Labelixa Privacy Policy
Effective Date: September 6, 2026
Last updated: September 6, 2026
This Privacy Policy explains how Newempo LLC ("Newempo," "we," "us," or "our") processes personal data in connection with the Labelixa website, tools, REST API, customer panel, documentation, and related services (together, the "Service").
Legal notice and mailing address:
Newempo LLC 30 N Gould St #40045 Sheridan, WY 82801, USA
Contact email: [email protected]
The address above is provided solely as Newempo LLC's legal notice and mailing address.
This Privacy Policy is a transparency notice. Your use of the Service is governed by the Labelixa Terms of Service.
1. Introduction and Scope
1.1 This Policy describes how we process personal data relating to people who interact with the Service, including public website visitors; people who use the ZPL preview, rendering, or barcode tools without an account; registered account holders; API users; paid subscribers; customer panel users; people who contact support; and business customers (including Enterprise and On-Premise customers) that submit label content.
1.2 The personal data we process depends on how you use the Service — for example, on how you access it, whether you have an account, whether you use a paid plan, whether you submit content for rendering, and whether you contact support. Not all of the data described in this Policy is collected from every user.
1.3 This Policy does not apply to third-party websites or services that we do not operate, or to a business customer's own handling of personal data.
2. Who Is Responsible for Personal Data
2.1 Controller. For most processing connected to operating the Service, Newempo LLC is the controller — for example, account administration, authentication, subscription and billing administration, usage measurement, service security, abuse prevention, support communications, account deletion, and legal compliance.
2.2 Processor. Where a business customer submits personal data contained in label content for us to process on the customer's behalf (for example, to render a label), Newempo LLC generally acts as a processor for that content.
2.3 The precise role depends on the actual processing context. The business customer generally remains responsible for determining the purposes and means of processing its own customer-label data. Where legally required, an applicable Data Processing Addendum ("DPA") must be entered into before the relevant processing begins. We do not claim to be always a controller or always a processor.
3. Personal Data We Collect
We may process the following categories, depending on how you use the Service:
- Account and profile information — such as your email address, account creation date, account status, selected plan, subscription status, paid-period information, and account-deletion status.
- API and credential information — credentials issued to registered users and used to authenticate API requests.
- Usage information — such as usage dates, request counts, rendered-label counts, plan-limit and quota information, rate-limiting and abuse-prevention information, and pseudonymous usage identifiers.
- Authentication information — such as your email address, authentication state, session information, and information received from an authentication provider if you choose third-party sign-in.
- Billing and subscription information — limited information necessary to operate subscriptions (see Section 10).
- Label and barcode content — data you deliberately submit for rendering or generation (see Section 7).
- Support communications — information you provide when you contact us (see Section 11).
We describe these categories in more detail in Sections 7–11.
4. How We Obtain Personal Data
We may obtain personal data:
- directly from you (for example, when you create an account or contact support);
- from your use of the Service (for example, usage measurement and security processes);
- from your organization (for example, if a business enrolls you or submits content);
- from an authentication provider, if you choose third-party sign-in;
- from a payment processor, in connection with subscriptions;
- through service-security and abuse-prevention processes.
We do not purchase personal data from data brokers, and we do not enrich your data with externally sourced profiling.
5. How We Use Personal Data
We use personal data to:
- provide and operate the Service;
- create and administer accounts;
- authenticate users;
- issue and manage API access;
- measure usage and enforce quotas;
- process subscriptions and payments;
- manage cancellation and account deletion;
- provide support;
- protect the security of the Service;
- detect abuse, fraud, or unauthorized use;
- troubleshoot and improve reliability;
- comply with legal obligations;
- establish, exercise, or defend legal claims; and
- send material service, billing, security, or policy notices.
We do not currently sell personal data, and we do not use personal data for behavioral advertising or cross-site tracking. We do not use Customer Content to train machine-learning or AI models. If any of this were to change, we would update this Policy and, where required, obtain consent or provide an opt-out before doing so.
6. Legal Bases for Processing
Where the EU General Data Protection Regulation ("GDPR") or the UK GDPR applies, we rely on the following legal bases, depending on the purpose:
- Performance of a contract, or steps taken at your request before entering a contract — for account creation, authentication necessary to provide the Service, provision of the tools and API access, subscription administration, cancellation, account deletion, and support directly related to the Service.
