Privacy Policy
Last updated: October 2026
This Privacy Policy applies to merchants and storefront visitors in the United States. For questions, contact mlewis@sustainablesouls.com.
1. Who We Are
The RetailLAB is a Shopify application operated by Sustainable Souls, Inc. (“we,” “us,” or “our”). The RetailLAB calculates how much revenue a store loses when products go out of stock by analyzing the store's sales and inventory history, detecting inventory stockouts, and estimating lost revenue broken down by size, color, or any variant.
2. What Data We Collect
From the Shopify API (with Merchant Authorization)
When a merchant installs The RetailLAB and authorizes access through Shopify's OAuth flow, we access:
- Product catalog: titles, handles, variants, SKUs, prices, images, product types, vendor, collections
- Inventory levels: quantities per variant, unit costs
- Orders: order number, order dates, totals, line items, refunds and returns, across the store's order history
- Sales analytics via ShopifyQL: sales totals by product, vendor, product type and time period
- Store traffic analytics via ShopifyQL: visitor and session counts by device type and day, as totals only
- The store's name
At this time, The RetailLAB does not request customer records from Shopify, and does not request or store customers' names, email addresses, phone numbers, addresses or IP addresses.
What Shopify's Permission Screen Shows
Shopify's install screen lists every permission Shopify has approved for The RetailLAB. We keep those permissions as approved. This is what we use of them today:
- Customer contact details (name, email address, phone number, address): Shopify requires this approval for any app that reads Shopify's own sales and inventory reports, which The RetailLAB does. At this time, The RetailLAB does not request or store these details
- Staff and contributor data (store owner details): at this time, The RetailLAB does not request them from Shopify
- Edit products: at this time, The RetailLAB does not change any product, inventory or order data in a merchant's store
- Locations: at this time, The RetailLAB does not request location details
If our use of any of these changes, this policy will be updated to say so.
Storefront Tracking Script (Retired)
Earlier versions of The RetailLAB installed a tracking script on the merchant's storefront. That script was retired in October 2026. The RetailLAB no longer installs or runs any script on a merchant's storefront, and no longer collects product page views or visitor identifiers. Stores that connect after that date have never had the script.
From Merchants Directly
- Account details for the people who sign in to The RetailLAB: organization name, email address and a hashed password
- Files a merchant chooses to upload, such as sales or inventory spreadsheets
Stock Changes and Receipts (Not Active Yet)
The RetailLAB will read a store's record of stock changes: units received, returned to stock and corrected, by product and variant, with the date and the reason. Where a merchant uses Shopify purchase orders and shipments, it will also read the supplier name, units ordered, unit cost, and expected and received dates. It does not read staff names. This is not active yet. Each merchant will be asked to approve it in Shopify before any of it is read.
3. What We Do NOT Collect
The RetailLAB explicitly does not collect, store, or process:
- No customer names, email addresses, phone numbers, or mailing addresses
- No IP addresses or precise geolocation data
- No device fingerprinting data (screen resolution, installed fonts, plugins)
- No cookies, scripts or browser storage on the merchant's storefront
- No session recordings, mouse movements, hover tracking, scroll tracking, or keystroke data
- No advertising identifiers or cross-site tracking
- No retargeting, remarketing, or behavioral advertising of any kind
- No data sharing with advertising networks or data brokers
4. How We Use Data
All data collected is used exclusively for:
- Calculating estimated lost revenue from out-of-stock products
- Generating inventory analytics reports
- Detecting inventory stockouts, restocks, and receipt events
- Auto-detecting markdown events and identifying backorder products
- Powering AI-driven merchandising insights (Pro tier)
- Computing sell-through percentages, size curves, and demand patterns
- Providing actionable buying recommendations
How We Do NOT Use Data
The RetailLAB does not use merchant or visitor data for:
- Advertising, retargeting, or marketing of any kind
- Selling or licensing data to third parties
- Building consumer profiles for any purpose other than the merchant's own analytics
- Email collection or outreach to the merchant's customers
- Competitive benchmarking that identifies individual merchants
- Training AI models on merchant-identifiable data
A Shared Workspace
The RetailLAB is a shared service. A merchant's team and The RetailLAB team share one workspace in The RetailLAB: the merchant's users can sign in at any time, and The RetailLAB team signs in alongside them to run reports, review results and prepare recommendations for the merchant, with help from AI tools from Anthropic.
