Legal
Privacy policy
Last updated: August 6, 2026
LabelKit is a Shopify app built and operated by Creatix, LLC. This policy covers the LabelKit app installed on a Shopify store and this website, labelkit.app. Questions about anything here go to info@creatix.io.
The short version
LabelKit reads your Shopify product catalog and stores the nutrition label content you enter. It does not read your orders, your customers, or any buyer personal data. Everything is stored in the United States. When you uninstall the app, your data is deleted.
What the app collects
From your Shopify store
- Your shop domain (for example your-store.myshopify.com). Every record we store is scoped to it.
- The Shopify access token issued when you install the app, used to call the Shopify Admin API on your behalf.
- A mirror of your product and variant catalog: Shopify IDs, product and variant titles, SKUs, and product status. This is what lets the app list your products and attach a label to the right variant.
- Your plan and subscription state, including the Shopify subscription ID, so plan limits can be enforced.
From you
- Label content you enter: serving size and servings per container, nutrient values, ingredient lists, and allergen statements.
- Draft and published versions of each label, so you can see what is currently live on your store.
Permissions the app asks for
LabelKit requests two Shopify access scopes and nothing else: read_products to read your catalog and variants, and write_products to publish label data back to your products as metafields.
What the app does not collect
- No buyer or customer personal data. LabelKit has no access to orders, customers, checkout, or shipping information.
- We do not request access to Shopify protected customer data.
- We do not receive or store payment card details. App subscriptions are billed by Shopify.
- We do not sell your data, and we do not share it with advertisers.
Why we collect it
- To show your products and variants inside the app and attach labels to them.
- To generate FDA-format Nutrition Facts panels and print-ready PDF exports.
- To publish label data to your store as product and variant metafields when you press Publish.
- To enforce plan limits and process your subscription.
- To answer your support requests.
- To understand aggregate product usage (which features get used, where merchants get stuck) so the app can be improved.
Where it is stored, and who processes it
LabelKit data is stored and processed in the United States. If your store is outside the United States, using LabelKit means your data is transferred there. These are the subprocessors involved:
- Shopify. The platform your store runs on. It is the source of the product data we read and the destination of the label metafields we publish.
- Supabase. The Postgres database holding shop records, the product mirror, and your label content. Hosted in the us-west-1 region (United States).
- Vercel. Hosting for the app and for this website, served from the sfo1 region (United States).
- PostHog. Product analytics, US cloud. The app sends events such as install, label published, PDF exported, and plan changed. Events are identified by shop domain, never by a buyer or an individual.
- Postmark. Transactional email, used only for the early-access list on this website.
This website
If you join the early-access list on labelkit.app, we collect your email address, and optionally your first name and what kind of store you run. That goes into the same Supabase database, and Postmark sends you a confirmation email and notifies us of the signup. We use it to email you about LabelKit. Ask us at info@creatix.io and we will remove you.
The website also uses PostHog to count page views, which sets a cookie in your browser to recognize return visits. There are no advertising trackers on this site.
Retention and deletion
- While LabelKit is installed, we keep your shop record, the product mirror, and your label content so the app works.
- When you uninstall, the app deletes your Shopify access tokens immediately.
- Shopify then sends a shop redaction request (normally about 48 hours after uninstall). On receiving it, we hard-delete every record we hold for your shop: labels, variants, products, sessions, and the shop record itself.
- Early-access list entries are kept until you ask to be removed.
- Product analytics events stay in PostHog under its retention settings. They are keyed to a shop domain, not to a named person.
You do not have to wait for an uninstall. Email info@creatix.io from an address associated with the store and we will delete your data on request.
Shopify compliance webhooks
LabelKit implements all three of Shopify's mandatory privacy webhooks on a single verified endpoint in the app:
customers/data_requestis acknowledged. We hold no customer data, so there is nothing to return.customers/redactis acknowledged. There are no customer records to erase.shop/redactdeletes every record we hold for that shop.
Your rights
Wherever you are, you can ask us what we hold about you, ask us to correct it, ask for a copy of it, or ask us to delete it. Email info@creatix.io and include the myshopify.com domain of your store so we can identify the right records. We respond within 30 days.
If you are in the EEA, the UK, or Switzerland
You have the rights to access, rectification, erasure, restriction of processing, data portability, and objection under the GDPR. You can also lodge a complaint with your local supervisory authority. Where LabelKit processes store data on your instructions as the merchant, we act as your processor and follow your deletion requests.
If you are in California
You have the right to know what personal information is collected, to have it deleted, to have it corrected, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA.
Security
The app and this website are served over HTTPS. Label data lives in a database that is closed to public access: only LabelKit's own server-side code holds credentials that can read it, and every query is scoped to a single shop domain. Access tokens are deleted at uninstall rather than kept around.
Changes to this policy
If this policy changes, the revised version is posted on this page with a new last updated date at the top.
Contact
LabelKit is operated by Creatix, LLC. For privacy questions, data requests, or anything else, email info@creatix.io. For product help, see the support page.
Creatix, LLC
1819 Euclid St. Apt D
Santa Monica, CA 90404
United States