Privacy Policy
Last updated: July 28, 2026
Saleslabz ("Saleslabz," "we," "us," or "our") operates the website at https://saleslabz.com and related applications, including our Shopify app. This Privacy Policy explains what information we collect from merchants and other users, how we use it, how we handle Google user data obtained through Google APIs, and how Shopify uninstall and data-deletion events are handled.
By creating an account, installing our Shopify app, connecting a store or advertising/social account, or otherwise using the Service, you agree to the practices described in this Privacy Policy.
1. Who this policy applies to
This policy applies to:
- Merchants who install the Saleslabz Shopify app or register a Saleslabz workspace ("Merchants")
- Staff and team members invited to a merchant workspace
- Visitors to our marketing website, blog, landing pages, and funnel pages
Saleslabz is a business-to-business platform. We do not knowingly offer the Service to children under 16.
2. Information we collect from merchants (explicit list)
For merchants using Saleslabz, we collect and process the categories of data below. What we receive depends on the features and integrations you enable and the permissions you grant.
2.1 Account and workspace information
- Name, email address, phone number (if provided)
- Password (stored in hashed form)
- Company / workspace name, language preferences, role and permissions
- Login history and basic security/audit events
How we use it: create and administer your account, authenticate users, manage access within your workspace, and communicate about the Service.
2.2 Shopify store data
When you install or connect our Shopify app, we receive data authorized through Shopify OAuth, which may include:
- Shop domain, shop name, shop ID, and store metadata
- OAuth access tokens (and related token metadata) and granted API scopes
- Products, variants, collections, inventory, media/files, and theme-related information needed for connected features
- Orders, line items, and sales metrics used for dashboards, reporting, and optimization features you enable
- Customer records and related identifiers only where required for features you enable (for example sync or recovery workflows)
- Discounts, promotions, and checkout/abandoned-checkout data when those features are enabled
How we use it: operate store dashboards and readiness/health checks; power marketing calendar and campaign planning; sync or publish product/creative content; run analytics and ad-optimization workflows you enable; and comply with Shopify partner and legal requirements (including mandatory webhooks).
2.3 Meta / Instagram data
- Instagram Business/Creator or Facebook Page identifiers, username, and page name
- OAuth access tokens and connection status
- Posts, captions, media URLs, permalinks, comments, and publishing metadata
- Ad account identifiers, campaigns, creatives, and performance metrics when you use Meta Ads features
- Direct messages and contact records when you enable messaging features
How we use it: social publishing, comment/inbox management, insights, and paid media workflows you request.
2.4 Google user data (OAuth / APIs)
Saleslabz lets authorized merchants connect Google accounts so they can use Google Analytics, Google Tag Manager, Google Merchant Center, and Google Ads features inside the Service. We access Google user data only after you complete Google’s OAuth consent screen and only within the scopes you approve.
Depending on the features you enable, those scopes may include:
https://www.googleapis.com/auth/analytics.readonly(Google Analytics read access)https://www.googleapis.com/auth/tagmanager.readonly(Google Tag Manager read access)https://www.googleapis.com/auth/content(Google Merchant Center / Content API)https://www.googleapis.com/auth/adwords(Google Ads)
How we access Google user data:
- Connection data: OAuth access and refresh tokens, Google account or customer identifiers, and the list of Google properties/accounts you authorize (for example GA4 properties, GTM accounts/containers, Merchant Center accounts, and Google Ads customer accounts).
- Google Analytics: property metadata and aggregated performance metrics (such as sessions, users, conversions, and related reports) needed to display analytics in Saleslabz dashboards.
- Google Tag Manager: account/container metadata and tag/trigger/variable configuration visibility needed to help merchants understand and audit their tagging setup.
- Google Merchant Center / Content API: product and feed-related data required to sync, review, or manage catalog/feed workflows you enable in Saleslabz.
- Google Ads: account, campaign, ad group, ad/creative, and performance metrics (and related configuration) needed to connect Ads and manage/report campaigns inside Saleslabz.
- Derived views: dashboards and summaries derived from the above (for example totals, trends, and ROAS-style metrics) shown only inside the authorizing merchant’s workspace.
How we use Google user data:
- Only to provide and improve user-facing features that are prominent in the Saleslabz interface for the merchant who connected Google: analytics visibility, tag/setup checks, Merchant Center/catalog workflows, and Google Ads connection, reporting, and campaign management.
- To authenticate the Google connection, refresh tokens as needed, troubleshoot integration errors, and maintain security of the connection.
