Skip to content
Only Bundlesonly bundles
FeaturesDemoPricingHelpTutorialsDevelopersBlog
Install on Shopify ↗
Menu
FeaturesDemoPricingHelpTutorialsSDKBlogInstall on Shopify ↗

Legal

Privacy Policy

This policy explains how Only Bundles handles information when merchants use our Shopify application and when anyone visits this website.

Effective: September 3, 2026 · Last updated: September 3, 2026

Only Bundles ("Only Bundles," "we," "us," or "our") is based in Delhi, India. This Privacy Policy applies to the Only Bundles Shopify application, its bundle storefront components, our support services, and this public website (together, the "Services").

Shopify merchants are responsible for their own privacy notices and practices. This policy does not replace a merchant's privacy policy or govern information that a merchant processes independently of Only Bundles.

1. Our role

For shopper and store data that we process to provide the application to a merchant, the merchant generally determines why and how the data is used, and Only Bundles acts as a processor or service provider on the merchant's instructions. For merchant account administration, support, security, legal compliance, and this website, Only Bundles may act as a controller or business. The exact role can vary under applicable law and the facts of the processing.

2. Information we process

Merchant and staff informationShop domain, Shopify account and staff identifiers, name, email address, locale, role information, authentication session records, and access or refresh tokens supplied through Shopify.
Store, catalogue, and bundle configurationStore name and contact email; product, variant, collection, image, price, availability, and inventory-related data; bundle rules, discounts, design settings, custom text, selectors, scripts, and other settings a merchant chooses to configure.
Storefront device and activity informationInternet Protocol address in server logs, browser and operating-system information, user agent, a browser-session identifier, page and landing path or query, country context supplied by Shopify, and interactions such as bundle views, selections, and add-to-cart events.
Order attribution and checkout informationWhere enabled by a merchant through Shopify's web pixel environment: order identifier and number, line-item product and variant identifiers, titles, quantities, prices and bundle properties, order total and currency, landing page, and permitted campaign parameters such as UTM values. We do not request payment-card numbers or shopper billing or shipping addresses for this functionality.
Support informationEmail address, messages, attachments, and technical or diagnostic information you choose to provide when contacting us or using our support chat.
Operational and compliance informationWebhook and job records, error and security logs, installation and uninstall dates, business events, and the payload and status of privacy-rights requests sent through Shopify.
Public website informationBasic request logs needed to deliver and secure the site. We do not operate visitor analytics or use the public site for behavioural advertising.

3. How we receive information

We receive information from Shopify and its APIs, from merchants and authorized staff, from storefront visitors' interactions with merchant-enabled bundle components or Shopify web pixels, from support communications, and automatically from systems used to operate and secure the Services.

4. Why we use information

We use information only as reasonably necessary to:

  • install, authenticate, operate, maintain, and improve the Services;
  • render merchant-configured bundle experiences and carry shopper selections into Shopify's cart;
  • calculate or report bundle performance, attribution, and engagement to the merchant;
  • provide support and communicate about the Services;
  • bill for paid plans through Shopify;
  • detect abuse, troubleshoot faults, maintain security, and protect legal rights; and
  • comply with law, Shopify requirements, and valid privacy-rights requests.

Where a legal basis is required, we rely as applicable on performance of a contract, legitimate interests in providing and securing the Services, compliance with legal obligations, consent, or the merchant's documented instructions. A merchant is responsible for establishing the appropriate basis for its use of shopper data.

5. How we disclose information

We disclose information only for the purposes described above, including to:

  • Shopify, whose platform, APIs, app billing, checkout, and privacy-webhook systems make the application possible;
  • hosting and infrastructure providers, including Render and its database infrastructure;
  • event and job infrastructure, including Inngest;
  • support providers, including Crisp, when support chat is used;
  • website infrastructure, including Cloudflare for static-site delivery and security;
  • professional advisers, auditors, insurers, or authorities where reasonably necessary; and
  • a successor in a merger, financing, acquisition, reorganization, or sale, subject to appropriate safeguards.