- The RetailLAB team sees the same data inside The RetailLAB that the merchant's own users see
- This work happens inside The RetailLAB. We do not sign in to a merchant's Shopify admin
- Access on our side is limited to the people who deliver the service, for as long as the merchant uses The RetailLAB
- Each time The RetailLAB team opens a merchant's workspace through our admin tools, it is recorded with the date and time
5. Data Sharing and Third Parties
The RetailLAB shares merchant data only with the following parties:
| Third Party | Purpose | Data Shared |
|---|---|---|
| Shopify Inc. | Platform provider for OAuth and API access | Store domain, access tokens, API requests |
| Render Services, Inc. | US-based hosting for the application backend and its managed PostgreSQL database | All application data (encrypted at rest and in transit) |
| Vercel Inc. | Frontend hosting and edge delivery | Frontend code only; no merchant data persisted |
| Anthropic, PBC | AI Insights feature (Pro tier), and AI tools The RetailLAB team uses to prepare and check reports. The only AI provider that receives data from a connected store | Store metrics and product-level sales, inventory and cost figures. No customer data. We do not allow Anthropic to use this data to train its models. |
| OpenAI | Competitor, product-matching and advertising analysis in The RetailLAB's lead-report tools | Publicly available website and product-listing information. No data from a connected store. |
| SearchAPI | Web and advertising-library search used by the same lead-report tools | Search terms such as brand and competitor names. No data from a connected store. |
| Stripe, Inc. | Subscription billing | Account email address, organization name, and the payment details a merchant enters at checkout |
| Resend and Postmark | Sending email from The RetailLAB, from retailishard.ai addresses | Recipient email address, organization name, store address, and the contents of the email, which can include reports. No customer data |
We do not sell, rent, license, or share merchant or visitor data with advertising networks, data brokers, or analytics aggregators.
6. Data Storage and Security
- Managed PostgreSQL on US-based Render infrastructure, reached by the application over a private network. Connections from outside that network are limited to addresses approved for administration
- When The RetailLAB team uses Anthropic's AI tools to prepare or check a report, the figures reviewed are also kept in our Anthropic account, in a separate project for each merchant. One merchant's figures are never shown to another merchant or used in another merchant's reports
- Frontend hosted on Vercel; it stores no merchant data and reads and writes data only through the authenticated backend API
- Encrypted at rest (AES-256) and in transit (TLS 1.2+)
- Multi-tenant architecture with logical data isolation per store
- Access is by invitation only: accounts are created by The RetailLAB, and a store is connected through an invitation link issued to that account
- OAuth tokens are stored in the encrypted database and never exposed to the client
- Daily automated backups with point-in-time recovery
- The RetailLAB has not completed a SOC 2 audit. Our hosting providers, Render and Vercel, each hold SOC 2 Type 2 attestations
7. Data Retention and Deletion
Active merchants: Data retained for as long as the app is installed. Inventory snapshots and stockout history are retained permanently for seasonal planning.
After uninstall: Upon receiving Shopify's shop/redact webhook, ALL store data is permanently deleted within 48 hours. This is irreversible.
Visitor data: The RetailLAB does not collect data from visitors to a merchant's storefront.
8. Your Privacy Rights (US State Laws)
The RetailLAB respects privacy rights under CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, and other state laws effective through 2026. You have the right to know what personal information we collect, request access, request deletion, opt out of sale/sharing (note: we do not sell data), and not be discriminated against for exercising your rights.
To exercise any right, contact mlewis@sustainablesouls.com. We respond within 45 days as required by law.
9. Do Not Track Disclosure
The RetailLAB does not run a tracking script on merchant storefronts. We do not track visitors across third-party websites or serve advertising. The Do Not Track signal therefore does not change our data practices.
10. Children's Privacy
The RetailLAB is a business-to-business application. We do not knowingly collect personal information from children under 13. The RetailLAB does not collect data from storefront visitors.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be notified via email and/or dashboard notice. Continued use after changes constitutes acceptance.