Terms of Service
Last updated: July 28, 2026
These Terms of Service ("Terms") govern access to and use of the Saleslabz platform, website, applications, and related services (collectively, the "Service") operated by Saleslabz ("Saleslabz," "we," "us," or "our") at https://saleslabz.com.
By creating an account, installing our Shopify app, connecting integrations, or using the Service, you ("Merchant," "you," or "your") agree to these Terms, including the Data Protection Agreement in Section 10 and the Security Incident Response Policy in Section 11. If you use the Service on behalf of a company, you represent that you have authority to bind that company.
1. The Service
Saleslabz is a marketing and commerce operations platform for Shopify merchants and brands. Features may include, depending on your plan and enabled modules:
- Store dashboards, readiness scoring, and health checks
- Marketing calendar, campaigns, events, and tactical planning
- Studio and AI-assisted creative generation
- Shopify store connection, product sync, and publishing
- Instagram, Meta, and Google advertising / social workflows
- Lead funnels, landing pages, blogs, and email capture
- Other optional marketing and commerce tools we make available
We may add, modify, or discontinue features at any time. Beta or experimental features may be offered as-is without warranties.
2. Eligibility and accounts
- You must be at least 18 years old and able to form a binding contract
- You must provide accurate registration information and keep it current
- You are responsible for safeguarding login credentials and all activity under your account
- You must promptly notify us of unauthorized access or security incidents
- Workspace owners may invite staff; the merchant is responsible for their users' compliance with these Terms and applicable data-protection laws
3. Subscriptions, billing, and trials
Paid plans, add-ons, and usage limits are described at checkout or in your account. By subscribing, you authorize us and our payment processors to charge applicable fees on a recurring basis until canceled. Fees are generally non-refundable except where required by law or expressly stated in writing.
We may offer free trials or promotional access. At the end of a trial, continued use may require payment. You may cancel according to the process shown in your account settings; cancellation stops future charges but may not entitle you to a refund for the current billing period unless stated otherwise.
4. Shopify app and third-party integrations
The Service integrates with third-party platforms such as Shopify, Meta/Instagram, and Google. Your use of those integrations is also subject to each third party's terms and policies. You are responsible for obtaining all rights and permissions needed to connect stores and accounts and to process or publish content through the Service.
If you install Saleslabz from the Shopify App Store or otherwise connect a Shopify store, you also agree to the Shopify Terms of Service and applicable Partner Program terms. Installing or continuing to use the Shopify app constitutes acceptance of these Terms, the Data Protection Agreement in Section 10, and the Security Incident Response Policy in Section 11 for Merchant Data processed through the app.
Uninstall is not deletion. Uninstalling the Shopify app is a soft disconnect of the Shopify connection (Shopify access token cleared or disabled) while your Saleslabz workspace may remain during the grace window. Hard wipe of Shopify shop data follows Shopify’s shop/redact request (typically about 48 hours after uninstall if not reinstalled), as described in our Privacy Policy. Meta, Google, calendar, and similar connections may remain until you disconnect them or redact/deletion rules apply.
5. Acceptable use
You agree not to:
- Use the Service for unlawful, deceptive, infringing, or harmful purposes
- Violate platform rules for Shopify, Meta, Instagram, Google, or other connected services
- Upload malware, attempt unauthorized access, or interfere with the Service
- Scrape, reverse engineer, or resell the Service except as expressly permitted
- Send spam or collect personal data without appropriate notices, lawful basis, and consent where required
- Use AI features to generate illegal content or content that violates third-party rights
- Misrepresent your identity or affiliation
We may investigate violations and suspend or terminate access where we reasonably believe these Terms or applicable law have been breached.
6. Your content and data
You retain ownership of content, assets, and data you submit to the Service ("Customer Content"), including store, marketing, and creative materials. You grant Saleslabz a worldwide, non-exclusive license to host, process, transmit, display, and otherwise use Customer Content solely to operate, provide, secure, and improve the Service and as otherwise instructed by you through product features.
You represent that you have all rights necessary for Customer Content and that its use through the Service does not violate law or third-party rights. You are solely responsible for content published to Shopify, Instagram, ads platforms, funnels, blogs, and other destinations, and for privacy notices to your own customers and end users.
7. AI-generated output
AI-assisted features may produce inaccurate, incomplete, or offensive output. You are responsible for reviewing, editing, and approving all generated creatives, copy, and campaigns before publication. Saleslabz does not guarantee that AI output will be error-free, legally compliant, or suitable for your intended use.
8. Intellectual property
The Service, including software, design, branding, documentation, and underlying technology, is owned by Saleslabz or its licensors and is protected by intellectual property laws. These Terms do not grant you any right to our trademarks or brand features except as needed to use the Service in accordance with these Terms.
