Privacy Policy

Bundle Architect · Last updated: 10 July 2025

1. Who We Are

Saniere Ltd operates Bundle Architect (the "App"), a Shopify application available at https://saniere-price-sync.vercel.app. We are committed to protecting your privacy and handling your data responsibly.

If you have any questions about this policy, contact us at sales@saniere.co.uk.

2. What Data We Collect

When you install the App, we collect and process the following:

  • Shopify store domain — to identify your store and route webhook events correctly
  • Shopify access token — to authenticate API requests made on your behalf (stored securely in an encrypted database)
  • Product data — product IDs, variant IDs, prices, and metafield values are read during sync operations. This data is processed in memory and not stored persistently.
  • Order data — order line items are read when an order is placed to identify bundle components and trigger inventory deductions. Order data is not stored.
  • Inventory levels — stock quantities are read and written to keep bundle inventory in sync with components. Not stored persistently.

We do not collect any personal data about your customers.

3. How We Use Your Data

The data we access is used solely to provide the App's functionality:

  • Calculating and updating bundle prices when component prices change
  • Adjusting inventory levels when bundles are sold or component stock changes
  • Rendering storefront blocks (bundle components, upsells, specifications)

We do not sell, rent, or share your data with third parties for marketing purposes.

4. Data Storage & Security

Your Shopify access token is stored in an encrypted key-value store (Upstash Redis) hosted on infrastructure within the EU. We use industry-standard security practices to protect this data.

No customer personal data (names, addresses, payment details) is ever stored or processed by the App.

5. Third-Party Services

The App uses the following third-party services:

  • Shopify Admin API — to read and write product, order, and inventory data on your store
  • Vercel — for hosting the App's server infrastructure (data processed in the USA/EU)
  • Upstash Redis — for secure, temporary storage of authentication tokens (EU region)

Each of these providers has their own privacy policies and security certifications.

6. Data Retention

We retain your Shopify access token for as long as the App is installed on your store. When you uninstall the App, we receive a webhook notification and queue your authentication data for deletion within 30 days.

7. Your Rights (GDPR)

If you are based in the UK or EU, you have the right to:

  • Request access to the data we hold about your store
  • Request deletion of your data at any time by contacting us or uninstalling the App
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, email us at sales@saniere.co.uk.

8. Cookies

The App itself does not use cookies. Any cookie usage on your Shopify storefront is governed by Shopify's own privacy policies and your store's cookie settings.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the App or by email. Continued use of the App after changes are posted constitutes your acceptance.

10. Contact

For privacy-related queries, please contact:

Saniere Ltd
Email: sales@saniere.co.uk

Terms & Conditions·Shopify Privacy Policy