software lab
LEGAL

Privacy Policy

last updated: 2026-09-20

01What this covers

This policy covers the website www.mdflabs.dev and every application MDF Labs publishes, including MDF Inventory Forecasting for Shopify.

MDF Labs is the trade name of Jorge Bolois, NIF 73166129R, a sole trader (autónomo) established in Zaragoza, Spain. It is run by one person. "We" means MDF Labs. "You" means the merchant who installs one of our apps or visits the site.

We act in two roles, and the law treats them differently:

Section 09 of the Terms of Service contains the data processing terms that apply between us as processor and you as controller.

02What we collect

The website. Nothing you type. It has no accounts, no forms, no cookies and no analytics. Our host keeps ordinary server logs (IP address, requested page, time) for a short time to operate the service. We do not copy or keep them ourselves.

MDF Inventory Forecasting. When you install the app, Shopify asks you to grant five permissions. Here is what each one lets the app read or change, and what we keep.

From your Shopify account. Your shop domain, shop name, time zone, currency and primary language, plus the API access token Shopify issues to the app. The token is stored encrypted. Your shop's contact email and postal address are read live from Shopify when you generate a purchase order PDF, so they can be printed as the buyer; they are not stored.

What you type into the app.

A supplier's contact name, email and phone are personal data about people who work at your suppliers. You decide to enter them; we store them only so they can be printed on your purchase orders.

Your customers' data. Orders in Shopify contain customer data. The app does not ask for it and Shopify does not send it to us. What we hold about your sales cannot be traced back to a person.

Usage milestones. The app reports four events to Shopify, once per shop and never again: first forecast ready, first buying table viewed, first purchase order generated, supplier lead time confirmed. Each carries your shop's ID and a timestamp. No product, sales or supplier data travels with them. Shopify uses them to measure whether the app does what it says.

Support. If you write to hello@mdflabs.dev, we keep the email thread for as long as we need it to help you, and at most 24 months after it closes.

03What we do with it

One thing: run the app.

We do not advertise, profile, score or make automated decisions about any person. The forecast is about products, not people.

04Subprocessors

We use these companies to run the service and to read your email. Each has access only to what its job requires.

WhoWhat forWhere
Shopify International Ltd. / Shopify Inc. The platform the app runs inside: authentication, API, billing, webhooks, the four usage milestones above Governed by Shopify's own terms and data location
Fly.io, Inc.Runs the app servers and the websiteFrankfurt, Germany (EU)
Neon, Inc.The Postgres database Frankfurt, Germany (EU)
Porkbun LLCForwards email sent to hello@mdflabs.devUnited States
Google LLCThe mailbox where forwarded support email is readUnited States / EU, under Google's terms

Your shop's data is stored in the EU. Fly.io and Neon are US companies; our agreements with them include the EU Standard Contractual Clauses for any access from outside the EU. Support email is the only data that leaves the EU by design, and only because you sent it to us.

We will update this table before adding a subprocessor and say so in the app. If you object, you can uninstall.

05What we never do

06Your rights

As a merchant. You can ask us at any time for a copy of what we hold about your shop, ask us to correct it, or ask us to delete it. Write to hello@mdflabs.dev from an email address associated with your shop. We answer within 30 days, usually much sooner. Most of your data you can also correct or delete yourself inside the app or, for products, orders and inventory, in Shopify — the app follows.

When you uninstall. Shopify tells us the moment you uninstall. We immediately delete the access token, so the app can no longer read your shop. Your other data stays for 30 days so that, if you reinstall soon after, you do not wait for two years of history to be read again. Forty-eight hours after uninstall Shopify also sends us a mandatory shop/redact request; a nightly job then erases everything the shop left behind, and in every case within 30 days of the uninstall. If you want it gone sooner, email us.

Your customers. Shopify forwards us two mandatory requests when one of your customers exercises their rights with you: customers/data_request and customers/redact. Because we hold no data about individual customers, in both cases our answer is that we have nothing to return and nothing to delete. If you need a written confirmation of that for a customer, email us.

If you are in the EU/EEA. You have the right to access, rectify and erase your personal data, to restrict or object to its processing, to data portability, and to lodge a complaint with a data protection authority. Ours is the Agencia Española de Protección de Datos (www.aepd.es); you may also complain to the authority of your own country. We do not require you to justify a request.

Legal basis. As processor, we act on your instructions. As controller, we process your shop domain and account data because we need them to perform the contract with you, and we keep support emails and accounting records under our legitimate interest in running the service and our legal duty to keep accounts.

07Security & retention

Security, honestly stated. All traffic is encrypted in transit (TLS). The database is encrypted at rest by Neon. Shopify access tokens are additionally encrypted by us before being written to the database, with a key that is never stored next to the data. Every database query is scoped to one shop. Webhooks from Shopify are checked for a valid signature before anything is read. Access to production systems is limited to the one person who runs MDF Labs, with two-factor authentication. The website sends a strict Content Security Policy and cannot load third-party scripts. There is no such thing as perfect security; we keep the attack surface small by keeping as little data as we can.

If something goes wrong. If we become aware of a breach affecting your data, we will tell you without undue delay, and in any case within 72 hours of becoming aware, with what we know and what we are doing.

Retention.

Backups follow the same lifecycle as the live database. Neon's point-in-time restore keeps a copy for a few days, after which erased data is gone from backups too.

08Changes & contact

If we change this policy in a way that matters — new data, a new subprocessor, a new purpose — we will update the date at the top and note the change in the app before it takes effect. Small wording fixes just update the date.

Questions, requests, complaints: hello@mdflabs.dev. We reply within a few working days.

MDF Labs · Jorge Bolois, NIF 73166129R · Zaragoza, Spain