Legal

Privacy Policy

Version 2.4  ·  Effective date: 5 September 2026

Short version. The catalogue pages are built on our servers and sent to you finished, so reading them makes no request from your browser to our database and no request to anyone else’s. There are no pictures in the catalogue, so no image loads from a third party. No page sets a cookie and no analytics script runs. Signing in is optional and gets you one page, your shelf, which reads what the app holds against your account: the beers you have recorded and the tastings you have written. It reads and never writes. Nothing here is for sale. The gear page carries links to Amazon.se, each marked Annons; buying through one pays us a commission and does not change your price, and none of them lead to beer. Nothing from Amazon loads on any page here. We do not sell your data. You can delete all of it with the button in the account panel, which works; version 2.0 of this policy said it was broken, and it is not.

1. Who we are

My Beer Shelf is a product of Nisshagen Advisory AB (Org.nr 559526-6742), a company registered in Stockholm, Sweden. We are the data controller for personal data collected through the mybeershelf.com website.

Contact hello@mybeershelf.com for any privacy question, including data subject requests under the GDPR.

This policy covers the website, including the shelf page you reach by signing in.

About the app. The My Beer Shelf app is in internal TestFlight, which means invited testers, and it is not on any public store. It has sign-in, a shelf and a tasting log, and it does not yet have a Delete account button of its own. Section 8 says what that means and what to use instead. It will carry its own policy for what happens on your phone before it reaches a store, and this page will point to it. Three services it uses are named in section 5 anyway, because they outlive a deletion and you should learn about them here rather than later.

2. Reading the site

The pages themselves

The front page, the catalogue at /beers and the styles pages are assembled on our servers and sent to your browser as finished HTML. The catalogue’s filters are a plain form that reloads the page, so searching for a brewery changes the address bar and nothing else. There is no sign-up, no interest list and no form on this site that sends us anything about you.

No page sets a cookie. There is no analytics: no page-view counter, no session recording, no product analytics and no tracking pixel belonging to us or to anyone else. Vercel Web Analytics is not switched on for this project. Our host keeps the request logs any web server keeps, and section 6 covers those. Nothing else on this site watches you read it.

The one thing that runs in your browser on every page is a check for a sign-in token on your own device. If there is no token, nothing is sent anywhere and the page stays signed out.

Where the catalogue comes from

The 4,858 beers at /beers are Systembolaget’s range: product facts about what a Swedish state off-licence stocks. We did not get them from Systembolaget directly. Their public API portal no longer resolves, so the rows were collected through a community mirror at susbolaget.emrik.org and stored in our own database, where this site reads them. They are facts about products, not about people, and there is no column in that table for a user.

We show the name, brewery, style, strength, size and country, and nothing else. The price came off the catalogue on 1 September 2026. Systembolaget’s own tasting prose and food-pairing suggestions are in the source data and are excluded from the query this site makes, so those columns never leave the database and no page can render one by accident. The catalogue leans Swedish because Systembolaget’s range does: 71% of the rows are beers brewed here.

No pictures from anyone else

The catalogue shows no product photographs. The source rows carry image addresses pointing at Systembolaget’s own servers, and we do not use them, so your browser never requests an image from them or from any other company while you browse. The cards are typographic, and so is your shelf page.

There are no photographs of yours either. Earlier versions of this policy described photographs you had uploaded. There is no way to upload one. The app has no photo-library feature and no image-editing library, its camera is a barcode reader and nothing else, and there is no file storage area for beer for a file to land in. Each beer record has an unused slot for a picture and the shelf page would render one if it were filled, but we checked every place that value could come from and no screen in the app supplies one. If that changes, this section changes first.

The app also sends no photograph anywhere, because it has no AI scan. We searched it for a scan of that kind and found none: the camera screen takes no picture, reads only barcodes, and no frame ever leaves your device. There is therefore no free scan allowance in this app, no scan ledger row written for it, and no image processor in the list in section 5. If you have read about a label scan on another Shelf app's site, that is that app; this page describes this one.

Nothing here is for sale, and where the gear links go

This site sells no beer and links to nowhere that does. There is no basket, no checkout and no arrangement with Systembolaget or any brewery. The catalogue shows no price and has no buy link on any beer.

The site does carry affiliate links to Amazon.se, on the gear page and next to the glass suggestions on the styles pages. They point at accessories: glasses, growlers, cellar kit. None of them lead to beer or to any other alcohol. Every one is marked Annons. If you buy something through one, Amazon pays us a commission and the price you pay does not change.

What that means for your privacy is short. The links are ordinary links: nothing from Amazon loads on our pages, no Amazon cookie is set here, and Amazon learns nothing about your visit unless you click one. If you do click, your browser goes to Amazon.se and the address carries our affiliate tag, so Amazon knows the visit came from our link; from that moment Amazon’s own privacy policy governs. What Amazon reports back to us is totals of clicks and purchases, never who you are.

