Legal
Privacy Policy
Short version. Reading this site is anonymous. The registry pages are built on our servers and sent to you finished, so a signed-out browser never asks our database anything, and no page sets a cookie. The pages carry one counter, Vercel’s cookieless analytics, which counts views without identifying you; section 2 sets it out. The photographs are the exception: they belong to two cigar shops and are linked from their servers, so opening a marque page makes your browser fetch those files from cigarworld.de and neptunecigar.com. Signing in is optional and gets you one page, your humidor, which reads what the app holds against your account: your boxes, the cigars resting in them, and the humidity readings. It reads and never writes. Nothing on this site is for sale by us. The gear page and the humidor page carry links to Amazon.se; a purchase through one pays us a commission, the price you pay does not change, every such link is marked Ad, and none of them leads to a cigar. We do not sell your data. You can delete all of it with the button in the account panel, which works and which section 8 sets out; version 2.0 of this policy said that button was broken and dangerous, and that was wrong. The app is a separate surface, and two things it does send more away from your phone than anything on this site does: the band scan photographs a cigar band and sends the picture to Google, and Nearby lounges takes a position fix and sends it to a mapping provider. Section 5 sets out both. Version 2.1 of this policy named neither, and counted the app’s outside services as three when there are six.
1. Who we are
My Cigar Shelf is a product of Nisshagen Advisory AB (Org.nr 559526-6742), a company registered in Stockholm, Sweden. We are the data controller for personal data collected through the mycigarshelf.com website.
Contact hello@mycigarshelf.com for any privacy question, including data subject requests under the GDPR.
This policy covers the website, including the humidor page you reach by signing in.
About the app. The My Cigar Shelf app is built and running. It is in internal TestFlight, which means invited testers, and it is not on any public store. It is a working app rather than a sketch: it keeps your humidors, takes photographs of your cigars, reads a cigar band with an AI scan, finds lounges near you, and has a Delete account button of its own. It will carry its own policy for what happens on your phone before it reaches a public store, and this page will point to it. Two things about it belong here rather than there, because they bear on what this site does: the deletion in section 8 removes app data as well as website data, and the app’s own outside services, all six of them, are named in section 5 because that deletion does not reach them.
2. Reading the site
The pages themselves
The front page, the registry and the care pages are assembled on our servers and sent to your browser as finished HTML. Reading them involves no request from your browser to our database, no form, no sign-up and no interest list. There is nothing on those pages to fill in.
No page on this site sets a cookie. There is one analytics tool: Vercel Web Analytics, run by the company that hosts the site, switched on on 4 September 2026. It counts page views, and clicks on the Amazon links described below, so we can see which pages and which links are used. It sets no cookie and stores nothing on your device. Vercel does not store your IP address in those statistics; it tells visits apart with an identifier derived from the request and discarded within a day, so the counter cannot follow you from one day to the next or across sites. What we see is counts, never a person. Our host also keeps the request logs any web server keeps, and section 6 covers those. Version 2.3 of this policy said there was no analytics at all, and from 4 September until this version that sentence was false; section 11 records it.
The photographs, and the two shops they come from
Most cigars in the registry show a photograph. Those photographs are not ours and they are not stored on our servers. Each one is linked to the shop that published it, so when a marque page loads, your browser fetches those image files from www.cigarworld.de and images.neptunecigar.com. Around 5,000 of the roughly 5,900 cigars in the registry carry one; the rest show no picture at all.
What those two servers see is an ordinary request for a picture: your IP address, which any web request reveals to the server answering it, whatever your browser says about itself, and which image was asked for. They are not told who asked, and they are not told where the request came from: we set the image requests to send no referrer, so the shops do not learn that the reader was on My Cigar Shelf or which page they were reading. There is no account identifier in an image request, the page is the same public page for every reader signed in or not, and we send them nothing about you. Images load as you scroll, so a shop only hears about the ones that came into view.
We name the two hosts because your browser contacts them whether or not you meant to, and because you can see it in your own network log. A list of only the companies we pay would leave that out.
