Privacy Policy
Last updated: 9 September 2026
This Privacy Policy describes how Product Labels (“the App”) collects and uses information when a merchant installs and uses the App on a Shopify store. The App is developed independently by Qasim Malik.
Who this policy covers
This policy applies to Shopify merchants and staff who install or use Product Labels. It does not apply to shoppers on a merchant’s storefront. The App does not collect personal information from storefront customers.
Information we collect
When you install and use the App, we may store:
- Shop identifiers such as your Shopify shop domain, provided by Shopify during OAuth.
- Authentication data including access tokens and session details needed to keep the App connected to your store.
- Merchant account details that Shopify may provide during authentication, such as name or email of the installing staff account, when available.
- App settings you choose in the App, including badge design, colors, size, layout, optional custom CSS, and your selected plan.
- Billing status from Shopify Billing, such as plan name, subscription ID, and subscription status. We do not receive or store card numbers. Payments are processed by Shopify.
Product badge text (Product Label 1, 2, and 3) is saved as Shopify product metafields on your store. Shop-wide style settings may also be stored as a shop metafield. That content lives on Shopify, not as a separate customer database on our side.
Information we do not collect
- Storefront customer names, emails, addresses, or order data.
- Payment card details.
- Analytics or advertising cookies on the merchant or storefront beyond what Shopify itself provides.
How we use information
We use this information only to:
- Authenticate the App and keep it installed on your shop.
- Save and display your label settings.
- Render product badges on your storefront via the App proxy.
- Provide billing plans and a trial through Shopify Billing.
- Respond to support requests you send us.
We do not sell merchant or customer data.
Storefront behaviour
On the storefront, a small script may keep label text in the shopper’s browser sessionStorage for a short time so product cards can show badges quickly. That data stays on the shopper’s device and is not sent to us as a personal profile.
Service providers
We use:
- Shopify for authentication, metafields, webhooks, and billing.
- Railway to host the App and its PostgreSQL database.
These providers process data only as needed to run the App. Shopify’s own policies also apply to data on the Shopify platform.
Data retention and deletion
We keep shop sessions and settings while the App is installed. When you uninstall Product Labels, we delete the stored Shopify session and the App’s shop settings for that store.
Metafields on your products and shop are owned by your Shopify store. Uninstalling the App may leave those metafields in place until you remove them in Shopify.
You can also email us to request deletion of App data we hold for your shop.
Security
Access tokens and shop data are stored on our hosted database and transmitted over HTTPS. We take reasonable steps to protect this information, but no method of transmission or storage is completely secure.
Children
The App is intended for business use by Shopify merchants. It is not directed at children.
Changes
We may update this policy from time to time. The “Last updated” date at the top of this page will change when we do. The current version is always published at this URL.
Contact
For privacy questions or data requests, contact the developer:
- Qasim Malik
- Email: qasimmlk097@gmail.com
- WhatsApp: +92 414 5098262