9. Privacy Policy
Our collection and use of personal information is described in our Privacy Policy, which is incorporated into these Terms by reference. Where there is a conflict between the Privacy Policy and Section 10 regarding processing of Merchant Personal Data on your behalf, Section 10 controls for that processing.
10. Data Protection Agreement (Shopify merchants)
This Section 10 is the Data Protection Agreement ("DPA") between you (the Merchant) and Saleslabz. It applies when you install or use the Saleslabz Shopify app or otherwise instruct us to process personal data from your Shopify store or connected marketing tools on your behalf. By installing the app or continuing to use the Service, you enter into this DPA.
10.1 Roles
- You are the Controller (or "Business") of personal data relating to your store customers, shoppers, and other end users that you process through Shopify and instruct Saleslabz to process ("Merchant Personal Data").
- Saleslabz is the Processor (or "Service Provider") of Merchant Personal Data when we process it solely to provide the Service to you.
- Saleslabz is an independent controller of account, billing, security, and product-improvement data about you and your workspace users, as described in the Privacy Policy.
10.2 Subject matter, nature, and purpose
Saleslabz will process Merchant Personal Data only to provide the Service you enable, including store dashboards and metrics; marketing calendar and campaigns; Studio and creatives; product sync/publishing; Meta/Google advertising workflows; funnels and lead tools you configure; support; and compliance with Shopify mandatory webhooks and applicable law. We will not sell Merchant Personal Data or process it for purposes other than providing the Service, except as required by law or with your documented instructions.
10.3 Types of data and data subjects
Depending on scopes and features you enable, Merchant Personal Data may include:
- Customer and shopper identifiers, names, emails, phone numbers, addresses, and order history
- Checkout, abandoned-checkout, and purchase-related data
- Marketing engagement data (for example form submissions on your funnels, campaign events)
- Other personal data present in Shopify Admin API payloads or connected ad/social APIs that you authorize
Data subjects are typically your customers, prospective customers, and other end users of your store or marketing channels—not Saleslabz’s own employees.
10.4 Merchant responsibilities
- You warrant that you have a lawful basis and all required notices/consents to instruct Saleslabz to process Merchant Personal Data.
- You are responsible for your Shopify store privacy policy, cookie/consent practices, and responses to your customers’ privacy requests, except where Shopify or law requires us to act on a compliance webhook.
- You will not instruct us to process special-category or prohibited data unless the Service expressly supports it and you have a lawful basis.
10.5 Saleslabz obligations as processor
- Process Merchant Personal Data only on your documented instructions (including configuration of the Service and these Terms) unless required by law
- Ensure persons authorized to process Merchant Personal Data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Assist you, taking into account the nature of processing, with data-subject requests and Shopify compliance webhooks (customers/data_request, customers/redact, shop/redact)
- Notify you of a personal-data breach affecting Merchant Personal Data in accordance with Section 11 (Security Incident Response Policy)
- Delete or return Merchant Personal Data at the end of providing Shopify-related services in accordance with Section 10.7 and the Privacy Policy, unless retention is required by law
10.6 Sub-processors
You authorize Saleslabz to engage sub-processors to help deliver the Service (for example hosting, email delivery, payment processing, AI providers, and analytics). We will impose data-protection obligations on sub-processors no less protective than those in this DPA for the services they provide. A current list of material sub-processors is available on request at contact@saleslabz.com. We may update sub-processors as reasonably needed to operate the Service; continued use after notice constitutes acceptance where permitted by law.
10.7 Duration; uninstall vs. deletion
Processing continues for as long as you use the Service and instruct us to process Merchant Personal Data.
- Shopify app uninstall is a soft disconnect: we clear or disable the Shopify access token; your Saleslabz workspace may be retained during the grace window; other integrations (Meta, Google, calendar, etc.) may remain connected unless you disconnect them.
- Hard wipe of Shopify shop data occurs when Shopify sends the shop/redact webhook (commonly ~48 hours after uninstall if the app is not reinstalled)—not on a day-30 schedule and not solely because uninstall was clicked.
- Uninstall ≠ delete. Deletion of Shopify shop/customer data follows Shopify’s redact requests (shop/redact, customers/redact) and related compliance requirements.
- If you want your full Saleslabz workspace deleted outside Shopify’s flow, email contact@saleslabz.com.
10.8 International transfers
Where Merchant Personal Data is transferred internationally, Saleslabz will use appropriate safeguards required by applicable law (such as standard contractual clauses or equivalent mechanisms where applicable).
10.9 Audits and information
Upon reasonable written request, and no more than once per twelve (12) months unless required by a supervisory authority or following a confirmed breach, Saleslabz will provide information reasonably necessary to demonstrate compliance with this DPA. Audits will be limited to avoid compromising security or other customers’ confidentiality, and may be satisfied by security summaries, questionnaires, or third-party reports where available.
