Privacy Policy
Last updated: August 25, 2026
This Privacy Policy describes how Flex Bundles ("we", "us", or "our") collects, uses, stores, and shares information when you install and use our Shopify app.
Information We Collect
Merchant Account & Staff Information
When you install and authenticate Flex Bundles, Shopify provides and we store in our database:
- Your Shopify store domain
- Access and refresh tokens used for API communication
- Identifying details for the Shopify staff user who authenticated, including user ID, first and last name, email address, locale, and account-owner/collaborator role flags
- If you generate a key for the Bundles API, a SHA-256 hash of that key (never the key itself) along with when it was created and last used
Demo Requests
If you request a demo through the form on this website, we collect the name, email address, store URL, Shopify plan, and message you provide. This information is emailed to us through Resend, our email delivery provider, and used only to respond to your request. If you choose to book a time with Calendly, whether from this website or from the app's setup guide, any information you provide there is collected by Calendly under its own privacy policy.
Store Data Accessed Through Shopify's API
To create and manage bundles and report on their performance, the app requests permission to read and write the following types of store data through Shopify's API: products, inventory, orders, order edits, customers, files, cart transforms, and publications. We access this data only as needed to operate the app's features.
Order, Analytics & Bundle Data
When orders are placed, updated, or refunded, we process order data to power bundle analytics and reorder features. To provide analytics with full history, we store order-level analytics records in our database:
- Per-order facts: the Shopify order ID, order date, order total, currency, and whether the order contained a bundle
- For orders containing bundles: which bundles were sold, their revenue and units, and the component products, variants, and quantities
- Refund amounts, so analytics figures are net of refunds
These records contain no customer information: no names, email addresses, shipping or billing addresses, and no payment details. If you start the optional order history import from the Analytics page, we import the same order-level facts for past orders, reaching back to when you installed the app plus roughly 90 days before that as a comparison baseline.
Some data is stored within your own Shopify store as metafields, not in our database:
- Per-order bundle breakdowns saved to order metafields
- Bundle component selections saved to a customer metafield (keyed by the Shopify customer ID, limited to the most recent 20 entries) so customers can easily reorder previous bundles
How We Use Your Information
We use the information we collect to:
- Authenticate your access to the app
- Provide bundle creation, management, and reorder functionality
- Display analytics on your bundle performance
- Determine your plan tier from your Shopify subscription status
- Communicate with you about your account and onboarding
Data Storage, Location & Retention
Session, staff-user, and order-level analytics data is stored securely in a PostgreSQL database hosted on Neon (on AWS infrastructure in the United States); the application itself is hosted on Heroku. Bundle configuration and customer-specific bundle component selections (used for reordering) live inside your own Shopify store as metafields and remain under your control. Analytics records are retained for as long as the app remains installed, with no rolling window, so your reports keep their full history. Session data is automatically removed on uninstall, and all remaining shop data, including session records, API key hashes, and analytics records, is deleted no later than 48 hours after uninstall via Shopify's shop redaction webhook.
Data Sharing & Subprocessors
We do not sell, rent, or share your personal information for marketing purposes. We rely on the following service providers to operate the app:
- Shopify: the platform the app runs on and the source of store data
- Heroku: application hosting
- Neon: database hosting
- Papertrail: application log management (logs may include your store domain and order IDs, never customer names, emails, addresses, or payment details)
- Calendly: demo scheduling, only if you choose to book a demo
We may also disclose information if required by law or to protect our rights.
Your Rights
You may request access to, correction of, or deletion of your personal information by contacting us. We respond to data requests in compliance with GDPR and other applicable privacy regulations.
Shopify Data Compliance
We comply with Shopify's API terms and implement the mandatory privacy webhooks:
- Customer data request: we hold no customer personal data in our own database and respond accordingly. Any bundle-selection data lives in your own store's customer metafields, which you can access directly.
- Customer redaction: we delete the customer's stored bundle-selection metafield.
- Shop redaction: we delete the store's session records, API key records, and order-level analytics records from our database.
Contact Us
For privacy questions or data requests, contact:
Email: robbie@handstand.codes
Mail: Handstand, 1000 Main Street, Unit #2163, Pittsburgh, PA 15215, US