last updated: 2026-09-20
This policy covers the website www.mdflabs.dev and every application MDF Labs publishes, including MDF Inventory Forecasting for Shopify.
MDF Labs is the trade name of Jorge Bolois, NIF 73166129R, a sole trader (autónomo) established in Zaragoza, Spain. It is run by one person. "We" means MDF Labs. "You" means the merchant who installs one of our apps or visits the site.
We act in two roles, and the law treats them differently:
Section 09 of the Terms of Service contains the data processing terms that apply between us as processor and you as controller.
The website. Nothing you type. It has no accounts, no forms, no cookies and no analytics. Our host keeps ordinary server logs (IP address, requested page, time) for a short time to operate the service. We do not copy or keep them ourselves.
MDF Inventory Forecasting. When you install the app, Shopify asks you to grant five permissions. Here is what each one lets the app read or change, and what we keep.
read_products). Product and
variant titles, vendor, SKU, barcode, price, unit cost and image
link. Kept, so the app can show you what to reorder and by what
name.read_locations). The names
and IDs of your inventory locations. Kept, so a purchase order can
say which shelf it is for.read_orders) and read all
orders (read_all_orders). Order lines: which
variant sold, how many units, at what price, on what date, and any
refunds. Shopify only lets an app read the last 60 days by
default; read_all_orders lets us read up to two years
of history, which is what a sales forecast needs. We do not
keep the order lines. We add them up into one row per variant
per day — units sold, units refunded, revenue, cost, number of
orders — and discard the lines. We never request your customers'
names, emails, phone numbers, addresses or customer IDs; our
Shopify access is filed with zero protected customer fields, so
that data does not reach our servers.write_inventory). Shopify
pairs this permission with reading inventory. Reading: your
current stock levels per variant and location (available, on
hand, committed, incoming), kept as a daily snapshot from the day
you install. Writing: used for one thing only — when you mark a
purchase order as received, the app increases the available
quantity at the location you chose. It never changes stock on its
own.From your Shopify account. Your shop domain, shop name, time zone, currency and primary language, plus the API access token Shopify issues to the app. The token is stored encrypted. Your shop's contact email and postal address are read live from Shopify when you generate a purchase order PDF, so they can be printed as the buyer; they are not stored.
What you type into the app.
A supplier's contact name, email and phone are personal data about people who work at your suppliers. You decide to enter them; we store them only so they can be printed on your purchase orders.
Your customers' data. Orders in Shopify contain customer data. The app does not ask for it and Shopify does not send it to us. What we hold about your sales cannot be traced back to a person.
Usage milestones. The app reports four events to Shopify, once per shop and never again: first forecast ready, first buying table viewed, first purchase order generated, supplier lead time confirmed. Each carries your shop's ID and a timestamp. No product, sales or supplier data travels with them. Shopify uses them to measure whether the app does what it says.
Support. If you write to hello@mdflabs.dev, we keep the email thread for as long as we need it to help you, and at most 24 months after it closes.
One thing: run the app.
We do not advertise, profile, score or make automated decisions about any person. The forecast is about products, not people.
We use these companies to run the service and to read your email. Each has access only to what its job requires.
| Who | What for | Where |
|---|---|---|
| Shopify International Ltd. / Shopify Inc. | The platform the app runs inside: authentication, API, billing, webhooks, the four usage milestones above | Governed by Shopify's own terms and data location |
| Fly.io, Inc. | Runs the app servers and the website | Frankfurt, Germany (EU) |
| Neon, Inc. | The Postgres database | Frankfurt, Germany (EU) |
| Porkbun LLC | Forwards email sent to hello@mdflabs.dev | United States |
| Google LLC | The mailbox where forwarded support email is read | United States / EU, under Google's terms |
Your shop's data is stored in the EU. Fly.io and Neon are US companies; our agreements with them include the EU Standard Contractual Clauses for any access from outside the EU. Support email is the only data that leaves the EU by design, and only because you sent it to us.
We will update this table before adding a subprocessor and say so in the app. If you object, you can uninstall.
As a merchant. You can ask us at any time for a copy of what we hold about your shop, ask us to correct it, or ask us to delete it. Write to hello@mdflabs.dev from an email address associated with your shop. We answer within 30 days, usually much sooner. Most of your data you can also correct or delete yourself inside the app or, for products, orders and inventory, in Shopify — the app follows.
When you uninstall. Shopify tells us the moment you
uninstall. We immediately delete the access token, so the app can
no longer read your shop. Your other data stays for 30 days so
that, if you reinstall soon after, you do not wait for two years of
history to be read again. Forty-eight hours after uninstall Shopify
also sends us a mandatory shop/redact request; a
nightly job then erases everything the shop left behind, and in
every case within 30 days of the uninstall. If you want it gone
sooner, email us.
Your customers. Shopify forwards us two mandatory requests
when one of your customers exercises their rights with you:
customers/data_request and
customers/redact. Because we hold no data about
individual customers, in both cases our answer is that we have
nothing to return and nothing to delete. If you need a written
confirmation of that for a customer, email us.
If you are in the EU/EEA. You have the right to access, rectify and erase your personal data, to restrict or object to its processing, to data portability, and to lodge a complaint with a data protection authority. Ours is the Agencia Española de Protección de Datos (www.aepd.es); you may also complain to the authority of your own country. We do not require you to justify a request.
Legal basis. As processor, we act on your instructions. As controller, we process your shop domain and account data because we need them to perform the contract with you, and we keep support emails and accounting records under our legitimate interest in running the service and our legal duty to keep accounts.
Security, honestly stated. All traffic is encrypted in transit (TLS). The database is encrypted at rest by Neon. Shopify access tokens are additionally encrypted by us before being written to the database, with a key that is never stored next to the data. Every database query is scoped to one shop. Webhooks from Shopify are checked for a valid signature before anything is read. Access to production systems is limited to the one person who runs MDF Labs, with two-factor authentication. The website sends a strict Content Security Policy and cannot load third-party scripts. There is no such thing as perfect security; we keep the attack surface small by keeping as little data as we can.
If something goes wrong. If we become aware of a breach affecting your data, we will tell you without undue delay, and in any case within 72 hours of becoming aware, with what we know and what we are doing.
Retention.
shop/redact
request if that arrives first. The access token is deleted the
moment you uninstall.Backups follow the same lifecycle as the live database. Neon's point-in-time restore keeps a copy for a few days, after which erased data is gone from backups too.
If we change this policy in a way that matters — new data, a new subprocessor, a new purpose — we will update the date at the top and note the change in the app before it takes effect. Small wording fixes just update the date.
Questions, requests, complaints: hello@mdflabs.dev. We reply within a few working days.
MDF Labs · Jorge Bolois, NIF 73166129R · Zaragoza, Spain