Effective date: April 14, 2026
Last updated: April 14, 2026
This Privacy Policy explains how NeatoLabs LLC (“NeatoLabs,” “we,” “us”) collects, uses, and discloses information in connection with the Neatolabs Customizer application (the “App”) we make available through the Shopify App Store.
NeatoLabs LLC
4420 E Miraloma Ave, Anaheim, CA 92807, USA
Contact for privacy inquiries: support@neatolabs.io
When a merchant installs and uses the App, we receive or process the following categories of data from the merchant’s Shopify store:
orders/create, orders/paid, orders/fulfilled, and refunds/create include fields such as the customer’s name, email, and shipping address, the App ignores and does not persist those fields. We do not request access to customer account data and do not have a read_customers scope.We do not use merchant or customer data for advertising, profiling, or resale. We do not sell personal information.
We disclose data only to the following categories of recipients:
We do not share data with advertising networks, data brokers, or other third parties not listed above.
We retain merchant store data and associated order/customer data for 90 days after the App is uninstalled. After 90 days the data is deleted from our active systems. Backups in which the data may persist are rotated according to the retention schedule of the relevant infrastructure provider and are not used for any active processing. A merchant may request earlier deletion at any time by emailing support@neatolabs.io.
The App subscribes to the three compliance webhooks Shopify requires:
customers/data_request — when a store customer requests a copy of their personal data through Shopify, Shopify forwards the request to the App. Because the App does not store customer personal information (see Section 2), we have no customer PII to export. We acknowledge the request and confirm this to the merchant within 30 days.customers/redact — Shopify notifies us when a customer has exercised their right to erasure. Because the App does not store customer personal information, there is no customer PII to delete; we acknowledge the request.shop/redact — 48 hours after a merchant uninstalls the App, Shopify fires this webhook. We use it to schedule deletion of all store data associated with that shop, completed within the retention window described in Section 5.The App’s servers and databases are located in the United States. If you are accessing the App from outside the United States, your data may be transferred to, stored, and processed in the United States. We rely on the European Commission’s Standard Contractual Clauses and equivalent mechanisms where applicable.
We protect data in transit using TLS and at rest using provider-managed encryption (Google Cloud SQL). Access to production data is limited to authorized NeatoLabs personnel who need it to operate or support the App. OAuth tokens are stored encrypted in our database and are revoked when a merchant uninstalls the App.
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data, or to object to or restrict certain processing. Merchants and customers may exercise these rights by emailing support@neatolabs.io. We respond within 30 days. Customers of a merchant’s store should, where possible, submit these requests through the merchant’s own customer support so that Shopify’s compliance webhook flow is triggered.
The App is not directed to children under 13. We do not knowingly collect personal data from children.
We may update this Privacy Policy to reflect changes in the App, our practices, or applicable law. When we make material changes we will update the “Last updated” date at the top of this page and, where required, notify merchants through the App or by email.
Questions, concerns, or data subject requests:
NeatoLabs LLC
4420 E Miraloma Ave, Anaheim, CA 92807, USA
Email: support@neatolabs.io