Bundles ProInstall on Shopify

Privacy Policy

Bundles Pro by F12 Labs. Last updated September 30, 2026.

1. Introduction

Bundles Pro ("we", "our", "the app") is a Shopify application that lets merchants build product bundles, price them from their component products, show them on the storefront and see how they sell. This policy explains what data the app collects, how it is used, where it is stored and how it is protected.

2. Data We Collect

Bundles Pro collects only what it needs to run bundles for a store:

We do not store customers' names, email addresses, shipping addresses or payment details, and we do not store the names or email addresses of the store's staff.

When a request is made to the Bundles Pro API, its IP address is held briefly in memory to limit repeated failed sign-in attempts. It is not written to our database.

3. How We Use Data

We do not use data for advertising and we do not build profiles of shoppers.

4. Where Data Is Stored

5. Why We Access Store Data

The app requests these access scopes:

6. Storefront

The storefront blocks are rendered by the store's theme from the product metafields above. They run no scripts, make no requests to our servers and set no cookies. When a shopper adds a bundle from the "Buy the bundle instead" block, it goes straight to the store's own Shopify cart. Bundles Pro receives no data about shoppers' visits.

7. The Bundles Pro API

On the Pro plan, a merchant can create API keys so their own systems, such as an ERP or PIM, can read and manage the store's bundles. Data is returned only to requests signed with one of that store's keys, and only for bundles made with Bundles Pro. The merchant chooses which systems receive their keys and can revoke a key at any time.

8. Data Sharing

We do not sell, rent or share store or customer data with third parties. Data is processed only by Shopify and by our hosting and database providers, who process it on our behalf to run the app.

9. Data Retention

10. GDPR and Data Requests

Bundles Pro handles Shopify's privacy requests automatically:

Merchants and shoppers can also send access or deletion requests to the email below.

11. Security

All traffic uses HTTPS. Access to the app in the Shopify admin requires an authenticated Shopify session. API key secrets are shown once when created and stored only as a one-way hash. Keys can be read-only, can be revoked at any time, and are rate limited, and repeated failed sign-in attempts are blocked.

12. Changes to This Policy

If this policy changes, we update the date at the top of this page.

13. Contact

For privacy questions or data requests, contact us at:

Email: support@ftwelvelabs.com


This privacy policy applies to the Bundles Pro Shopify application.