What we earn, and from whom
Since two shops have just been named, the fair question is what we get from them. Nothing. There is no affiliate code on any of those addresses, no commission, no tracking parameter and no arrangement of any kind with either shop.
Amazon is different, and it is new in version 2.4. The site carries links to Amazon.se: a gear page of keeping accessories, and a suggestion on the humidor page when a reading drifts or goes stale. My Cigar Shelf is an Amazon Associate. If you buy something through one of those links, Amazon pays us a commission. The price you pay does not change. Every such link is marked Ad. Each one carries a code that tells Amazon the visit came from this site, so the commission can be paid; the code says nothing about you, and we send Amazon nothing. Once you are on amazon.se, Amazon’s own privacy notice governs what it collects there.
This site still does not sell cigars, still does not link to anywhere that sells them, and still does not show the prices our database holds, because a price on a page reads as an offer. The gear links go to accessories only: packs, hygrometers, boxes. Never a cigar, never any tobacco product. Apple’s App Store guideline 1.4.3 and the EU Tobacco Advertising Directive both bear on that line, and it stands.
3. Signing in, and your humidor
Your account
Most of the site needs no account. One page, your humidor, does, and there is a Sign in button in the navigation on every page. Sign-in runs on Supabase, our database and authentication provider, hosted in the EU. What we hold depends on how you sign in:
- Email and password: your email address, and a password we never see in readable form. It is hashed by Supabase.
- A magic link: your email address. We send you a link, and following it signs you in.
- Sign in with Google: your email address and the account identifier Google returns. We do not receive your Google password, your contacts or anything else in your Google account.
- Sign in with Apple: the account identifier Apple returns, and the email address you choose to share. If you use Apple’s Hide My Email, we only ever see the relay address, never your real one.
If you type a name when you create the account, we store it and use it to greet you in the account panel. Nothing else about you is asked for.
One login across the shelf apps
The account is the ShelfHub account, and it is one login across My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf, My Cigar Shelf, My Coffee Shelf and My Supply Shelf. Signing in here signs you in with the same credentials you use there. The login is shared. The shelves are not: your humidor is not visible to those apps, and what you keep in them is not visible here. This matters most when you delete something, so section 8 sets it out in full.
Where your session is kept
Nothing on this site sets a cookie. When you sign in, one entry goes into your browser’s local storage, named sb-tlqlbnhaqpqgaxfihdlj-auth-token after our database project, holding the token that keeps you signed in. Signing out removes it. If you sign in with Google or Apple, the token comes back in the address bar and is moved into that same entry.
That entry is the only thing this site stores on your device, and it is there because you asked to be signed in. Storage that is strictly necessary for something you requested does not require consent under the ePrivacy rules, which is why you are not looking at a cookie banner. If we ever add storage that is not necessary, you will be given a real choice about it and this policy will say so first.
What the humidor page shows
It shows what the app holds against your account, and nothing else:
- Your humidors: the name you gave each box, the humidity and temperature you are aiming at, its capacity, and when you created it.
- The cigars in them: which cigar from the registry it is or the name you typed yourself, how many, which box it is in, the format you bought, the date you put it away, an aging target date if you set one, your notes, and when the record was made.
- Readings: humidity, temperature and the time each was taken. The page fetches the hundred most recent and shows the latest one per box.
To label your cigars it also reads names, vitola, ring gauge, length and strength from the public registry. That is the same catalogue every reader sees and it holds nothing about you.
Read as a run, those records are a dated inventory of what someone owns and when they acquired it. We would rather say what it amounts to than file it under “your data”. It is private to your account: the database restricts every row in those three tables to the account that created it, and that restriction lives in the database rather than in this website’s code, so it holds no matter what this page asks for.
This page reads and does not write
Nothing you do on this website changes your humidor. Adding a cigar, logging a reading and editing anything happen in the app. There is not one write to shelf data anywhere in this site’s code. The only things this site can change are the account itself: creating it, resetting the password, and the deletion described in section 8.
What this site does not do
Every line below is about this website. Several of them do not hold for the app, and where that is so the line says which section of this policy covers the app instead. Reading a list like this as though it covered both is exactly the mistake version 2.1 invited.
