SupaBundlesBack to home

Legal

Privacy Policy

Last updated: 7 September 2026

1. Controller

The controller responsible for processing personal data in connection with the Shopify app SupaBundles is:

YISAN Products Group UG (haftungsbeschränkt)
Erkrather Straße 401
40231 Düsseldorf, Germany
Email: privacy@supabundles.yisan.de
App URL: https://supabundles.yisan.de

If you are a merchant using SupaBundles in your Shopify store, this policy describes how we process data when you install and use the app. For your own storefront visitors and customers, you remain the controller; SupaBundles does not store direct buyer identifiers or order contents. When a merchant runs an A/B test, we process only pseudonymous technical identifiers as described below.

2. What SupaBundles is

SupaBundles is a Shopify application that lets merchants configure quantity- or value-based bundle offers, product labels, product-page quantity offers, and automatic percentage discounts via Shopify Functions and theme app extensions.

3. Categories of data we process

3.1 Data we do not process

SupaBundles does not request customer scopes and does not store store customers’ names, email addresses, phone numbers, postal addresses, payment data, or order contents in our database. The limited read_orders scope is used only to receive a Shopify-filtered orders/paid webhook when a paid order contains the SupaBundles cart-line marker. From that payload we retain only a hashed technical order identifier, timestamp, bundle handle, aggregate item quantity, currency, and monetary totals needed for usage billing and merchant-facing bundle analytics. Customer and product identity fields are neither requested in the webhook configuration nor stored.

Mandatory Shopify webhooks customers/data_request and customers/redact are acknowledged; because we hold no buyer personal data, there is nothing to export or erase for an individual customer in our direct-identifier systems. Experiment records cannot be linked by us to a named Shopify customer.

3.2 Merchant / shop data (required to run the app)

We store the following in our PostgreSQL database (hosted on Supabase):

CategoryExamplesPurpose
Shop identityShopify shop domainIdentify the installation
AuthenticationOAuth access/refresh tokens, session state, scopes, expirySecure access to the Shopify Admin API
Staff sessionWhen Shopify provides an online session: user id, first name, last name, email, account-owner / collaborator flags, locale, email-verified flagAuthenticate the merchant user in the embedded admin
App configurationBundle names/handles, collection IDs/titles, product/variant IDs, tier thresholds and percentage rewards, optional gift variant IDs, discount title/scope/combine flags, label badge texts/colors, PDP offer copy/optionsProvide bundling, labels, discounts, and storefront widgets
Technical identifiersShopify discount/metafield IDs, shop GID, and a non-reversible billing key derived from the shop and order identifierKeep automatic discounts and usage billing in sync
Billing event metadataEvent time, delivery status, retry count, next retry time, and technical error messageReport paid SupaBundles orders to Shopify App Pricing exactly once
Aggregated bundle analyticsDaily offer impressions, unique daily shopper-view counts, product-selection interactions, cart commits, tier unlocks, paid bundle-order count, anonymized bundle-line revenue and discount totals, currency, storefront/surface attribution, and a hashed order identifier used only for deduplicationShow merchants how their bundles perform without creating customer profiles or storing product/order contents
A/B experiment analyticsExperiment and variant IDs, anonymous persistent browser or session assignment, exposure and interaction events, cart commits, paid-order attribution, and daily aggregates. Browser/session keys are converted immediately to shop-specific keyed hashes and are never stored in raw form.Keep a shopper in a consistent test variant, prevent duplicate events, measure variant performance, and show data-quality warnings to the merchant

3.3 Data processed on Shopify’s systems

The following is not stored as customer personal data in our database, but is processed in Shopify as part of providing the app:

3.4 Storefront analytics and diagnostic logging

The storefront widget sends allowlisted, non-identifying performance events such as offer impression, product selection, bundle cart commit, and tier unlock. We store daily counts by shop, bundle handle, and storefront placement. A first-party localStorage flag may mark the first view of a day so we can count unique shoppers (reach) without sending or storing a visitor identifier. No cookie ID, customer ID, IP address, product title, or free-form URL query is stored for analytics.

If a merchant enables an A/B test, the widget assigns eligible traffic to a variant. An anonymous first-party browser key keeps that assignment stable across visits. If persistent browser storage is unavailable, the assignment falls back to the current browser session. The key is sent only with experiment events and is immediately transformed into a shop-specific keyed hash; we do not retain the raw key. We do not use Shopify customer IDs, names, email addresses, IP addresses, or advertising identifiers for experiments.

The widget may also send technical diagnostic events (e.g. failed add-to-cart commits). These are written to server logs and may include shop domain, an allowlisted event name, storefront path without query parameters, and timestamp. Free-form technical details are discarded. Neither analytics nor diagnostics are used for advertising or customer profiling.

