Skip to main content

Privacy policy

Last updated

Bundlex makes two Shopify apps: Bundlex, for product bundles, volume discounts, BOGO offers, and free gifts, and Bundlex Cart, a cart drawer with upsells and rewards. This policy covers both. Where something applies to only one app, we name it; otherwise "Bundlex" and "the app" mean either app. This policy explains what data we collect, why we collect it, and the choices and rights you have. It is written for three audiences: merchants who install our apps, shoppers who visit stores that use them, and visitors to this website.

1. Who we are

The Bundlex and Bundlex Cart apps and the bundlex.io website are operated by Devus, UAB, a private limited liability company registered in the Republic of Lithuania.

  • Company: Devus, UAB
  • Company code: 304197295
  • VAT code: LT100010009112
  • Registered address: Tiltų g. 19, Klaipėda, LT-91249, Lithuania
  • Email: [email protected]

For the purposes of the EU General Data Protection Regulation (GDPR), Devus, UAB is the data controller of the personal data described in this policy, except for storefront data that we process on behalf of merchants. For that data the merchant is the controller and we act as a data processor (see section 3).

2. What this policy covers

This policy covers:

  • the Bundlex and Bundlex Cart apps installed from the Shopify App Store,
  • the widgets, cart drawer, and discounts our apps render in merchants' online stores, and
  • this website, bundlex.io, including the blog and help center.

It does not cover the Shopify platform itself or the stores of merchants who use Bundlex. Shopify and each merchant publish their own privacy policies, and we encourage you to read them.

3. Information we collect

From merchants who install Bundlex

When you install Bundlex on your Shopify store, Shopify shares basic store information with us so the app can work:

  • Store details: your store name, myshopify.com domain and primary domain, store owner contact details (name, email address, and phone number where provided), store currency, country, city, and time zone, and the languages your store supports.
  • An API access token that lets Bundlex read your products, themes, and orders and manage the discounts you create, within the permissions you approve during installation.
  • Billing information from Shopify (Bundlex only): your selected plan, charge identifiers, charge status, and trial dates. Payments are processed entirely by Shopify. We never see or store your card or bank details.
  • Content you create in the app: offer configuration, cart drawer settings, widget styling, custom CSS, translations, and any images you upload.
  • Order analytics: to show you how your offers perform, we store order identifiers and numbers, order dates, totals, discount amounts, currency, and line items (product, variant, SKU, quantity, and prices). We do not request or store your customers' names, email addresses, shipping addresses, phone numbers, or payment details. Bundlex Cart stores only orders that include a product added through its cart drawer, and from those orders only the lines the drawer added.
  • App usage (Bundlex Cart): when you last opened the app, ratings and comments you leave inside the app, load-time measurements of the app's pages (with country and page path), and, if you use Shopify Sidekick, a log of which Bundlex Cart tools it called.
  • Support conversations: if you contact us through chat or email, we receive the contact details you use and the content of your messages.
  • Install IP address: when you install the app, we record the IP address the installation came from and the network range it belongs to. We use it only to detect fraud, such as fake App Store reviews posted from related stores, and never for marketing or tracking.

From visitors to stores that use Bundlex

We designed both apps' storefront features to work without collecting shoppers' names, email addresses, or other contact details.

Bundlex widget

  • Anonymous offer events: when an offer is shown or a shopper adds an offer to the cart, the shopper's browser sends us the offer ID, the product ID, the event type, and a random session identifier generated in the browser for that tab session. This identifier is not linked to a name, email address, Shopify customer ID, or account of any kind.
  • Performance measurements: we collect technical page speed metrics (such as loading times) together with country-level location, so we can keep the widget fast. These measurements use the same kind of random session identifier and contain no personal details.
  • IP addresses are visible to our servers when these requests arrive, as with any web request. We use them transiently for rate limiting and abuse prevention and do not store them with analytics events.

