Privacy Policy

Last updated August 31, 2026

This policy explains what information Shelfmark, Inc. (“Shelfmark,” “we,” “us”) collects through this website, why we collect it, and what choices you have. It covers this marketing website (shelfmark.com) only. The Shelfmark visual-inspection platform we provide to customers is governed by a separate platform privacy policy under your service agreement.

The short version: this is a simple marketing site. We collect what you choose to send us through our contact form, plus website analytics. A form submission is forwarded to our team so we can reply. We also use a third-party service that can identify some business visitors from United States companies by name and employer, so our team can follow up; the “Identifying business visitors” section below explains exactly what that means and how to opt out. We don’t run advertising trackers and we don’t share your information with ad networks.

What we collect

Information you give us. When you use the contact form to talk to an expert or request a meeting, we collect the details you submit: typically your name, work email address, phone number (if you provide one), and anything you write about your line or your needs. That message is forwarded to our team to follow up; the website does not keep a copy at rest.

Website analytics. Like most websites, we collect limited, aggregate technical information automatically, such as pages viewed, approximate region, and browser and device type. We use it to understand what’s useful and to improve the site. It isn’t used to build a profile of you.

We don’t use advertising trackers or cross-site advertising pixels, and we don’t share what we collect with ad networks.

Identifying business visitors

We use third-party services that can match some visits from United States business networks to the company you work for, and in some cases to a named individual, without you submitting anything. We are describing this plainly because it is the kind of thing people reasonably want to know about. We are currently evaluating two such providers, RB2B and Snitcher, and may use either or both.

What we may receive when it matches: the name of the company you work for, company details such as industry, size and location, and which pages were viewed on our site and when. Depending on the provider, we may also receive an individual’s name, job title, work email address and LinkedIn profile URL.

What we do with it: a notification goes to our team and a contact record is created in our customer relationship system, so someone can follow up about your line. It is used for our own sales and marketing follow-up. We don’t sell it on to advertisers.

Who else is involved: RB2B resolves identities through LiveIntent, an identity network it partners with, so when RB2B runs your browser also connects to LiveIntent (liadm.com). One provider’s code also performs its own approximate, IP-based location check through ip-api.com; our own United States gate (described below) runs separately on our infrastructure. We name these because they are real connections your browser makes, even though neither shows you ads on our behalf.

Where it applies: only to visitors determined to be located in the United States, and the check runs before any provider code loads. When our network edge can tell us the visiting country, our own servers make the call. When it cannot, a deliberately cautious check in your browser stands in, and it only allows the code to load when your device's own settings indicate a United States location; if the location cannot be confirmed either way, the identification code is simply not loaded and no provider cookie is placed on your device. We have also switched off the worldwide company-level lookup that one provider offers by default.

How to stop it. Any of these work, and none of them require contacting us first:

  • Email us and ask. This is the simplest route and it covers every provider we use: we will delete what we hold about you and suppress future identification.
  • Turn on Global Privacy Control in your browser (some browsers and extensions send this signal automatically). We honor it for both analytics and visitor identification, and it stops the provider code from loading at all.
  • Opt out with RB2B directly at app.retention.com/optout, which covers every site that uses them, not just ours.
  • Snitcher does not offer a self-serve opt-out page; email us and we will suppress you on our side and pass the deletion request to Snitcher, or contact Snitcher through the privacy contact in their own policy at snitcher.com/privacy-policy.

How we use it

  • To respond to you: route your message to the right person and follow up about your line.
  • To schedule and prepare for a meeting you request.
  • To understand and improve how the website performs.
  • To keep the site secure and prevent abuse (for example, blocking spam submissions).

Cookies & analytics

We use PostHog for first-party website analytics. It stores information in your browser’s local storage rather than using advertising cookies, and we don’t share the data with ad networks.

The visitor-identification services described above do set cookies on our domain, including identifiers that persist for up to a year, so they can recognize a returning visitor. These are not advertising cookies and they are not used to follow you around other websites for ads, but we would rather name them than describe them vaguely. Most browsers let you block or clear cookies in their settings, and the opt-out options above stop them entirely.

Who we share it with

When you submit the form, your message is passed to the service providers we use to receive it and follow up: our team messaging tool, our email tools, and our customer relationship system. We also use an analytics provider (PostHog), the visitor-identification providers described above, and a hosting provider to run the site. We share information with each only as needed for that purpose, or where we’re legally required to.

We don’t sell access to your information to advertisers. There is one nuance we would rather over-explain than gloss over: one of our visitor-identification providers acts as an independent controller of the identification data it resolves, rather than only as a processor following our instructions, and is a registered data broker in several US states. Under some state privacy laws that arrangement can be treated as “sharing” or a “sale” of personal information. That is why the opt-out options above exist and why we point you at the provider’s own opt-out as well as ours.

How long we keep it

The website doesn’t hold your information at rest. Once you submit the form, your message is forwarded to our team, who keep your contact details for as long as needed to follow up and maintain the business relationship. Analytics data is retained only in aggregate for a limited period. Records created by visitor identification are kept while we are actively following up and are deleted when we are not; if nothing comes of it, we remove them. You can ask us to delete your information at any time (see below).

Your choices & rights

Depending on where you live (for example, under GDPR in the EU and UK or the CCPA in California), you may have the right to access, correct, or delete the personal information we hold about you, and to object to certain processing. You can also stop visitor identification yourself at any time using any of the three options in the “Identifying business visitors” section above. To exercise any of these, email us at help@shelfmark.com and we’ll take care of it.

Contact

Questions about this policy or your data? Email help@shelfmark.com or write to us at 544 Miltenberger St, Suite 2, Pittsburgh, PA 15219. If you believe your data-protection rights have been violated, you also have the right to lodge a complaint with your local data protection authority.