SecondShelf

Privacy policy

Last updated: 8 September 2026

Draft notice: This policy describes the current SecondShelf service and is a plain-language draft/template. It is not legal advice. Please review it for the laws and obligations that apply to your use of the service.

1. Scope and contact

This policy explains how SecondShelf handles information in its mobile application and related services. The service is operated as SecondShelf. Where an operator name is needed, this service may identify the operator as Tausif Mohammad. For privacy questions, requests, or concerns, contact support@secondshelf.in.

2. Information we handle

Depending on how you use SecondShelf, the service currently handles:

  • Account information: email address, display name, password hash, account type (such as employee or administrator), enabled/locked status, and security roles. We never store a plaintext password.
  • Organizations and memberships: organization name and settings, ownership, membership, member role, active/deactivated status, and related administrative information.
  • Work information: projects, activities (including personal or shared activities), tasks, task status and due dates, work entries, descriptions, work dates, work and travel hours, billable status, hourly rates, reimbursements, and dashboard or report totals.
  • Invite information: organization invite tokens and their active, creator, and organization association. A current invite can be rotated or deactivated; using one can add an account as a member.
  • Authentication and security information: access/session security records, refresh-token hashes and their issue, expiry, rotation, revocation, and replacement state, plus IP address and user-agent information used with security events.
  • Password-reset information: the email account being reset, a hash of the emailed one-time code, a hash of the short-lived reset token, expiry and attempt information, consumed/verified timestamps, and IP address and user-agent information. Reset codes and reset tokens are never stored in plaintext.
  • Audit information: authentication and authorization event type and result, account reference, request method and path, timestamp, IP address, user agent, and limited event details used to investigate abuse and protect the service.

3. How we use information

We use this information to:

  • create and administer accounts, organizations, memberships, projects, and work records;
  • authenticate users, issue and rotate sessions, detect token reuse, and secure accounts;
  • send password-reset emails and provide the requested reset flow;
  • produce dashboards and reports requested by an authorized user or organization;
  • enforce role-based access, prevent misuse, troubleshoot faults, and maintain auditability; and
  • respond to support, privacy, deletion, and security requests.

4. When information is shared

We do not add advertising trackers or sell personal information. Information is shared only as needed to operate the service: with authorized members and administrators of an organization according to the application's permissions; with infrastructure and service providers acting for SecondShelf; or when disclosure is required to comply with law, protect rights, or investigate security and abuse.

Current service providers include Amazon Lightsail for hosting the application infrastructure and, when configured, Hostinger SMTP for delivering password-reset emails. Providers may process information in providing those services and are expected to protect it under their own terms and policies.

5. Retention and deletion

We keep information for as long as needed to provide the service, maintain account and organization history, meet security and operational needs, resolve disputes, and comply with legal obligations. The current application does not publish a single fixed retention period for every data type. Core records support soft deletion, while authentication audit records are append-only and may need to remain after an account is deleted to preserve security history. Expired or consumed reset challenges and revoked/expired session records may be retained as security records.

To request account or data deletion, email support@secondshelf.in from the registered address (or include enough information for us to verify account ownership). State whether you want the account closed, specific organization/work data removed, or a full deletion review. We may need to confirm the request, coordinate with an organization administrator where team records are involved, and retain limited information where necessary for security, fraud prevention, legal compliance, or an audit trail.

6. Security

SecondShelf uses password hashing, short-lived reset credentials, refresh-token rotation, revocation, access controls, and security auditing. These measures reduce risk but cannot guarantee that any service, transmission, or stored information will always be secure. Keep credentials private, use a unique password, and contact us promptly if you suspect unauthorized access.

7. Children's privacy

SecondShelf is intended for adults and workplace or team use. It is not directed to children, and we do not knowingly collect personal information from children. Contact support@secondshelf.in if you believe a child has provided information so we can review and remove it where appropriate.

8. International processing

SecondShelf and its providers may process or store information in countries other than where you live, including where Amazon Lightsail or email infrastructure operates. By using the service, you understand that cross-border processing may occur. Where required, we will use appropriate safeguards and honor applicable data-protection rights.

9. Changes to this policy

We may update this policy when the service, providers, or legal requirements change. We will update the date above and, where appropriate, provide additional notice. Continued use after an update means the revised policy applies to future use.

10. Contact

Privacy, account, and deletion requests: support@secondshelf.in. See the SecondShelf support page for troubleshooting guidance.