ShelfMerch
Terms of Service Sign in Home

Privacy Policy

Last updated: 30 July 2026

This Privacy Policy describes how Chitlu Innovations Private Limited (“Chitlu”, “we”, “us”, or “our”) collects, uses, stores, and shares personal information in connection with ShelfMerch (the “Service”), including the ShelfMerch for Zoho People integration, available at https://shelfmerch.io.

This policy is intended for organisations that use ShelfMerch and for individuals whose information is processed through ShelfMerch (for example, employees synced from Zoho People). Where ShelfMerch processes employee data on behalf of a customer organisation, that organisation is typically the controller of the employee data, and ShelfMerch acts as a processor or service provider — subject to the customer’s instructions and applicable law. (Legal review recommended for controller/processor characterisation in your jurisdictions.)

1. Information We Collect

Depending on how ShelfMerch is used, we may process the following categories of information:

Account and organisation information

  • ShelfMerch user identifiers and profile details associated with signed-in users
  • Tenant / company (workspace) identifiers and related organisation metadata
  • Role and permission information used to enforce access control

Employee and contact information

ShelfMerch stores contact records that customers create manually, import (for example via CSV), or sync from connected systems such as Zoho People. Contact fields may include name, work email, phone number (when provided through ShelfMerch features other than Zoho sync), department, employee code, designation, work location, date of joining, employment status, shipping address fields, and related contact metadata.

Zoho People integration data

When a customer connects ShelfMerch for Zoho People, ShelfMerch processes the data described in Section 3.

Security and technical logs

  • Request identifiers used to correlate support and security investigations
  • IP address information recorded in application HTTP access logs and used for rate limiting

ShelfMerch’s current HTTP logging configuration does not record browser or device user-agent strings as a dedicated logged field.

2. How We Use Information

We use personal information to:

  • Connect ShelfMerch with Zoho People at a customer’s request
  • Import and update employee records in the customer’s ShelfMerch workspace
  • Help customers prepare employee onboarding kits, rewards, and corporate gifts
  • Prevent duplicate employee records within a tenant (for example by Zoho record ID and email matching)
  • Maintain integration security, including encrypted token storage and access controls
  • Provide troubleshooting and customer support
  • Meet legal and compliance obligations
  • Operate, maintain, and improve the ShelfMerch Service

3. Zoho People Integration

ShelfMerch for Zoho People allows a company administrator to authorise ShelfMerch to read organisation and employee form data from Zoho People using OAuth. The integration requests Zoho People read scopes for forms and organisation information.

When connected, ShelfMerch may process:

  • Employee name (including first name, last name, and derived display name)
  • Work email address
  • Employee ID / employee code and Zoho record ID
  • Employment-related fields used for syncing, such as department, designation, work location, date of joining, and employment status
  • Zoho organisation / company identifiers and organisation name (when returned by Zoho)
  • ShelfMerch user and tenant identifiers associated with the connection
  • Integration connection status, connected timestamps, and last-sync information
  • Encrypted Zoho OAuth access and refresh tokens (see Section 4)

The Zoho People sync implementation does not currently import work phone numbers from Zoho into ShelfMerch contact records. Phone numbers may still appear on ShelfMerch contacts if they were entered or imported through other ShelfMerch features.

Employee information synced into ShelfMerch is stored in the customer’s tenant-scoped workspace and is not displayed publicly on the ShelfMerch marketing website.

4. OAuth Tokens and Account Access

  • Zoho OAuth access and refresh tokens are stored encrypted at rest using application-managed encryption.
  • Zoho OAuth tokens are not exposed to browser JavaScript through ShelfMerch’s public Zoho status APIs.
  • Tokens are used only to call Zoho People APIs needed for organisation verification and employee sync.
  • Access to connect, sync, and disconnect Zoho People is restricted by tenant and company permissions (company administrators manage the connection).

5. How We Share Information

We may share personal information only as needed to operate the Service, including:

  • With the customer organisation that owns the relevant ShelfMerch workspace
  • With service providers that host or support the Service (see Section 6)
  • With Zoho, when a customer authorises the Zoho People integration and ShelfMerch calls Zoho APIs on the customer’s behalf
  • When required by law, regulation, legal process, or to protect rights, safety, and security
  • In connection with a corporate transaction such as a merger or acquisition, subject to appropriate safeguards

ShelfMerch does not sell employee personal data. (Legal review recommended if “sale” / “share” has a specific statutory definition in your markets, such as under CCPA/CPRA.)

6. Service Providers

We use infrastructure and operational service providers (for example cloud hosting, databases, email delivery, and observability tooling) to run ShelfMerch. These providers process data only as needed to provide their services to us and are expected to protect it under appropriate contractual and technical measures.

7. Data Storage and Security

We implement technical and organisational measures designed to protect personal information, including encryption of Zoho OAuth tokens at rest, HTTPS for network transport in production deployments, tenant-scoped data access, and role-based permissions.

No method of transmission or storage is completely secure. We do not promise absolute security, and customers should use strong account controls and promptly report suspected unauthorised access to support@shelfmerch.com.

8. Data Retention

We retain personal information for as long as needed to provide the Service to the customer, to maintain security and auditability, and as required by applicable legal obligations. Specific retention periods may vary by data category and customer configuration. (Legal review recommended before publishing fixed retention periods.)

9. Disconnecting Zoho People

A company administrator can disconnect Zoho People from ShelfMerch. Disconnecting:

  • Clears stored Zoho OAuth tokens for that tenant
  • Stops further Zoho People syncing for that connection
  • Does not automatically delete previously imported employee contacts or related ShelfMerch records

Previously imported data may remain until deleted according to the customer’s instructions and ShelfMerch retention requirements.

10. Data Deletion Requests

Customers and authorised individuals may contact support@shelfmerch.com to request:

  • Access to stored information
  • Correction of inaccurate information
  • Export of information
  • Deletion of information
  • Integration disconnection

We may need to verify identity and authority before processing organisation or employee-data requests. Where ShelfMerch processes employee data for a customer organisation, some requests may need to be handled by or with that organisation. Deletion may be soft-deleted or staged according to product capabilities and legal holds; we do not guarantee immediate irreversible deletion in every case.

11. International Data Transfers

ShelfMerch may process and store information in India and in other countries where we or our service providers operate. Where required, we use appropriate safeguards for cross-border transfers. (Legal review recommended for transfer mechanisms applicable to your customers.)

12. User and Organisation Rights

Depending on applicable law, individuals and customer organisations may have rights to access, correct, delete, restrict, or export personal information, and to object to certain processing. To exercise these rights, contact support@shelfmerch.com. We may redirect employee requests to the relevant customer organisation when that organisation controls the data.

13. Children’s Privacy

ShelfMerch is a business service and is not directed to children. We do not knowingly collect personal information from children for the purpose of offering the Service to them. If you believe a child has provided personal information to us inappropriately, contact support@shelfmerch.com.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. Material changes may also be communicated through the Service or by email where appropriate. Continued use of ShelfMerch after an update means the updated policy applies to that use, except where applicable law requires additional consent or notice.

15. Contact Us

For privacy questions, data requests, or integration concerns:

  • Legal entity: Chitlu Innovations Private Limited
  • Product: ShelfMerch
  • Email: support@shelfmerch.com
  • Website: https://shelfmerch.io

This page is a product privacy notice tailored to the current ShelfMerch implementation. Statements marked for legal review, and the policy as a whole, should be reviewed by qualified counsel before reliance in regulated procurement or contractual disclosures.

© 2026 Chitlu Innovations Private Limited · ShelfMerch · Terms of Service · Privacy Policy