Your store’s data stays your store’s.
Label needs your product data to answer questions about your products. Here is what it keeps, where, for how long, and who can see it.
Kept apart, store by store
One store’s data is never read on behalf of another.
- Separate storage
Each store’s content, settings and history are kept in their own storage, apart from every other store’s.
- Decided by us
Which store a request is for is worked out by our servers, from a signed-in session, a site key or a verified webhook. Never from what a browser claims.
- Only what’s needed
Product data and what you write in the dashboard. Label never receives your customers’ details or your orders.
Shoppers
They don’t sign in, and they aren’t tracked.
- Sign-in
- None
- Cookies
- None set by the widget
- Typed questions
- Emails and long numbers removed before they’re stored
- Kept for
- 90 days, so you can see what people ask
The widget asks shoppers not to include personal details. To keep bots from running up your bill, a quick human check appears after a few typed questions, and requests are rate-limited.
Keys and connections
The links to your platform are protected end to end.
- Encrypted tokens
Access tokens for your platform, such as Shopify’s, are encrypted before they’re stored.
- Signed webhooks
Every update from Shopify, WooCommerce or our billing provider is checked for a valid signature before it’s used.
- Payments
Cards are handled by our billing provider, or by Shopify for Shopify stores. Label never sees card numbers.
The AI
It sees what an answer needs, and nothing else.
Answers are written by Claude, Anthropic’s AI model, through Cloudflare’s AI Gateway. Each request carries what that one answer needs: the product, the parts of your policies that apply, your voice settings and the shopper’s question with personal details removed.
Our access
Label staff work through an audited console.
The few people who support Label sign in through a separate, access-controlled console. Every action they take on a store, and every time they open one, is recorded with who did it and why.
If you leave
Your content goes with you, or goes.
- At once
Cancel and the widget turns off on your store.
- 30 days
Your content is kept in case you come back.
- Then
It’s deleted everywhere it’s stored, apart from the billing records the law requires us to keep.
Where it runs
On Cloudflare’s network.
Label runs on Cloudflare, served over HTTPS only. Dashboard pages are never cached, and can’t be framed by other sites; only Shopify admin may show the dashboard, for a Shopify store’s own app.
Questions about your data?
Start a trial and ask us from the dashboard’s Support page.