Security
This page describes how The RetailLAB stores and protects your data. Full detail is in our Privacy Policy.
Two Separate Systems
The RetailLAB runs two databases that are not connected to one another.
The Shopify App database holds data from stores that have installed our app: product catalog, inventory levels and order history. This is your private data. It is used only to produce your own reporting, and it is never exposed to any other merchant in any form.
The Insight Tool database powers our market reporting. It holds no sales, order, customer or inventory-quantity data from any source. It is built entirely from publicly available product information.
Because the two systems are separate, the database that produces market reporting has never held sales data from anyone, and structurally cannot.
Data Protection
Data is encrypted at rest using AES-256, and in transit using TLS 1.2 or higher. Access to production systems is restricted.
Infrastructure
Our databases run on managed PostgreSQL on US-based infrastructure. The application reaches them over a private network, and connections from outside that network are limited to addresses we have approved for administration. Backups are automated daily.
The RetailLAB Shopify app has been reviewed and approved by Shopify, which includes their security and data handling requirements for public apps.
What We Use Today
When you install the app, Shopify's permission screen lists everything Shopify has approved The RetailLAB to access. We keep those permissions as approved, and we want to be plain about what we actually use today.
The RetailLAB reads your product catalog, inventory levels, orders (order number, dates, line items and refunds) and sales totals.
At this time, The RetailLAB does not:
- Request or store your customers' names, email addresses, phone numbers, addresses or IP addresses
- Request your store owner's or staff's details from Shopify
- Change any product, inventory or order data in your store
- Install any script, tag or cookie on your storefront
Shopify's permission screen lists customer contact details because Shopify requires that approval for any app that reads Shopify's own sales and inventory reports, which The RetailLAB does. We do not request or store those details.
An earlier version of the app used a storefront tag to measure product page traffic. That tag was retired in October 2026.
Planned Next (Not Active Yet)
Stock changes and receipts. The RetailLAB will read your store's record of stock changes: units received, returned to stock and corrected, by product and variant, with the date and the reason. Where you use Shopify purchase orders and shipments, it will also read the supplier name, units ordered, unit cost, and expected and received dates. It does not read staff names. This is not active yet. You will be asked to approve it in Shopify before any of it is read.
A Shared Workspace
The RetailLAB is a shared service. Your team and ours share one workspace in The RetailLAB: your people can sign in whenever they like, and our team signs in alongside them to run the reports, read the results and bring you recommendations.
- We see what you see. Our team has the same view of your data inside The RetailLAB that your own users have.
- We work inside The RetailLAB, not inside your store. We do not sign in to your Shopify admin.
- Access on our side is limited to the people who deliver the service to you, for as long as you use The RetailLAB.
- Each time our team opens your workspace through our admin tools, it is recorded with the date and time.
Third Parties
We rely on a small number of infrastructure and service providers to run The RetailLAB. Each is named individually in our Privacy Policy, along with what it receives.
Development work is performed under a confidentiality agreement. Production access is restricted.
How We Use AI
We use AI in two places: the AI Insights feature inside The RetailLAB, and tools our team uses to prepare and check your reports. Our AI provider is named in our Privacy Policy.
- It sees figures, not people. The AI receives store metrics and product-level sales, inventory and cost figures. No customer records, and nothing personally identifiable.
- Your figures do not train AI models. We do not allow our AI provider to use your data to train its models.
- Your figures stay with your account. Each merchant has its own separate project in our AI provider account. One merchant's figures are never shown to another merchant or used in another merchant's reports.
- When you uninstall, we delete your project along with your store data.
Retention and Deletion
Sales history, inventory snapshots and stockout history are retained for as long as the app is installed.
When a merchant uninstalls the app, Shopify issues a redaction webhook and all store data is permanently deleted within 48 hours. Deletion can also be requested directly at any time.
Security Incidents
In the event of a confirmed security incident affecting your data, we will notify you without undue delay and in any case within 72 hours of becoming aware, including what is known about the scope and what is being done about it.
Privacy Rights
We honor access, correction and deletion requests under CCPA, CPRA and comparable US state privacy frameworks. A data processing agreement is available on request.
Reporting Issues
If you discover a security vulnerability, please report it responsibly through our contact page.