- No ad network, no advertising identifiers, no third-party ad script. The Amazon links in section 2 are advertising in the legal sense, which is why each one is marked Ad, and they are plain links: nothing loads from Amazon when a page shows one, and nothing is sent to anyone unless you click.
- No session recording and no third-party trackers. Page views and clicks on the gear links are counted by the cookieless Vercel analytics in section 2, and that is the whole of the analytics on this site.
- No location on this website. No page here asks your browser for a position, and there is no geolocation call anywhere in this site’s code. The app is a different matter: its Nearby lounges list takes a position fix and sends it to a mapping provider, and section 5 sets that out.
- No camera, contacts, calendar or photographs of yours on this website. The app uses the camera, both for the photographs you attach to a cigar and for the band scan, which sends the picture to Google. Section 5 again.
- No selling, renting or sharing of personal data with data brokers, ever.
- No purchases. There is no subscription, no in-app purchase and no paywall on this site. The app is where the subscription lives, and section 5 names RevenueCat.
If any of that changes, we will update this policy before the change goes live rather than after. Version 2.3 also promised that analytics in particular would stay off until you consented to it, and the cookieless counter in section 2 went live on 4 September without either the update or the consent. Section 11 records the break. The promise now reads: anything that stores on your device or identifies you stays off until you consent, and this page changes before the site does.
4. Legal basis for processing
Version 2.2 of this policy gave a basis for the website and none for the app, while section 5 described the app’s processing in full. That left the largest things this policy describes with no lawful basis attached to them. Both are covered here.
- Performance of a contract, Article 6(1)(b): creating and holding your account; reading your humidor back to you on this site; and, in the app, storing your humidors, the cigars in them, your readings, your smoke sessions, your wishlist, the lounges and gear you record and the photographs you attach, running a band scan or a barcode lookup or a Nearby lounges search when you ask for one, and managing a subscription you bought. Without this there is no service to provide.
- Consent, Article 6(1)(a): the app’s usage analytics, and nothing else. Off until you switch it on in the app’s Profile screen, withdrawable in the same place at any time, and withdrawal does not affect what was processed before. Nothing on this website relies on consent: there is no marketing list, no newsletter and no non-essential storage. Version 2.2 said consent was relied on for nothing at all, which was true of the site and not of the app.
- Legitimate interests, Article 6(1)(f): keeping the site working and secure, and serving the public registry to the people reading it; crash and error reporting from the app, so that we find out when it is broken; the AI scan ledger, so the free allowance in section 5 can be counted and not circumvented; and the nearby place cache and the pooled lounge list, so a lookup that works for one person works for the next and we do not pay a mapping provider twice for the same query. In each case the interest is running and paying for a working app, and it is balanced against the fact that none of these carries anything you wrote.
Giving us this data is not a statutory requirement. It is what the app needs in order to be a humidor: without an account there is nowhere to put a cigar. There is no automated decision-making that produces legal or similarly significant effects and no profiling. A band reading is a machine guess that fills a form, and you review and edit every field before anything is saved.
5. Third parties we use
- Supabase – the database and the sign-in system, holding the registry, your account and your humidor records. Hosted in the EU. The sign-in emails (confirmation, password reset, magic link) are sent through it.
- Vercel – hosting for this website, and the Web Analytics described in section 2. Beyond the server-side request logs any host sees, it holds the page-view and click counts, with no cookie and no stored IP address in them.
- Google and Apple – only if you choose to sign in with one of them, and only for that sign-in. Choosing one sends your browser to them. Not choosing one means your browser never contacts them.
- cigarworld.de and neptunecigar.com – the two shops whose photographs the registry links to, described in section 2. They receive a request for an image file. They receive nothing from us.
- Amazon – only if you click one of the gear links described in section 2. Clicking takes your browser to amazon.se with a code naming this site, so Amazon can pay the commission. The code carries nothing about you, and we send Amazon nothing.
Fonts are the last one, and it applies to three pages rather than the site. This policy, the terms and the deletion page are static pages that load their two typefaces from Google Fonts, so your browser requests those files from Google’s servers and Google receives your IP address as part of that request. No font cookies are set. Every other page on the site serves its fonts from our own domain, so reading the registry involves no request to Google at all.
