Skip to main content

Privacy Policy — Smart Bundles & Margin Guard

Effective date: July 17, 2026 Operator: Smart Bundles Labs Inc. Privacy contact: admin@lamininco.com Support: https://sbmg-admin-web.fly.dev/help

This policy describes how Smart Bundles Labs Inc. ("Smart Bundles," "we," "us") processes information when a Shopify merchant installs or uses Smart Bundles & Margin Guard (the "App"). It is intended to describe the App as currently released. It does not claim a certification that has not been independently verified.

1. Information the App processes

Merchant and shop information

  • Shopify shop domain and Shopify shop identifier.
  • Store currency and configuration needed for calculations.
  • App settings, including margin floors, feature settings, and subscription tier.
  • Shopify staff identity contained in a short-lived Shopify session token when a staff member opens the embedded App. Session tokens are validated for authentication and are not stored as long-lived browser credentials.

Product and bundle information

  • Product and variant identifiers, titles, SKUs, prices, images, inventory fields, and app-managed metafields.
  • Cost of goods sold supplied by the merchant or read from permitted Shopify product data.
  • Bundle definitions, bundle line items, prices, discounts, and projected margin results.

Order and decision information

  • Order identifiers, timestamps, financial status, line-item identifiers, quantities and prices, discounts, and order totals.
  • Margin decision, reason, rule path, model version, confidence, and calculation inputs required for the merchant's reporting and audit history.

The App's order-reporting query and configured order webhook do not request customer names, customer email addresses, postal addresses, or payment-card data. Shopify may deliver additional fields if its webhook configuration is changed outside this repository; we limit configured order webhook fields and do not use customer identity for margin reporting.

Technical and support information

  • Request metadata, IP address, user agent, timestamps, error details, rate-limit events, and security/audit events.
  • Information a merchant chooses to include in a support request.

2. Shopify permissions

The current App configuration requests exactly six Shopify permissions:

Permission What it allows
read_products Read your product catalogue so you can select variants and record costs
write_products Write the cost you enter back to a product metafield, so Shopify shows the same figure the App enforces against
read_orders Read order line items and totals to compute the gross margin actually achieved
read_discounts Read your existing discounts, so the App can show which are App-managed and detect if one is deleted
write_discounts Create and update the automatic discount that runs the margin check. Scoped to discounts the App itself owns
write_validations Create the checkout rule that can stop an order whose applied discounts would push it below your configured gross-margin floor. Also grants the matching read access. Nothing is blocked until you create a Margin Guard discount and enable the rule

The App does not request read_customers, write_customers, read_all_orders, read_shipping, write_shipping, metaobject, checkout-write, price-rule, or Shopify Analytics permissions. It therefore never queries customer profiles through the Shopify API, and never receives customer names or postal addresses.

There is one exception, and we state it plainly because the distinction matters: the mandatory Shopify privacy webhooks deliver a customer identifier and, where Shopify includes them, an email address and phone number — in the body of the request itself, not through any API we call. These arrive only when a shopper exercises a data right.

We use them for two purposes and no others: to locate the records the request concerns, and to send the response to the person who made it. They are not used for marketing, analytics, profiling, or any other processing, and they are not retained once the response has been delivered.

3. How information is used

We process information to:

  • authenticate the merchant's shop and staff requests;
  • synchronize products and merchant-provided COGS;
  • calculate and display merchant-only margins;
  • create and manage bundle records and margin-aware discount configuration;
  • record order-level margin decisions;
  • manage subscription status and usage limits through Shopify Billing;
  • provide support, diagnose errors, prevent abuse, and maintain security logs;
  • respond to authenticated privacy requests and meet legal obligations.

We do not sell personal information. We do not use customer identity for advertising. We do not display merchant COGS, profit, or gross-margin data to buyers at checkout.

4. Billing

Paid App subscriptions are created through Shopify Billing. We store plan, subscription, charge, and status identifiers needed to enforce the merchant's selected plan. Shopify, not Smart Bundles, processes the merchant's payment-card details. We do not use Stripe for App subscription billing.

5. Service providers and disclosures

Information is disclosed only as needed to operate the App, comply with law, protect the service, or complete a merchant request. Current service categories include:

  • Shopify: installation, authentication, Admin GraphQL API, Functions, webhooks, and billing.
  • Fly.io: current application and database hosting for the production services identified by the production deployment.
  • Infrastructure services: encrypted secrets, object storage, backups, email delivery, error reporting, or monitoring when enabled for the production environment.

The exact production subprocessor inventory can change as infrastructure changes. Material changes that affect personal-data processing will be reflected in this policy. We do not list a vendor as active merely because an unused integration or example configuration exists in source control.

We may disclose information when required by a valid legal process or when reasonably necessary to investigate fraud, abuse, or a security incident.

6. Security

The App uses HTTPS in transit, validates Shopify session tokens and webhook signatures, encrypts stored Shopify offline access tokens using authenticated encryption, applies tenant identifiers to application data access, and records security-relevant events. Access to production infrastructure is restricted through service credentials and provider access controls.

No security program eliminates all risk. We do not claim SOC 2, ISO 27001, PCI DSS, or another independent certification unless a current audit report specifically confirms it.

7. Retention and deletion

  • Active merchant business records are retained while needed to provide the App and meet the selected plan's reporting functions.
  • A Shopify app/uninstalled event disables the tenant and revokes normal App access.
  • Shopify's shop/redact privacy event triggers deletion of shop data after Shopify's uninstall waiting period.
  • Authenticated customer and shop deletion requests delete or anonymize matching App records. Backups age out through the applicable backup lifecycle, targeted within 90 days.
  • Security and compliance audit entries may be retained longer when necessary to demonstrate processing or investigate abuse. Any retained entry should be minimized and de-linked from directly identifying customer data.

8. Merchant and data-subject choices

Merchants can update App settings in Shopify Admin, request privacy assistance through Shopify's verified privacy-request channels or at admin@lamininco.com, or uninstall the App.

Customers of a merchant should normally submit access or deletion requests to that merchant. Shopify then delivers the applicable mandatory privacy webhook to the App. We will also assist a merchant with a verified request sent to the privacy contact above.

Depending on applicable law, a person may have rights to access, correct, delete, restrict, or object to processing and to lodge a complaint with a regulator. We will verify and respond to requests as required by applicable law.

9. International processing

The current production service is operated using United States-based or globally distributed infrastructure. A merchant that requires a particular transfer mechanism or data location should contact admin@lamininco.com before enabling the App. A separate Data Processing Agreement is available at /legal/dpa.

10. Children

The App is a business tool for Shopify merchants and is not directed to children. We do not knowingly use customer identity to provide the App.

11. Changes

We may update this policy when the App, vendors, or legal obligations change. The effective date above identifies the current version. Material changes will be communicated through the App or the merchant contact available through Shopify when required.

12. Contact

Questions and verified privacy requests can be sent to admin@lamininco.com. General product support is available at https://sbmg-admin-web.fly.dev/help.