Beer staying unsold and unlinked is still a standing rule rather than a description of how things happen to stand today. If it changed, this page and the terms would say so before anything on the site did, which is how the gear links themselves arrived: section 11 records it.

3. Signing in, and your shelf

Your account

Most of the site needs no account. One page, your shelf, does, and there is a Sign in button in the navigation on every page. Sign-in runs on Supabase, our database and authentication provider, hosted in the EU. What we hold depends on how you sign in:

If you type a name when you create the account, we store it and use it to greet you on your shelf. Nothing else about you is asked for.

One login across the shelf apps

The account is the ShelfHub account, and it is one login across My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf, My Cigar Shelf, My Coffee Shelf and My Supply Shelf. Signing in here signs you in with the same credentials you use there. The login is shared. The shelves are not: your beers are not visible to those apps, and what you keep in them is not visible here. This matters most when you delete something, so section 8 sets it out in full.

Where your session is kept

Nothing on this site sets a cookie. When you sign in, one entry goes into your browser’s local storage, named sb-tlqlbnhaqpqgaxfihdlj-auth-token after our database project, holding the token that keeps you signed in. Signing out removes it. If you sign in with Google or Apple, the token comes back in the address bar and is moved into that same entry.

That entry is the only thing this site stores on your device, and it is there because you asked to be signed in. Storage that is strictly necessary for something you requested does not require consent under the ePrivacy rules, which is why you are not looking at a cookie banner. If we ever add storage that is not necessary, you will be given a real choice about it and this policy will say so first.

What the shelf page shows

It shows what the app holds against your account, and nothing else:

Read as a run, those records are a dated account of what someone owns and what they have been drinking. We would rather say what it amounts to than file it under “your data”. It is private to your account: the database restricts every row in both tables to the account that created it, and that restriction lives in the database rather than in this website’s code, so it holds no matter what this page asks for.

This page reads and does not write

Nothing you do on this website changes your shelf. Adding a beer, logging a tasting and editing anything happen in the app. There is not one write to shelf data anywhere in this site’s code. The only things this site can change are the account itself: creating it, resetting the password, and the deletion described in section 8.

What this site does not do

If any of that changes, we will update this policy before the change goes live rather than after, and analytics in particular would stay switched off until you consent to it.

4. Legal basis for processing

Version 2.2 of this policy gave a basis for the website and none for the app, while section 5 described the app’s processing in full. That left the largest things this policy describes with no lawful basis attached to them. Both are covered here.

Giving us this data is not a statutory requirement. It is what the app needs in order to be a shelf: without an account there is nowhere to put a beer. There is no automated decision-making that produces legal or similarly significant effects, and no profiling.

5. Third parties we use

Fonts are the last one, and it applies to three pages rather than the site. This policy, the terms and the deletion page are static pages that load their two typefaces from Google Fonts, so your browser requests those files from Google’s servers and Google receives your IP address as part of that request. No font cookies are set. Every other page on the site serves its fonts from our own domain, so reading the catalogue involves no request to Google at all.

We do not sell your data to any third party. Supabase and Vercel are the two companies we contract with to run this site, and neither uses your data for advertising. The Associates agreement with Amazon is a contract too, but it runs nothing on this site and your data plays no part in it. If we ever add a provider that would, we will update this policy before the arrangement starts.

Google and Apple are not working for us, so we will not make a promise on their behalf. What their servers do with a request they receive is governed by their own policies. What we control is how little we hand them, and section 2 says exactly what that is.

Three that the app sends your account identifier to

None of these is contacted by this website. They are named here because the deletion in section 8 does not reach them, so they outlive it however you ask. They are not the whole of what the app contacts: the barcode lookup below asks three more, and those receive a barcode rather than anything about your account.

On the Mixpanel entry, one thing worth being exact about: your analytics answer is one row on your account, and five apps read and write that row: My Beer Shelf, My Bar Shelf, My Whiskey Shelf, My Wine Shelf and My Cigar Shelf. So it is the same answer in all five. It is not the answer in My Coffee Shelf, which keeps a separate one in its own table and asks you again there. My Supply Shelf sends no analytics at all.

On the RevenueCat entry, one more: what a subscription unlocks depends on which one you bought. A bundle subscription is honoured by the Shelf apps that check for it. A single-app subscription, which is what most current subscribers hold, unlocks the app it was bought for and is not honoured elsewhere. This page has never claimed otherwise and is not going to start; it is written down because the neighbouring Shelf policies used to claim otherwise and have been corrected.

Scanning a barcode in the app asks three outside databases

This was missing from version 2.1 and it belongs here, because it is the app sending something to companies we have not named.

When you scan a barcode, the app checks the pooled table in section 6 first. If that misses, it asks up to three external barcode databases in order and stops at the first that gives a usable answer:

Each request is made by your phone rather than by our server, so the database answering it receives the barcode digits and your device’s IP address, and a fixed line identifying the app as My Beer Shelf. None of them receives your account identifier, your email or anything from your shelf: the request carries the barcode and nothing else of yours.