Bundlex Cart drawer

  • Analytics only with permission: the drawer collects analytics only after the shopper allows analytics in the store's privacy settings, which Shopify manages. If the shopper declines or later withdraws, or the browser sends a Do Not Track or Global Privacy Control signal, nothing is collected and any data waiting in the browser is deleted.
  • Cart events: when the drawer opens, when checkout is clicked, and when an offer is shown, added, or removed, the browser sends us the event type, the offer and product IDs, and a random session identifier. A new identifier starts after 30 minutes without activity or after 24 hours. There is no lasting visitor identifier, and events are not linked to a name, email address, or Shopify customer account.
  • What we do not collect: these requests reach us through Shopify, and we do not store shoppers' IP addresses, browser details, or location with cart analytics.
  • Counting sales: when a shopper adds a product through the drawer, the cart line carries a small tag naming the offer, so the merchant can see which sales the drawer made. The tag holds no information about the shopper. If the shopper allowed analytics, the tag also holds a random action ID, which lets us match the order to the drawer session for up to 7 days.
  • Choosing offers: the drawer may read the shopper's country and customer tags in the browser to show the right offers and prices. This happens in the browser and is not sent to us.

We do not use storefront data for advertising, profiling, or cross-site tracking, and we process it only on behalf of the merchant whose store you visited. If you have questions about how a specific store handles your data, contact that store first.

From visitors to this website

  • Server logs: like virtually every website, our servers record the IP address, browser type, requested page, and time of each request. We use logs for security and troubleshooting.
  • Usage analytics: in production we use Google Tag Manager and Google Analytics to understand which pages are visited, where visitors come from, and what device and browser they use. These tools only run if you accept optional cookies in our cookie banner (see section 7).
  • Support chat: our chat widget (Crisp) loads only when you choose to open it. If you start a conversation, we receive your messages and any contact details you share.
  • Help center feedback: when you mark a help article as helpful or not helpful, we store an anonymous counter. The vote is remembered in your browser session so you are not asked twice, but it is not tied to your identity.

4. How we use information

  • To provide and operate Bundlex: render your offers and cart drawer, apply discounts, and keep your configuration in sync with your store.
  • To show merchants analytics about their own offers, such as views, add-to-carts, and attributed revenue.
  • To manage subscriptions and billing through Shopify.
  • To answer support requests and help with setup.
  • To monitor errors and performance and improve the product. If you use the automatic translation feature, the offer text you ask to translate is sent to our translation provider; this is product copy, not personal data.
  • To keep our services secure, including rate limiting, abuse prevention, and detecting fraud such as fake App Store reviews.
  • If you use Shopify Sidekick, to answer its questions about your Bundlex Cart settings and results.
  • To send merchants service messages about their account, such as billing notices or important product changes.
  • To comply with legal obligations, such as accounting and tax rules.

We do not sell or rent personal data, and we do not run third-party advertising.

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract: processing merchant and store data needed to provide the app under our terms of use.
  • Legitimate interests: securing our services, preventing abuse and fraud, debugging errors, improving the product, and communicating with merchants about the service.
  • Consent: optional analytics cookies on this website, and Bundlex Cart storefront analytics, which the store asks the shopper to allow. You can withdraw consent at any time.
  • Legal obligation: keeping accounting and tax records.

6. Who we share information with

We share data only with service providers that help us run Bundlex, and only to the extent needed:

  • Shopify: the platform our apps run on, including billing through the Shopify Billing API and, if you use it, Shopify Sidekick, which can read your Bundlex Cart settings and results to answer your questions.
  • Amazon Web Services: cloud hosting and storage for Bundlex's uploaded files such as offer images.
  • DigitalOcean: hosting for Bundlex Cart's servers, database, and uploaded images, in the United States.
  • Cloudflare: network security and delivery for our apps.
  • Google: Tag Manager and Analytics for usage statistics on this website, subject to your cookie consent.
  • Crisp: the support chat on this website. Conversations are stored with Crisp. Support chat inside the apps runs on our own server.
  • Sentry: error monitoring. Error reports are technical and may include your store domain.
  • OpenAI: only when you use the automatic translation feature, to translate the offer text you submit.

We may also disclose information if the law requires it, to professional advisers under confidentiality, or as part of a merger, acquisition, or sale of assets, in which case this policy will continue to apply to your data.

This website uses a small set of cookies:

Cookie Type Purpose
bundlex_session Essential Keeps your browsing session, for example which help articles you have voted on.
XSRF-TOKEN Essential Protects forms and requests against cross-site request forgery.
_ga, _ga_* (Google Analytics) Analytics, optional Anonymous usage statistics. Set only in production and only after you accept cookies in the banner.
crisp-client/* (Crisp) Functional Set only if you open the chat widget, so your conversation can continue across pages.

