Website

Metto Privacy Policy

Effective date: January 1, 2026 · Last updated: September 10, 2026

Overview

This Privacy Policy explains how Morrow Labs, Inc., doing business as Metto (“Metto,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you visit gometto.com or another website that links to this policy (the “Site”), use Metto’s products and services, or interact with a merchant’s online store where the Metto Shopify application or another Metto service is installed (collectively, the “Services”).

This policy applies to merchants and their personnel, website visitors, shoppers, prospective customers, and other individuals who interact with the Services. It does not apply to a merchant’s independent handling of personal information. Merchants should review and maintain their own privacy notices.

For information Metto processes on a merchant’s behalf, the merchant generally determines why and how the information is processed, and Metto acts as its service provider or processor. If you are a shopper, you should usually direct privacy requests to the merchant whose store you visited. We will assist the merchant as required.

Information We Collect

Information from Shopify and merchants

When a merchant installs, configures, or uses the Metto app, we may receive information through Shopify APIs or directly from the merchant, depending on the permissions granted and the features enabled:

  • Store and account information, such as shop name, Shopify domain, store URL, locale, currency, time zone, business contact details, user identifiers, roles, and authentication or installation tokens.
  • Catalog and merchandising information, such as products, variants, collections, descriptions, images, tags, metafields, pricing, availability, inventory, promotions, taxonomy, and related product data.
  • Commerce and performance information, such as searches, product impressions, clicks, carts, conversions, aggregated sales or order information, and other events used to operate, measure, and improve search, discovery, personalization, and merchandising.
  • Customer and order information only when a merchant enables a feature that requires it and Shopify has approved the applicable access. This may include Shopify customer or order identifiers, purchase history, and, only if strictly necessary and expressly authorized, name, email address, phone number, or shipping information.
  • Merchant communications and support information, such as messages, meeting notes, feedback, requests, and files provided to us.
  • Technical and usage logs generated when merchant personnel use the app, including IP address, device and browser information, timestamps, pages or features used, diagnostic events, and error logs.

Metto seeks to request and process only the Shopify data and protected customer fields necessary for the features a merchant uses. The exact Shopify permissions requested are presented during installation and may change if a merchant enables additional functionality.

Information from shoppers and Site visitors

When an individual visits the Site or interacts with a Metto-powered experience on a merchant storefront, we may collect:

  • Interaction information, such as search queries, conversational prompts, product preferences, filter selections, products viewed, clicks, recommendations shown, add-to-cart activity, and whether a recommendation or search result led to a purchase.
  • Device and network information, such as IP address, browser type, operating system, device type, referring page, approximate location derived from IP address, timestamps, and identifiers associated with cookies or similar technologies.
  • Information submitted voluntarily, such as name, business email, company, message content, demo requests, support inquiries, or other information entered into a form or Metto-powered interface.
  • Information a merchant instructs us to process or makes available through its systems, subject to the merchant’s instructions and applicable law.

Please do not submit sensitive personal information in free-text searches, prompts, or support messages unless it is necessary and you are authorized to do so.

Cookies and Similar Technologies

We and our service providers may use cookies, local storage, pixels, SDKs, and similar technologies to keep the Services secure, remember settings, understand usage, diagnose problems, and improve performance. On Shopify storefronts, Metto will use Shopify-approved mechanisms, including consent-aware web pixels where required, for analytics or marketing-related behavioral collection. A merchant’s storefront may use additional technologies governed by the merchant’s privacy notice and consent settings.

You can control cookies through your browser and, where available, a website or storefront consent tool.

Blocking some technologies may affect functionality.

How We Use Information

We use personal information for the following purposes:

  • Provide, operate, configure, secure, and support the Services.
  • Power and improve product search, discovery, recommendations, personalization, product intelligence, merchandising, reporting, and related agentic commerce functions requested by merchants.
  • Authenticate users, manage installations and accounts, process billing, and communicate about the Services.
  • Measure performance, troubleshoot errors, prevent fraud or abuse, and maintain security and reliability.
  • Develop and improve Metto’s technology, including through aggregated, deidentified, or merchant-authorized information.
  • Respond to questions, provide requested demos, and send product or marketing communications where permitted. Recipients may opt out of marketing emails at any time.
  • Comply with law, enforce agreements, protect rights and safety, and establish or defend legal claims.