We do not sell your data to any third party. Supabase and Vercel are the two companies we contract with to run this site, and neither uses your data for advertising. If we ever add a provider that would, we will update this policy before the arrangement starts.
Google, Apple, Amazon and the shops are not working for us, so we will not make a promise on their behalf. What their servers do with a request they receive is governed by their own policies. What we control is how little we hand them, and section 2 says exactly what that is.
Six that belong to the app
None of these is contacted by this website. They are named here because the app hands them things this site never touches, and because the deletion in section 8 does not reach them, so they outlive it whichever button you press. Version 2.1 of this policy listed three and called that the whole set. It was not.
- Sentry – crash and error reports from the app, on Sentry’s German service. We switch off the sending of personal data and we never attach an account to a report. The honest limit is that the library keeps a trail of the network requests leading up to a fault, and some of our database requests carry your account identifier in the address, so a report can contain it. We are not going to claim a crash report holds nothing about you.
- Mixpanel – usage events from the app, on Mixpanel’s EU service, and only if you turned analytics on yourself in the app’s Profile screen. It is off until you do, and while it is off the library is never started at all. The events are keyed to your account identifier rather than your name or your email, which makes them pseudonymous rather than anonymous. Your answer is one row on your account, and five apps read and write that row: My Cigar Shelf, My Bar Shelf, My Whiskey Shelf, My Wine Shelf and My Beer Shelf. So it is the same answer in all five. It is not the answer in My Coffee Shelf, which keeps a separate one in its own table and asks you again there. My Supply Shelf sends no analytics at all.
- RevenueCat – in the United States. The app asks it on launch whether your account holds a subscription, so it receives your account identifier when you sign in whether or not you ever buy anything, along with your platform and the IP address of the request. It is also asked from our own server every time you run a band scan, to decide whether the scan counts against your free allowance, and that request carries your account identifier too. Nothing on this website contacts it and nothing on this website is for sale.
- Google – the Gemini API, which reads the photograph the band scan takes. This is the largest thing the app sends anywhere and it has its own subsection below.
- Geoapify – a mapping provider, in Germany. When you press Nearby lounges it receives your coordinates and a search radius, by way of our server.
- Overpass – a query service for OpenStreetMap data, answered by mirrors in Europe. It receives the same coordinates and radius when it is the provider serving the request. Both it and Geoapify have answered for this app.
The band scan sends a photograph to Google
The app’s add sheet has a Band scan. It opens the camera, you photograph a cigar band, and the picture leaves your device. This is the part of the app that sends the most away from your phone, so it is set out in full.
- The picture comes from the camera rather than your photo library, and the app takes it without the camera metadata a phone would normally write into a photo file. It is then re-encoded, which drops that metadata a second time. So the position tag a photograph can carry does not travel with it.
- It is resized on your device to 768 pixels on its long edge, re-encoded as a JPEG, and sent to our own server function, which runs on Supabase in the EU. Your sign-in token goes with it, so the function knows whose allowance to count.
- Our function forwards the image and a fixed instruction to Google, to the Gemini API, which reads the band and returns text. What goes in that request is the picture and the instruction. Your account identifier, your email and everything in your humidor stay here.
- The reading comes back and fills in the add form. You review and edit every field.
This happens before anything is saved, and it happens even if you then discard the reading and add nothing. Cancelling the form does not undo the upload.
We keep no copy of the band photograph. Our function writes it to no storage area and returns nothing but the text. This is separate from the photographs you attach to a cigar, a box or a session: those are uploaded to our file storage and kept with the record, and the deletion in section 8 removes them.
What our function does write is one row per scan, holding your account identifier, which Shelf app ran the scan, what kind of scan it was and the time. That row exists to count your free allowance, which is five AI scans in total, for the lifetime of the account. It is not a daily or a monthly allowance and it does not reset.
