Roles
TreStack Bundles reads the orders that match your deals and receives storefront analytics events, so it processes some personal data about your store's customers. For that data you are the controller and TreStack is the processor, and we process it only to run the app you installed, only on your instruction, and never for our own purposes. For our own account and billing records about your store, we are the controller, and the Bundles privacy policy covers those.
This agreement forms part of the TreStack Bundles terms and conditions. Installing the app accepts it. If your organisation needs it as a countersigned document, write to us and we will sign one.
Scope and duration of processing
Processing lasts for as long as the app is installed, and ends when Shopify's shop redaction, sent 48 hours after uninstall, deletes your store's data.
- Subject matter
- Running TreStack Bundles on your Shopify store: showing your deals and applying their discounts at checkout, running A/B tests, attributing order revenue to deals for your analytics and for usage billing, and billing your plan through Shopify.
- Categories of data
- Order data for orders that match a deal: order id, creation time, test flag, and per line the product, variant, quantity, price, discounts, and the app's own line property. Storefront pixel events (deal view, add to cart, checkout started) with deal, product, and A/B variant ids, a timestamp, and a one way hash of Shopify's anonymous browser id. The IP address that arrives with a pixel request, used only to rate limit and not stored with the events. Your store's contact email and name, and the reply email you may give with feedback.
- Data subjects
- Your shoppers whose orders contain a deal's products or whose browsers send pixel events, and you and your staff who use the app admin or send feedback.
- Not processed
- Customer names, emails, phone numbers, and addresses: the orders/create webhook is set up to leave every customer field out, and the 60 day order read on reinstall does not ask for them. No payment data. No cookies are set on your storefront, and the pixel runs only for shoppers who allowed analytics.
- Special categories
- None. Nothing in the app needs sensitive personal data, and none should be written into a deal.
Sub processors
You authorise the sub processors below. The Bundles privacy policy carries the same list and is the live copy. We remain responsible for their performance. If we add or replace one, we will date the change in the privacy policy and announce it inside the app before it goes live, which gives you the chance to object by uninstalling.
- Shopify
- The platform the app runs on. It sends the order and store data described above, runs the app's discount and cart functions, and bills your plan.
- Contabo
- Hosts the one server the app runs on, in the United States, operated by the studio. It holds the store data listed in the privacy policy.
- Cloudflare
- Sits in front of bndl.trestack.app and bndl-px.trestack.app and passes requests to that server, seeing the IP address and request of each. Its R2 storage holds the nightly database backups, which are encrypted before upload, so Cloudflare cannot read them.
Transfers
Data is hosted in the United States, on the server named in the privacy policy. Where personal data from the European Economic Area, the United Kingdom, or Switzerland reaches it, the transfer relies on the standard contractual clauses or another mechanism valid at the time. The mechanism is to be confirmed.
Security measures
The measures below are the ones we actually run. We hold no security certification and do not claim one.
- Every connection uses HTTPS: Cloudflare runs in Full strict mode, and our server presents a Cloudflare origin certificate
- The access tokens Shopify issues are stored encrypted with AES-GCM, and deleted when you uninstall
- The app's database is encrypted at rest: its MySQL InnoDB tablespaces and its redo and undo logs
- No customer fields are requested from Shopify: the order webhook names only the fields the app reads
- Every webhook and app proxy request from Shopify is checked against Shopify's signature, and each pixel request must carry a per store key
- Pixel requests are rate limited per IP address, and the browser id is stored only as a one way hash
- Server logins by SSH key only
- Nightly database backups, with the transaction log every 15 minutes, encrypted on our server before upload to Cloudflare R2, kept for 30 days, and restored as a test every month
Assistance, audits, and breach notification
We handle Shopify's privacy webhooks: a customer data request is answered with what the app holds about that customer, which is no personal information beyond order ids; a customer redaction deletes the app's records of that customer's orders; and a shop redaction deletes all of your store's data. We will help by hand where your case falls outside those, and we will answer reasonable written security questionnaires. We do not offer on site audits.
If we become aware of a personal data breach affecting your store, we will tell you without undue delay, with what we know, what we are doing, and what you may need to tell your own customers. The notification window is a placeholder to be confirmed.
Deletion and return
While the app is installed, raw pixel events are deleted after 45 days, hourly statistics and webhook receipts after 7 days, and the working file of a 60 day order read after 8 days at most; daily statistics and order line records are kept until uninstall. On uninstall the access tokens are deleted at once, and deals stop showing because nothing was written into your theme files. The shop redaction Shopify sends 48 hours later deletes the store record and everything tied to it: deals, statistics, events, order lines, and feedback. Backups roll off within 30 days of that. You can ask for an export of your analytics before you uninstall, or for deletion sooner, by writing to us.
Questions about this document go to [email protected] and are answered by the people who wrote the app.