided by the Client to provision your account.
How We Use Information
ShelfOptix processes the information collected through the Services and Dashboard strictly for legitimate business purposes aligned with our contractual obligations, the improvement of our proprietary technology, and the maintenance of a secure analytics environment. Further, Robot Data is processed to provide analytics to the Client and to support system performance. We utilize the categories of data for the following objectives:
A. Utilization of Personal Data and Usage Metrics
We process your Personal Data and Technical Usage Data to facilitate the secure and efficient operation of the Dashboard. Specifically, we use this information:
- To verify your identity, grant access to the specific data sets authorized under the relevant Service Agreement and manage your User account.
- To monitor for suspicious activity, prevent unauthorized access to proprietary commercial data, and enforce the security protocols of the Dashboard. We utilize IP logging and behavioral analytics to detect anomalies that may indicate a breach of our Service Agreements or an attempt to scrape or exfiltrate data.
- To send administrative notifications regarding your account, including security alerts, policy updates, and technical notices. We also utilize your contact information to respond to your support requests and to solicit feedback regarding Dashboard functionality.
- To analyze aggregate usage patterns within the Dashboard, such as identifying frequently accessed modules or common navigation paths, to optimize the user interface, enhance system performance, and guide the development of new analytics features.
B. De-Identification and Prohibition on Re-Identification
We maintain Derived Data in a strictly de-identified form. We will not attempt to re-identify any individual from the anonymized data sets, and prohibit any recipients of such data from attempting to do so.
Disclosure of Information
To operate the Dashboard and execute the commercial objectives of our Services Agreements, ShelfOptix discloses Personal Data and Robot Data to the following specific categories of third parties:
A. Third-Party Service Providers
We engage select third-party companies and independent contractors ("Service Providers") to perform specific functions on our behalf necessary for the operation of the Dashboard. We disclose your Personal Data and Usage Data to these Service Providers solely for the purpose of performing these functions. These Service Providers are contractually obligated to maintain the confidentiality of your information and are prohibited from retaining, using, or disclosing your Personal Data for any other purpose.
- Infrastructure and Hosting: We utilize cloud computing and data storage providers to host the Dashboard, store the Robot Data, and ensure availability and disaster recovery.
- Authentication and Security: We share necessary credentials and identification data with identity management and cybersecurity vendors to facilitate Single Sign-On (SSO) capabilities, multi-factor authentication, and threat detection.
- Analytics and Performance: We disclose technical Usage Data to analytics providers to monitor the health of the Dashboard, diagnose latency issues, and track user engagement with specific features.
B. Affiliates and Subsidiaries
We may share your Personal Data and Robot Data with our parent companies, subsidiaries, joint ventures, and corporate affiliates, including Brain Corporation ("Brain") (collectively, "Affiliates"). Our Affiliates utilize this information to support the development, maintenance, and improvement of our Services, Dashboard, and/or Deliverables, including, without limitation, improvements to any robotics technology. All Affiliates are subject to this Policy or privacy standards at least as protective as those described herein.
C. Commercial Disclosures
You acknowledge that ShelfOptix commercializes anonymized Derived Data. We do not disclose your Personal Data for marketing purposes, nor do we share non-anonymized Robot Data with third parties other than the Service Providers described in Section V.A. or as necessary to support authentication, security, or other operational functions permitted under this Policy.
D. Compliance and Safety
We may disclose your information to legal authorities or third parties if required by law or if we believe in good faith that such action is necessary to enforce our agreements, prevent fraud, or protect the rights and safety of ShelfOptix, our Clients, or the public.
E. Business Transfers and Corporate Transactions
In the event that ShelfOptix is involved in a merger, acquisition, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, Personal Data and Robot Data held by ShelfOptix regarding our Users and Clients will be among the assets transferred to the acquiring entity. You acknowledge that such transfers may occur and that any acquirer of ShelfOptix may continue to use your Personal Data as set forth in this Policy.
