BundleKit

Legal

Privacy Policy

Last updated: August 28, 2026

This policy describes how BundleKit ("the app"), provided by MPC Trades, handles data when a merchant installs it on a Shopify store.

What we access and why

Scope requestedWhy
read_products, write_productsShow your catalog in the offer builder and write the metafield an offer needs
write_discountsCreate the automatic discount that powers each offer
read_ordersRead the price and quantity of order line items tagged by the widget, so we can total revenue attributed to each offer

What we do NOT collect

BundleKit never reads, stores, or transmits your customers' personal information. Specifically, we do not access customer names, email addresses, phone numbers, or shipping/billing addresses, even though our read_orders scope makes the order object available to us. Our order-webhook handler reads only line items (price, quantity, and an internal attribution tag) — nothing else in the order payload is read or persisted.

What we do store

Data retention

When you uninstall BundleKit, our uninstall handler deletes your shop's session, configuration, offers, and stats. No data is retained after uninstall.

Data sharing

We do not sell or share your data with third parties. We do not use your data for advertising.

Security

All data is transmitted over HTTPS/TLS.

Your rights

Shopify merchants and their customers can request data access or deletion per Shopify's standard data subject request process. We support Shopify's mandatory compliance webhooks: customers/data_request, customers/redact, and shop/redact.

Contact

Questions about this policy: team@mpctrades.com

Changes

We'll update this policy as the app's data use changes and note the date at the top.