Privacy, data and sub-processors
Applies to: TreStack Bundles, every plan
Updated: 11 October 2026
- Customer names, emails, addresses: Never received
- Cookies on your storefront: None
- Store data deleted: 48 hours after uninstall
About your store
Access. When you install the app, Shopify gives it the access scopes it asks for: products, publications, inventory, discounts, cart transforms, orders, themes, markets, languages, files, the web pixel and customer events, plus storefront read access to product listings, stock and subscription options. It asks for no access to your customer records or to payments.
What it keeps. Your shop domain and id, store name, contact email, currency, main language, Shopify plan type (for example whether it is a development store), markets and languages; encrypted access tokens; your plan, subscription and charge records as Shopify reports them, and the added revenue figure plans are billed on; your deals with their settings, translations, brand colors and custom CSS; and daily statistics per deal. If you send feedback from the "How's your experience with the app?" card on Home, it keeps the rating, the text and the reply email if you give one. If you cancel your plan, it keeps the reason you chose.
Orders. For orders that contain a deal's products, the app keeps the order id, its creation time and test flag, and for each matching line the product, variant, quantity, price, discounts and the app's own hidden line property. These come from Shopify's order webhook, set up so that Shopify leaves out every customer field, and on a reinstall from a one-time read of the last 60 days of orders, which asks for no customer fields either. No customer name, email, phone number or address reaches the app.
Images. Images you upload in the editor (JPG, PNG, GIF, WebP or SVG, up to 20 MB) go to your own Shopify Files, not to our server.
About your shoppers
The app sets no cookies on your storefront.
The web pixel "Bundle deal analytics" counts deal views, add to carts and checkouts started. It runs only for shoppers who allowed analytics under your store's cookie and consent settings, inside Shopify's strict pixel sandbox. For each event it sends bndl-px.trestack.app the deal, bar, A/B variant and product ids, a timestamp and Shopify's anonymous browser id. The server keeps only a one-way hash of that id, so the data is pseudonymous, not anonymous: it cannot name a shopper, but it can tell repeat visits from one browser apart. The IP address of each request is used to limit how many requests one address can send and is not stored with the events.
For a running A/B test, the shopper's own browser keeps a random id in local storage (bndl_sid) so the shopper sees the same variant on later visits. It is never sent to our servers.
Nothing is sold or used for advertising.
Retention and Shopify privacy requests
| Data | Kept |
|---|---|
| Raw pixel events | 45 days |
| Hourly statistics | 7 days |
| Daily statistics and order lines | While the app is installed |
| Access tokens | Deleted at uninstall |
| Everything about your store | Deleted 48 hours after uninstall |
| Backups | Roll off within 30 days |
Shopify forwards three kinds of privacy request to installed apps, and the app handles each automatically:
- Customer data request: answered with what the app holds about that customer, which is no personal information beyond order ids.
- Customer redaction: deletes the app's records of that customer's orders.
- Shop redaction, sent 48 hours after you uninstall: deletes the store record and everything tied to it, including deals, statistics, events, order lines and feedback.
Sub-processors and the agreement
The app uses four sub-processors, each only for its own service:
- Shopify: the platform the app runs on. It sends the store and order data above, runs the app's discount and cart functions, bills your plan, and holds your uploaded images in your Shopify Files.
- Contabo: hosts the one server the app runs on, in the United States, operated by us. The same server runs TreStack Timer.
- Cloudflare: sits in front of
bndl.trestack.appandbndl-px.trestack.appand sees the IP address of each request. Its R2 storage holds the nightly database backups, encrypted before upload. - Chaport: the live chat inside the app admin, never on your storefront. It receives your myshopify domain and plan, plus whatever you write in the chat.
For your shoppers' data, you are the controller and we are the processor. The data processing agreement is published at trestack.app/bundles/dpa and forms part of the terms; installing the app accepts it. The full privacy policy is at trestack.app/bundles/privacy. We hold no security certification and do not claim one.
Getting your position straight, in four steps.
Read the lists above
That is what the app keeps. If something is not on them, the app does not hold it.
Read the privacy policy and the DPA
Both are public at trestack.app/bundles/privacy and trestack.app/bundles/dpa, so there is nothing to request before reading them.
Update your own privacy policy
Name the app, its analytics pixel (which runs only with consent) and the bndl_sid browser storage it uses for A/B tests. It sets no cookies.
Ask about anything unclear
Privacy requests go to legal@trestack.app. Other questions go to support@trestack.app or the live chat in the app admin.
Settings reference
If this does not work
The failures most likely on this procedure, with the check that resolves each one.
Pausing, cancelling and uninstalling
Why deals pause and how they come back, what cancelling a plan does, and what uninstalling removes, what it leaves in your store, and when your data is deleted.
When a deal does not show or prices look wrong
The store widget is off, deals are paused, a deal is not reaching one product, or the cart and checkout price surprise you. What to check, in order, and how to reach us.