10.10 Order of precedence
For processing of Merchant Personal Data, this Section 10 prevails over conflicting terms in the rest of these Terms, except that incident handling and breach notification timelines are governed by Section 11. Nothing in this DPA reduces Shopify’s rights or your obligations under Shopify’s terms or Partner Program requirements.
11. Security Incident Response Policy
This Section 11 is Saleslabz’s Security Incident Response Policy ("SIRP"). It explains how our team detects, responds to, and communicates about security incidents and data breaches affecting the Service, including Merchant Data processed through our Shopify app. It is designed to align with Shopify Partner Program obligations and Shopify’s protected-customer-data expectations for apps (severity scales, roles, escalation, evidence handling, and required actions).
11.1 Purpose and scope
The SIRP applies to security events involving Saleslabz systems, credentials, repositories, production infrastructure, employee devices used for the Service, and third-party processors that handle Merchant Data or Merchant Personal Data. Goals: protect merchants and customers; contain and remediate incidents quickly; meet Shopify and legal notification duties; preserve evidence; and improve controls after incidents.
11.2 Definitions
- Security Incident — a suspected or confirmed event that compromises the confidentiality, integrity, or availability of the Service or data we process (for example unauthorized access, malware, credential theft, misconfiguration exposing data, or failed integrity of webhooks/API auth).
- Data Breach / Merchant Data Breach — an actual or suspected breach or compromise of Merchant Data or Merchant Personal Data, including Shopify store or customer data processed by the app.
- Becoming aware — when Saleslabz confirms with reasonable certainty that a Security Incident or Data Breach has occurred (or, for Shopify Partner reporting of suspected compromise of Merchant Data, when we first have credible notice of such an occurrence).
11.3 Severity scale
| Severity | Description | Initial response target | Examples |
|---|---|---|---|
| SEV-1 — Critical | Confirmed or highly likely unauthorized access to Merchant Data / protected customer data, or active exploitation of production | Immediate (≤ 15 minutes after triage) | Stolen Shopify/API tokens in use; production DB exposure; ransomware on production hosts |
| SEV-2 — High | High likelihood of exploitation or limited confirmed data exposure | ≤ 1 hour | Leaked secret with possible access; critical unpatched CVE on an internet-facing system; webhook signature validation failure at scale |
| SEV-3 — Medium | Vulnerability or anomaly with lower likelihood; no confirmed Merchant Data exposure | ≤ 24 hours | Misconfigured permissions; dependency CVE without known exploit; suspicious but inconclusive login alerts |
| SEV-4 — Low | Informational / best-practice gap | ≤ 7 days | Logging gaps; hardening improvements; documentation updates |
Severity may be raised or lowered as investigation proceeds. Any credible Merchant Data Breach is treated as at least SEV-2 until scoped.
11.4 Roles and responsibilities
- Incident Commander — owns the incident lifecycle, severity, escalation, and go/no-go on external notifications
- Technical Lead — investigates root cause, implements containment and remediation, preserves forensic evidence
- Communications Lead — drafts merchant notices; coordinates Shopify Partner reporting; supports regulatory messaging where required
- On-call / engineering — detect, acknowledge, and execute runbooks under the Incident Commander
Contact for security reports and privacy-related breaches: contact@saleslabz.com.
11.5 How we detect incidents
- Application, access, and infrastructure logs and alerts
- Authentication anomalies, failed webhook signature validation, and API abuse signals
- Dependency / vulnerability scanning and hosting provider notices
- Shopify Partner Dashboard alerts or communications from Shopify
- Merchant, researcher, or employee reports (responsible disclosure)
11.6 Response lifecycle (what we do)
- Identify & triage — confirm the event, assign severity and Incident Commander, open an incident record, and freeze careless “cleanup” that would destroy evidence.
- Contain — stop ongoing unauthorized access (revoke/rotate tokens and secrets; disable compromised credentials; isolate affected systems; block malicious traffic; temporarily disable impacted features if needed).
- Eradicate — remove root cause (patch, rebuild, revoke sessions, rotate keys, fix misconfigurations).
- Recover — restore service safely, verify integrity, increase monitoring, and confirm the threat is no longer active.
- Notify — follow Section 11.7 timelines for Shopify, merchants, and authorities as applicable.
- Post-incident review — within a reasonable period after closure, document timeline, root cause, impact, and corrective actions; track remediation to completion.
