Legal
Privacy Policy
Last updated: August 10, 2026
1. Who we are
Aigento and Dash Labs are operated by SIA "DashLabs" ("DashLabs", "we", "us", or "our"), a Latvian limited liability company founded in 2024, registration No. 50203563401, Krišjāņa Valdemāra iela 24–5, Rīga, LV-1010, Latvia.
For any privacy question or request, contact us at [email protected].
2. Scope
This Privacy Policy applies to all products and services we operate (collectively, the "Services"), including:
- our websites, including dashlabs.lv and aigen.to;
- Aigento and related products;
- all applications we publish on the Shopify App Store and other app marketplaces; and
- related support, documentation, and communication channels.
It explains what personal data we collect, why we collect it, how we use and share it, and the rights you have under applicable data protection law, including the EU General Data Protection Regulation ("GDPR").
3. Our role: controller and processor
As a controller, we decide how and why to process personal data relating to merchants and visitors — for example, your account details, billing information, support requests, and usage of our websites and apps.
As a processor, when a merchant installs one of our apps, we may process personal data of the merchant's customers (such as order or review data) on the merchant's behalf and under the merchant's instructions. In that case, the merchant is the controller and should be contacted first for requests concerning that data.
4. Data we collect
Merchant and account data. When you install one of our apps or sign up for a Service, we receive information such as your store name and domain, contact name, email address, country, plan, and app configuration.
Store data via platform APIs. Depending on the app and the permissions you grant, we access data from your store through platform APIs (for example, the Shopify Admin API), such as products, orders, themes, or analytics data. We only request the API scopes that an app needs to provide its functionality.
End-customer data. Some apps process limited personal data of a merchant's customers on the merchant's behalf — for example, order details, email addresses, or delivery information needed to collect reviews or track conversions. We process this data only as needed to provide the relevant app.
Usage and technical data. We collect log and analytics data about how the Services are used, such as IP address, browser and device information, pages viewed, and in-app events. We use this to operate, secure, and improve the Services.
Support and communications. When you contact us, we keep the correspondence and any information you choose to share so we can help you and improve our support.
5. How we use data
- to provide, operate, and maintain the Services;
- to set up, bill, and manage your account and subscriptions;
- to provide customer support and respond to requests;
- to monitor performance, debug issues, and improve the Services;
- to send service communications (such as onboarding, changes to the Services, or security notices);
- to prevent fraud and abuse and to secure the Services; and
- to comply with legal obligations.
We do not sell personal data, and we do not use end-customer data processed on behalf of merchants for our own marketing.
6. Legal bases
Where the GDPR applies, we rely on the following legal bases:
- Contract — to provide the Services you have signed up for;
- Legitimate interests — to secure, analyse, and improve the Services and to communicate with business customers;
- Consent — where required, for example for certain cookies or marketing communications; and
- Legal obligation — for example accounting and tax requirements.
7. Sharing and subprocessors
We share personal data only as needed to run the Services, with:
- hosting and infrastructure providers that store and process data for us;
- analytics and error-monitoring providers;
- platform providers such as Shopify, which handle app billing and distribution;
- third-party services an app integrates with at your direction (for example Google or advertising platforms), as described in the relevant app listing; and
- professional advisers and authorities where required by law.
All service providers acting on our behalf are bound by contracts that restrict their use of personal data to providing services to us.
8. International transfers
We are based in the European Union and store data in the EU/EEA where feasible. Where personal data is transferred outside the EU/EEA (for example to a service provider in the United States), we rely on appropriate safeguards such as adequacy decisions or the European Commission's Standard Contractual Clauses.
9. Retention and deletion
We keep personal data only as long as needed for the purposes described above, and then delete or anonymise it. In particular:
- when you uninstall one of our Shopify apps, we delete the associated store data in line with Shopify's requirements;
- we honour Shopify's mandatory GDPR webhooks — customer data requests, customer data erasure, and shop data erasure — and action them within the required timeframes; and
- billing and accounting records are retained for the periods required by law.
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and the principle of least privilege for API scopes and internal access. No system is perfectly secure; if we become aware of a personal data breach affecting you, we will notify you and the competent authorities as required by law.
11. Your rights
Subject to applicable law, you have the right to access, rectify, erase, or receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent at any time. To exercise these rights, email [email protected].
If you are a customer of a store using one of our apps, please contact the store (the controller) first; we will assist them in responding to your request.
You also have the right to lodge a complaint with a supervisory authority, in particular the Latvian Data State Inspectorate (Datu valsts inspekcija, www.dvi.gov.lv) or the authority in your country of residence.
12. Cookies and analytics
Our websites use cookies and similar technologies for essential functionality and, where permitted, for analytics that help us understand how the Services are used. You can control cookies through your browser settings; essential cookies are required for the Services to function.
13. Children
The Services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children under 16.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and adjust the "Last updated" date above. For material changes, we will provide more prominent notice where appropriate.
15. Contact
SIA "DashLabs", registration No. 50203563401, Krišjāņa Valdemāra iela 24–5, Rīga, LV-1010, Latvia — [email protected].
See also our Terms of Service.