Those five are not five per app. The count is kept on your ACCOUNT, in one ledger, and the check that reads it does not filter by app. So an AI scan you ran in any Shelf app comes off the same five. We checked the ledger rather than reasoning about it: it currently holds scans recorded by My Bar Shelf, My Cigar Shelf and My Wine Shelf. Not every Shelf app meters its AI features this way, and each of their policies is the place to read how theirs works. Two earlier versions got this wrong in opposite directions: one said the five were shared across every Shelf app, which was more than we had checked, and the correction named three apps as a closed set, which was less than the ledger actually counts.
Subscribers are not metered, and the row is still written. The app’s own wording calls this a daily limit in one place; that string is wrong and is being corrected.
What we cannot tell you. We call Google’s general endpoint and have not pinned it to a European region, so you should assume the photograph is processed outside the EU. We do not control what Google does with the image after it has read it, and we are not going to state a retention period or a non-use promise we cannot verify. Google’s own terms for that API govern it. If that is not acceptable to you, do not use the band scan. Adding a cigar by barcode, from the registry or by hand never sends a photograph anywhere.
Nearby lounges sends your position to a mapping provider
The smoke session write-up in the app has a Nearby lounges list. It does nothing on its own: it sits idle until you press it.
- When you press it, the app asks for foreground location permission and takes one position fix at balanced accuracy. It does not follow your position, and it does not ask for background location. Android background location is switched off in the app’s own configuration.
- That fix, a latitude and a longitude at full precision, goes to our own server function on Supabase in the EU, along with which Shelf app asked.
- Our function looks for places around that point using Geoapify where we have a key configured, and Overpass, which answers from OpenStreetMap data, otherwise. Whichever one serves the request receives your coordinates and a search radius, 600 metres by default. The Overpass request also carries our own contact address in the header those mirrors ask for; that is ours, not yours.
- A list of places comes back. Your account identifier, your email and everything in your humidor stay here.
What is kept. Our server caches the provider’s answer against a map tile rounded to roughly a kilometre, and reuses it for seven days. The cached row holds that tile, what was searched for, the answer and which provider gave it. It does not hold your account identifier and it does not hold the fix you sent. Your position fix itself is not written to any table.
If you save one of the places to a session, that place’s own coordinates are written to a pooled lounge list, so the next person searching the area finds it. Those are the venue’s coordinates as the mapping provider gave them, not your position. We checked the columns on that table: it has no column for who added a row.
If you never press Nearby lounges, the app never asks for your location. That one list is the only place in the app that reads a position at all.
6. How long we keep things
- Your account and your humidor: for as long as the account exists. Delete it and the boxes, the cigars recorded in them, every humidity and temperature reading, the humidor maintenance you logged, your smoke sessions with their scores, flavour notes, paired drink, location and duration, and the first, second and final third you recorded within each one, your wishlist, the lounges and the gear you recorded, and every photograph the app uploaded for you go with it. Nothing expires on its own and no clean-up job removes it. Version 2.2 of this policy wrote this list as though it were complete and left the sessions and the maintenance log out of it.
- The registry: kept indefinitely, and not touched when an account is deleted, because it is not about you. A registry row says a cigar exists, not that anyone owns one, and it has no column for a user.
- Barcode contributions: if you scanned a barcode in the app and confirmed which cigar it was, that mapping goes into a pooled table so the next person who scans it gets an answer. The row holds the barcode, the cigar and the account identifier of whoever contributed it. That identifier is cleared only when your sign-in record itself is deleted. If your sign-in is kept because another Shelf app still holds your data, the identifier stays on the row until the sign-in goes. Version 2.1 said deletion strips it off, full stop. That is true on one of the two paths, and section 8 sets out which.
- The AI scan ledger: one row for each band scan, holding your account identifier, which Shelf app scanned, the kind of scan and the time. It is kept for the life of the sign-in record, because the free allowance is a lifetime one and counting it needs the rows. It goes when the sign-in record goes.
- The nearby place cache: the answer a mapping provider gave for a map tile, reused for seven days. It holds no account identifier and no position of yours, so there is nothing in it to trace to you and nothing we could find to delete on request.
