Privacy Policy
LabelCraft - barcode labels for Shopify that print at exactly the size you set.
Last updated: August 7, 2026
LabelCraft is a Shopify app that prints barcode labels for your products. This policy explains what data the app handles when you install it on your Shopify store, why, and how to get it deleted. The last section covers the public website at labelcraft.tech, which you can read without installing anything.
Data we store
When you install LabelCraft, we store:
Store information. Your shop’s .myshopify.com domain, subscription plan, monthly label usage count, and app settings (default quantities, GS1 prefix, your declared printer brand and model, and any printer calibration offsets).
Printer connection and station settings. If you connect a printer through PrintNode, we store the PrintNode API key you paste, the printer you pick, and its name, so the app can send jobs to it. That key is used server-side only to talk to PrintNode and is never sent back to your browser. If you set up per-location print stations, we also store, for each Shopify location, the label template and the copies rule that station last used. Both live in the same app settings record as your store information above.
Product data snapshots. Label templates you create and your print job history, which includes the product details printed on labels (titles, variants, SKUs, prices, barcodes). Product data is read from Shopify’s API only to render your labels.
Staff account details. Shopify’s app authentication shares the installing staff member’s name, email address, and locale with us as part of the login session.
Data we do NOT collect
LabelCraft never reads, processes, or stores your customers’ personal data. No customer names, emails, addresses, orders, or payment information - the app only works with your product catalog.
Order and return access
Two features - printing labels straight from an order, and relabeling a return - need Shopify’s read_orders and read_returns permissions. These are optional: the base install asks only for your products and inventory. You grant order or return access in-context, only when you open those pages, and you can revoke each permission from the page that uses it: order access on “Order labels”, return access on “Returns to label”. Relabeling a return needs BOTH, because in Shopify a return belongs to an order, so “Returns to label” asks for both and “Order labels” is where the order permission is turned off again.
When granted, we read only the label fields. From each order or return line we read the product and variant details needed to print a label - title, variant, SKU, barcode, price, compare-at price, vendor, and weight - plus the quantity (and, for a return, the restocked quantity and the return's status) and the order or return number and date.
We never read customer identity. No customer name, email, phone number, or shipping or billing address is ever requested, read, or stored. Shopify’s install screen names a broad order data category, but LabelCraft selects only the product lines inside an order - never the shopper. See Data we do NOT collect above.
Read live, not stockpiled. Order and return data is read at the moment you print. Nothing from it is kept except the product details and the order or return number saved in your print-job history, so you can reprint the same label (see Data we store).
Hosted in the EU, erased on uninstall. These reads run on our EU servers (see Where data lives) and, like all of your data, are purged when you uninstall (see Data retention and deletion).
How we use data
Solely to provide the service: rendering label PDFs, remembering your templates and settings, enforcing plan quotas, and responding to support requests. We do not sell data, share it with third parties for marketing, or use it for advertising.
Where data lives
Our servers and database are hosted on Fly.io in Paris, France (European Union). All traffic between your browser, Shopify, and LabelCraft is encrypted with TLS.
One outbound exception, only if you set it up. If you connect a printer through PrintNode, the finished label is sent to PrintNode’s service so it can reach your printer. That means the label’s own content - whatever your template prints, such as titles, SKUs, prices, and barcodes - leaves our EU servers for PrintNode, outside the EU, for as long as it takes them to deliver the job. Nothing is sent there unless you have saved a PrintNode key and chosen a printer, and disconnecting PrintNode in Settings stops it.
Data retention and deletion
When you uninstall LabelCraft, Shopify sends us a deletion request and we purge all of your store’s data - templates, print history, settings (including any PrintNode key you saved), and login sessions. We run that purge once Shopify confirms the uninstall to us, which Shopify’s data protection terms put at 48 hours; the confirmation is Shopify’s to send, so it can occasionally reach us later than that.
Four narrow records outlive that purge, and nothing else does. Two are markers, each one line: if your store started a Pro free trial we keep your .myshopify.com domain with the date the trial was used, and if your store uninstalled while we still had it recorded as installed we keep the domain with the date the install was first announced. They exist to stop one store taking an endless run of free trials by reinstalling, and to stop a returning store being announced as brand new. The third is a churn record, written once when a store uninstalls: how long the install lasted, which setup steps it reached, how many templates, presets, print jobs and labels there were, and which warning codes came up. It is stored under a shortened one-way hash of your domain rather than the domain itself - a pseudonym, not full anonymisation - and it holds no product, order, customer or staff data and no label content. We keep it to understand why stores leave. The fourth is an opt-out list: if anyone asks us to stop emailing an address, we keep that address so we can honour it. It outlives your store on purpose, because a request to be left alone that we forget is a request we did not honour.
You can also request deletion or a copy of your data at any time by emailing support@labelcraft.tech.
The labelcraft.tech website
This section is about the public site you are reading, not about the app. Browsing labelcraft.tech installs nothing, creates no account, and is never tied to a Shopify store.
We run Google Analytics 4 on the public pages to count visits and see which pages lead to an install. It never loads inside the Shopify admin or during login. Visitors in the United States, Canada outside Quebec, Australia and New Zealand get one first-party cookie, _ga, holding a random number so that several page views count as one visit. Everyone else gets none at all, including the whole European Economic Area, the United Kingdom, Switzerland and Quebec: the tag runs and stores nothing on the device. Advertising storage and ad personalisation are switched off for every visitor without exception, so nothing here builds an advertising profile or follows you to another site.
Google receives your IP address to work out an approximate country, and does not store it. We never send your name, your email, or anything else that identifies you. To opt out, block or delete the _ga cookie in your browser settings, or install Google’s opt-out add-on. Every page keeps working either way.
GDPR
LabelCraft implements Shopify’s mandatory privacy webhooks. We store no customer identity - no name, email, phone number or address ever reaches us - but if you use Order labels or Returns to label, the order or return number stays in your print-job history (see Order and return access).
A customer data request is answered from that history. When a shopper asks a store you run for the data we hold about them, Shopify tells us which orders the request covers. We record the request, look those orders up in your print-job history, and undertake to provide you, the store owner, with what we hold about them - the order or return number, the date, and how many labels were printed - or to tell you there are none, within the 30 days Shopify allows. We keep one record of each request we receive, holding the order numbers it named and the dates it arrived and was answered, so that it can be shown to have been answered. No shopper name, email address or phone number is stored: the request carries them, and we drop them. The record is erased with the rest of your store’s data (see Data retention and deletion).
A customer erasure request removes those numbers. The order numbers named in the request are erased from your print-job history, and from our record of any earlier request about the same orders. Shop data erasure is honored automatically as described above. If you are in the EU/EEA you may also contact us to exercise your rights of access, rectification, erasure, and portability.
Changes
If this policy changes materially we will update this page and note the new date at the top. Continued use of the app after a change constitutes acceptance.
Contact
Privacy questions: support@labelcraft.tech