Who this applies to
This policy covers:
- Merchants who install and use BundleWise on Shopify
- Data that flows through Shopify APIs, webhooks, app proxy routes, and our app database
- Messages you send us for support or account help
Shopify handles its own platform data under Shopify's privacy policy. That is separate from this page.
Shopify permissions we use
BundleWise asks for Shopify API scopes that match what the app actually does. Here is what each one is for:
read_customersLook up a customer email when we need it for Next Order Coupon delivery.
read_ordersRun order-based automations and check whether a reward qualifies.
read_productsPower product pickers and read product/variant data for your campaigns.
write_productsUpdate product data when a feature in the app requires it.
read_discountsLoad existing Shopify discounts tied to your campaigns.
write_discountsCreate and update discounts that BundleWise generates in Shopify.
read_script_tagsCheck existing storefront script tags.
write_script_tagsAdd or update the preview script tag on your theme.
write_app_proxyServe storefront endpoints under /apps/discount/*.
read_metaobject_definitionsRead metaobject definitions for platform compatibility.
write_metaobject_definitionsWrite metaobject definitions when the app needs them.
We do not request broad marketing or customer scopes beyond what the features above need.
What we collect
Shop & installation
- Shop domain
- OAuth session details (scopes, token expiry, Shopify user/account metadata)
- Whether you finished in-app onboarding
Campaigns & discounts
- Campaign name, type, status, and configuration
- Linked Shopify discount IDs
- Discount codes the app creates (code, type, usage settings)
Storefront analytics
- Campaign events (impression, add to cart) with optional campaign ID, session key, timestamp, and shop
- Product view events (product ID, optional variant ID, viewer key, timestamp, shop)
sessionKey lives in the browser's sessionStorage. viewerKey lives in localStorage. Both are random IDs for counting, not profiles of individual shoppers.Next Order Coupon
- Order ID, campaign ID, generated code, and Shopify discount ID
- A matching key like
cust:<customerId>orem:<email> - Optional expiry and whether the reward email was sent
Email (if you turn it on)
- Recipient address from Shopify webhooks or admin lookups
- Send status so we do not email the same reward twice
We do not store email open or click tracking in our database.
How we use it
We use this data to run the app, for example:
- Log you in and secure app proxy requests
- Create, sync, and show your discount campaigns
- Report impressions and add-to-cart trends in the dashboard
- Power Stock Scarcity counters and Next Order Coupon flows
- Respond to Shopify privacy webhooks when required
We do not sell merchant or customer data.
How long we keep it
We keep data while your shop uses BundleWise and as long as we need it for security, billing disputes, or legal requirements.
Shopify compliance webhooks also trigger deletion:
customers/redact, removes customer-linked Next Order Coupon records for that shopshop/redact, removes shop data across sessions, campaigns, analytics, and related tablesapp/uninstalled, clears session/onboarding data and unlinks discount IDs on campaigns
Security
We use measures such as:
- App Proxy signature checks on storefront requests
- Validation on IDs and event payloads
- HTTPS in production
- Access controls and logging for operations
No system is 100% secure, but we treat security as ongoing work.
Legal bases
Where privacy law applies, we rely on:
- Performing our contract with you (running the app)
- Legitimate interests (security, fraud prevention, improving the product)
- Legal obligations (including Shopify webhook requirements)
- Consent when the law requires it
Your rights
Depending on where you are, you may have rights to access, correct, delete, or export personal data, or to object to certain processing.
Shopify App Store apps also honor Shopify's mandatory webhooks: customers/data_request, customers/redact, and shop/redact.
International transfers
Our infrastructure may process data in countries other than yours. When required, we use appropriate safeguards for cross-border transfers.
Changes to this page
We update this policy when the app or legal requirements change. The date at the top of the page is the latest revision.
Contact us
Privacy questions or requests:
- Email[email protected]
- Support[email protected]
- CompanyDeveloperLook
- LocationSheridan, Wyoming, United States