- Crash reports, usage events and the subscription record: Sentry, Mixpanel and RevenueCat keep their own copies on their own schedules, and no deletion of ours reaches them. Section 8 says what to do about it. What Google keeps of a band photograph after reading it is governed by Google’s terms for that API, and we cannot delete it for you.
- On your own device: the single sign-in entry described in section 3. Signing out removes it.
- Analytics counts: the page-view and click counts at Vercel hold no identifier of yours. The identifier Vercel derives to tell one visit from another is discarded within a day.
- Request logs: our host keeps server-side request logs on its own operational retention schedule. We do not read them to build a picture of any reader, and there is no tool on this site that would let us.
7. Your rights under the GDPR
As a user in the European Economic Area you have the right to:
- Access: request a copy of the data we hold about you
- Rectification: ask us to correct anything inaccurate
- Erasure: ask us to delete your account and everything in your humidor
- Portability: request your data in a portable format. There is no export button on this site. We assemble the file by hand and send it to you.
- Withdraw consent: tell us to stop at any time, without giving a reason; withdrawal does not affect processing carried out before then
- Object and restrict: object to processing based on legitimate interests, or ask us to restrict it
To exercise any of these, write to hello@mycigarshelf.com from the address on the account. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority; in Sweden that is Integritetsskyddsmyndigheten (IMY).
8. Deleting your account
There are three routes and all three work.
- The Delete account button in the account panel on this site. It tells the shared deletion function that it is being called from My Cigar Shelf, and the function has a My Cigar Shelf branch, so it deletes cigar data and nothing else.
- Delete account in the app, under Profile, behind two confirmations. It sends the same request to the same function.
- hello@mycigarshelf.com, from the address on the account, if you would rather a person did it or you cannot get into the account you want gone.
What the button removes: every photograph the app uploaded for you, which goes first, and then your smoke sessions and the thirds you recorded within them, your humidors, the cigars recorded in them, every humidity and temperature reading, the humidor maintenance you logged, your wishlist, the lounges you saved and the gear you recorded. If the photographs cannot be removed the whole deletion stops before any record is touched, so a half-finished deletion is not one of the outcomes. Deletion is permanent and we cannot restore it afterwards. Version 2.2 of this policy wrote this list as the whole of what goes and left the sessions and the maintenance log off it. They were being deleted; they were simply not written down.
This section used to say the opposite, and it was wrong. Version 2.0 told you the button would erase your My Bar Shelf and My Whiskey Shelf data and leave your humidor untouched, and told you not to use it. That was false when it was published and it has been false ever since: this site has always told the function which shelf it is, and the cigar branch went live before that sentence was written. It frightened people away from a working feature, which is worse than a stale note. Section 11 records it.
One thing to know about the shared login. If the same login is also used for another shelf app, deleting your cigar records does not delete the login itself, because that would destroy your account in the other app. The function checks the other shelf apps for you, erases the cigar records, and keeps the login. It tells the app which of the two happened. Ask and we will remove the login too.
What is left afterwards. Saying “nothing” would be easier and it would not be true. Crash reports at Sentry, usage events at Mixpanel if you ever turned analytics on, and your subscriber record at RevenueCat all survive, because no deletion of ours reaches those three. What Google holds of a band-scan photograph after reading it is governed by Google’s own terms, and we cannot reach that either.
The rest depends on which of the two paths above your deletion took, and version 2.1 described only one of them:
- If the login is deleted, your identifier comes off any pooled barcode row you contributed and the mapping stays without it, and your analytics choice, your AI scan tally and the log of notifications sent to you go with the login.
- If the login is kept because another shelf app still holds your data, four things are kept with it: your analytics choice, your AI scan tally, the log of notifications sent to you, and your identifier on any pooled barcode row you contributed. Version 2.1 named the first three and said the barcode identifier was always stripped. On this path it is not.
Write to us and we will remove by hand whatever the button cannot.
9. Age
My Cigar Shelf is about cigars and the keeping of a humidor, and it is meant for adults who are of legal age to buy tobacco where they live: 21 or over in some countries, 18 in others. It is not directed at anyone below that age, and we do not knowingly hold data about them. If you believe a minor has an account here, write to us and we will delete it.
