Bundle AI Autopilot — Privacy Policy
Effective July 12, 2026
Bundle AI Autopilot is a Shopify app that generates and displays product bundles on a merchant's storefront. This policy describes exactly what data the app processes, why, for how long, and the choices merchants and their customers have. We process the minimum data required to provide the service, we never use it for marketing, and we never sell it.
What we process, and why
- Merchant/store data: your shop domain, a Shopify API access token, your subscription plan, and aggregate usage counters (bundle orders and revenue over the last 30 days). Used to operate the app and meter plan limits.
- Product catalog data: product titles, variants, prices, and inventory status, used to generate and price bundles.
- Bundle interaction events: when a bundle is shown, clicked, added to cart, or purchased, we record the event with the bundle's revenue amounts, a pseudonymous browser session ID, and — for purchases — optionally the Shopify customer ID. These events power the analytics we show the merchant (click-through rates, revenue attribution, A/B test results) and nothing else.
We do not collect or store customer names, email addresses, physical addresses, phone numbers, or payment details. We do not enrich, resell, or share personal data with advertisers, and we do not use it for automated decisions with legal or similarly significant effects.
AI processing
Bundle suggestions are generated in scheduled batch jobs using Anthropic's Claude models. Those jobs receive product catalog data and anonymous, aggregated purchase statistics — never customer names, IDs, or any other personal data.
Customer consent
The storefront widget honors Shopify's customer privacy (consent) signals: where a merchant's store requires consent for analytics, no interaction events are recorded for visitors who have not consented or who have declined.
Retention and deletion
- Bundle interaction events are automatically deleted 24 months after they occur.
- When a merchant uninstalls the app, all of the store's data — including every interaction event — is erased in response to Shopify's
shop/redactrequest (sent by Shopify ~48 hours after uninstall). - Individual customer data requests and erasure requests submitted through Shopify (
customers/data_request,customers/redact) are fulfilled automatically for the events tied to that customer ID.
Security
All data is encrypted in transit (TLS) and at rest. API credentials and secrets are stored in environment configuration, never in code or logs. Access to production data is limited to the app's operators.
Contact
Questions or requests about this policy: phandung122@gmail.com. We answer data-protection inquiries within 30 days.