SetMint Bundles

Privacy policy

This policy explains how SetMint Bundles handles information when a Shopify merchant installs or uses the app.

Effective July 25, 2026

Information we process

We process only the information needed to install, operate, secure, support, and improve the app:

  • Merchant and store information, including the shop domain, installation and session records, plan and entitlement status, and app settings.
  • Product and bundle configuration, including Shopify product, variant, inventory, publication, and cart-transform identifiers.
  • Order and refund analytics needed to attribute bundle performance, including Shopify resource identifiers, timestamps, currency, quantities, and monetary totals.
  • Operational records such as signed webhook delivery status, audit events, error details, and security-relevant request metadata.
SetMint Bundles does not request customer name, email, phone, or address fields. Customer profile fields are not used for bundle analytics.

Why we process information

We use information to:

  • Create, synchronize, publish, and operate bundle offers.
  • Apply configured bundle behavior in the online store, cart, and checkout workflows.
  • Calculate bundle sales and refund analytics for the merchant.
  • Authenticate requests, isolate stores, verify webhook signatures, prevent abuse, troubleshoot errors, and provide support.
  • Maintain billing entitlements and comply with Shopify platform requirements.

We process merchant data to provide the app under our agreement with the merchant and follow the merchant's instructions for customer-related data.

Sharing and service providers

We do not sell personal data. Information is shared only when necessary to provide or protect the service, comply with law, or follow a merchant's instructions. The app uses Shopify as its commerce platform and Google Cloud services for application hosting, managed database storage, secrets, and operational infrastructure. These providers process information on our behalf under their applicable service and data-protection terms.

Retention and deletion

  • Bundle analytics are retained for 30 days on Starter, 180 days on Growth, and 24 months on Pro.
  • Security and audit events are retained for up to 90 days.
  • Completed webhook-delivery records are retained for up to 30 days.
  • Data is deleted or anonymized when it is no longer needed. A verified Shopify shop-redaction request removes the corresponding shop data, including app sessions and business records.

Security

We use TLS in transit, encryption at rest through managed Google Cloud services, Shopify HMAC verification, tenant isolation, access controls, secret management, and data-minimizing webhook processing. No system can guarantee absolute security, but we maintain safeguards appropriate to the information processed.

Merchant and customer requests

Merchants may request access, correction, export, or deletion of app data by contacting us. Customers should normally direct privacy requests to the Shopify merchant they interacted with; we assist merchants with verified requests that concern data processed by SetMint Bundles.

International processing

Information may be processed where Shopify, Google Cloud, or our service operations are located. We use the contractual and technical safeguards made available by those providers for applicable cross-border transfers.

Changes to this policy

We may update this policy when the app, legal requirements, or service providers change. The effective date above identifies the current version.

Contact

Privacy or data-protection questions can be sent to [email protected].