This site does not put an age prompt in front of you and stores no answer to one. Version 1.0 of this policy said otherwise; see section 11.
10. International transfers
Our database, our authentication and everything in your humidor are hosted in the European Union.
What stays inside it: crash reporting on Sentry’s German service, usage analytics on Mixpanel’s EU service, and the lounge lookups, which go to Geoapify in the EU or to Overpass mirrors in Europe.
These reach past the boundary:
- Sign in with Google and Sign in with Apple, handled by Google and Apple under their own terms, and only if you pick one.
- Google Fonts, which serves the typefaces on this page, on the terms and on the deletion page.
- The two cigar shops whose photographs the registry links to, one German and one American. Those requests carry your IP address to them.
- Google, which receives the band-scan photograph at a general endpoint we have not pinned to a European region. This belongs to the app rather than to this site, and section 5 sets it out.
- RevenueCat, in the United States, which receives your account identifier: from the app when you sign in, and from our own server on every band scan. Also the app rather than this site.
For Google and RevenueCat we rely on the European Commission’s standard contractual clauses, which form part of the data processing terms those providers publish. Version 2.1 of this policy counted four transfers and did not include Google, which was wrong on both the count and the set. If a provider we choose ever needs to process data outside the EEA, we will only use one that relies on an adequacy decision or those clauses, and we will say so here.
11. Changes to this policy
If we make material changes we will publish the updated version here and update the version number and effective date at the top of this page. If a change materially affects data we already hold about you, we will tell you before it takes effect.
Version 2.4, 5 September 2026. Two changes, and one of them is late.
- The site now carries affiliate links to Amazon.se. A gear page of keeping accessories, and a suggestion on the humidor page when a reading drifts or goes stale. We earn a commission if you buy through one, the price you pay does not change, every such link is marked Ad, and none leads to a cigar or any other tobacco product. Version 2.3 said there was no affiliate code and no commission on anything; that was true until this release, and this version was published with the release that switched the links on. Sections 2 and 5 describe the arrangement.
- An analytics counter went live before this page said so. Vercel Web Analytics, cookieless and without stored IP addresses, was switched on on 4 September 2026, and until this version the policy still said there was no analytics and that analytics would stay off pending consent. The counter ran for a day while those sentences stood. That is a broken promise on the ordering, and we record it rather than restate the promise as if it had been kept. Section 2 now describes exactly what is counted, and section 3 states the promise as it now reads.
Version 2.3, 1 September 2026. Version 2.2 described the free scan allowance as something the whole Shelf portfolio shares, assigned no lawful basis to anything the app does, and wrote two lists as complete when they were not. What was wrong, and what replaces it:
- “Five AI scans in total, for the lifetime of the account, shared across every Shelf app you use.” The five are shared between My Cigar Shelf, My Whiskey Shelf and My Coffee Shelf, which call the same scan function on our server and count against one ledger. The remaining Shelf apps meter their AI features on their own terms and this policy does not speak for them. Section 5.
- Section 4 gave a lawful basis for the website and none for the app. Section 5 described the band scan, the location lookup, the analytics and the crash reports in full, and section 4 was silent about all of them. It now assigns Article 6(1)(b) to the account and the features you ask for, Article 6(1)(a) to analytics, and Article 6(1)(f) to crash reporting, the scan ledger and the place cache, with the interest named in each case.
- Section 4 said consent was relied on for nothing. True of this website. The app has an analytics switch and that switch is consent. Corrected.
- The retention list and the “what the button removes” list both left out your smoke sessions and the humidor maintenance you log, and both were written as complete. The sessions carry your scores, your flavour notes, the drink you paired, where you were and how long it took, and the thirds recorded within a session carry more of the same. They were being deleted and kept exactly as described; they were simply missing from the two lists that claimed to name everything. Sections 6 and 8.
- The Mixpanel entry in section 5 named four apps as sharing your analytics answer. It is five, this one included, and they are now named as five. My Supply Shelf sends no analytics at all, which was also not said.
