Apps Privacy
Last updated: July 2026
This page describes, in general terms, how the Shopify apps built by EcomLabs handle data. Individual apps may have their own policy linked from their page; where they conflict, the app-specific policy prevails.
Data apps access
Our apps request only the Shopify scopes needed for their function. They typically access product data, store content and settings required to operate; the specifics are shown at install time and in each app's policy.
Customer data
Where an app does not need personal customer data, it does not request it. If an app processes customer data, its use, legal basis and retention are detailed in that app's policy.
How data is used
Data is used only to provide the app's function in your store. We do not sell merchant or customer data.
Compliance webhooks
Our public apps implement Shopify's mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact) with HMAC verification, to handle data and deletion requests.
Subprocessors
We may use infrastructure providers and, for AI-assisted apps, model providers that process data on our behalf under appropriate agreements, solely to deliver the app's function.
Retention and deletion
We keep data only while the app is installed or as needed for its function. On uninstall, data is deleted in line with Shopify's redaction requests.
Contact
For questions about app privacy or to exercise your rights, email hola@ecomlabs.dev. Effective date: July 2026.