Cobundle — Privacy Policy
Effective October 4, 2026
Cobundle (“the app”, “we”) is a Shopify app that lets merchants offer product bundles with automatic discounts. This policy explains what data the app processes. In short: the app stores no personal information about your customers.
What we access and store
- Store & authentication data. When you install the app, Shopify provides an access token so the app can operate on your store. Sessions are stored securely by the app.
- Product and bundle configuration. The bundles you configure (product/variant IDs, discount tiers, and settings) are stored in your own shop’s Shopify metafields and mirrored onto the app’s automatic discount. This contains no customer data.
- Anonymous usage analytics. To show you how bundles perform (views, add-to-carts, conversion), the storefront widget sends anonymous events. Each event carries a random, per-page-load identifier used only to compute conversion — it is not linked to any person, email, IP address, or Shopify customer. Add-to-cart events also record the bundle's discounted value, used only to measure your plan's monthly bundle sales.
- Emails to you. We use your store’s contact email (provided by Shopify) to send plan and usage emails, such as when you’re close to or past your plan’s monthly bundle orders, and a monthly recap. Every one has an unsubscribe link. We keep a record of which of these emails were sent and whether you’ve unsubscribed. Emails are delivered by our email provider, Resend.
- Partner referrals (optional). If an agency or partner referred you and you enter their partner code, we record which partner referred your store, plus when the app was first installed (the code can be entered for 30 days). To pay partner commissions we use the app billing records Shopify provides to app developers (store domain and amounts billed for the app). This contains no customer data. If a store’s referral is forfeited under the partner rules, we keep a keyed one-way hash of the store domain (never the domain itself), even after shop redaction, only to stop that store being credited to the same partner again.
- Partner links. Partners share links such as cobundle.org/r/<code>, which pass through the app server on the way to Cobundle’s Shopify App Store listing. For each click on an active partner’s link we record the partner, the time, the link path, the domain of the referring website, any UTM campaign tags, and one-way hashes of the visitor’s IP address and browser user agent. The hashes are keyed with a secret and scoped to each day; we don’t use them to match visitors across days, only to count unique same-day clicks and limit abuse. We don’t store the IP address or user agent itself, set cookies, or link a click to a store or a person. Click records are kept for partner reporting for as long as the partner’s account exists.
What we do NOT collect
We do not collect, store, or process customer personal data — no names, emails, addresses, phone numbers, IP addresses, order details, or payment information. (Partner-link clicks, described above, store only a daily-changing hash of the visitor’s IP address, never the address itself.) The app’s access is limited to managing discounts and reading product information (write_discounts, read_discounts, read_products).
How data is used
Data is used solely to provide the app’s functionality — applying bundle discounts at checkout and showing you bundle analytics in the admin, plus the plan and usage emails described above. We do not sell data or use it for advertising. We share data only with service providers that run the app for us: hosting, our database, and Resend for email delivery.
Retention and deletion
- Analytics events are automatically deleted after 90 days.
- When you uninstall the app, your bundle configuration and session data are removed.
- We honor Shopify’s mandatory GDPR/CCPA compliance webhooks (customer data request, customer redact, shop redact). Because the app stores no customer personal data, a customer-data request or redaction has no personal data to return or erase; shop redaction removes the shop’s stored records (including email logs and email preferences), except partner commission records (store domain and amounts billed), which we keep as financial records of payments to partners.
Security
Data is stored in a managed, access-controlled database. Credentials are held as encrypted environment secrets and are never exposed to the storefront or committed to source control.
Changes
We may update this policy; material changes will be reflected on this page with a new effective date.
Contact
Questions about this policy or your data? Contact us at nathan@sacredscaling.com.