- “One login for the whole family: My Bar Shelf, My Whiskey Shelf, My Coffee Shelf and the rest.” Section 3 now names all seven apps rather than trailing off.
Version 2.2, 1 September 2026. Version 2.1 was published and went live with false statements in it. It described the app’s outside services as a closed set of three, and the app has six. It counted the transfers out of the EEA as four and left out the largest one. What was wrong, and what replaces it:
- “Three more that belong to the app” named three processors and there are six. Missing were Google, which receives a photograph of a cigar band every time the band scan runs, and Geoapify and Overpass, which receive your coordinates when you press Nearby lounges. The band scan was live and had run in production when version 2.1 was published. Section 5 now names all six and describes the scan and the location lookup in full.
- “Four things reach past that boundary” in section 10 was wrong on the count and on the set. The band-scan photograph goes to Google at an endpoint we have not pinned to a European region, and that was not in the list. Section 10 is rewritten as a list rather than a count.
- “The three services in section 5 that the app uses” in section 1 repeated the same closed count. Corrected.
- “No location. The site never asks for it.” That sentence is true of this website, and we checked: there is no geolocation call anywhere in this site’s code. It sat in a list that reads as though it covered the app, and the app does ask for location. The list in section 3 now says which lines stop at the website, and section 5 describes what the app does.
- “Deleting your account strips your identifier off the row” for pooled barcode contributions, in sections 6 and 8 and on the deletion page. That happens only when your sign-in record is deleted. When the sign-in is kept because another Shelf app holds your data, your identifier stays on the row. Both sections now say so.
- “Three shared records are kept” in section 8. On the path where the login is kept there are four: the barcode identifier above is the one that was missing.
- RevenueCat was understated. Version 2.1 said the app asks it on launch. Our own server also asks it, with your account identifier, on every band scan.
- Added: the AI scan ledger and the free allowance of five scans for the lifetime of the account, the nearby place cache and what it holds, the pooled lounge list, and the fact that the analytics answer covers five of the Shelf apps rather than all of them. The description of the allowance as shared across every Shelf app was itself wrong and version 2.3 corrects it.
What we did not change, because we checked it and it held: the registry carries no column for a user, the pooled lounge list carries no column for who added a row, this website makes no geolocation call, and the release status in section 1 is still accurate.
Version 2.1, 31 August 2026. Version 2.0 promised that this section would say so when the Delete account button was fixed. The button was never broken, and this page is late saying it. What changed:
- Section 8 is rewritten. Version 2.0 said the button would erase your My Bar Shelf and My Whiskey Shelf records, leave your humidor where it was, and should not be used. Every part of that was false. This site names its own shelf when it calls the shared deletion function, that function has a My Cigar Shelf branch, and the branch removes cigar data and touches no other app. The section now sets out all three deletion routes and what each removes.
- Section 1 no longer says the app is unreleased. It said the app was still being built and had not been released. The app is a working build in internal TestFlight, with photographs and a Delete account button of its own. It is not on a public store, and that is now the claim rather than the stronger one.
- Sentry, Mixpanel and RevenueCat are named for the first time, in section 5. They belong to the app rather than to this website, and they were left out on that reasoning. They should have been in here anyway, because no deletion of ours reaches them.
- The font paragraph in section 5 said two pages. It is three: this policy, the terms and the deletion page all load Google Fonts.
- Section 6 was incomplete. It did not mention the photographs the app uploads, the wishlist, the lounges or the gear, and it did not mention that a pooled barcode contribution survives with your identifier stripped off it.
- Sections 8 and 10 now name what survives a deletion, including the three shared records kept alongside a login that is retained because another shelf app holds your data.
Version 2.0 replaced the version dated July 2026. That one described a pre-launch page with an interest-list form, an age prompt and no accounts, and it was written for the earlier mycigarshelf.com landing page. It was wrong about this site, which has a registry, sign-in and a humidor, and no form of any kind. Nothing was collected under it: no address was ever submitted to that form on any of our sites.
12. Contact
Questions or concerns about your privacy? Write to hello@mycigarshelf.com.
Nisshagen Advisory AB, Stockholm, Sweden.