Billing, privacy, and when something is wrong

Privacy, data and sub-processors

What TreStack Bundles keeps about your store, its orders and your shoppers, how long, how Shopify privacy requests are handled, and the four sub-processors.

Applies to: TreStack Bundles, every plan
Updated: 11 October 2026

At a glance
  • Customer names, emails, addresses: Never received
  • Cookies on your storefront: None
  • Store data deleted: 48 hours after uninstall

About your store

Access. When you install the app, Shopify gives it the access scopes it asks for: products, publications, inventory, discounts, cart transforms, orders, themes, markets, languages, files, the web pixel and customer events, plus storefront read access to product listings, stock and subscription options. It asks for no access to your customer records or to payments.

What it keeps. Your shop domain and id, store name, contact email, currency, main language, Shopify plan type (for example whether it is a development store), markets and languages; encrypted access tokens; your plan, subscription and charge records as Shopify reports them, and the added revenue figure plans are billed on; your deals with their settings, translations, brand colors and custom CSS; and daily statistics per deal. If you send feedback from the "How's your experience with the app?" card on Home, it keeps the rating, the text and the reply email if you give one. If you cancel your plan, it keeps the reason you chose.

Orders. For orders that contain a deal's products, the app keeps the order id, its creation time and test flag, and for each matching line the product, variant, quantity, price, discounts and the app's own hidden line property. These come from Shopify's order webhook, set up so that Shopify leaves out every customer field, and on a reinstall from a one-time read of the last 60 days of orders, which asks for no customer fields either. No customer name, email, phone number or address reaches the app.

Images. Images you upload in the editor (JPG, PNG, GIF, WebP or SVG, up to 20 MB) go to your own Shopify Files, not to our server.

About your shoppers

The app sets no cookies on your storefront.

The web pixel "Bundle deal analytics" counts deal views, add to carts and checkouts started. It runs only for shoppers who allowed analytics under your store's cookie and consent settings, inside Shopify's strict pixel sandbox. For each event it sends bndl-px.trestack.app the deal, bar, A/B variant and product ids, a timestamp and Shopify's anonymous browser id. The server keeps only a one-way hash of that id, so the data is pseudonymous, not anonymous: it cannot name a shopper, but it can tell repeat visits from one browser apart. The IP address of each request is used to limit how many requests one address can send and is not stored with the events.

For a running A/B test, the shopper's own browser keeps a random id in local storage (bndl_sid) so the shopper sees the same variant on later visits. It is never sent to our servers.

Nothing is sold or used for advertising.

Retention and Shopify privacy requests

DataKept
Raw pixel events45 days
Hourly statistics7 days
Daily statistics and order linesWhile the app is installed
Access tokensDeleted at uninstall
Everything about your storeDeleted 48 hours after uninstall
BackupsRoll off within 30 days

Shopify forwards three kinds of privacy request to installed apps, and the app handles each automatically:

  • Customer data request: answered with what the app holds about that customer, which is no personal information beyond order ids.
  • Customer redaction: deletes the app's records of that customer's orders.
  • Shop redaction, sent 48 hours after you uninstall: deletes the store record and everything tied to it, including deals, statistics, events, order lines and feedback.

Sub-processors and the agreement

The app uses four sub-processors, each only for its own service:

  • Shopify: the platform the app runs on. It sends the store and order data above, runs the app's discount and cart functions, bills your plan, and holds your uploaded images in your Shopify Files.
  • Contabo: hosts the one server the app runs on, in the United States, operated by us. The same server runs TreStack Timer.
  • Cloudflare: sits in front of bndl.trestack.app and bndl-px.trestack.app and sees the IP address of each request. Its R2 storage holds the nightly database backups, encrypted before upload.
  • Chaport: the live chat inside the app admin, never on your storefront. It receives your myshopify domain and plan, plus whatever you write in the chat.

For your shoppers' data, you are the controller and we are the processor. The data processing agreement is published at trestack.app/bundles/dpa and forms part of the terms; installing the app accepts it. The full privacy policy is at trestack.app/bundles/privacy. We hold no security certification and do not claim one.

Getting your position straight, in four steps.

Read the lists above

That is what the app keeps. If something is not on them, the app does not hold it.

Read the privacy policy and the DPA

Both are public at trestack.app/bundles/privacy and trestack.app/bundles/dpa, so there is nothing to request before reading them.

Update your own privacy policy

Name the app, its analytics pixel (which runs only with consent) and the bndl_sid browser storage it uses for A/B tests. It sets no cookies.

Ask about anything unclear

Privacy requests go to legal@trestack.app. Other questions go to support@trestack.app or the live chat in the app admin.

Settings reference

Access scopes
Products, discounts, cart transforms, orders, themes, markets, languages, files, pixel and storefront reads. No customer or payment scopes.
Order data
Order id, time, test flag, and per matching line the product, variant, quantity, price and discounts. No customer fields.
Pixel events
Deal viewed, added to cart, checkout started. Only with the shopper's analytics consent. Browser id stored as a one-way hash.
Cookies
None. A/B tests use bndl_sid in local storage, never sent to us.
Retention
Raw events 45 days, hourly statistics 7 days, the rest until uninstall. All store data deleted 48 hours after uninstall.
Sub-processors
Shopify, Contabo, Cloudflare, Chaport.
Contact
legal@trestack.app for privacy requests, support@trestack.app for everything else.

If this does not work

The failures most likely on this procedure, with the check that resolves each one.

Copyright © 2026