Legal and privacy

Privacy Policy for MorganLabs apps.

This Privacy Policy applies to MorganLabs-operated apps, including Shopify apps such as ReturnSense, PackBridge, Script Sentinel, and StockLock. It explains what information we collect, how we use it, and how we protect it when merchants install or use our apps.

Effective date

April 21, 2026

This page is intended to serve as the public privacy policy for MorganLabs apps currently in use, live, or under review.

Shopify app

ReturnSense

Merchant-facing return analysis and recommendation workflows built from order, return, product, variant, and related operational data.

Shopify app

StockLock

Paired-store inventory sync workflows built from product, variant, inventory, SKU, mapping, sync-log, and related app-configuration data.

Shopify app

PackBridge

B2B pack-unit translation workflows built from order, product, company, customer, rule, job, payload, and audit-trail data.

Shopify app

Script Sentinel

Read-only Scripts-to-Functions parity workflows built from shop context, product/order fixtures, scrubbed cart shapes, Function output, drift findings, and audit records.

1. Information we collect

When you install or use a MorganLabs app, we may collect and store information from your Shopify store that is reasonably necessary to operate that app.

  • Basic store information, such as shop domain and app installation context.
  • For ReturnSense: order, return, product, variant, SKU, return-note, and related merchant workflow data needed to analyze return patterns and present recommendations.
  • For StockLock: product, variant, inventory, SKU, mapping, sync-log, and related app-configuration data needed to support paired-store inventory workflows.
  • For PackBridge: order, product, company, customer, rule, job, payload, delivery, and audit-trail data needed to translate B2B orders into downstream-safe pack units.
  • For Script Sentinel: shop context, product/order fixtures, scrubbed cart shapes, Function output, drift findings, and audit records needed to support read-only migration parity evidence.
  • Operational records created through the apps, such as sync state, recommendation state, publishing state, configuration settings, and diagnostic logs.
  • Technical and troubleshooting information related to app performance, webhook delivery, errors, and reliability monitoring.

We collect only the data reasonably necessary to provide and support the app functionality we offer. We do not use merchant or customer data for advertising or resale.

2. How we use information

We use collected information to operate, maintain, and improve MorganLabs apps.

  • Provide the specific workflows and features of ReturnSense, PackBridge, Script Sentinel, StockLock, or any related MorganLabs app a merchant chooses to install.
  • Generate merchant-facing analyses, configuration outputs, operational recommendations, or stock-aware behaviors.
  • Maintain app settings, sync state, review state, and related workflow history.
  • Troubleshoot problems, monitor reliability, improve app performance, and provide support.
  • Comply with applicable law, platform rules, and legitimate business obligations.

3. How we share information

We do not sell merchant data.

We may share information only in limited circumstances, such as:

  • With infrastructure, hosting, monitoring, or support providers that help us operate the apps.
  • When required by law, legal process, or regulatory obligation.
  • To protect the security, rights, or integrity of MorganLabs, merchants, Shopify, or others.

4. Data retention

We retain data only as long as reasonably necessary to operate the apps, provide support, resolve disputes, comply with legal obligations, or enforce our agreements. We may delete or anonymize data when it is no longer needed, including in response to applicable Shopify privacy or compliance obligations.

5. Data security

We take reasonable administrative, technical, and organizational measures to protect information against unauthorized access, loss, misuse, or alteration. No system is perfectly secure, so we cannot guarantee absolute security.

6. Merchant choices and responsibilities

Merchants are responsible for ensuring they have the right to use Shopify and any store data connected to a MorganLabs app. Merchants are also responsible for configuring the app in a way that fits their business operations.

If you uninstall an app, we may retain certain information for a limited period as necessary for legal compliance, dispute resolution, fraud prevention, operational integrity, or legitimate business purposes. You may contact us regarding deletion requests, subject to applicable law and platform obligations.

7. Third-party services

MorganLabs apps operate with Shopify and may rely on third-party infrastructure or hosting providers. Your use of Shopify is also subject to Shopify's own terms, policies, and privacy practices.

8. Children's privacy

MorganLabs apps are intended for business use by merchants and are not directed to children.

9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and post the revised version at this URL.

10. Contact

If you have questions about this Privacy Policy or the data practices of ReturnSense, PackBridge, Script Sentinel, StockLock, or another MorganLabs app, contact:

MorganLabs

Email: [email protected]

Website: https://morganlabs.org