ModuBundle: Mix & Match
Privacy Policy
Last updated: September 16, 2026
This policy describes how ModuBundle: Mix & Match (the “App”) handles information when merchants install and use the App and shoppers interact with its bundle features. It covers the App, rather than a merchant’s entire online store. Merchants and Shopify have their own privacy policies for their services.
Information we receive and store
Merchant and authentication information. We receive the store’s Shopify domain and authentication information needed to connect the App to Shopify. Our database stores session identifiers, authorization state, granted scopes, session type and expiry information, access tokens and, when supplied, refresh tokens and their expiry. If Shopify supplies an online merchant-user session, session storage can also hold that user’s ID, name, email, locale, and account-owner, collaborator and email-verification flags. These are merchant-user details, rather than shopper profiles.
Catalog and bundle information. We access Shopify products and variants, including identifiers, handles, titles, options, images, SKUs, prices, currency and inventory or availability information. We store merchant-created bundle names, descriptions, images, status, discounts, product and variant references, component quantities and ordering, option settings, resolution rules, media details, configuration versions and creation/update timestamps. We publish bundle configuration to an App-owned Shopify Cart Transform metafield and manage the associated Cart Transform. The current bundle implementation does not read or write metaobject records.
Storefront requests and shopper information
Shopify’s app proxy forwards requests to the App with store and signature information, timestamps and a path prefix. It can also include a logged-in Shopify customer ID. That ID is received as part of the request and signature verification; the App does not use it to look up a customer profile or store it in its database.
Bundle requests include product, parent-variant and bundle identifiers, a storefront country code, configuration version, and selected component variants and quantities. We process these temporarily to present bundles and check current availability. These selections are not saved as shopper records in our database. The country code supplies storefront market context, rather than a postal address.
The storefront extension sends selected items and bundle grouping properties to Shopify’s cart, and reads cart responses in the shopper’s browser to confirm additions or perform cleanup. Shopify runs the Cart Transform using cart-line IDs, quantities, variant IDs, SKUs, prices, currency, bundle attributes and the App’s configuration. Its input does not request buyer identity, customer contact details or delivery addresses.
The current App does not query customer profiles, orders, shopper names, email addresses, phone numbers, payment details or billing/shipping addresses. This does not mean that requests are anonymous: proxy customer IDs and technical connection information can be received. Information supplied through a privacy or support request is used to handle that request.
How we use information
We use information to authenticate merchants, keep each store’s bundle configuration separate, manage and publish bundles, display catalog information, check market eligibility and inventory, apply configured cart behavior, diagnose failures and respond to support or privacy requests.
Storage, retention and uninstall
Sessions and bundle configuration are stored in a PostgreSQL database. The App does not implement a fixed retention period or scheduled database cleanup. Merchants can delete bundles through the App; deleting a bundle also removes its related component configuration records and republishes the active configuration to Shopify when that operation succeeds.
On receipt of an authenticated Shopify uninstall notification, the current handler deletes that store’s session records when a session is available. It does not delete the store’s bundle records or explicitly remove Shopify-held configuration. Uninstalling alone therefore does not guarantee deletion of all App data. Please contact us to request deletion of retained information. Shopify controls retention of information held in its platform. Infrastructure log and backup retention depends on the service configuration; this policy does not promise a specific period.
Technical information and diagnostics
The backend receives request URLs, headers and connection information needed to serve requests; browser user-agent information is used for page rendering. Hosting infrastructure can receive IP addresses and other technical request information. App diagnostics log webhook topics and store domains, error names/messages and, in some error paths, error objects. The storefront extension writes bundle IDs and cart-operation status/reason information to the browser console. These console messages are not sent to a separate analytics service by the App. We do not intentionally log access tokens or customer contact information, but error messages can contain contextual technical information.
Service providers and sharing
Shopify provides the commerce platform, authentication, catalog APIs, app proxy, cart and Cart Transform runtime. Railway hosts the production backend and can process runtime diagnostics. The configured PostgreSQL database connection also points to Railway infrastructure. Pages load font resources from Shopify’s content delivery network, which receives browser requests for those resources.
The current App has no integrated advertising, third-party analytics, external monitoring or email-delivery service. We do not sell information or share it for advertising. Information is exchanged with Shopify and infrastructure providers to operate the App and may be disclosed when required by law or necessary to address security issues. A merchant’s other store integrations operate under their own policies.
Security
Merchant administration uses Shopify authentication. Storefront proxy requests use Shopify signature verification, and implemented webhook handlers use Shopify webhook authentication. Database operations scope bundle access to the authenticated store. Credentials are supplied through runtime configuration and session storage is server-side. No method of storage or transmission is completely secure.
International processing
Information may be processed in countries where Shopify, Railway and the configured database infrastructure operate. The App does not choose processing locations based on a shopper’s country code. Actual hosting regions and any applicable transfer arrangements depend on the providers and service configuration.
Privacy requests
Merchants and individuals may contact us to ask about information we hold or request access, correction or deletion, subject to applicable rights and limitations. We may need to verify the requesting person’s identity and store authority before acting. Shoppers should contact the merchant for requests concerning that merchant’s broader store, orders or customer records.
Changes to this policy
We may update this policy when the App’s information handling changes. The current policy will be available on this page with its updated date.
Contact
For privacy questions or requests, email hello@dcplabs.com.