Privacy policy
Better Bundles is a Shopify app operated by Valera Labs. This page explains what the app stores about your store, why, how long it is kept and how to have it removed. Last updated 17 September 2026.
The short version
- The app stores information about your store and its bundle products, nothing else.
- It does not collect, store or process your customers’ personal data.
- It does not sell or share data, run advertising or use tracking cookies.
- Everything it holds is deleted when you uninstall the app.
What the app stores
When you install Better Bundles, the app keeps the following on its own servers:
- Store identity and access. Your store’s
myshopify.comdomain and the API access token Shopify issues to the app, so it can read and update products on your behalf. The token is scoped to products, cart transforms, discounts and inventory, and is never shown to staff or third parties. - Install records. The identifiers of the cart transform and automatic discount the app registers in your store, so the Setup page can check and repair them.
- A bundle index. For each bundle: the parent product and variant identifiers, the bundle title, price and currency, the component variants and their prices, an image URL and a health status. This is a cache of what already lives in your Shopify store as product data; the app rebuilds it from product webhooks and does not store anything Shopify does not already hold.
The bundle definitions themselves are stored in your Shopify store as app-owned metafields on the bundle’s parent variant, not on our servers. They are yours and stay with the product.
What the app does not store
- Customer data. The app never reads or stores customer names, emails, addresses, orders or payment details. The mix-and-match choices a customer makes ride on the cart line as a line-item property and are stored by Shopify with the order, not by us.
- Staff data. The app uses a store-level (offline) access token. It does not store the names or emails of the staff members who use it.
- Browsing data. Neither the app nor this website uses analytics or advertising cookies. The embedded admin relies solely on Shopify’s session tokens.
How the app uses data on your storefront and POS
The theme block, the POS extension and headless storefronts fetch a public catalogue of your bundles from the app: bundle titles, prices, component variants and images. These requests carry your store domain and, on POS, a Shopify session token that identifies the store, so the app can answer for the right shop. They are served from the bundle index above and are not logged against individual customers.
Who else processes data
- Shopify provides the platform, the APIs and the checkout, and processes all order and customer data under its own privacy policy.
- Hostinger hosts the app’s server and database.
- Sentry receives error reports when something in the app fails. Reports carry the error, the store domain and technical context, never customer data.
Server access logs record the request path, timing and status, as is standard for any web service, and are rotated.
Retention and deletion
- Uninstall. When you uninstall the app, Shopify notifies us and the app deletes your store’s access token, install records and bundle index at once. Shopify removes the app’s metafields, cart transform and discount from your store itself.
- Shop redaction. Shopify sends a further redaction request 48 hours after uninstall; the app honours it by deleting anything that remains for the store.
- Customer requests. The app receives Shopify’s customer data request and customer redaction webhooks. Because it holds no customer data, there is nothing to export or erase, and it acknowledges each request.
Security
All traffic between your browser, Shopify and the app is encrypted with TLS. Access tokens are stored in a database that is not reachable from the public internet. The app requests only the API scopes it needs to build and sell bundles.
Your rights and how to contact us
You can ask what the app holds about your store, ask for it to be corrected or deleted, or raise any other privacy question by emailing cjvalera542@gmail.com. Uninstalling the app deletes everything without needing to ask.
Changes to this policy
If the app starts storing something new, this page changes first and the date at the top moves. Material changes are also announced inside the app.