This Privacy Policy explains what information the TrueBundle app (“TrueBundle”, “we”, “us”) accesses when a merchant installs it on their Shopify store, why we use it, and the choices and rights you have. By installing or using TrueBundle you agree to this policy.
Who this policy is for
TrueBundle is a Shopify app used by merchants to build mix-and-match bundles that expand into their component products at checkout. This policy covers:
- Merchants who install and operate the app.
- Store customers, only to the limited extent below. TrueBundle does not store customer personal information. It works with your products and bundle definitions, not with your shoppers’ identities.
What we access and why
TrueBundle requests only the access it needs to build and price bundles:
| Data | Why we use it |
|---|---|
| Products and product variants (read) | To load the products you pick as bundle parents and components into the builder, show their titles, images, and prices, and keep the price snapshots inside a bundle current. |
| Products and product variants (write) | To save a bundle’s configuration to a private app metafield on the parent variant, register the component relationships, and flag the parent as requiring components so it only sells as the full bundle. |
| Merchant account and session details provided by Shopify during install | To authenticate the app to your store and keep it connected. |
TrueBundle does not access your orders and does not access your customers. The bundle is expanded at checkout by a Shopify Function that runs inside Shopify, so the app never needs to read, create, or edit orders, and never reads shopper personal information.
What we store, and where
- A bundle’s configuration (its pools, pricing, and the component list-price snapshots) is stored in Shopify as a private metafield on the parent variant. This is the source of truth the checkout Function reads.
- We keep a small application record to run the builder: for each bundle, the store domain, the parent product and variant references, the bundle title, its draft or active status, and a copy of the same configuration used to render the admin list. None of this contains customer personal information.
- We keep the store domain and the access token Shopify issues at install, used to authenticate the app to your store.
- We do not maintain any database of your store’s shoppers or their personal information.
What we do not do
- We do not sell, rent, or share your data or your customers’ data for advertising.
- We do not access your orders or your customers.
- We do not build cross-merchant profiles; data is scoped per store.
- We do not collect storefront-shopper personal information.
Service providers
TrueBundle runs on standard cloud hosting used to operate the app. Any such provider processes data only to host the service, under confidentiality and data-protection obligations, and not for their own purposes. We do not use third-party analytics or advertising trackers inside the app.
Data retention and deletion
- When a merchant uninstalls TrueBundle, the app stops accessing the store and its stored credentials for that store are deleted.
- TrueBundle supports Shopify’s privacy webhooks. Because the app holds no customer personal information, a customer data request has nothing to compile and a customer redaction request has nothing to erase. On a shop redaction request (sent by Shopify after uninstall), we delete the store’s remaining app records.
- A bundle’s configuration metafield lives in Shopify and follows your store’s own data lifecycle; delete the bundle or the metafield to remove it.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data, and to object to or restrict certain processing (for example under the GDPR or CCPA). Because TrueBundle does not hold store-customer personal information, customer requests are best directed to the merchant, who can act on them in Shopify. Merchants can contact us using the details below for help with any request.
Security
Data is transmitted over encrypted connections (TLS), and access to the app’s systems is limited to what is needed to operate the service. No method of transmission or storage is perfectly secure, but we work to protect the limited data we handle.
Children
TrueBundle is a tool for merchants and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as the app evolves or as legal requirements change. The “Last updated” date reflects the current version. Material changes will be reflected here.
Contact
TrueBundle is operated by Conatus Creative Inc., the company behind the Hurdle app brand. For privacy questions or requests, contact us using the email and postal address at the bottom of this page.