Legal
Privacy policy
This policy explains what Bundles Extend stores, what it reads in Shopify, and how merchants can ask us to delete it. Last updated 16 August 2026.
Who we are
Bundles Extend is a Shopify app from Scallop. It runs mix and match bundles, Buy One Get One, quantity breaks, and complete the set offers on your shop. This policy covers merchants who install the app, not your storefront shoppers.
What we store
Our database keeps the Shopify OAuth session needed to open the embedded admin, and messages you send from the support portal:
- Shop domain
- Access token and session identifiers
- Staff name, email, user id, and locale when Shopify includes them in the session
- Support requests: reply email, shop you typed, topic, and message
Offer rules, products, discounts, and theme blocks live in your Shopify shop. We do not keep a copy of your catalog or orders in our database.
What we read in Shopify
While the app is installed, it uses Admin API access to:
- Create and update offers (products, metafields, publications)
- Turn on Cart Transform and automatic line discounts
- Read orders so mix items can be listed, including after a selling-plan order is created
- Show customer display names in the app’s Orders list. Those names are fetched live from Shopify and are not saved in our database
How we use it
- Authenticate you in Shopify admin
- Expand mix and match picks onto the order as real lines
- Apply percent off for Buy One Get One, Buy X Get Y, quantity breaks, and complete the set
- Respond to Shopify compliance webhooks
- Reply to support requests you submit on this site
We do not sell shop, staff, or customer data. We do not use it for ads. Card numbers and Shopify billing are handled by Shopify, not by us.
Your customers
Bundles Extend does not keep a customer database. Shopify may send customers/data_request and customers/redact webhooks. We acknowledge them and have nothing to export or delete for store customers.
Who else sees data
- Shopify: the platform the app runs on
- Railway: hosts the app and its Postgres session store. Request logs may include shop domain and IP for a short time
Cookies
The app uses cookies and similar storage only for Shopify OAuth and the embedded admin session. There are no advertising cookies.
How long we keep it
Session rows stay until you uninstall the app or Shopify sends shop/redact. Uninstall deletes those rows. Support requests for that shop domain are deleted on shop/redact. After uninstall we cannot open your shop.
Your choices
- Uninstall Bundles Extend to remove our session for that shop
- Use Shopify admin to change or delete products, discounts, and orders
- Ask us to confirm what we hold for your shop. For store customers we hold nothing
Contact
Privacy questions about Bundles Extend: use the support portal or read Help and FAQs. If the data lives only in your Shopify shop, change it there.
Effective 16 August 2026.