- We do not use Google user data for Saleslabz’s own advertising, for serving ads to other users, for creditworthiness or lending decisions, for selling data, or for any purpose unrelated to providing or improving those merchant-facing features.
- We do not use Google user data to train generalized AI/ML models. Any AI-assisted features operate only within the authorizing merchant’s workspace and only to support that merchant’s requested workflows.
How we store Google user data:
- OAuth tokens and related Google connection metadata are stored in our application database with access controls limited to the authorizing merchant’s workspace.
- Google API responses used for dashboards and workflows may be cached or stored temporarily as needed to operate the connected features for that workspace.
- Data in transit is protected using HTTPS/TLS.
How we share / transfer Google user data:
- Google user data is processed in the authorizing merchant’s Saleslabz workspace and may be visible to that merchant’s authorized team members according to workspace permissions.
- Infrastructure and operational subprocessors (for example hosting and database providers) may process data solely to operate the Service, under contractual and technical controls.
- We do not sell Google user data. We do not transfer Google user data to data brokers, advertising networks, or independent third parties for their own marketing or unrelated purposes.
- Transfers are limited to: providing or improving the user-facing features you enable; security investigations; compliance with law; or a merger/acquisition/sale of assets with appropriate notice/consent where required.
- Saleslabz staff do not read Google user data except where necessary for security, compliance with law, or with the merchant’s affirmative agreement for support troubleshooting of specific issues.
How we protect Google user data:
- Workspace-scoped access controls for tokens and connected account data.
- Administrative and technical controls that restrict staff access to production systems on a need-to-know basis.
- Merchants can disconnect Google integrations in the product, which stops further Google API access using that connection.
Retention and deletion of Google user data:
- Google connection tokens and related Google data are retained while the Google integration remains connected and the workspace is active, or as needed to provide the Service and meet legal/security obligations.
- When you disconnect Google in Saleslabz, we stop using that connection for API calls and remove or invalidate stored Google OAuth tokens for that workspace as part of normal disconnect handling.
- To request deletion of your Saleslabz workspace (including Google connection data where applicable), email contact@saleslabz.com. Shopify compliance redaction flows are described in Sections 4 and 7.
- Additional deletion instructions for connected platforms are summarized at https://saleslabz.com/page/data-deletion.
Limited Use compliance: Saleslabz’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data (including aggregated, anonymized, or derived data obtained through Google APIs) is used only to provide or improve user-facing features that are prominent in the Saleslabz interface for the authorizing merchant, and not for any prohibited Limited Use purpose.
2.5 Marketing calendar, campaigns, and creative content
- Marketing plans, calendar entries, campaigns, tasks, and events you create
- Emailer / social activation settings and related content drafts
- Studio prompts, uploaded assets, brand kits, generated creatives, and related metadata
- Media library files you upload or generate
How we use it: provide Marketing Plan, Marketing Calendar, Activation, Studio, and Media Library features for your workspace.
2.6 Products, funnels, blogs, and lead capture
- Product/offer catalog entries you create in Saleslabz
- Landing pages, funnel configuration, and tracking events
- Lead emails and form fields submitted on your funnels or landing pages
- Blog posts and related publishing metadata
How we use it: host and operate your offers, landing pages, content, and lead pipeline inside your workspace. Merchants remain responsible for their own notices to end customers whose data they collect through those tools.
2.7 Billing and support
- Subscription plan, billing status, and limited payment metadata from processors such as Stripe or PayPal (card details are typically handled by the processor)
- Support tickets, chat transcripts, and emails you send to us
How we use it: process subscriptions, invoices, credits, and customer support.
2.8 Website visitors and cookies
- IP address, browser/device information, referring URLs
- Pages viewed, session timestamps, and interaction events
- Emails or form fields voluntarily submitted on Saleslabz marketing pages
- Cookies and similar technologies for authentication, security, preferences, and optional analytics/marketing where consented
How we use it: operate our website, measure performance, secure the Service, and (where applicable) follow up on demo or lead requests.
3. Summary of how we use merchant data
- Provide, operate, maintain, and improve the Service
- Authenticate users and enforce account security
- Connect and operate Shopify, Meta/Instagram, Google, calendar, and other integrations you authorize
- Generate, schedule, publish, and analyze marketing content and ads
- Process subscriptions, invoices, and account administration
- Send service, security, and product communications
- Provide customer support and troubleshoot issues
- Comply with legal obligations and Shopify/Meta/Google partner requirements
- Detect, prevent, and address fraud, abuse, or security incidents
We do not sell merchant personal information.