- Compliance with a legal obligation — for financial and transaction records, regulatory obligations, lawful requests, and compliance with applicable law.
- Legitimate interests — for service security, fraud and abuse prevention, quota enforcement, troubleshooting, defending legal claims, and maintaining reliable operation of the Service. We rely on these interests only where they are not overridden by your interests or rights.
- Consent — only where processing is genuinely optional and consent is the appropriate basis. We do not use consent as the basis for the account, payment, security, or service processing that is necessary to provide the Service.
The current confirmed Service uses service-related and transactional communications and does not operate behavioral advertising through the application.
7. Label and Barcode Content
7.1 When you use the rendering, preview, or barcode tools or the API, you submit content for processing. This "Customer Content" may include ZPL, barcode values, text, images, names, shipping or recipient addresses, order information, product information, and other label content that you choose to include.
7.2 Application-level rendering is designed not to retain submitted label content as a persistent content store. Content you render, preview, validate, or convert is returned in the response and is not written to a content store. However, request metadata, and any data you place in a URL (for example, in a query parameter), may be processed by the infrastructure that delivers and secures the Service.
7.2a We store label content only where you ask us to. That means: a label or folder you save to your account; a font you add to your account font library; a file you upload while working; the output of a bulk job, so that you can download it; and a print job you send to your own printer, which waits in a delivery store until your local print agent collects it. Each of these has its own retention period in Section 15.2. Rendering alone never creates a stored copy.
7.3 To reduce the exposure of sensitive data, you should avoid placing sensitive information in URL parameters and should use request-body methods where the Service supports them. We do not guarantee that content placed in a URL will never appear in provider logs, and we do not claim that all submitted data is never stored or processed.
7.4 Where you submit personal data contained in label content, you are responsible for having a lawful basis and the necessary authority to do so, and Newempo LLC generally acts as processor for that content (Section 2).
8. Anonymous Usage and Pseudonymous Identifiers
8.1 Some functionality can be used without an account. We measure usage and apply rate-limiting and abuse-prevention controls to anonymous use.
8.2 We use pseudonymous identifiers for certain usage measurement, rate-limiting, and abuse-prevention functions. We do not store raw IP addresses in the application usage records. Infrastructure providers may still process IP addresses and request metadata as part of delivering, securing, and operating the Service.
9. Account and Authentication Data
9.1 If you create an account, we process account and profile information such as your email address, account creation date, account status, selected plan, and subscription and deletion status.
9.2 Registered users receive credentials used to authenticate API requests. You are responsible for keeping your credentials confidential.
9.3 We provide one or more authentication methods, which may include third-party sign-in or email-based authentication. If you choose third-party sign-in, we receive information from that provider to identify your account (such as a verified email address). We process authentication state and session information to keep you signed in to the customer panel.
10. Billing and Subscription Data
10.1 Paid plans are billed through our payment processor, Stripe, with whom you interact directly during checkout. Stripe independently processes your payment information under its own terms and privacy policy.
10.2 Full payment-card details are collected and processed by Stripe and are not stored on Labelixa application servers. We do not claim to receive no billing information: we receive limited information necessary to operate your subscription, such as a payment-processor customer identifier, a subscription identifier, subscription status, the billing interval, paid-period information, and limited transaction or billing metadata.
10.3 We use this information to administer your plan, apply your quota, manage renewals and cancellation, and keep records required by law.
11. Support Communications
11.1 If you contact support, we may process the sending email address, the content of your message, any account or billing information you choose to provide, and any attachments you submit.
11.2 We retain support communications for as long as reasonably necessary to resolve the request, maintain appropriate business records, comply with law, and establish or defend legal claims.
12. Cookies and Similar Technologies
12.1 The Service uses a small number of cookies that are necessary to operate it:
- Authentication session cookie — keeps you signed in to the customer panel; lasts up to 30 days; necessary for authenticated panel access.
- Authentication-security cookies — protect the sign-in flow against request forgery and, when you start signing in from a tool page, remember which page to return you to; last approximately 10 minutes; necessary for the login process.
