Privacy Policy
Bundles Pro by F12 Labs. Last updated September 30, 2026.
1. Introduction
Bundles Pro ("we", "our", "the app") is a Shopify application that lets merchants build product bundles, price them from their component products, show them on the storefront and see how they sell. This policy explains what data the app collects, how it is used, where it is stored and how it is protected.
2. Data We Collect
Bundles Pro collects only what it needs to run bundles for a store:
- Store data: the store's Shopify domain and ID, the access token Shopify issues when the app is installed, the store's currency, whether it is a development store, and its Bundles Pro plan.
- Bundle settings: for each bundle the app creates, its product ID and title, the IDs of its component products, its pricing choice, and whether it was created in the app or through the API. We also keep a record of each bundle save while Shopify builds it.
- API keys (Pro plan): each key's name, public key ID, last four characters, access level, and when it was created, last used or revoked. The secret part of a key is never stored; we keep only a one-way hash of it.
- Order data for analytics: for each order that includes a bundle made with Bundles Pro, the order ID and number, the date, which bundle was bought, the quantity, and the revenue and currency for that bundle.
We do not store customers' names, email addresses, shipping addresses or payment details, and we do not store the names or email addresses of the store's staff.
When a request is made to the Bundles Pro API, its IP address is held briefly in memory to limit repeated failed sign-in attempts. It is not written to our database.
3. How We Use Data
- To create bundles in Shopify and keep their prices and components up to date.
- To show which bundles a product belongs to, in the Shopify admin and on the storefront.
- To publish bundles to the sales channels the merchant chooses.
- To report bundle revenue, units and orders in the app's analytics.
- To let the merchant's own systems manage bundles through the API.
We do not use data for advertising and we do not build profiles of shoppers.
4. Where Data Is Stored
- Our database: the store record and access session, bundle settings, API key records and the analytics order records.
- Shopify: the bundles themselves, which are products in the merchant's store, and product metafields in the app's own
$appnamespace that list a bundle's components and the bundles a product is part of. The storefront blocks read these metafields.
5. Why We Access Store Data
The app requests these access scopes:
write_products: create and update bundle products and their components, set their prices, and let the merchant choose products and variants.read_orders: record sales of bundles for the app's analytics.read_publications,write_publications: list the store's sales channels and publish bundles to the ones the merchant chooses.read_themes: check whether the app's product page blocks are on the live theme. The app never edits the theme.
6. Storefront
The storefront blocks are rendered by the store's theme from the product metafields above. They run no scripts, make no requests to our servers and set no cookies. When a shopper adds a bundle from the "Buy the bundle instead" block, it goes straight to the store's own Shopify cart. Bundles Pro receives no data about shoppers' visits.
7. The Bundles Pro API
On the Pro plan, a merchant can create API keys so their own systems, such as an ERP or PIM, can read and manage the store's bundles. Data is returned only to requests signed with one of that store's keys, and only for bundles made with Bundles Pro. The merchant chooses which systems receive their keys and can revoke a key at any time.
8. Data Sharing
We do not sell, rent or share store or customer data with third parties. Data is processed only by Shopify and by our hosting and database providers, who process it on our behalf to run the app.
9. Data Retention
- Data is kept while the app is installed, so bundles, settings and analytics stay available.
- When the app is uninstalled, the store's access session is deleted and every API key is revoked immediately.
- Shopify notifies us 48 hours after uninstall, and we then delete all of the store's data: the store record, bundle settings, API keys and analytics records.
10. GDPR and Data Requests
Bundles Pro handles Shopify's privacy requests automatically:
- Customer data request: Bundles Pro holds no personal data about customers. For the orders named in the request, we identify the bundle sales records we hold (order number, bundle, quantity and revenue).
- Customer erasure: we delete the bundle sales records for the orders Shopify asks us to erase.
- Store erasure: after uninstall, all of the store's data is deleted as described above.
Merchants and shoppers can also send access or deletion requests to the email below.
11. Security
All traffic uses HTTPS. Access to the app in the Shopify admin requires an authenticated Shopify session. API key secrets are shown once when created and stored only as a one-way hash. Keys can be read-only, can be revoked at any time, and are rate limited, and repeated failed sign-in attempts are blocked.
12. Changes to This Policy
If this policy changes, we update the date at the top of this page.
13. Contact
For privacy questions or data requests, contact us at:
Email: support@ftwelvelabs.com
This privacy policy applies to the Bundles Pro Shopify application.