Privacy Policy
Last updated: July 13, 2026
This Privacy Policy describes how Flex Bundles ("we", "us", or "our") collects, uses, stores, and shares information when you install and use our Shopify app.
Information We Collect
Merchant Account & Staff Information
When you install and authenticate Flex Bundles, Shopify provides and we store in our database:
- Your Shopify store domain
- Access and refresh tokens used for API communication
- Identifying details for the Shopify staff user who authenticated, including user ID, first and last name, email address, locale, and account-owner/collaborator role flags
- If you generate a key for the Bundles API, a SHA-256 hash of that key (never the key itself) along with when it was created and last used
Install Notifications & Demo Bookings
When you install the app, we receive your store name, store domain, account owner email address, and Shopify plan from Shopify's API and use them to send ourselves a one-time install notification email so we can offer onboarding support. This information is delivered by email and is not retained in our application database.
If you choose to book a demo from the app's setup guide, scheduling is handled by Calendly, and any information you provide there is collected by Calendly under its own privacy policy.
Store Data Accessed Through Shopify's API
To create and manage bundles and report on their performance, the app requests permission to read and write the following types of store data through Shopify's API: products, inventory, orders, order edits, customers, files, cart transforms, and publications. We access this data only as needed to operate the app's features.
Order, Analytics & Bundle Data
When orders are placed or updated, we process order data to power bundle analytics and reorder features. The data we generate is stored within your own Shopify store as metafields, not in our database, and includes:
- Aggregate bundle metrics (revenue, units sold, order totals, currency) saved to your shop metafields and pruned to a rolling 60-day window
- Per-order bundle breakdowns saved to order metafields
- Bundle component selections saved to a customer metafield (keyed by the Shopify customer ID, limited to the most recent 20 entries) so customers can easily reorder previous bundles
We do not store customer names, addresses, or payment details, and we do not copy this order or customer data into our own database.
How We Use Your Information
We use the information we collect to:
- Authenticate your access to the app
- Provide bundle creation, management, and reorder functionality
- Display analytics on your bundle performance
- Determine your plan tier from your Shopify subscription status
- Communicate with you about your account and onboarding
Data Storage, Location & Retention
Session and staff-user data is stored securely in a PostgreSQL database hosted on Neon (on AWS infrastructure in the United States); the application itself is hosted on Heroku. Bundle configuration, analytics, and customer-specific bundle component selections (used for reordering) live inside your own Shopify store as metafields and remain under your control. We retain session data for as long as the app remains installed; it is automatically removed on uninstall, and any remaining shop data, including session records and API key hashes, is deleted no later than 48 hours after uninstall via Shopify's shop redaction webhook. Aggregate analytics are automatically pruned to the most recent 60 days.
Data Sharing & Subprocessors
We do not sell, rent, or share your personal information for marketing purposes. We rely on the following service providers to operate the app:
- Shopify: the platform the app runs on and the source of store data
- Heroku: application hosting
- Neon: database hosting
- Resend: delivery of onboarding and notification emails
- Papertrail: application log management (logs may include your store domain and order IDs, never customer names, emails, addresses, or payment details)
- Calendly: demo scheduling, only if you choose to book a demo
We may also disclose information if required by law or to protect our rights.
Your Rights
You may request access to, correction of, or deletion of your personal information by contacting us. We respond to data requests in compliance with GDPR and other applicable privacy regulations.
Shopify Data Compliance
We comply with Shopify's API terms and implement the mandatory privacy webhooks:
- Customer data request: we hold no customer personal data in our own database and respond accordingly. Any bundle-selection data lives in your own store's customer metafields, which you can access directly.
- Customer redaction: we delete the customer's stored bundle-selection metafield.
- Shop redaction: we delete the store's session records and API key records from our database.
Contact Us
For privacy questions or data requests, contact:
Email: robbie@handstand.codes