Privacy Policy

Bundle & Upsell Suite — Privacy Policy

Effective date: July 15, 2026

This Privacy Policy explains how the Bundle & Upsell Suite application (the “App”, “we”, “us”) collects, uses, stores and protects information when a Shopify merchant (the “Merchant”, “you”) installs and uses the App on a Shopify store, and when visitors of that store (“Customers”) interact with the storefront widgets the App provides (bundles, volume discounts, “pair with” recommendations, product add-ons and cart upsell).

Summary: The App is a merchant-facing sales tool. It reads your store’s products, themes and orders to build and display offers, and it creates automatic discounts. It stores your promotion settings and anonymous performance analytics. It does not store customer personal data — no names, emails, addresses or payment details.
Contents
  1. Who we are
  2. What data we access and store
  3. Customer (shopper) data
  4. How and why we use data
  5. Shopify permissions we request
  6. Sharing & sub-processors
  7. Storage, security & location
  8. Data retention & deletion
  9. Cookies & tracking
  10. Your rights (GDPR / CCPA)
  11. Children’s data
  12. Changes to this policy
  13. Contact us

1. Who we are

Bundle & Upsell Suite is the developer and data controller/processor for the App. The App is distributed through the Shopify App Store and runs as an embedded Shopify admin app together with a theme app extension that renders widgets on your storefront. You can reach us at xpapion@gmail.com.

With respect to store and order data processed on your behalf, you (the Merchant) are the data controller and we act as your data processor. Shopify is the platform provider.

2. What data we access and store

The App accesses the following categories of data through Shopify’s official APIs and webhooks, using only the permissions you grant at installation:

CategoryExamplesDo we store it?Purpose
Store & account Store domain (*.myshopify.com), Shopify access token, staff user id / name / email associated with the installing session, granted scopes Yes Authenticate the App and keep it connected to your store
Product catalog Product & variant ids, titles, images, prices, handles, inventory/status, collections, publications Snapshots only (title/image/price/handle needed to render widgets) Let you select products for offers and display them on the storefront
Discounts Automatic discount configurations created by the App via Shopify Functions The discount id is stored; the discount itself lives in Shopify Apply your bundle / volume / “bought together” discounts at checkout
Themes Read access to theme information for widget placement No Auto-place widgets in the correct spot on product pages / cart drawer
Orders Order id, line items, line prices/quantities, and the App’s own line-item properties (e.g. _bs_bundle) Only order id, attributed revenue, and which offer was used Measure which offers drove sales (attribution & revenue reporting)
Promotion settings Your bundles, volume discounts, add-ons, cross-sell and cart-upsell rules, and widget appearance settings Yes Store your configuration so your offers work across sessions
Widget analytics Event type (impression / add-to-cart / order), the module (bundle, pair, add-on, cart upsell) and an internal offer id Yes (aggregated, non-identifying) Show you performance metrics in the App dashboard
Important about order data: the App subscribes to the orders/create webhook and has read_orders access. Order payloads delivered by Shopify may contain customer information, but the App reads only the line items and their prices/properties to calculate attribution. We do not read, store or transmit customer names, email addresses, shipping/billing addresses, phone numbers or payment information.

3. Customer (shopper) data

The storefront widgets run in the shopper’s browser to display offers and add products to the Shopify cart. In doing so:

4. How and why we use data

We do not use your data for advertising and we do not sell it.

5. Shopify permissions we request

At installation the App requests only the access scopes it needs to function:

ScopeWhy it is needed
read_products, write_productsRead products/variants for offers; create hidden linked products for paid add-ons
write_discountsCreate and manage the automatic discounts that power bundle, volume and “bought together” offers
read_ordersAttribute completed orders to the offers that generated them (for your reporting)
read_themesDetect where to place widgets on your storefront
read_publications, write_publicationsPublish add-on products to your sales channels so they are purchasable

6. Sharing & sub-processors

We do not sell your data. We share data only with the infrastructure providers required to run the App:

Sub-processorPurpose
Shopify Inc.Platform, APIs, webhooks, checkout and discount execution
Railway (application hosting & PostgreSQL database)Hosts the App server and stores the data described above

We may also disclose information if required by law or to protect our rights and users’ safety.

7. Storage, security & location

8. Data retention & deletion

9. Cookies & tracking

10. Your rights (GDPR / CCPA and similar laws)

Depending on your jurisdiction, you and your customers may have rights to access, correct, delete, restrict or port personal data, and to object to certain processing. Because the App does not store customer personal data, shopper requests are typically handled directly by the Merchant in Shopify. For data the App holds on your behalf, contact us and we will assist. You may also lodge a complaint with your local data protection authority.

11. Children’s data

The App is a business tool for merchants and is not directed to children. We do not knowingly collect data from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Effective date” above and, where appropriate, by notifying you. Continued use of the App after changes take effect constitutes acceptance of the updated policy.

13. Contact us

Questions or requests regarding this Privacy Policy or your data can be sent to:

Bundle & Upsell Suite
Email: xpapion@gmail.com