Your accept or reject choice is stored in your browser's local storage, not in a cookie. You can change your mind at any time using the cookie icon in the bottom left corner of the site, and you can delete cookies through your browser settings. The Bundlex storefront widget does not set cookies in merchants' stores; it uses short-lived browser session storage to generate the anonymous session identifier described in section 3. The Bundlex Cart drawer does not set cookies either. It keeps product lists and timer state in session storage and, only when the shopper has allowed analytics, a short queue of events in the browser's IndexedDB storage, which is sent or discarded within 24 hours and deleted if the shopper withdraws permission.

Inside the Shopify admin, the Bundlex Cart app sets essential cookies that keep you signed in to your store (bxc_auth_*, bxc_active_shop), remember your language (bxc_locale), and remember that you have seen an update notice (bxc_seen_deploy), each for up to 30 days, plus standard session and security cookies. The in-app support chat keeps an identifier in your browser's local storage.

8. How long we keep information

  • Order analytics: kept while the app is installed to power your dashboard. After you uninstall, Shopify sends us a redaction request (normally 48 hours later), and we delete your order data in response. We may keep aggregated statistics that identify no one.
  • Install IP address: kept after you uninstall, because fake reviews are often discovered weeks or months later. We keep it only while it can still help us investigate that kind of fraud.
  • Storefront events (Bundlex): anonymous from the moment of collection, retained in aggregate to power merchant dashboards.
  • Storefront analytics (Bundlex Cart): individual events and sessions are kept for 7 days and daily totals for up to 400 days. All of it is deleted when you uninstall.
  • App usage (Bundlex Cart): load-time measurements are kept for 90 days and the Sidekick log for 30 days.
  • Support conversations: kept while they remain relevant to supporting you.
  • Website server logs: kept for a short period and rotated automatically.
  • Billing and accounting records: kept as long as Lithuanian accounting and tax law requires, even after you uninstall.

9. Your rights

If you are in the European Economic Area or the United Kingdom, you have the right to:

  • access the personal data we hold about you,
  • correct inaccurate data,
  • have your data deleted,
  • restrict or object to processing,
  • receive your data in a portable format, and
  • withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email [email protected]. We respond within 30 days. You also have the right to complain to a supervisory authority. Our lead authority is the State Data Protection Inspectorate of the Republic of Lithuania (vdai.lrv.lt), but you may also contact the authority in your own country.

If you are a shopper in a store that uses Bundlex, the merchant is the controller of that store's data, so please direct requests to the merchant. We will assist them in fulfilling your request. Bundlex Cart's storefront analytics uses random session identifiers that are not tied to a name or account, so we cannot find one shopper's events from their name or email address.

10. Privacy requests through Shopify

As a Shopify app, Bundlex subscribes to Shopify's mandatory privacy webhooks and honors them:

  • customers/data_request: a merchant's customer asks for their data. Because we do not store shoppers' names, email addresses, or customer accounts, there is normally nothing to provide, and we respond accordingly.
  • customers/redact: a merchant's customer asks for deletion. As above, we hold no shopper names, email addresses, or customer accounts to delete.
  • shop/redact: sent after a merchant uninstalls Bundlex. We delete the store's order data, and for Bundlex Cart its storefront analytics, as described in section 8.

11. International transfers

For Bundlex, we aim to store data within the European Economic Area. Bundlex Cart is hosted in the United States, so its data is stored there. Some of our service providers may also process data outside the EEA, for example in the United States. Where that happens, we rely on safeguards recognized by the GDPR, such as European Commission adequacy decisions or Standard Contractual Clauses.

12. Security

We protect data with measures appropriate to its sensitivity, including encryption in transit (HTTPS/TLS), restricted access on a need-to-know basis, and monitoring for abuse. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to respond quickly if something goes wrong. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities as the law requires. If you discover a security issue, please report it to [email protected].

13. Children

Bundlex is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

14. Changes to this policy

We may update this policy as Bundlex evolves. The date at the top of this page shows when it was last changed. If a change is material, we will announce it in the app or by email to merchants before it takes effect. Continued use of Bundlex after a change means you accept the updated policy.

15. Contact us

Questions about privacy or this policy:

  • Email: [email protected]
  • Post: Devus, UAB, Tiltų g. 19, Klaipėda, LT-91249, Lithuania

We use a few cookies to keep this site working, measure how it is used, and power our chat widget when you open it. See our cookie policy.