Last updated: 2026-08-25
Simple Bundle Deals ("the app") is operated by ID_within ("we", "us"). This policy explains what the app stores and why.
The short version
The app stores the minimum data needed to run the embedded Shopify app, check billing status, and save your bundle rule. It does not store customer names, email addresses, addresses, payment details, order contents, or cart contents.
Shopify access scopes
The app requests these Shopify Admin API scopes:
- write_discounts - to create, update, deactivate, and reactivate the app's automatic bundle discount.
- read_products - so Shopify can evaluate product-tag eligibility for the discount logic.
What we store
- Your Shopify shop domain.
- Shopify app session data, so the app stays installed and authenticated.
- Your billing status and plan name for the app subscription.
- Your bundle rule settings, including discount name, customer message, eligible product tag, minimum quantity, discount type, discount value, enabled state, and the Shopify discount ID.
What we do not store
We do not store customer names, email addresses, shipping addresses, billing addresses, payment details, order contents, cart contents, uploaded files, images, or documents.
How the discount works
Shopify runs the discount logic at cart and checkout time. The app checks whether cart lines are for products tagged simple-bundle-deal, counts eligible quantities, and returns a discount result to Shopify when the rule qualifies.
V1 supports one automatic bundle deal for one tagged product group.
This process does not persist customer or cart data in our database.
How we use stored data
- To keep the app installed and authenticated.
- To render the embedded admin page inside your Shopify admin.
- To save and update your bundle rule.
- To create and manage the automatic Shopify discount.
- To check whether your subscription is active.
- To help you when you contact support.
We do not sell merchant or customer data, and we do not use it for advertising or profiling.
Where it is stored
App data is hosted on Render in their Frankfurt (EU) region, in a managed PostgreSQL database.
Who else processes it
Shopify - authentication, billing, the embedded admin surface, discount creation, cart, checkout, and order processing.
Render - application hosting and the database.
We use no analytics, advertising, or tracking services in the app.
Retention
When you uninstall the app, its sessions and cached billing status are deleted. We also implement Shopify's mandatory privacy webhooks: customers/data_request, customers/redact, and shop/redact, and respond to them as Shopify requires. Because we hold no customer records, customer redaction requests have no customer records to erase.
Your rights
Depending on where you are, you may have the right to request access to, correction of, or deletion of the data we hold about you. Email apps@idwithin.com and I will respond.
Changes
If this policy changes we will update the date at the top of this page.