How We Disclose Information

We may disclose personal information to:

  • The applicable merchant, because information generated through that merchant’s storefront is processed for and made available to that merchant.
  • Service providers that support cloud hosting, data storage, security, monitoring, analytics, communications, customer support, payments, and AI or machine-learning functionality. They may process information only for the services they provide to us and subject to contractual restrictions.
  • Professional advisers, auditors, insurers, and financing sources subject to appropriate confidentiality obligations.
  • Government authorities or other parties when required by law or reasonably necessary to protect rights, security, safety, or the integrity of the Services.
  • A buyer, investor, successor, or other relevant party in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to customary protections.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising or use merchant customer data to advertise unrelated products to shoppers.

Legal Bases for Processing

Where the European Economic Area, United Kingdom, or similar laws apply, we process personal information as necessary to perform a contract, pursue legitimate interests such as operating and securing the Services, comply with legal obligations, or based on consent. When we process personal information for a merchant, the merchant determines the applicable legal basis.

Data Retention

We retain personal information only as long as reasonably necessary for the purposes described in this policy, including to provide the Services, comply with law, resolve disputes, and enforce agreements.

Retention depends on the type of information, the merchant’s instructions, contractual requirements, security needs, and legal obligations.

Unless a longer period is required or permitted by law or agreed with a merchant, Metto deletes or de-identifies merchant personal information within 30 days after termination or uninstall. Metto deletes or overwrites backups on a rolling basis within 30 days. Security, billing, and audit records may be retained for upto 7 years.

Shopify Privacy Requests and App Uninstall

Metto supports Shopify’s mandatory privacy request process. When Shopify sends a valid customers/data_request webhook, we identify and provide the responsive customer data to the merchant. When Shopify sends a valid customers/redact or shop/redact webhook, we delete or deidentify the applicable customer or shop data unless retention is legally required. We verify webhook authenticity and complete required action within Shopify’s required timeframe.

Your Privacy Rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of personal information; restrict or object to processing; withdraw consent; opt out of certain sales, sharing, targeted advertising, or profiling; and appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.

Merchant personnel and Site visitors may submit a request using the contact information below.

Shoppers should first contact the merchant whose store they visited. We may verify identity and authority before completing a request. An authorized agent may submit a request where permitted by law. We will respond within the period required by applicable law.

Metto does not currently respond to browser-based Global Privacy Control signals because we do not sell or share personal information for cross-context behavioral advertising.

International Data Transfers

Metto is based in the United States, and we and our service providers may process information in the United States and other countries. Where required, we use appropriate safeguards for international transfers, such as adequacy decisions, approved contractual clauses, and supplementary measures.

Individuals may contact us for additional information about applicable safeguards.

Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit and at rest where appropriate, logging, vulnerability management, and incident-response procedures. No system is completely secure, and we cannot guarantee absolute security.

Children

The Services are intended for businesses and general audiences and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information to us, please contact us so we can take appropriate action.

Merchants are responsible for configuring and using the Services consistently with age-related laws applicable to their stores and customers.

Third Party Services and Links

The Services may interoperate with Shopify and other third-party services or link to third-party websites.

Their privacy practices are governed by their own notices. This policy does not cover personal information those third parties process independently of Metto.

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version and revise the “Last updated” date. If changes are material, we will provide additional notice when required by law or contract.

Contact Us

Questions, complaints, and privacy requests may be directed to:

Morrow Labs, Inc. d/b/a Metto

Attn: Privacy

Email: hello@metto.com

Website: https://metto.com

Individuals in the EEA or UK may also have the right to lodge a complaint with their local data protection authority.