International Data Transfers
We may process and store Personal Data in the United States or in other countries where our Service Providers operate. These locations may have data protection laws that differ from those in your jurisdiction. We take reasonable steps to safeguard Personal Data during such transfers, including requiring Service Providers to maintain appropriate security measures.
Your Choices and Controls
We provide you with control over how your Personal Data is used for communication and account management.
A. Marketing Communications
We may send you emails regarding new features, industry insights, or ShelfOptix updates. You may opt out of receiving these promotional communications at any time by following the "unsubscribe" instructions in the email or by contacting us.
B. Service-Related Exceptions
Please note that even if you opt out of marketing emails, you will continue to receive mandatory administrative messages related to your account security, updates to the Terms, and critical Dashboard functionality. You cannot opt out of these transactional communications.
C. Account Information
You may review and update your profile information (such as your name or password) by logging into the Dashboard and navigating to your account settings. If you are unable to change certain information (such as your corporate affiliation or authorized access level), please contact your organization's administrator, as these settings are controlled by the Client's applicable Service Agreements.
D. Cookie Controls
As described in Section XI, you can set your browser to refuse all or some cookies. However, disabling cookies may prevent you from logging into the Dashboard.
Privacy Rights
Certain state privacy laws, including the CCPA/CPRA, grant individuals specific rights regarding their Personal Data (collectively, "State Privacy Laws").
A. Your Rights Regarding Personal Data
Depending on your jurisdiction, you may possess the following rights regarding the Personal Data we process:
- Right to Know and Access: Request confirmation of processing and a copy of the specific Personal Data we have collected.
- Right to Correction: Request correction of inaccurate Personal Data.
- Right to Deletion: Request deletion of your Personal Data, unless retention is necessary for security, legal compliance, or contractual performance.
- Right to Non-Discrimination: Exercise these rights without discriminatory treatment or denial of service.
- Right to Appeal and Other Rights: Depending on your state of residence, you may also have the right to appeal a decision we make regarding your privacy request or request the portability of your data. If you are unsatisfied with our response to a request, you may submit an appeal by contacting us at the email below.
B. "Sale" and "Sharing" of Personal Data
Under the definitions provided by the CCPA/CPRA and other State Privacy Laws, a "sale" is broadly defined to include the disclosure of Personal Data for monetary or other valuable consideration.
- ShelfOptix does not sell the Personal Data (names, emails, passwords) of its Dashboard Users to third parties. We do not disclose your contact information to data brokers or third-party advertisers for their direct marketing purposes.
- We monetize anonymized Derived Data. Because this data is non-personal, this activity does not constitute a "sale" or "sharing" of Personal Data under State Privacy Laws, and consumer opt-out rights do not apply.
C. Exercising Your Rights
To exercise any of the rights described above, please submit a verifiable consumer request to us by emailing [email protected] or by writing to us at the address provided in the "Contact Us" section below. We may need to verify your identity before processing your request. If your access to the Dashboard is managed by your employer, we may direct certain requests to the Client for verification or fulfillment, consistent with our contractual obligations. Authorized agents may submit requests on your behalf where permitted by law, provided they supply documentation demonstrating their authority. We will respond to requests as required by applicable privacy laws.
Data Security and Protection Measures
We implement industry-standard safeguards to protect Personal Data and Robot Data, including TLS encryption for data in transit, encryption at rest, and strict role-based access controls (RBAC). Despite these measures, no system is entirely secure, and we cannot guarantee absolute security. You are solely responsible for securing your login credentials. ShelfOptix assumes no liability for unauthorized access resulting from compromised credentials or your organization's failure to manage employee access rights.
Data Retention Policy
We retain Personal Data and Usage Data only as long as necessary to fulfill the collection purposes, including the duration of the Client's Service Agreements, or to comply with legal obligations.
A. Account and Profile Data
Generally, we retain your profile and credentials while your account is active. Upon termination of the Client's Service Agreements or your removal as a User, we delete or anonymize your Personal Data. However, even after account closure, we may retain specific records (including access logs) to:
- Comply with legal, tax, or regulatory obligations;
- Detect and prevent fraud or abuse; and
- Exercise, establish, or defend legal claims.
