Legal
Privacy Policy
Last updated: 7 June 2026
This policy explains what information Shoe Box collects, why, and the control you have over it. The short version: we collect the little we need to run the app, we never sell your data, and we don't track you across the web.
1. Who we are
Shoe Box ("Shoe Box", "we", "us", "our") is a mobile app and website operated by Shepherd Holding W.L.L, a company registered in the Kingdom of Bahrain. For the purposes of data protection law, Shepherd Holding W.L.L is the data controller responsible for your personal information.
This policy covers the Shoe Box mobile app (iOS and Android) and the website at shoe-box.app. If you have any questions, reach us at support@shoe-box.app.
2. What we collect
We deliberately collect very little. Here's the complete picture:
| Category | What it is |
|---|---|
| Account & sign-in | Your email address. If you use Sign in with Apple or Google, the name and email address they share with us (Apple may give you a private relay email). We use passwordless sign-in (a one-time code), so we never store a password. |
| Profile | A display name you choose, your sizing preference (Men's, Women's or Unisex), your preferred size system (US, UK, EU or JP cm), and a starting size to get you set up. |
| Your shoes | The pairs you log: brand, model, size, size system, and how each fits (Tight, Perfect or Loose). If you request a brand or model we don't list yet, the name you submit. |
| Technical & diagnostic | Standard server logs from our infrastructure providers — such as IP address, timestamps, app version and basic device type — kept for security, fraud prevention and reliability. |
What we do not collect
- No precise or background location.
- No photos, camera or microphone access.
- No contacts, health, or biometric data.
- No advertising identifiers and no third-party ad or social-media trackers.
- No payment card details — Shoe Box is free, with no in-app purchases, so we never handle payments.
The website (shoe-box.app) uses only the essential request logs kept by our hosting provider to serve the pages and keep the site secure. It does not run advertising cookies or cross-site tracking.
3. How we use it
- To run the app — store your shoebox, sync it securely across your devices, and show you your sizes.
- To sign you in — send one-time codes and verify Apple/Google sign-in.
- To improve Shoe Box — learn brand-to-brand patterns from aggregated, anonymised data (see section 4).
- To communicate — occasional service messages, such as sign-in codes or important account or policy notices. We don't send marketing spam.
- To keep things safe and working — security, fraud prevention, debugging and meeting legal obligations.
Legal bases (for EEA/UK users). We process your data to perform our contract with you (providing the app), for our legitimate interests (keeping the service secure and improving sizing through aggregates), to comply with legal obligations, and — where required — with your consent, which you can withdraw at any time.
4. Aggregated & anonymised data
Shoe Box gets more useful as more people log their shoes. We compute statistical patterns across the community — for example, "on average, people who wear a 10 in brand A wear a 10½ in brand B." This processing is designed to be privacy-protecting:
- It is aggregated across many users and stripped of anything identifying.
- Patterns are only produced where there are enough contributors to prevent any individual from being singled out.
- Your individual shoebox is never shown to other users and is never part of a public or shared dataset in an identifiable form.
If we ever license or share these aggregated, anonymised insights with partners (for example, retailers or brands), that data will not identify you and will not include your personal shoebox.
6. How long we keep it
We keep your account and shoebox for as long as your account is active. When you delete your account, we delete your personal data from our active systems. We may retain a limited amount of information where the law requires it, or in anonymised form that can no longer identify you (such as the aggregated patterns in section 4).
7. Your rights & choices
Wherever you live, you can access, correct, export or delete your information. Most of this is built right into the app — edit your profile any time, and delete your account in one step (see section 8). For anything else, email support@shoe-box.app and we'll help.
If you're in the EEA or the UK (GDPR)
You have the right to access, rectify, erase, restrict or object to processing, and to data portability, plus the right to withdraw consent and to lodge a complaint with your local data protection authority.
If you're in California (CCPA/CPRA)
You have the right to know what we collect, to access and delete it, to correct it, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information for cross-context behavioural advertising, and we will never discriminate against you for exercising your rights.
If you're in Bahrain
We handle personal data in line with Bahrain's Personal Data Protection Law (Law No. 30 of 2018), including your rights to access and correct your data and to object to processing.
8. Deleting your data
You're always in control of your shoebox:
- In the app: go to Profile → Delete account. This permanently removes your profile and every shoe you've logged.
- By email: if you can't access the app, write to support@shoe-box.app from your account email and we'll delete your data for you.
More detail is on our Support page.
9. International data transfers
We and our providers operate on cloud infrastructure that may be located outside your country, including outside Bahrain, the EEA or the UK. Where personal data is transferred internationally, we rely on appropriate safeguards — such as standard contractual clauses — to protect it.
10. Children
Shoe Box is not directed to children under 13 (or under 16 where required by local law), and we don't knowingly collect their data. If you believe a child has provided us information, contact us and we'll remove it.
11. Security
We protect your data with encryption in transit, passwordless authentication, and strict per-user database access rules so that one account can never read another's shoebox. No system is perfectly secure, but we take reasonable, industry-standard measures to keep your information safe.
12. Changes to this policy
We may update this policy from time to time. When we do, we'll revise the "Last updated" date above, and for material changes we'll provide a more prominent notice in the app or by email.
13. Contact us
Questions, requests, or concerns about your privacy? We read every message.
Shepherd Holding W.L.L — Kingdom of Bahrain
support@shoe-box.app
Need help or want to exercise a privacy right? Email support@shoe-box.app or visit our Support page — we typically reply within 2–3 business days.