Privacy Policy

Last updated: July 13, 2026

This Privacy Policy describes how Flex Bundles ("we", "us", or "our") collects, uses, stores, and shares information when you install and use our Shopify app.

Information We Collect

Merchant Account & Staff Information

When you install and authenticate Flex Bundles, Shopify provides and we store in our database:

  • Your Shopify store domain
  • Access and refresh tokens used for API communication
  • Identifying details for the Shopify staff user who authenticated, including user ID, first and last name, email address, locale, and account-owner/collaborator role flags
  • If you generate a key for the Bundles API, a SHA-256 hash of that key (never the key itself) along with when it was created and last used

Install Notifications & Demo Bookings

When you install the app, we receive your store name, store domain, account owner email address, and Shopify plan from Shopify's API and use them to send ourselves a one-time install notification email so we can offer onboarding support. This information is delivered by email and is not retained in our application database.

If you choose to book a demo from the app's setup guide, scheduling is handled by Calendly, and any information you provide there is collected by Calendly under its own privacy policy.

Store Data Accessed Through Shopify's API

To create and manage bundles and report on their performance, the app requests permission to read and write the following types of store data through Shopify's API: products, inventory, orders, order edits, customers, files, cart transforms, and publications. We access this data only as needed to operate the app's features.

Order, Analytics & Bundle Data

When orders are placed or updated, we process order data to power bundle analytics and reorder features. The data we generate is stored within your own Shopify store as metafields, not in our database, and includes:

  • Aggregate bundle metrics (revenue, units sold, order totals, currency) saved to your shop metafields and pruned to a rolling 60-day window
  • Per-order bundle breakdowns saved to order metafields
  • Bundle component selections saved to a customer metafield (keyed by the Shopify customer ID, limited to the most recent 20 entries) so customers can easily reorder previous bundles

We do not store customer names, addresses, or payment details, and we do not copy this order or customer data into our own database.

How We Use Your Information

We use the information we collect to:

  • Authenticate your access to the app
  • Provide bundle creation, management, and reorder functionality
  • Display analytics on your bundle performance
  • Determine your plan tier from your Shopify subscription status
  • Communicate with you about your account and onboarding

Data Storage, Location & Retention

Session and staff-user data is stored securely in a PostgreSQL database hosted on Neon (on AWS infrastructure in the United States); the application itself is hosted on Heroku. Bundle configuration, analytics, and customer-specific bundle component selections (used for reordering) live inside your own Shopify store as metafields and remain under your control. We retain session data for as long as the app remains installed; it is automatically removed on uninstall, and any remaining shop data, including session records and API key hashes, is deleted no later than 48 hours after uninstall via Shopify's shop redaction webhook. Aggregate analytics are automatically pruned to the most recent 60 days.

Data Sharing & Subprocessors

We do not sell, rent, or share your personal information for marketing purposes. We rely on the following service providers to operate the app:

  • Shopify: the platform the app runs on and the source of store data
  • Heroku: application hosting
  • Neon: database hosting
  • Resend: delivery of onboarding and notification emails
  • Papertrail: application log management (logs may include your store domain and order IDs, never customer names, emails, addresses, or payment details)
  • Calendly: demo scheduling, only if you choose to book a demo

We may also disclose information if required by law or to protect our rights.

Your Rights

You may request access to, correction of, or deletion of your personal information by contacting us. We respond to data requests in compliance with GDPR and other applicable privacy regulations.

Shopify Data Compliance

We comply with Shopify's API terms and implement the mandatory privacy webhooks:

  • Customer data request: we hold no customer personal data in our own database and respond accordingly. Any bundle-selection data lives in your own store's customer metafields, which you can access directly.
  • Customer redaction: we delete the customer's stored bundle-selection metafield.
  • Shop redaction: we delete the store's session records and API key records from our database.

Contact Us

For privacy questions or data requests, contact:
Email: robbie@handstand.codes