B. Retention Criteria
In cases where we retain Personal Data, we do so in accordance with any limitation periods and records retention obligations imposed by applicable law. Generally, to determine the appropriate retention period, we consider:
- The amount, nature, and sensitivity of the data;
- The potential risk of harm from unauthorized use or disclosure;
- Whether there is a contractual or legal need to retain the data (including under the Service Agreements); and
- Whether we can achieve our purposes through other means.
C. Operational and Derived Data (Perpetual Rights)
ShelfOptix retains Robot Data, aggregated data, and Derived Data for the periods specified in the applicable Service Agreement. Notwithstanding the foregoing, you acknowledge that ShelfOptix has a perpetual, irrevocable right to retain fully anonymized and aggregated data that has been incorporated into our machine learning models, algorithms, or market intelligence products.
Cookies and Tracking Technologies
ShelfOptix utilizes cookies, pixel tags, local storage, and similar tracking technologies (collectively, "Cookies") within the Dashboard to distinguish you from other Users, ensure the security of your session, and optimize the performance of the interface. ShelfOptix uses only first-party Cookies that operate solely within the Dashboard and does not use advertising or cross-site tracking Cookies.
A. Categorization of Cookies
We strictly limit the use of Cookies within the Dashboard to those necessary for business operations:
- Strictly Necessary and Authentication Cookies: These Cookies are essential for the operation of the Dashboard. They enable you to navigate the portal, access secure areas, and maintain your active login session. Without these Cookies, the Dashboard cannot function, and we cannot verify your authority to access proprietary Client data.
- Performance and Analytics Cookies: These Cookies allow us to count visits and traffic sources so we can measure and improve the performance of our Dashboard. They help us know which pages are the most and least popular and see how Users move around the platform.
- Functionality Cookies: These Cookies enable the Dashboard to provide enhanced functionality and personalization, such as remembering your preferred data visualization settings or the specific store filters you last applied.
B. Management of Cookies and Global Privacy Control
You can set your browser to refuse all or some browser Cookies, or to alert you when websites set or access Cookies. However, if you disable or refuse Cookies, the Dashboard may become inaccessible or fail to function properly.
- Do Not Track (DNT): Because the Dashboard is a secure B2B environment requiring continuous authentication, we do not currently respond to "Do Not Track" (DNT) signals.
- Global Privacy Control (GPC): Some browsers transmit "Global Privacy Control" (GPC) or similar "universal opt-out mechanisms" to indicate a preference to opt-out of the sale or sharing of Personal Data. Because ShelfOptix does not sell or share Personal Data (as defined by State Privacy Laws) and utilizes Cookies strictly for authentication and essential performance, processing a GPC signal will not change your experience or functionality within the Dashboard.
Third-Party Links and Integrations
The Dashboard may contain links to third-party websites, plug-ins, or applications that are not owned or controlled by ShelfOptix. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. ShelfOptix does not control these third-party websites and is not responsible for their privacy statements or data handling practices. Where the Dashboard integrates with third-party tools to support authentication, hosting, or analytics, such integrations operate solely as service providers acting on ShelfOptix's behalf under written agreements. When you leave the Dashboard, we encourage you to read the privacy policy of every website you visit.
Changes to This Privacy Policy
ShelfOptix reserves the right to modify, amend, or update this Policy at any time to reflect changes in our data practices, legal requirements, or the functionality of the Services, Dashboard, and/or Deliverables. When we make material changes to this Policy, we will update the "Last Updated" date at the top of this document and, where appropriate, provide you with notice within the Dashboard (such as a pop-up notification or a requirement to re-accept the terms upon login). Your continued access to or use of the Dashboard following the posting of the revised Policy constitutes your acceptance of the changes.
Contact Information
If you have any questions, concerns, or requests regarding this Policy or the data practices of ShelfOptix's Services, Dashboard, and/or Deliverables, please contact us using the information below: