Privacy Policy
Last Updated: July 18, 2026
This document is provided in English only.
Introduction
ShopDesk is operated by Arkwell Studio LLC ("we," "us," or "our"). The ShopDesk platform is accessible at shopdeskapp.com and its subdomains. This Privacy Policy describes how we collect, use, and protect information when you use our platform.
This policy applies to all users of our platform, including business owners who manage accounts ("Merchants"), their staff members, and customers who interact with businesses through ShopDesk ("End-Customers").
Our Role: Platform vs. Merchant
ShopDesk operates in two distinct roles depending on the data involved:
As a Controller
We are the controller for Merchant account data — the information business owners and staff provide to create and manage their ShopDesk accounts.
As a Processor
We process End-Customer data (bookings, feedback, gift card usage) on behalf of Merchants. The Merchant is the controller of their customer data. Merchants are responsible for providing their own privacy notices to their customers.
If you are an End-Customer and wish to access, correct, or delete your personal data, please contact the business you interacted with directly. ShopDesk will assist Merchants in fulfilling such requests.
Data We Collect — Business Accounts
When Merchants and staff create and use ShopDesk accounts, we collect:
- Account information: email address, password (hashed via Supabase Auth), Google OAuth credentials if used
- Business profile: business name, address, phone number, logo, timezone, currency, operating hours
- Staff data: name, email, phone number, working hours, service assignments, notification preferences
- Service data: service names, descriptions, pricing, durations, categories, images
- Billing data: Stripe customer ID and subscription status. Credit card details are stored by Stripe, not ShopDesk.
Data Collected on Behalf of Merchants
When End-Customers interact with a business through ShopDesk, we process the following data on the Merchant's behalf:
- Booking information: guest name, email, phone number, selected service, assigned staff, appointment date and time
- Customer profiles: phone number (primary identifier), name
- Gift cards: if provided by the Merchant, purchaser or recipient information may be stored in connection with a gift card, along with card balance and transaction history. ShopDesk does not process or store gift card funds — payments are handled directly by the Merchant.
- Rewards: if provided by the Merchant, recipient information may be stored in connection with a reward, along with redemption status
- Feedback: rating, comment text. IP addresses are hashed (one-way) for rate limiting — raw IP addresses are never stored.
- SMS reminders: If the Merchant enables SMS appointment reminders and the customer opts in during booking, the customer's phone number is used to deliver a single transactional reminder message before the appointment.
- AI Receptionist call data: if the Merchant enables the AI Receptionist add-on, we process inbound call data including the caller's phone number (from caller ID), the call transcript, an AI-generated summary, logs of actions the AI took on behalf of the Merchant (such as bookings created, rescheduled, cancelled, or messages taken), call metadata (duration and outcome), and cost metadata. Audio recordings of calls are not currently stored.
Gift cards and rewards may be generated without collecting personal information. Personal data is processed only if the Merchant chooses to associate a gift card or reward with a specific individual.
Cookies & Tracking Technologies
ShopDesk uses a small number of cookies, all for functional purposes:
- Locale cookie — stores your language preference, shared across subdomains, expires after 1 year
- Analytics session identifier — a random ID kept in your browser's session storage (not a cookie) that is deleted when the tab closes; it is never linked to your identity and never persists across visits
- Authentication session cookies — managed by Supabase Auth, httpOnly, required for login
- Consent preference cookie — records your cookie-banner choice, shared across subdomains, expires after 12 months
- Attribution cookie — records which marketing channel brought you to our site (source, medium, campaign), shared across our subdomains only, expires after 30 days
On our public marketing pages — the landing page (shopdeskapp.com), /pricing, /signup, and the onboarding completion step — we may load third-party advertising and conversion tracking tags as described in Section 5a below. These tags are not loaded on the merchant dashboard (manage.shopdeskapp.com) or on any merchant booking subdomain.
Advertising & Conversion Tracking
On our public marketing surfaces only — the landing page, pricing page, signup page, and the onboarding completion step — we may load Meta Pixel and the Google Ads conversion tag. We use these tags solely to measure the effectiveness of our advertising and to attribute sign-up conversions.
These tags are not loaded on the merchant dashboard (manage.shopdeskapp.com) or on any merchant booking subdomain. You can control these tags through standard browser-level ad-tracking controls and through the privacy controls offered by their respective providers.
Advertising cookies are set only if you accept them via the cookie banner shown on our marketing pages, and we honor Global Privacy Control (GPC) browser signals as an advertising opt-out. You can change your choice at any time using the Cookie preferences link in the page footer.
