Privacy Policy – Lab Results & COA

Effective date: 21 August 2026

This Privacy Policy explains how the Lab Results & COA app ("the App", "we", "us"), published by Northbound Apps, handles information when a Shopify merchant installs and uses it. By installing the App you agree to this policy.

The short version: the App is built so that your lab-certificate data and files stay inside your own Shopify store. The App's own database stores only the security token Shopify issues so the App can talk to your store. We do not collect, store, or sell your customers' personal information.

1. Who this policy is for

The App is installed by Shopify merchants. This policy covers merchant data (the store owner and staff who use the App in the Shopify admin) and store customer data (the shoppers who visit a merchant's storefront).

2. Information the App accesses and stores

2.1 What the App stores in its own database. The App keeps a single record per installed store: the Shopify session. That record contains your store's domain, the access token Shopify issues to the App, the granted permission scopes, and related session state. This is what lets the App securely make requests to your store on your behalf. That is the only data the App keeps in its own database.

2.2 What the App reads from and writes to your store. To do its job, the App uses the permissions you grant at install (write_products, write_files) to read your products so you can pick which product a certificate belongs to, write lab-certificate details (batch number, test date, lab name, and an optional potency or pass/fail summary) into that product's metafields, and upload certificate PDFs to your store's Shopify Files. This certificate data and the PDF files are stored in your Shopify store, not on our servers. You can view, edit, or delete them at any time.

2.3 Storefront and batch verification. The App shows a "Lab Tested" panel on your product pages and offers a batch verification page (reached by scanning a QR code) that displays the certificate you published for that batch. These pages read the certificate data you already stored in your store. They do not collect any personal information from shoppers. There is no login, no form, and no tracking cookie set by the App for this purpose.

2.4 Customer personal data. The App does not collect, request, store, or process your customers' personal information (names, addresses, emails, payment details, or order data).

3. How we use the information

We use the Shopify session token solely to authenticate the App with your store and provide the App's features. We do not use it for advertising, and we do not sell or rent any data to third parties.

4. Data sharing and subprocessors

We do not sell your data. The App relies on a small number of service providers to operate:

ProviderPurposeData involved
ShopifyThe platform the App runs on; hosts your products, metafields, and FilesYour store and certificate data live here
RailwayHosts the App's serverHandles requests in transit; runs the App
SupabaseDatabase for the App's session recordsStores the Shopify session token described in 2.1

Each provider processes data only to run the App, under its own security and privacy commitments.

5. Data retention and deletion

The session record is kept while the App is installed. When you uninstall the App, Shopify sends an uninstall notification and the session record is deleted. Your certificate data and PDFs remain in your own store's metafields and Files under your control, and are governed by Shopify's own data handling. You can request deletion of any data associated with your store at any time by contacting us (see Section 8).

6. GDPR and CCPA compliance webhooks

Shopify requires apps to respond to its mandatory privacy webhooks. The App handles all three:

7. Security

Data in transit is protected with HTTPS/TLS. The App stores no customer personal data and keeps only the minimum needed (the Shopify session token) to function. Access to the App's infrastructure is restricted to the App's operator.

8. Contact

If you have questions about this policy or want to make a data request, contact: Northbound Appspandeyhardik425@gmail.com

9. Changes to this policy

We may update this policy as the App evolves or as legal requirements change. We will revise the "Effective date" above when we do. Continued use of the App after a change means you accept the updated policy.