4. Shopify uninstall vs. deletion (important)
Uninstalling the Saleslabz Shopify app is not the same as deleting your Saleslabz account or workspace.
4.1 App uninstall = soft disconnect
When a merchant uninstalls the Saleslabz Shopify app:
- We treat the event as a soft disconnect of the Shopify store connection.
- Your Saleslabz workspace is kept (plans, calendar, creatives, funnels, settings, and other non-Shopify workspace data remain available during the grace window described below).
- Your Shopify access token is cleared or disabled so Saleslabz can no longer call the Shopify Admin API for that shop until you reinstall and reconnect.
- Other connected services such as Meta/Instagram, Google, calendar, email platforms, and similar integrations may remain connected during the grace window unless you disconnect them separately or a hard wipe is triggered.
4.2 Hard wipe follows Shopify’s shop/redact request (~48 hours)
Shopify—not the uninstall click alone—controls when a shop’s data must be fully removed from an app. After uninstall, Shopify typically sends a mandatory shop/redact webhook (commonly about 48 hours later if the app is not reinstalled). When we receive Shopify’s shop/redact request:
- We perform a hard wipe of Shopify-related shop data associated with that store connection as required by Shopify’s compliance program.
- This hard wipe is triggered by Shopify’s redact webhook, not by a day-30 timer and not solely by the uninstall event.
- Customer-specific deletion requests are handled when Shopify sends customers/redact (and related compliance webhooks).
4.3 Plain-language rule
- Uninstall ≠ delete. Uninstall soft-disconnects Shopify (token cleared/disabled) while keeping the workspace during the grace window.
- Deletion of Shopify shop data follows Shopify’s redact request (shop/redact), usually about 48 hours after uninstall if you do not reinstall—not at day 30.
- If you reinstall and reconnect before redact, Shopify connection can be restored and the grace window ends without that redact-driven wipe.
If you want your entire Saleslabz workspace deleted outside of Shopify’s compliance flow, contact us at contact@saleslabz.com.
5. Legal bases (EEA, UK, and similar regions)
Where applicable, we process personal data based on: performance of a contract with you; legitimate interests in operating and improving a secure B2B platform; compliance with legal obligations (including Shopify’s mandatory webhooks); and consent where required, such as for non-essential cookies or certain marketing communications.
6. How we share information
We may share information with:
- Service providers that host infrastructure, send email, process payments, provide AI capabilities, or support customer service
- Integration partners such as Shopify, Meta, and Google when you connect those services
- Your team members within the same workspace according to permissions you assign
- Professional advisers or authorities when required by law, court order, or to protect rights and safety
- Successors in connection with a merger, acquisition, or asset sale, subject to this policy
We do not sell personal information. Google user data sharing is further limited as described in Section 2.4. Merchants are responsible for their own privacy notices to their customers when they use Saleslabz to collect leads, run funnels, or publish marketing content.
7. Data retention
We retain workspace information while your account is active or as needed to provide the Service, comply with law, resolve disputes, and enforce agreements. Shopify-related shop data is retained under the uninstall / redact rules in Section 4. Google connection tokens and related Google data follow the retention and disconnect/deletion practices in Section 2.4. Billing records, security logs, and other records may be kept longer where required by law or legitimate business needs.
8. Security
We use administrative, technical, and organizational measures designed to protect information, including access controls, encrypted transport, and hashed credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. International transfers
We may process and store information in countries other than where you are located. Where required, we use appropriate safeguards for cross-border transfers.
10. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to or withdraw consent for certain processing. You can update account details in settings, disconnect integrations, and manage cookies through our consent tools. To exercise rights, contact contact@saleslabz.com. We may verify your request before responding.
If you are an end customer of a merchant using Saleslabz, contact that merchant directly for requests about data they control. Shopify merchants may also use Shopify’s privacy tools; we honor Shopify’s mandatory compliance webhooks (including customers/data_request, customers/redact, and shop/redact).
11. Third-party services
The Service links to or integrates with third-party platforms whose privacy practices are governed by their own policies, including Shopify, Meta/Instagram, Google, and payment providers. Review those policies before connecting an account.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may also be communicated by email or in-product notice where appropriate.
13. Contact us
Questions about this Privacy Policy or our data practices:
- Saleslabz
- Email: contact@saleslabz.com
- Website: https://saleslabz.com
- Policy URL: https://saleslabz.com/page/privacy-policy