A barcode is not personal data, but the address it arrives from is, which is the reason this paragraph exists.

6. How long we keep things

7. Your rights under the GDPR

As a user in the European Economic Area you have the right to:

To exercise any of these, write to hello@mybeershelf.com from the address on the account. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority; in Sweden that is Integritetsskyddsmyndigheten (IMY).

8. Deleting your account

The Delete account button in the account panel on this site works. It tells the shared deletion function that it is being called from My Beer Shelf, the function has a My Beer Shelf branch, and that branch removes your tastings and then your beers, and nothing belonging to any other shelf app. Version 2.0 of this policy said the function had no branch for beer and refused the request. That was true when it was written and stopped being true shortly afterwards, and this page is late saying so. Section 11 records it.

The app does not have a delete button yet, and that is a separate thing. It is not that the app tries and fails. The screen simply has no such button on it, so there is nothing to press. This is the opposite way round from what version 2.0 implied: the website route is the one that works and the app is the one still missing. When the app gets one, this section will say so, and we would rather you held us to that than took it on trust, given the last promise of that shape.

You can also email hello@mybeershelf.com from the address on the account and we will delete it by hand, which is the route to use if you cannot get into the account you want gone. Either way we remove everything held against it: every beer, every tasting, and the notification records for this app. Deletion is permanent and we cannot restore it afterwards. Deleted rows can sit in our database provider’s routine backups until those age out, and we are not going to quote a number for that, because it is our provider’s schedule rather than ours. The deletion page sets out the whole procedure and is reachable without signing in.

One thing to know about the shared login. If the same login is also used for another shelf app, deleting your beer records does not delete the login itself, because that would destroy your account in the other app. The function checks the other shelf apps for you, erases the beer records, and keeps the login. Ask and we will remove the login too.

What is left afterwards. Saying “nothing” would be easier and it would not be true. Crash reports at Sentry, usage events at Mixpanel if you ever turned analytics on, and your subscriber record at RevenueCat all survive, because no deletion of ours reaches those three.

The rest depends on whether your sign-in record is deleted or kept, and version 2.1 of this policy described only one of the two:

Write to us and we will remove by hand whatever the button cannot, including a barcode attribution on either path.

9. Age

My Beer Shelf is about keeping beer and writing down what you thought of it, and it is meant for adults who are of legal drinking age where they live: 21 in some countries, 18 or 20 in others. It is not directed at anyone below that age, and we do not knowingly hold data about them. If you believe a minor has an account here, write to us and we will delete it.

This site does not put an age prompt in front of you and stores no answer to one. Version 1.0 of this policy said otherwise; see section 11.

10. International transfers

Our database, our authentication and everything on your shelf are hosted in the European Union.

What stays inside it: crash reporting on Sentry’s German service, usage analytics on Mixpanel’s EU service, and two of the three barcode databases, which are in France.

These reach past the boundary:

For RevenueCat we rely on the European Commission’s standard contractual clauses, which form part of the data processing terms it publishes. Version 2.1 of this policy counted three transfers and left out UPCitemdb, because it did not describe the barcode lookup at all. If a provider we choose ever needs to process data outside the EEA, we will only use one that relies on an adequacy decision or those clauses, and we will say so here.

11. Changes to this policy

If we make material changes we will publish the updated version here and update the version number and effective date at the top of this page. If a change materially affects data we already hold about you, we will tell you before it takes effect.

Version 2.4, 5 September 2026. The site now carries affiliate links, and this policy is updated before they go live, as section 3 promised. What changed:

Version 2.3, 1 September 2026. Version 2.2 assigned no lawful basis to anything the app does, and it described the rest of the Shelf portfolio in places where it had only checked this app. What was wrong, and what replaces it:

Version 2.2, 1 September 2026. Version 2.1 said the pooled barcode table held nothing about you. It holds your account identifier. What was wrong, and what replaces it:

What we did not change, because we checked it and it held: the app uploads no photograph and has no AI scan, the Systembolaget catalogue carries no column for a user, and this site runs no analytics.

Version 2.1, 31 August 2026. Version 2.0 promised that section 8 would say so when the Delete account button was fixed. It was fixed and this page is late saying it. What changed:

Version 2.0 replaced the version dated August 2026. That one was written for the earlier mybeershelf.com landing page and described a site that does not exist: it said there was no app, no accounts and no product data, and most of it explained an interest-list form that collected an email address, a consent record, a referrer, a browser language and a hashed IP address. This site has no form of any kind, it has sign-in and a shelf page, and it has a catalogue of 4,858 beers. Nothing was collected under it: no address was ever submitted to that form on any of our sites. Two smaller claims were also wrong and are corrected here. It said the site used Vercel Web Analytics, which has never been switched on for this project, and it described an age confirmation stored in your browser, which this site does not ask for and does not store.

12. Contact

Questions or concerns about your privacy? Write to hello@mybeershelf.com.

Nisshagen Advisory AB, Stockholm, Sweden.