Privacy Policy
Last updated: September 8, 2026
This Privacy Policy describes how NerdLabs ("we," "us," or "our") collects, uses, and protects information through the TraceKit application ("the App"). TraceKit is a Shopify application, embedded in the Shopify admin, that lets merchants log and track lot, batch and expiry information against their products — for food, cosmetics, supplements, and any other perishable or regulated goods.
1. Information We Collect
1.1 Shopify Store Data
TraceKit requests only the minimum Shopify API access it needs:
- Products (read): so you can pick a product from your catalog when logging a lot (a lot attaches to the product, and to its variant when the product has exactly one)
That is the only Shopify API scope the App requests. TraceKit does not read your orders, your customer records, or any personal data about your store's customers, and it does not write to your store.
1.2 Store and Session Data
To run the App for your store, we store:
- Your store's
myshopify.comdomain - An app session token issued by Shopify (short-lived and refreshed automatically)
- The plan tier your store has chosen
1.3 Lot Records You Enter
To provide the App's core functionality, we store the lot records that you and your staff enter:
- Product ID and title, and optionally the variant ID and SKU the lot is attached to
- Lot or batch code, quantity, and unit
- Supplier name (merchant-entered business data)
- Manufactured, received, and expiry dates
- Status (active, depleted, expired, or recalled)
- Free-text notes
- Timestamps for when the record was created and last changed
No customer personal data. TraceKit does not collect, store, or process personal data about your store's customers. The only people-related data it holds is the supplier name you choose to type into a lot record.
2. How We Use Your Information
We use the collected data exclusively to:
- Display, edit, and manage the lot records you enter
- Calculate expiry summaries (lots expiring soon and lots past expiry) inside the App
- Apply the active-lot capacity of the plan tier you have chosen
- Authenticate your store's embedded-app session with Shopify
- Improve and maintain the App
3. Data Sharing and Disclosure
We do not sell, rent, or share your data with third parties for their marketing purposes. Your data may be shared only in the following circumstances:
- Service Providers: We use a hosting provider (DigitalOcean) that stores and processes data on our behalf. No other third-party service receives your data.
- Legal Requirements: We may disclose data if required by law, subpoena, or court order.
- Business Transfers: In the event of a merger or acquisition, data may be transferred as part of business assets.
4. Data Storage and Security
- Data is hosted on NerdLabs servers on DigitalOcean in the United States.
- Data is encrypted in transit (TLS 1.2+).
- Daily backups are taken and retained for 7 days.
- Access to production systems is restricted to authorized NerdLabs personnel only.
5. Data Retention and Deletion
We retain your data only as long as you have TraceKit installed. When you uninstall the App:
- Your store's session tokens are deleted immediately.
- Your lot records are retained for 48 hours, so an accidental uninstall can be reversed by reinstalling.
- Shopify then issues its shop-redaction request (about 48 hours after uninstall) and TraceKit permanently deletes every record for your store — always within 30 days of uninstall.
- Backups containing your data age out within 7 days after that.
6. Shopify Privacy Webhooks (GDPR)
TraceKit implements all three of Shopify's mandatory privacy webhooks:
- Customer data request: because TraceKit stores no customer personal data, there is nothing to return. The request is acknowledged as such.
- Customer redaction: because TraceKit stores no customer personal data, there is nothing to delete. The request is acknowledged as such.
- Shop redaction: TraceKit permanently deletes every record for the store, as described in Section 5.
7. Your Rights
You have the right to:
- Access: Request a copy of the data we hold about your store.
- Correction: Request correction of inaccurate data. Lot records can also be edited directly in the App.
- Deletion: Request deletion of your data at any time. Uninstalling the App triggers automatic deletion as described in Section 5.
- Portability: Request your data in a portable format.
To exercise any of these rights, email support@nerdlabs.us.
8. Cookies and Tracking
TraceKit does not use cookies for advertising or tracking purposes. It uses only what Shopify's embedded-app session requires in order to function. The App contains no third-party analytics and no advertising pixels.
9. Children's Privacy
TraceKit is a business tool for Shopify merchants. We do not knowingly collect information from children under 13.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting an update within the App or by email.
11. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at:
NerdLabs
Email: support@nerdlabs.us
Website: nerdlabs.us