BundleNest ("the App", "we", "our", "us"), published by AppNest Studio, is a Shopify app that lets a merchant create and manage fixed product bundles and multipacks as native Shopify bundle products, watch component stock, keep bundle prices in sync with component prices, and receive alerts when a bundle can no longer be sold. This policy explains what data the App accesses, why, how long we keep it, and who it is shared with.
Contact / Data Protection: support@appnest.studio
1. Who the data belongs to
The App acts as a data processor on behalf of the installing merchant (the data controller). We process the merchant's Shopify store data solely to provide the bundle features the merchant configures.
2. What we access and why
We request the minimum scopes needed:
| Scope | Why |
|---|---|
read_products |
Search for component products, read their options, variants and prices; read the bundle products the App created |
write_products |
Create bundle products (or convert a product the merchant explicitly chooses), and set price, SKU, barcode and status on the bundle's own variants |
read_inventory |
Read component stock per location to compute bundle availability and name the component that ran out |
read_locations |
Resolve the locations that stock is reported for |
The App has no inventory write permission: it cannot change a stock quantity. It does not request access to orders, customers, or any other personal data. Nothing the App stores identifies a shopper.
3. What we store
| Data | Stored? | Notes |
|---|---|---|
| Shopify session / access token | Yes | Required to call the Admin API |
| Bundle definitions (component product and variant IDs, quantities, option selections, pricing rule) | Yes | Your bundle set-up |
| IDs of the bundle products and variants Shopify created, with their SKU, barcode and price | Yes | So the App can show and update them |
| Component stock per location (a read-only cache) | Yes | Kept fresh by Shopify inventory webhooks and a nightly re-read |
| Alert email addresses / Slack webhook URL | Yes | Where to notify you |
| Run logs and incidents | Yes | Operational history (what was created, priced, deleted, and any failure) |
| Orders, customers, shopper personal data | No | Never requested, never received |
4. Data retention & deletion
- Bundle definitions, the stock cache and run logs are retained while the App is installed. Run logs older than 90 days are deleted automatically.
- On app uninstall and on the Shopify
shop/redactcompliance webhook, we delete all data the App holds for that shop. Your bundle products remain in your store. They are your products. - We respond to the Shopify
customers/data_requestandcustomers/redactcompliance webhooks; because the App holds no customer data, there is nothing to return or erase.
5. Subprocessors / third parties
| Provider | Purpose | Data shared |
|---|---|---|
| Hosting (Railway) + Postgres/Redis | Run the App | Stored data listed in §3 |
| Resend | Alert emails (creation failures, out-of-stock bundles, drift) | Your alert email + the alert text (bundle and product titles) |
| Slack | Alert messages (if you add a webhook) | Your webhook + the alert text |
| Sentry | Error tracking | Diagnostic error data (no shopper data exists to include) |
We do not sell data or use it for advertising.
6. International transfers
AppNest Studio operates from India, and the providers listed above may process data in regions outside your own. Where a transfer leaves the UK or the European Economic Area, we rely on the Standard Contractual Clauses incorporated into those providers' data-processing terms. Write to support@appnest.studio if you need detail on a specific provider.
7. Security
- All API traffic is over HTTPS; the database is encrypted at rest by the hosting provider.
- Access tokens are used only from our servers and are deleted on uninstall.
- The App writes only to products it created or that the merchant explicitly converted, and never writes an inventory quantity.
8. Your rights
Merchants can delete their data by uninstalling the App (which triggers full deletion of everything the App holds) or by contacting us at the address above. Because the App processes no shopper personal data, there are no data-subject records to export.
9. Changes
We will update this policy as the App evolves and revise the "Last updated" date above.
BundleNest by AppNest Studio · support@appnest.studio