We do not sell personal information. We do not share personal information for cross-context behavioural advertising or use it for targeted advertising. Because we do not conduct those activities, a browser-based opt-out preference signal such as Global Privacy Control ordinarily does not change our processing; we will honour it where applicable law requires otherwise.

6. Retention

We retain information only for as long as reasonably necessary for the purposes described in this policy, taking account of the merchant relationship, legal and Shopify requirements, security needs, dispute resolution, and the nature of the data.

  • Store and bundle configuration is generally retained while the application is installed or until the merchant deletes it.
  • Authentication sessions and tokens are retained until they expire, are replaced, become unnecessary, or the installation is removed.
  • Operational, webhook, security, and compliance records are retained for the period needed to investigate issues, demonstrate compliance, or meet legal obligations.
  • Order-attribution and engagement records may remain after uninstall where needed to preserve historical merchant reporting or legal records. We delete or de-identify them when they are no longer needed or when a valid legal or Shopify request requires action.
  • Support communications are retained while needed to resolve the request, maintain service history, or protect legal rights.

Deletion from active systems may not immediately remove data from disaster-recovery backups; backup copies are protected and age out under normal backup cycles.

7. International transfers

Only Bundles is based in India, and our providers may process information in India, the United States, Europe, or other countries where they operate. These countries may have different data-protection laws. Where required, we use contractual or other lawful safeguards for international transfers. Merchants remain responsible for any transfer obligations arising from their instructions and storefront use.

8. Security

We use reasonable administrative, technical, and organizational safeguards designed for the sensitivity of the information we process, including restricted access, authenticated Shopify sessions, encryption in transit, and provider security controls. No system can be guaranteed completely secure. Please notify us promptly if you believe the Services or your account have been compromised.

9. Your privacy rights

Depending on where you live and the law that applies, you may have rights to know or access information, correct inaccurate information, delete information, restrict or object to processing, receive portable information, withdraw consent, opt out of certain sale, sharing, or targeted advertising, request review of qualifying automated decisions, appeal a denied request, or complain to a data-protection authority. These rights are subject to exceptions and verification requirements.

This includes rights that may apply under laws in the European Economic Area, United Kingdom, and Switzerland; California and other U.S. states; Canada; Australia and New Zealand; Brazil; India; Japan; and Singapore. We do not discriminate against anyone for exercising an applicable privacy right.

Shopper requests

If your information came from a Shopify store, contact that merchant first. The merchant is generally best placed to identify the transaction and submit the appropriate request to us through Shopify. You may also email us and identify the Shopify store involved. We support Shopify's mandatory customer-data request, customer-redaction, and shop-redaction workflows.

Merchant, staff, and website requests

Email onlybundlesappsupport@gmail.com. Describe the right you wish to exercise and the account or store involved. We may verify your identity and authority before acting. If we cannot fulfil a request, we will explain why where the law requires and provide appeal or complaint information that applies.

10. Children

The Services are intended for Shopify merchants and are not directed to children under 16. We do not knowingly collect personal information directly from children through this website. Merchants are responsible for their storefront audience and any child-related legal requirements.

11. Automated decision-making

Only Bundles does not use personal information to make solely automated decisions that produce legal or similarly significant effects about individuals.

12. Changes to this policy

We may update this policy to reflect changes in the Services, providers, or law. We will post the revised policy here, update the date above, and provide additional notice where required.

13. Contact

Only Bundles
Delhi, India
onlybundlesappsupport@gmail.com

You may also complain to the data-protection authority or regulator in your place of residence where applicable.

Only Bundlesonly bundles

Beautiful bundle journeys for Shopify storefronts.

ProductFeaturesInteractive demoPricingShopify listing ↗
ResourcesHelpSDK for developersBlogChangelog
LegalPrivacyTerms
© 2026 Only BundlesBuilt for Shopify storefronts.