Introduction
LaBete Software LLC ("LaBete", "we", "our") builds operational software for ecommerce teams, including ArcCart (Shopify product bundling) and Stocketto (inventory operations). This policy explains how our applications handle data. Where an app is installed through Shopify, the data we access is provided by Shopify under the permissions you grant at installation.
Data we collect
Our apps collect and store only the data necessary to provide their functionality:
- Store information: your store domain and the access credentials Shopify provides at installation.
- Product data: product titles, images, prices, and variant information used to build bundles and track inventory.
- App configuration: the bundles, tiers, slots, settings, and operational records you create in the app.
- Order data: order identifiers, order names, dates, and amounts used to attribute bundle sales and report performance to the merchant who owns the store.
- Merchant admin data: limited staff account details (such as name, email, locale, and account-owner status) that Shopify provides for authentication and administration.
Data we do not collect
We do not collect or store direct customer contact or payment details, including:
- Customer names, emails, or addresses
- Payment or billing card information
- Browsing behavior or advertising analytics
All checkout and payment processing is handled entirely by Shopify's native systems.
How we use data
The data we access is used solely to:
- Power the app's features on your storefront and admin
- Manage your configuration in the app dashboard
- Check product and inventory status via the Shopify Admin API
- Record and display performance (such as bundle sales) to the merchant that owns the store
- Authenticate merchant staff and keep the app secure
Data sharing
We do not sell, trade, or rent your data. We do not share it with third parties except the infrastructure providers that host the app on our behalf, and only as needed to operate the service.
Data retention & deletion
Your data is retained for as long as the app is installed on your store. When you uninstall, Shopify sends us a redaction request and we delete the associated store data from our systems within 48 hours. We honor Shopify's mandatory customer-redaction and shop-redaction webhooks.
Data storage & security
Data is stored in a secure PostgreSQL database (hosted by Supabase) with access controls enabled. All data is transmitted over HTTPS/TLS, and is protected in transit and at rest.
GDPR & CCPA
We comply with applicable data-protection regulations and implement Shopify's mandatory privacy compliance webhooks for customer data requests, customer redaction, and shop redaction. Because our apps do not store direct customer contact fields, most customer requests do not involve customer-identifying data in our systems; we still review and respond to every compliance webhook promptly.
Changes to this policy
We may update this policy from time to time. Changes are reflected on this page with a new "last updated" date.
Contact
Questions about this policy? Email hello@labetesoftware.com.