- Language-preference cookie — remembers the site language you selected; lasts up to one year; not used for advertising.
12.2 Labelixa does not currently use non-essential cookies for behavioral advertising or cross-site tracking. Service providers may process technical request information as necessary to deliver, secure, and maintain the Service. We will update this Policy and, where required, provide consent controls before introducing any non-essential tracking technologies.
12.3 A separate Cookie Policy will contain any additional cookie-specific detail.
12.4 Browser local storage (editor draft). When you choose "See saving features" or "Sign in" from the ZPL editor, the label you are working on and its size settings are kept in your browser's local storage for up to 24 hours so they are not lost during sign-in or checkout, together with a one-word note of what you were doing (for example "save"). This data stays on your device: it is not transmitted to Labelixa, is not placed in any URL and is not used for analytics. It is deleted when the editor restores it or after 24 hours, and you can clear it at any time through your browser's site-data controls.
13. Categories of Recipients
We may disclose personal data to the following categories of recipients, where relevant and subject to appropriate safeguards:
- payment and subscription service providers;
- service providers that host, secure, maintain, and deliver the Service;
- authentication and transactional communication providers;
- professional advisers, where reasonably necessary;
- public authorities, where disclosure is required by law; and
- a successor or transaction party in a merger, acquisition, reorganization, or sale.
We identify our payment processor (Stripe) in Section 10 because you interact with it directly during checkout. We do not otherwise name individual service providers in this Policy.
14. International Data Transfers
14.1 Newempo LLC is established in the United States. Personal data may be processed in the United States and in other countries where our service providers operate. Privacy and data-protection laws may differ between these countries.
14.2 Where applicable law requires a safeguard for an international transfer, the required safeguard will be implemented before that transfer is carried out. We do not claim that any particular transfer mechanism is already in place. Transfer arrangements for business-customer data may also be addressed in an applicable DPA.
15. Data Retention
15.1 We retain personal data for different periods depending on the purpose and the type of data, as described below.
15.2 Certain retention periods for application data are:
- content you save (labels, folders and their version history): kept for as long as your account keeps it — there is no time-based expiry on saved content;
- content you delete (trash): permanently removed 30 days after deletion, together with its version history and its activity record;
- activity records for saved content: up to approximately 13 months (396 days);
- fonts you add to your account font library: kept for as long as your account keeps them — there is no time-based expiry;
- output files of a bulk job (kept so that you can download them): 7 days;
- print job payloads waiting for your local print agent to collect them: deleted as soon as the job is collected and reported, and in any case within 24 hours (a print history entry is kept without the label content);
- files you upload but do not save: 24 hours;
- registered-user usage records: up to approximately 13 months (396 days);
- anonymous pseudonymous usage records: up to 90 days;
- short-term rate-limiting records: approximately 60 seconds;
- local payment-event identifiers used for duplicate-event protection: up to 30 days;
- authenticated panel session: up to 30 days;
- authentication-security state: approximately 10 minutes;
- language preference: up to one year.
15.3 Account information is retained while your account remains active and as needed to provide the Service. When you delete an account (Section 16):
- for a free or non-subscription account, linked live account records are removed without undue delay;
- where a paid period remains, renewal is cancelled first, your access continues until the paid period ends, and final live-account deletion occurs after that period;
- if a subscription cancellation cannot be completed, local account deletion does not proceed;
- payment-processor financial records may remain for legal, accounting, fraud-prevention, and compliance purposes; and
- residual copies may remain in rolling backups until those backups expire under provider-controlled retention cycles. We cannot promise immediate deletion from backups.
15.4 Provider-controlled retention. Some service providers retain information according to their own legally permitted retention periods and operational settings. We seek to retain personal data only for as long as reasonably necessary for the purposes described in this Policy, subject to legal, security, accounting, dispute-resolution, and provider-controlled retention requirements.
16. Account Deletion
16.1 You may request deletion of your account from the customer panel using an authenticated session and email confirmation, or by contacting [email protected]. Identity verification may be required. Account deletion is intended to be irreversible.
16.2 Free or non-subscription accounts. On a confirmed request, your API access is invalidated, linked live account and usage records are removed, and your session is ended.
