Draft for review before publication. Effective date: to be set on publication.
Taylored Labs ("we", "us") builds apps for Shopify merchants. This policy explains what personal data our apps handle, why, and what rights you and your customers have. Each app has an appendix stating exactly what it stores.
Taylored Labs LLC, 809 Theresa Ave, Austin, TX 78703, United States. Contact: support@tayloredlabs.com.
We process data only to provide the app you installed. Our apps access your Shopify store through the permissions you grant at install, and they connect to third-party services you choose to connect (for example QuickBooks Online). We do not sell personal data, and we do not use it for advertising or profiling.
We store your store's domain, the settings you choose in the app, the connection to services you link, and operational logs describing what the app did. Connection credentials (such as OAuth tokens) are encrypted at rest.
Some apps handle order data that includes your customers' names, email addresses and addresses because the app's purpose requires it (for example, posting an order to your accounting system). We keep only what the purpose needs, for as long as it is needed, and we never contact your customers.
Data is encrypted in transit (TLS) and at rest. Access is limited to the people who operate the service, and access to production systems requires multi-factor authentication. We keep a security incident response process and will notify affected merchants without undue delay if a breach affects their data.
We host on Fly.io (application and database) and send transactional email through Amazon Web Services (Amazon SES). Apps that connect to accounting systems exchange data with that provider (Intuit QuickBooks Online) at your instruction.
Depending on where you are, you may have the right to access, correct, delete or export personal data we hold, or to object to its processing. Contact support@tayloredlabs.com and we will respond within 30 days. Merchants remain the controller of their customers' data; we act as a processor on the merchant's instructions.
We will post changes here and, for material changes, notify installed merchants by email.
Restocked stores, for your store only:
Shoppers' addresses are used only to send the restock alert they asked for. They are never sold, aggregated across stores, or emailed for anything else. Every restock email carries a one-click unsubscribe link.
Access logging: every privacy-law webhook the app processes is written to an access log with the store, the resource and the time.
Retention: sign-ups until the shopper unsubscribes, or 12 months after they were notified; delivery log 13 months; webhook payloads 30 days. Customer data requests return the shopper's sign-ups; redaction requests delete them and remove the address from the delivery log. Everything is deleted within 48 hours of uninstalling.