Legal
Privacy Policy
Last updated: 12 May 2025
1. Overview
Bundle MixMatch Builder ("the App", "we", "us") is a Shopify application developed and operated by Defyn Digital. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data when you install and use Bundle MixMatch Builder on your Shopify store.
By installing the App, you agree to the collection and use of information as described in this policy.
2. Data we collect
When you install and use the App, we may collect and process the following data:
- Shop information: Your Shopify store domain, shop name, email address, and plan level as provided by the Shopify API during installation.
- Product and catalog data: Product titles, variants, and IDs from your store catalog, used solely to power bundle configuration.
- Bundle configuration data: The bundles and discount tiers you create within the App.
- Order data: We access order information only to the extent required by Shopify to process bundle discounts at checkout.
- Access tokens: An OAuth access token issued by Shopify that allows the App to interact with your store on your behalf.
We do not collect personal data from your customers beyond what Shopify provides during normal checkout processing.
3. How we use your data
Data collected is used exclusively to:
- Provide and operate the App's core functionality (bundle creation, discount tier management, storefront widget).
- Apply discounts at checkout through Shopify's native discount engine.
- Respond to support requests and troubleshoot issues with your installation.
- Comply with Shopify's Partner Program requirements and data protection obligations.
We do not sell, rent, or share your data with third parties for marketing purposes.
4. Data storage and security
Store and configuration data is stored in a secure cloud database hosted on Neon (PostgreSQL), deployed via Vercel infrastructure. Data is encrypted in transit using TLS and encrypted at rest. Access to production data is restricted to authorised personnel only.
We retain your store data for as long as the App is installed on your store. When you uninstall the App, we process a deletion request via Shopify's mandatory GDPR webhooks and remove your store data within 30 days.
5. GDPR and data subject rights
We comply with Shopify's mandatory GDPR webhooks:
- Customer data requests: If one of your customers requests their data, we respond within 30 days.
- Customer data erasure: We process customer data erasure requests received via Shopify's webhook.
- Shop data erasure: When you uninstall the App, all store data is deleted within 30 days.
To exercise any data rights, contact us at dan@defyn.com.au.
6. Third-party services
The App operates on the following third-party infrastructure:
- Shopify: The App is built on Shopify's platform and is subject to Shopify's Privacy Policy and Terms of Service.
- Vercel: Application hosting and serverless compute. Vercel's Privacy Policy applies to infrastructure-level data.
- Neon: PostgreSQL database hosting. Neon's Privacy Policy applies to database-level data.
7. Cookies
The App sets a single session cookie (shopify_shop) during the OAuth flow to maintain your authenticated session within the Shopify admin. No tracking or advertising cookies are used.
This website (bundlemixmatch.com) does not use cookies for analytics or advertising.
8. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If changes are material, we will notify you via the Shopify admin or email where required by law.
9. Contact
If you have questions about this Privacy Policy or how we handle your data, contact us at:
Defyn DigitalEmail: dan@defyn.com.au
Website: defyn.com.au