16.3 Paid accounts. Your subscription renewal is cancelled first, your access continues until the paid period ends, and your account enters a pending-deletion state; final live-account deletion occurs after the paid period ends. If the subscription cancellation cannot be completed, local account deletion does not proceed.
16.4 Deletion does not require immediate deletion of payment-processor financial records or of residual copies in rolling backups, and mandatory legal exceptions may apply.
17. Security
17.1 Newempo LLC uses reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. Safeguards are selected according to the nature of the data and the level of risk.
17.2 No method of transmission or storage is completely secure, and we cannot provide an absolute guarantee of security.
18. Privacy Rights
18.1 Depending on your jurisdiction and the context, you may have rights to access, correct, delete, restrict, or object to processing; to data portability; to withdraw consent where processing relies on consent; to complain to a supervisory authority; and to non-discrimination for exercising your rights.
18.2 Your rights depend on jurisdiction and context. Identity verification may be required, and requests may be denied or limited where legally permitted — for example, where legal, security, fraud-prevention, accounting, or dispute-resolution obligations apply.
18.3 Where the personal data relates to label content submitted by a business customer, the individual may need to contact the business that submitted the information. Where Newempo LLC acts as processor, we may direct the requester to the relevant business customer and assist that customer as required by an applicable DPA.
18.4 To exercise a right, contact [email protected].
19. EEA and UK Rights
19.1 Where the GDPR or the UK GDPR applies, you have the rights described in Section 18 as provided by that law.
19.2 We generally handle requests within the timeframe required by applicable law. That period may be extended where legally permitted due to the complexity or number of requests, and we will inform you if an extension is used.
19.3 You may lodge a complaint with a competent supervisory authority.
20. California and Other US-State Privacy Rights
20.1 Residents of certain US states may have privacy rights, depending on whether the relevant state law applies to Newempo LLC and to the processing. Applicable rights may include access, correction, deletion, portability, opt-out, appeal, or non-discrimination, depending on the jurisdiction.
20.2 Under the current Labelixa business model, Newempo LLC does not sell personal information for monetary consideration and does not use personal information for cross-context behavioral advertising. Whether a particular state privacy law applies depends on its statutory scope and thresholds.
20.3 To submit a request, contact [email protected]. Identity verification may be required.
21. Children
21.1 The Service is intended for persons aged 18 or older. It is not directed to children, and we do not knowingly permit children to register for accounts.
21.2 A parent or guardian who believes a child has submitted personal data may contact [email protected].
22. Automated Decision-Making and Profiling
22.1 The current confirmed Service does not use personal data to make solely automated decisions that produce legal or similarly significant effects concerning you.
22.2 The Service uses automated technical processes for functions such as quota enforcement, rate limiting, subscription administration, abuse prevention, and security.
23. Do Not Track and Global Privacy Control
23.1 The Service does not currently use behavioral advertising or cross-site tracking technologies in the confirmed implementation. Because there is no such tracking to opt out from in the current implementation, browser signals such as "Do Not Track" or Global Privacy Control may not change how the Service behaves.
23.2 Where applicable law requires recognition of a legally valid opt-out preference signal in the future, we will implement and disclose the relevant process before using covered tracking technologies.
24. Marketing Communications
24.1 The Service currently uses service-related and transactional communications. The current confirmed application does not operate a marketing-email program as part of the Service.
24.2 If we introduce optional marketing communications, we will update this Policy and any required consent or opt-out process before doing so.
25. Changes to This Privacy Policy
25.1 We may update this Policy from time to time. When we do, we will change the Effective Date and, where required by law, communicate material changes by reasonable means. We will obtain your affirmative consent only where applicable law requires it. Continued browsing alone does not always constitute valid consent to changes.
26. Contact
You may contact us about this Policy at:
Newempo LLC 30 N Gould St #40045 Sheridan, WY 82801, USA
Email: [email protected]
The address above is Newempo LLC's legal notice and mailing address.
27. Language and Translations
27.1 English is the version we maintain and update for this Policy. We may provide translations for convenience; where we do, we intend them to convey the same information. Any mandatory local-language transparency requirement that applies to you continues to apply.
27.2 If you identify a discrepancy between versions, please contact [email protected].