4. Purposes and legal bases (GDPR Art. 6)

PurposeLegal basis
Provide, secure, and maintain the app for the installing merchant (OAuth, config, discounts, widgets)Art. 6(1)(b) — performance of a contract (app use / Shopify installation)
Comply with Shopify’s mandatory compliance webhooks and legal retention/deletion dutiesArt. 6(1)(c) — legal obligation
Measure paid orders processed through SupaBundles and submit usage to Shopify’s billing systemArt. 6(1)(b) — performance of the merchant’s app subscription
Operate infrastructure securely (hosting, authentication, abuse prevention)Art. 6(1)(f) — legitimate interests, balanced against merchant rights
Run merchant-configured A/B tests and measure storefront variant performanceLegitimate interests in consistent storefront functionality and experiment integrity; consent where required for analytics or preference storage. Merchants must reflect the test in their own storefront privacy information where applicable.

We do not sell personal data and do not use it for unrelated marketing.

5. Shopify API scopes

The app requires only:

read_products, write_discounts, read_orders

The optional write_products scope is requested only when a merchant explicitly enables the continue-selling inventory feature or per-offer storefront delivery, which writes app-owned offer configuration (no personal data) to the merchant’s own collections. The optional read_reports scope is requested only when a merchant enables the store-wide average-order-value benchmark in Analytics. SupaBundles stores only the resulting aggregate snapshot, not the underlying report rows. The optional write_pixels and read_customer_events scopes are requested only when a merchant turns on checkout tracking. The web pixel sends hashed checkout tokens and existing bundle line properties — no names, emails, or addresses.

6. Recipients / processors

Personal and shop data may be processed by:

  1. Shopify Inc. / Shopify International Ltd. — platform, APIs, authentication, Functions, theme extensions, and CDN assets used by the admin shell
  2. Supabase — PostgreSQL database hosting for app data
  3. Our hosting infrastructure for the Node application serving supabundles.yisan.de (and the development host dev.supabundles.yisan.de)

We do not integrate third-party analytics, advertising pixels, email marketing tools, or error-tracking SaaS in the application code as of this policy date.

7. International transfers

Shopify and Supabase may process data in the EU/EEA and/or other countries (including the United States). Where required, transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses) as provided by those processors. Details are available in Shopify’s and Supabase’s own privacy documentation.

8. Retention and deletion

Data that exists only in the merchant’s Shopify shop (products, carts, orders, metafields Shopify retains per its lifecycle) is governed by Shopify and the merchant’s own policies.

9. Cookies and similar technologies

SupaBundles’ public marketing/login pages do not set advertising or analytics cookies.

The embedded admin uses Shopify’s standard session / authentication mechanisms required to keep the merchant logged into the app. These are strictly necessary for providing the service and are not used for cross-site advertising.

The storefront widget may use first-party sessionStorage and localStorage only to avoid counting the same visit or shopper-day twice for merchant analytics. For an active A/B test, an anonymous assignment key may also be stored and sent with experiment events. We immediately replace it with a shop-specific keyed hash and do not store the raw key.

The anonymous experiment assignment key is used only to keep the selected storefront variant consistent and is not used for advertising or cross-site tracking. If localStorage is unavailable, SupaBundles falls back to sessionStorage. The merchant is responsible for configuring Shopify Customer Privacy and any required storefront consent banner for their markets.

10. Security

Access tokens and configuration data are stored in a private database and transmitted over HTTPS. Access to production systems is restricted to authorized operators. No method of transmission or storage is completely secure; we apply measures appropriate to the risk.

11. Your rights (EEA/UK and similar jurisdictions)

Where applicable, merchants (and any identified persons whose data we hold, such as staff emails in a Shopify online session) may have the right to:

To exercise these rights, contact the email listed in section 1. You may also lodge a complaint with your supervisory authority.

Merchants who need a copy of data we hold about their shop can contact us; shop configuration can also be reviewed in the app admin. Uninstalling the app triggers deletion of the merchant configuration data described above.

12. Children

The app is directed at business users (Shopify merchants), not at children.

13. Changes

We may update this policy when the app’s data practices change (e.g. new scopes, processors, or analytics). The “Last updated” date will be revised; material changes will be communicated where appropriate (e.g. App Store listing / in-app notice).

14. Contact

YISAN Products Group UG (haftungsbeschränkt) — SupaBundles
Erkrather Straße 401, 40231 Düsseldorf, Germany
Privacy: privacy@supabundles.yisan.de
Support: support@supabundles.yisan.de
Web: https://supabundles.yisan.de

This policy reflects the current application code: compliance webhooks at /webhooks/compliance, shop data deletion on uninstall and shop/redact, API scopes read_products, write_discounts, and read_orders, optional write_products, read_reports, write_pixels, and read_customer_events, no direct buyer identifiers in the app database, and pseudonymous experiment measurement.