Privacy Policy — Bundle Guard

Effective: 9 September 2026

Who we are. Bundle Guard ("the app") is operated by Matthew Schafer, reachable at support@aro-pcrm.com.

What we collect. The app stores only: your shop domain, the app's session tokens, your app settings, the bundle structure and component inventory data (product/variant IDs and titles, SKUs, quantities, inventory levels and policies), and a log of actions the app performed. The app requests only the read_products and read_inventory permissions only, and never writes to your store.

What we never collect. No customer names, emails, addresses, orders, payment data, or analytics identifiers. The app has no storefront component and sets no cookies for your shoppers.

How we use it. Solely to provide the features you configured: showing expiry status, sending your digest email to the address you chose, and applying the tagging/unpublishing automations you enabled. Nothing is sold, shared, or used for any other purpose.

Where it lives. On the app's server database. Digest emails are delivered via our email provider. Data is encrypted in transit (TLS).

Retention & deletion. Uninstalling the app stops all processing. When Shopify sends the shop/redact webhook (48 hours after uninstall), every record for your shop is permanently deleted. You can also email us for immediate deletion.

GDPR/CCPA webhooks. customers/data_request and customers/redact are acknowledged automatically; since the app stores no customer data, there is nothing to return or erase. shop/redact triggers full deletion as above.

Changes. We'll update this page and the effective date if practices change.

Back to Bundle Guard