1. Introduction
Bundle Optimizer processes merchant, store, and operational commerce data from Shopify, plus the settings merchants add inside the app. This Privacy Policy explains what we collect, how we use it, how long we keep it, and the rights available to merchants and customers.
2. What We Collect
We may collect and process the following categories of information:
Store and account information
Shop domain, plan and billing status, timezone and currency settings, and store contact details made available through Shopify.
Merchant authentication and audit data
Shopify session records and app authentication data, which may include merchant or staff user ID, name, email address, account-owner flag, locale, and encrypted access tokens. We use this for secure access, operational notices, and to understand who triggered certain actions in the app.
Product, inventory, and location data
Product titles, variant titles, SKUs, barcodes, pricing, compare-at pricing, unit cost, inventory quantities, inventory item IDs, tags, product type, vendor, product images, and location-level inventory facts used to discover which products sell together and choose bundle actions.
Order and bundle performance data
Recent order-line facts and bundle performance records used to calculate product relationship, attach rate, attribution, and bundle outcomes. This can include order IDs, product or variant IDs, quantities, prices, order timestamps, source channel, shipping country code, discount identifiers, and campaign outcome data.
Merchant-provided inputs
Automation rules, AI context notes, storefront campaign settings, approval choices, and other configuration data entered in the app.
3. How We Use Information
We use the information described above solely to provide and improve Bundle Optimizer's services. This includes:
- Analyzing product movement and which products sell together over time.
- Calculating product relationships, bundle readiness, and bundle opportunities.
- Generating AI-assisted bundle plans, recommendations, and campaign copy.
- Creating and tracking Shopify discount codes, bundles, tags, and storefront campaign assets when a merchant launches a bundle.
- Recording merchant approvals, overrides, state transitions, sync attempts, and bundle outcomes for support, rollback, and audit purposes.
- Sending operational reminders, audit notices, and privacy-response emails when needed.
- Processing billing and subscription management through Shopify.
- Maintaining service reliability, troubleshooting issues, and improving store-specific recommendations.
- Using infrastructure and application telemetry for security, fraud prevention, cost control, and service monitoring.
- Recording GDPR webhook handling and operational access events so privacy requests and security incidents can be audited.
We never sell, rent, or share store data with third parties for marketing or advertising purposes.
The embedded app is designed without third-party advertising trackers. If we introduce product analytics tooling in the future, we will update this policy before using it for merchant-facing behavior analysis.
4. AI Processing
Bundle Optimizer sends selected store-operational data to an AI service to generate bundle recommendations and merchant-facing copy. This may include product titles, variant titles, SKUs, prices, inventory levels, relationship metrics, campaign context, and merchant notes or preferences relevant to the recommendation.
This AI input is not fully anonymized because product and SKU data can identify items in a merchant's catalog. It is intentionally limited to business and operational data. We do not send customer names, payment details, or full customer contact records to the AI service as part of the normal recommendation pipeline.
We may also use store-level operational outcomes, such as which recommendations were accepted, campaign settings, and attributable bundle revenue, to improve future recommendations for that merchant.
5. Data Retention and Deletion
- Bundle Optimizer uses recent order history, typically the last 60 days, to power relationship calculations and bundle analysis.
- We retain merchant, store, and operational data only for as long as it is needed to provide the service, maintain auditability, support rollback and billing workflows, and comply with Shopify or legal obligations.
- If the app is uninstalled, we promptly remove Shopify session data and revoke app access tokens.
- When Shopify later sends the mandatory
shop/redactwebhook, we delete the shop record and related app data unless a longer retention period is required by law. - If the merchant reinstalls during the billing-period restore window, only the minimum non-PII operational data needed to restore paid-for settings is retained until that window ends.
- Some raw attribution records may be pruned after they have been rolled up into longer-term reporting records, but audit and operational history needed to run and support the app may remain while the merchant uses the service.
6. Shopify Privacy Compliance
Bundle Optimizer is designed with privacy by default. We comply with Shopify's mandatory privacy webhooks:
customers/data_request: we review what Bundle Optimizer holds that relates to the request and process the request through our privacy workflow, including the merchant data export endpoint where appropriate.customers/redact: when Shopify provides order IDs to redact, we delete matching order-line records from our database.shop/redact: we delete the shop record and related operational app data from our database after Shopify sends this webhook, unless a legal retention obligation applies.
7. Security
We implement reasonable administrative, technical, and organizational safeguards to protect merchant data against unauthorized access, disclosure, alteration, or destruction.
Examples include:
- MFA on the core control planes we rely on.
- Secret management in Azure Key Vault.
- Authenticated Shopify sessions.
- Redaction of sensitive fields in logs.
- Separation of production and development data where possible.
We protect access tokens and API credentials as sensitive data.
8. Privacy Rights
Merchants and customers may have rights under applicable privacy laws, including rights of access, deletion, correction, and objection. The exact rights depend on local law and the merchant's role as controller for their store data.
Bundle Optimizer assists merchants in responding to privacy requests through Shopify's required privacy webhooks and our merchant data export workflow. Customers should usually submit privacy requests through the merchant or Shopify.
9. Contact Us
For privacy-related requests, data deletion, or questions about this policy:
- Email: privacy@sparande.co.uk
For procurement or sales questions:
- Email: sales@sparande.co.uk
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our product, legal obligations, or processing practices. The latest version will be posted here with the updated effective date.
See also the Bundle Optimizer Terms of Service and the Sparande website privacy notice.