
Privacy policy
This policy explains what Mix & Match Bundle Builder stores, why, and for how long. It applies to merchants who install the app, to shoppers who use a bundle on a merchant’s store, and to anyone who writes to us through this site.
What we store about a merchant
When a merchant installs the app, we store:
- The store’s myshopify.com domain, name, contact email, country and currency
- An access token, encrypted, so the app can read and write on the store’s behalf
- The bundles the merchant creates: names, rules, pricing and appearance
- References to the merchant’s Shopify products and collections, by ID
- Which plan the store is on
Products, prices and images are read from Shopify when needed. We do not keep copies of a merchant’s catalogue.
What we store about shoppers
Nothing that identifies anyone. We do not store names, email addresses, postal addresses, phone numbers or payment details.
When a shopper uses a bundle, we record which steps were reached and which products were chosen, tagged with a random identifier generated in that browser. That identifier is not linked to a Shopify customer account and cannot be traced back to a person. It lets a merchant see how many people started a bundle and how many finished it, and nothing more.
A shopper’s bundle choices also travel on the order itself, as line item properties Shopify stores. That data belongs to the merchant and is governed by the merchant’s own privacy policy.
What we store when you write to us
Writing to support, whether from inside the app or from the contact form on this site, stores the message so it cannot be lost if a notification fails.
- From inside the app: the reply address given, the subject and body of the message, and the store, plan and bundle count the session already identified.
- From the public contact form: the name and reply address given, the subject and body, and the store address typed, if any. Nothing here is verified, because there is no Shopify session behind it.
A message is used to answer the question and for nothing else. We do not add a sender to a mailing list.
Where it is stored
Application data is held in a PostgreSQL database operated by Supabase, in the European Union. Access tokens are encrypted before they are written. The application runs on Render.
How long we keep it
- On uninstall: the app stops immediately and makes no further requests to the store. Bundle configuration is retained for 48 hours so a reinstall does not lose the merchant’s work.
- 48 hours after uninstall: Shopify sends a deletion request and all data for that store is erased.
- Analytics: retained for as long as the store is installed, then erased with everything else.
- Support messages sent from inside the app: erased with the rest of the store’s data, 48 hours after uninstall.
- Support messages sent from the public contact form: kept while the question is open and for up to 12 months afterwards, so a follow-up can be answered in context. There is no store to attach them to, so the uninstall window above does not apply. Ask us and we will delete yours sooner.
Shopify privacy requests
We implement the three privacy webhooks Shopify requires. Because we hold no personal data about shoppers, a request for a customer’s data returns nothing and a request to delete a customer’s data has nothing to delete. A request to delete a shop’s data erases everything we hold for that store.
Sharing
We do not sell data and we do not share it with advertisers. Data is processed by Shopify, Supabase and Render solely to run the app.
Contact
For any question about this policy, or to request deletion of your store’s data before the automatic window, contact dev@oatsafrica.com.