Privacy Policy — M: Simple Bundle Builder
Effective date: 2026 App: M: Simple Bundle Builder (the "App") Provider: Maya Innovations Inc. ("we", "us") Contact: reach@mayainnovations.ca
1. Overview
The App helps Shopify merchants create fixed product bundles and view bundle sales analytics. This policy explains what data we process, why, how long we keep it, and the choices available to merchants and their customers.
We act as a data processor on behalf of the merchant (the data controller) for any personal data we process from their store.
2. Data we process
Merchant / store data
- Shop domain, access token, and session details (to authenticate and call the Shopify Admin API).
- Bundle configurations the merchant creates (titles, products/variants, discounts, status).
Order data (protected customer data)
- When enabled, we receive order webhooks and read order line items, order name, totals, currency, and order date to attribute sales to bundles.
- We record only aggregate-style sales rows: bundle title, quantity sold, revenue, currency, and date. We do not store customer names, emails, phone numbers, or addresses.
We request the minimum order data required for analytics and do not access customer identity fields.
3. Why we process it (purposes)
- App functionality: authenticate the merchant, create the bundle product, and expand bundles at checkout.
- Analytics: measure bundle sales performance and present it to the merchant.
We limit our use of personal data to these purposes and do not use it for profiling, advertising, or any unrelated purpose. We never sell personal data.
4. Sub-processors
We rely on the following providers to run the App:
- Shopify — platform, OAuth, and order webhooks.
- Vercel — application hosting.
- Neon (PostgreSQL) — database storage.
5. Retention
- Bundle sales analytics (
BundleSale) are retained for 24 months, then automatically deleted by a scheduled cleanup. - All merchant data, bundles, and analytics are deleted when the merchant
uninstalls the App or upon a Shopify
shop/redactrequest.
6. Security
- Data is encrypted in transit (HTTPS/TLS) and at rest (managed Postgres).
- Access tokens and secrets are stored as environment configuration, not in source control.
- Access to production data is limited to authorized personnel.
7. Customer rights & GDPR/CCPA
We honor Shopify's mandatory privacy webhooks:
customers/data_request— we hold no customer identity data to export and acknowledge the request.customers/redact— we hold no customer identity data; acknowledged.shop/redact— we erase all data we hold for the shop.
Customers should direct data-subject requests to the merchant (the controller); we assist merchants in fulfilling them.
8. Consent
We process order data as transactional/analytics data on the merchant's behalf and respect customers' consent and opt-out decisions as surfaced by the merchant and Shopify. We do not perform automated decision-making that produces legal or similarly significant effects on customers.
9. Changes
We may update this policy; material changes will be communicated to merchants and reflected by a new effective date.
10. Contact
Questions or requests: reach@mayainnovations.ca, 848 Blythwood Rd, London, Ontario.