Solid Bundles — Privacy Policy
Last updated: July 15, 2026
Who we are
Solid Bundles ("the App") helps Shopify merchants create and monitor product bundles. This policy describes what data the App accesses and stores when a merchant installs it.
Data we access and why
- Products, variants, inventory levels — to create bundle products, compute per-location availability, and keep bundle inventory in sync.
- Orders (line items only) — to detect bundle purchases, adjust component inventory, and route fulfillment to the merchant's selected location. Order payloads are processed in memory; we act only on product and variant identifiers.
- Themes (publish events) — to trigger an immediate bundle health check after a theme change.
- Shop information — shop domain and an optional notification email for merchant alerts.
Data we store
- Bundle definitions (titles, prices, component product/variant IDs, selected fulfillment locations).
- Health check history (pass/fail results and timestamps).
- An encrypted offline API session token, as required by Shopify apps.
- We do not store customer personal information. No names, addresses, emails, or payment details of the merchant's customers are persisted.
Data sharing
We do not sell or share merchant data with third parties. We do not use personal data for advertising, profiling, or automated decision-making.
Security
All data is encrypted in transit (HTTPS/TLS is enforced on every request) and at rest on encrypted storage volumes. Webhook deliveries are verified with HMAC signatures.
Data retention and deletion
- On app uninstall, API access is revoked immediately by Shopify.
- On Shopify's
shop/redactrequest (48 hours after uninstall), all stored data for the shop — bundles, health history, session, shop record — is permanently deleted automatically. customers/data_requestandcustomers/redactare handled automatically; as no customer data is stored, there is nothing to export or erase.
GDPR / CCPA
The App implements Shopify's mandatory compliance webhooks. Merchants may also request deletion at any time by contacting support.
Contact
Support and privacy requests: djroyb@gmail.com