Effective date: July 15, 2026
This Privacy Policy explains how the Bundle & Upsell Suite application (the “App”, “we”, “us”) collects, uses, stores and protects information when a Shopify merchant (the “Merchant”, “you”) installs and uses the App on a Shopify store, and when visitors of that store (“Customers”) interact with the storefront widgets the App provides (bundles, volume discounts, “pair with” recommendations, product add-ons and cart upsell).
Bundle & Upsell Suite is the developer and data controller/processor for the App. The App is distributed through the Shopify App Store and runs as an embedded Shopify admin app together with a theme app extension that renders widgets on your storefront. You can reach us at xpapion@gmail.com.
With respect to store and order data processed on your behalf, you (the Merchant) are the data controller and we act as your data processor. Shopify is the platform provider.
The App accesses the following categories of data through Shopify’s official APIs and webhooks, using only the permissions you grant at installation:
| Category | Examples | Do we store it? | Purpose |
|---|---|---|---|
| Store & account | Store domain (*.myshopify.com), Shopify access token, staff user id / name / email associated with the installing session, granted scopes |
Yes | Authenticate the App and keep it connected to your store |
| Product catalog | Product & variant ids, titles, images, prices, handles, inventory/status, collections, publications | Snapshots only (title/image/price/handle needed to render widgets) | Let you select products for offers and display them on the storefront |
| Discounts | Automatic discount configurations created by the App via Shopify Functions | The discount id is stored; the discount itself lives in Shopify | Apply your bundle / volume / “bought together” discounts at checkout |
| Themes | Read access to theme information for widget placement | No | Auto-place widgets in the correct spot on product pages / cart drawer |
| Orders | Order id, line items, line prices/quantities, and the App’s own line-item properties (e.g. _bs_bundle) |
Only order id, attributed revenue, and which offer was used | Measure which offers drove sales (attribution & revenue reporting) |
| Promotion settings | Your bundles, volume discounts, add-ons, cross-sell and cart-upsell rules, and widget appearance settings | Yes | Store your configuration so your offers work across sessions |
| Widget analytics | Event type (impression / add-to-cart / order), the module (bundle, pair, add-on, cart upsell) and an internal offer id | Yes (aggregated, non-identifying) | Show you performance metrics in the App dashboard |
orders/create webhook and has read_orders access.
Order payloads delivered by Shopify may contain customer information, but the
App reads only the line items and their prices/properties to calculate
attribution. We do not read, store or transmit customer names, email
addresses, shipping/billing addresses, phone numbers or payment
information.
The storefront widgets run in the shopper’s browser to display offers and add products to the Shopify cart. In doing so:
/cart.js) to show relevant recommendations and progress bars.We do not use your data for advertising and we do not sell it.
At installation the App requests only the access scopes it needs to function:
| Scope | Why it is needed |
|---|---|
read_products, write_products | Read products/variants for offers; create hidden linked products for paid add-ons |
write_discounts | Create and manage the automatic discounts that power bundle, volume and “bought together” offers |
read_orders | Attribute completed orders to the offers that generated them (for your reporting) |
read_themes | Detect where to place widgets on your storefront |
read_publications, write_publications | Publish add-on products to your sales channels so they are purchasable |
We do not sell your data. We share data only with the infrastructure providers required to run the App:
| Sub-processor | Purpose |
|---|---|
| Shopify Inc. | Platform, APIs, webhooks, checkout and discount execution |
| Railway (application hosting & PostgreSQL database) | Hosts the App server and stores the data described above |
We may also disclose information if required by law or to protect our rights and users’ safety.
shop/redact request (typically 48 hours after uninstall). On receipt, the App permanently deletes all data associated with your store — bundles, add-ons, cross-sell and cart-upsell rules, analytics events, settings and session records.customers/data_request and customers/redact. Because the App stores no customer personal data, there is nothing to return or erase for these requests; they are acknowledged accordingly.Depending on your jurisdiction, you and your customers may have rights to access, correct, delete, restrict or port personal data, and to object to certain processing. Because the App does not store customer personal data, shopper requests are typically handled directly by the Merchant in Shopify. For data the App holds on your behalf, contact us and we will assist. You may also lodge a complaint with your local data protection authority.
The App is a business tool for merchants and is not directed to children. We do not knowingly collect data from children.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Effective date” above and, where appropriate, by notifying you. Continued use of the App after changes take effect constitutes acceptance of the updated policy.
Questions or requests regarding this Privacy Policy or your data can be sent to:
Bundle & Upsell Suite
Email: xpapion@gmail.com