LabelRun — Privacy policy
LabelRun is a Shopify app that prints barcode and price labels for the products of the store that installed it. This page says exactly what the app stores, what it never stores, how long it keeps it, and who else processes it.
“We”, below, is the individual developer who publishes LabelRun; the contact address is at the bottom of this page.
What LabelRun stores
Only what the app needs to render a label sheet and to apply the plan limits. All of it is store data, none of it is data about your shoppers.
- Your store’s .myshopify.com domain, its display name, and the access token Shopify issues when you install the app — this is what lets the app read your catalogue on your behalf.
- Your label templates: the name, the sheet or roll geometry, which fields are printed and where, the printer calibration offsets, and — if you add one — the logo image you upload (PNG or JPEG, 200 KB maximum), stored inside the template.
- Your app settings: default template, default quantity rule, default location, internal EAN prefix, the store’s language and currency format, and the plan your store is on (read from Shopify, cached).
- Print counts: how many labels the store printed in the current month, and one row per print run holding the date, whether it came from products or from an inventory transfer, the transfer’s Shopify id if it did, which template and quantity rule were used, and the number of labels.
- Barcode runs: when the app generates barcodes for variants that have none, it records which variant got which code, so that the run can be undone. The Undo button acts on runs from the last 30 days.
What LabelRun never stores
- No customer personal data. LabelRun does not request the customer or order access scopes, so it cannot read your customers’ names, addresses, emails, phone numbers or orders — and it holds no customer records of any kind.
- No payment data. Billing is handled entirely by Shopify; the app never sees a card, and never charges you itself.
- No copy of your catalogue. Product titles, SKUs, barcodes, prices and stock levels are read from Shopify each time you print and are turned into a PDF in your own browser. They are not written to the app’s database.
- No analytics, no advertising trackers, no third-party scripts on the pages the app serves.
Where the PDF is made
Label rendering happens entirely in your browser. The server sends the rows to your admin session and the PDF is built locally, so the label file itself never exists on our infrastructure and is never stored anywhere.
How long it is kept, and how it is deleted
- Uninstalling the app deletes your store’s access token and session immediately (Shopify’s app/uninstalled webhook).
- 48 hours after the uninstall, Shopify sends a shop/redact request. LabelRun then deletes everything else it holds for the store: templates (including any logo), print counters, print history, barcode runs, and the store row itself.
- Nothing else expires on a timer: print history and barcode-run records are kept for as long as the app is installed, and go with the rest at redaction.
- A customers/data_request or customers/redact request is acknowledged and nothing is returned or deleted, because there is no customer data to return or delete.
- Want it gone sooner? Uninstall the app and email the address below; the same deletion is run on request.
Who else processes the data
There is no one else. LabelRun does not sell, rent or share your data, and no other third party receives it.
- Shopify Inc. — the platform the data comes from and the one that hosts your admin, handles billing and delivers the app to you.
- Cloudflare, Inc. — the app runs on Cloudflare Workers and stores the data listed above in Cloudflare D1.
Where data is stored
The database is created with Cloudflare's Western Europe location hint; Cloudflare may serve reads from other regions. Shopify data is processed by Shopify under its own policy.
Cookies and session
LabelRun sets no cookies of its own in the embedded app; the admin session is authenticated with Shopify's App Bridge session token on each request. The public pages, including this one, set no cookies.
Security
Every request from the Shopify admin is authenticated by Shopify before the app answers it, all traffic is over HTTPS, incoming webhooks are verified by HMAC signature, and each store can only ever read and write its own rows.
Your rights
As the merchant, you can obtain a copy of everything the app holds for your store, have it corrected, or have it deleted, by writing to the address below. Because the app holds no data about your shoppers, a request on their behalf is answered by Shopify, not by LabelRun.
Changes to this policy
If this policy changes, the date at the top of the page changes with it. Material changes are announced in the app’s listing.
Contact
Questions about this policy, or a data request: soheyb.alouach.dev@gmail.com