Privacy Policy
BundleForge · Last updated 6 September 2026
1. Introduction
BundleForge is a Shopify app that lets merchants create and manage product bundles. This policy explains what information the app handles, why, and how long it is kept. It is written to describe the application as it is actually built, rather than to cover functionality BundleForge does not have.
BundleForge is provided by SRAR. In this policy, “we”, “us” and “our” refer to SRAR, and “you” refers to the merchant who installs the app on a Shopify store.
2. Information we collect
BundleForge receives information in two ways: from Shopify through its Admin API when you install and use the app, and directly from you when you configure a bundle. We do not buy information about you from anyone else, and the app has no separate sign-up.
Some of this information can identify a business or a person — a shop domain often includes a trading name — so we treat it carefully even where it is not obviously personal.
3. Shopify store and merchant information
For each store that installs the app, we store:
- the store’s Shopify domain;
- the store’s Shopify identifier;
- the date the app was installed, and if applicable uninstalled;
- record creation and update timestamps.
We also store the authentication records Shopify issues so the app can act on the store’s behalf. These include an access token, a refresh token, the granted permission scopes and expiry information. BundleForge uses offline access tokens, which are tied to the store rather than to an individual staff account.
4. Bundle and product information
When you build a bundle, BundleForge stores the configuration you create, so it can be edited and published later:
- the bundle’s title and description;
- Shopify product and variant identifiers for the bundle and its components;
- pricing configuration, quantities and currency;
- display settings for the storefront block;
- publication status and related timestamps.
This is merchant-authored catalogue configuration. The app requests only the Shopify permissions this requires: read_products, write_products and write_publications.
5. Customer and buyer information
BundleForge does not store your customers’ personal information. Based on our current implementation, the app holds no customer records, names, email addresses, phone numbers, postal addresses, order records, payment details or buyer identifiers. It does not hold carts or browsing histories.
This is enforced by the permissions the app asks for: BundleForge does not request access to customer or order data, so it has no means of reading it.
6. Storefront functionality
BundleForge adds a bundle block to your online store through a Shopify theme app extension. When a shopper adds a bundle to their cart, the block sends the bundle’s product variant to your store’s own Shopify cart endpoint. That request goes to Shopify, not to us.
The block does not intentionally collect shopper identity or behavioural analytics, and does not set cookies or browser storage for tracking. BundleForge contains no analytics or advertising software.
7. How we use information
We use the information described above to:
- authenticate the app with your Shopify store;
- create, update, publish, pause and remove the bundles you configure;
- display your bundles on your storefront;
- keep our records consistent with Shopify when products change;
- diagnose errors and keep the service working.
We do not use your information for advertising, and we do not profile your customers.
8. How we share information
We do not sell your information, and we do not share it with third parties for their own marketing. Information is shared only with Shopify — as an inherent part of operating an app on its platform — and with the infrastructure providers below who process it on our behalf so the service can run.
We may also disclose information where we are legally required to do so.
9. Service providers
BundleForge relies on the following providers:
- Shopify — the platform the app runs on. Shopify operates your store and handles your customers’ data under its own privacy terms.
- Vercel — application hosting.
- Neon — the managed PostgreSQL database, provisioned through Vercel’s integration, where the records described above are stored.
These providers process information so that BundleForge can operate. Their own handling of that information is governed by their respective terms and privacy policies.
10. Data retention and deletion
When you uninstall BundleForge, the app marks your store as uninstalled and deletes the Shopify authentication records for it. Your bundle configuration is kept at that point, so that reinstalling restores your work rather than making you rebuild it.
Shopify then sends us a shop redaction request after your store has been uninstalled. On receiving it, BundleForge deletes the store record together with its bundles, bundle components, quantity-break settings and display settings, along with any remaining authentication records. That deletion is carried out as a single database transaction.
We have not set a fixed retention period beyond this, and we do not promise a specific deletion timeframe. If you want your data removed sooner, contact us using the details below.
11. Shopify privacy requests
Shopify requires apps to respond to three privacy requests, and BundleForge implements all three:
- Customer data request — acknowledged. We hold no customer data to provide.
- Customer redaction — acknowledged. We hold no customer data to erase.
- Shop redaction — the store’s data is deleted as described in section 10.
Implementing these requests is part of how we handle data responsibly. It is not, by itself, a guarantee of compliance with any particular privacy law.
12. Data security
BundleForge is served over HTTPS, authenticates every Shopify request, verifies the authenticity of webhooks before acting on them, and scopes every database query to the store that made the request so one merchant’s data cannot be reached from another’s session. Access tokens are stored in the application database and are not exposed to the browser or written to application logs.
No service can promise absolute security, and we do not claim to. These are the measures the application actually implements.
13. Your privacy questions and requests
You can ask us what information we hold about your store, ask us to correct it, or ask us to delete it. Uninstalling the app and allowing Shopify’s shop redaction request to run will remove your store’s data as described in section 10; contact us if you would like it removed sooner or have any other request.
Requests about a shopper’s personal information are best directed to the merchant who runs the store, and to Shopify, since BundleForge does not hold that information.
14. Payments
BundleForge offers a free plan and paid plans. Subscriptions are handled entirely by Shopify: you choose and change your plan on Shopify’s own hosted pricing page, and Shopify bills you through your existing Shopify account.
BundleForge collects no payment details and contains no billing or checkout functionality of its own. It never sees your card details, bank details or billing address. To apply your plan’s bundle limit, the app reads which plan your store is subscribed to from Shopify’s Partner API. That tells us the plan name and its billing period — not your payment information.
15. Changes to this privacy policy
We may update this policy as BundleForge changes. When we do, we will update the date at the top of this page. Continued use of the app after a change means the updated policy applies.
16. Contact us
For any question about this policy or about the information BundleForge holds, contact SRAR at support@srar.uk.
SRAR4 St James' Rd
Mitcham CR4 2DA