Analytics
We use PostHog for product analytics to understand how our platform is used and to improve it. Our analytics implementation:
- Collects only allowlisted properties per event type — no personally identifiable information is sent
- On public pages (landing, signup, and booking pages), events are sent to our own servers first, which forward only a random session-scoped identifier, coarse location (city level), and broad device categories — no IP address, raw browser details, page URLs, or persistent identifiers are forwarded to PostHog
- Does not use session recording or autocapture
- Is not used for advertising purposes, and analytics events are suppressed for browsers sending the Global Privacy Control signal
How We Use Data
We use collected data for the following purposes:
- Service delivery: operating the platform, processing bookings, managing gift cards and rewards
- Account management: authentication, authorization, and account administration
- Transactional communication: booking confirmations, reminders (email and, where opted in, SMS), and notifications
- Security and abuse prevention: rate limiting, IP hashing, encrypted sessions, and fraud detection
- Product improvement: aggregated analytics to improve the platform experience
- Billing: processing subscription payments through Stripe
- Legal compliance: responding to legal requests and enforcing our Terms of Service
- Support and account access: authorized ShopDesk personnel may access merchant accounts and data only as needed for support, security, debugging, abuse prevention, or legal compliance. Certain support actions may be logged for audit, security, and accountability purposes.
We process data based on contractual necessity, legitimate interests in operating and improving the platform, and compliance with legal obligations.
Third-Party Service Providers
We may share personal information with service providers that help us operate the platform, including providers for:
- Hosting and infrastructure
- Database, authentication, and file storage
- Payment processing
- Transactional email delivery
- Product analytics
- SMS delivery
- Push notifications
- Business listing and location data
- AI voice orchestration (for the AI Receptionist add-on)
- Language model processing (for the AI Receptionist add-on)
- Inbound voice telephony (for the AI Receptionist add-on)
- Advertising and conversion measurement (limited to public marketing pages, as described in Section 5a)
These providers process data only as necessary to provide services to us and according to our instructions, where applicable.
Push Notifications
If you use our mobile application, we may send push notifications via Firebase Cloud Messaging (FCM). Device tokens are stored to deliver notifications and are automatically removed after 90 days of inactivity. You can control push notifications through your device settings at any time.
SMS Notifications
If a Merchant enables SMS appointment reminders through ShopDesk, and a customer opts in during the booking process, we send a single transactional SMS reminder before the scheduled appointment using a third-party SMS delivery provider.
Phone numbers are shared with our SMS provider solely for the purpose of delivering the message. No marketing messages are sent. Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. Customers can opt out at any time by replying STOP to any message, or by not opting in during future bookings.
SMS reminders are available only to Merchants on eligible plans.
ShopDesk may collect and use SMS operational data, such as message volume, send status, and delivery outcomes, to maintain service quality, detect misuse, and comply with carrier or provider requirements. This information is used for operational and compliance purposes, not for marketing.
AI Receptionist
If a Merchant enables the AI Receptionist add-on, inbound calls to the Merchant's ShopDesk-provisioned phone number may be answered by an automated AI assistant.
At the start of each call, the caller is informed that they are speaking with an AI assistant and that the call may be transcribed. Audio recordings of calls are not currently stored.
During a call, the AI uses third-party providers for voice orchestration, language model processing, and telephony solely to deliver the call. We share the caller's phone number, the call audio for real-time processing, and the resulting transcript with these providers as necessary to operate the service.
Calls may be transferred to a fallback phone number designated by the Merchant under documented conditions, including when the Merchant's usage allotment for the billing cycle has been reached, when the call falls outside the Merchant's configured hours, or when the AI is unable to continue the call. When a transfer occurs, the caller's phone number is forwarded to the destination as part of normal telephony routing.
Caller data processed through the AI Receptionist is treated as End-Customer data under the Merchant's control, consistent with Section 2.
Data Retention
We retain data while your account is active and as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:
- In-app notifications are automatically deleted after 90 days
- Push notification device tokens are cleaned up after 90 days of inactivity
- Account data is retained while the account remains active and for a reasonable period thereafter to comply with legal and operational requirements
- AI Receptionist call transcripts, summaries, and metadata are retained while the Merchant's account is active or as needed for operational, legal, or security purposes
International Data Processing
ShopDesk is operated from the United States. By using our platform, you understand that your information may be processed and stored in the United States and other jurisdictions where our service providers operate.
Data protection laws in these jurisdictions may differ from those in your country of residence. We take commercially reasonable steps to ensure your data is treated securely and in accordance with this Privacy Policy. Our service providers are contractually obligated to process data only according to our instructions.
Data Security
We implement commercially reasonable measures to protect your data, including:
- HTTPS encryption for all data in transit
- Database row-level security policies
- Rate limiting on public-facing endpoints
- Password strength requirements (8+ characters, mixed case, numeric)
- Encrypted and signed session tokens
No method of transmission or storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.
Your Rights
Merchants and Staff
You may access, correct, request an export of, or request deletion of your account data by contacting us at support@shopdeskapp.com.
End-Customers
Please contact the business you interacted with directly. ShopDesk will assist Merchants in fulfilling data requests from their customers.
We may need to verify your identity before fulfilling data requests. Please note that certain data may be anonymized rather than deleted where required for legal or audit purposes.
Children's Privacy
ShopDesk is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will take steps to remove it.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the platform or by email. Your continued use of ShopDesk after changes take effect constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, please contact us at:
support@shopdeskapp.com