Privacy policy
Last updated: 4 August 2026
ComplyBundle ("we", "us") is a Shopify app operated from the Netherlands. This policy describes what data the app collects when a merchant installs it, why, where it is stored, and how it is deleted. Questions are welcome at support@complybundle.com.
What we collect
When you install ComplyBundle on your Shopify store, we collect and store:
- Store identity — your store's myshopify.com domain and the API access token Shopify issues to the app.
- Product and price data — product and variant IDs, titles, prices, compare-at prices and the timestamps at which prices change. This price history is the core function of the app: it is what allows the "lowest price in the last 30 days" notice to be shown.
- Compliance details you enter — any GPSR information (manufacturer details, EU responsible person, warnings) you choose to save for your products.
What we do not collect
The app does not request access to customer data. We store no names, email addresses, shipping addresses, order contents or payment details of your shoppers. The storefront notice is rendered from product metafields and involves no tracking of visitors — no cookies, no analytics scripts, no fingerprinting.
Where data is stored
All data is stored on Cloudflare infrastructure in the European Union (Cloudflare D1, Western Europe region). Cloudflare, Inc. and Shopify International Ltd. act as our subprocessors for hosting and platform services respectively.
How long we keep it
We keep your store's data for as long as the app is installed. When you uninstall the app, Shopify sends us a mandatory deletion request (shop/redact) 48 hours later, and we permanently delete all data associated with your store — price history, GPSR entries and access tokens. You can also request deletion at any time by emailing us.
Legal basis and your rights
We process this data to perform our contract with you: providing the compliance tooling you installed. Under the GDPR you have the right to access, correct, export or delete the data we hold about your store. Email support@complybundle.com and we will respond within 30 days. If you believe we have mishandled your data, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Shopify's mandatory privacy webhooks
The app implements Shopify's required compliance webhooks. customers/data_request and customers/redact are acknowledged automatically — since we hold no customer data, there is nothing to return or erase. shop/redact triggers the full deletion described above.
Changes to this policy
If this policy changes materially, we will update this page and note the new date at the top. Continued use of the app after a change means you accept the updated policy.