11.7 Notification timelines (Shopify apps best practice)
- Shopify (Partner Program) — For any actual or suspected breach or compromise of Merchant Data, we notify Shopify immediately and no later than twenty-four (24) hours after becoming aware, via Shopify Partner support / the channels Shopify designates. We then promptly remedy the breach to prevent further loss, investigate, take reasonable steps to mitigate future harm to Shopify, merchants, and customers, and regularly update Shopify and cooperate with follow-up requests—at our own cost, as required by the Shopify Partner Program Agreement.
- Affected merchants — Without undue delay after becoming aware of a personal-data breach affecting your Merchant Personal Data, and using commercially reasonable efforts within seventy-two (72) hours of discovery (sooner for SEV-1), we will notify the affected merchant workspace contacts. Notice will include, to the extent then known: nature of the incident; categories and approximate volume of data/subjects concerned; likely consequences; measures taken or proposed; and a Saleslabz contact point. We will provide updates as facts develop and assist you with your own notification duties where reasonably possible.
- Supervisory authorities / individuals — Where Saleslabz is legally required to notify a regulator or data subjects (or to assist you as controller under the DPA), we will do so within the applicable legal timeframe (for example GDPR’s 72-hour authority notification where it applies to us).
The Shopify 24-hour clock and merchant/legal clocks run in parallel from awareness. We may delay merchant public detail only where legally required (for example law-enforcement direction) or where disclosure would increase risk; we will still meet Shopify Partner reporting duties.
11.8 Evidence and forensics
We preserve relevant logs, access records, configurations, and artifacts for a reasonable period to support investigation, Shopify inquiries, and legal obligations. Staff must not wipe or alter systems under investigation without Incident Commander approval except as needed for immediate containment (with documentation of what changed).
11.9 Merchant cooperation
You agree to promptly report suspected compromise of your Saleslabz credentials or workspace to contact@saleslabz.com, rotate any exposed secrets on your side, and reasonably cooperate with our investigation when your store or staff actions are in scope.
11.10 Testing and improvement
We review this SIRP at least annually and after material SEV-1/SEV-2 incidents. We may run tabletop exercises or technical drills. Updates to this Section 11 follow the change process in Section 16.
12. Disclaimers
To the maximum extent permitted by law, the service is provided "as is" and "as available" without warranties of any kind, whether express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement.
We do not warrant that the Service will be uninterrupted, secure, or error-free, that integrations with third-party platforms will remain available, or that marketing performance, ad delivery, or revenue outcomes will meet your expectations.
13. Limitation of liability
To the maximum extent permitted by law, saleslabz and its affiliates, officers, employees, agents, and suppliers will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for loss of profits, revenue, data, goodwill, or business opportunity, arising out of or related to the service or these terms, even if advised of the possibility of such damages.
Our total liability for any claim arising out of or relating to the service or these terms will not exceed the greater of (a) the amounts you paid to saleslabz for the service in the twelve (12) months before the event giving rise to the claim, or (b) one hundred u.s. dollars (usd $100).
Some jurisdictions do not allow certain limitations, so some of the above may not apply to you. Nothing in these Terms limits liability that cannot be limited under applicable data-protection law.
14. Indemnification
You will defend, indemnify, and hold harmless Saleslabz and its affiliates, officers, employees, and agents from claims, damages, losses, and expenses (including reasonable legal fees) arising from your use of the Service, Customer Content, Merchant Personal Data you instruct us to process, connected integrations, or violation of these Terms or applicable law.
15. Suspension and termination
You may stop using the Service at any time, including by uninstalling the Shopify app (soft disconnect) or requesting workspace deletion. We may suspend or terminate access immediately for cause, including non-payment, security risk, abuse, or legal requirement. Upon termination, your right to use the Service ends. Data handling after uninstall or Shopify redact is governed by Section 10.7 and the Privacy Policy. Provisions that by nature should survive termination will survive, including payment obligations, intellectual property, the DPA and SIRP (to the extent processing or incident obligations continue), disclaimers, limitations of liability, and indemnification.
16. Changes to these Terms
We may update these Terms (including the DPA and SIRP) from time to time. The revised version will be posted at this URL with an updated effective date. Continued use after changes become effective constitutes acceptance of the revised Terms. If you do not agree, you must stop using the Service and uninstall the Shopify app.
17. Governing law and disputes
These Terms are governed by the laws applicable to Saleslabz's place of establishment, without regard to conflict-of-law rules, except where mandatory consumer or data-protection laws in your jurisdiction provide otherwise. Courts located in that jurisdiction will have exclusive jurisdiction over disputes arising from these Terms or the Service, unless applicable law requires a different forum.
18. Contact
Questions about these Terms, the DPA, or the Security Incident Response Policy:
- Saleslabz
- Email: contact@saleslabz.com
- Website: https://saleslabz.com
- Terms URL: https://saleslabz.com/page/terms-of-service