Privacy policy

Applies to the Shopify app Scaly Bundle & Set Builder (formerly Custom Bundle Builder). Last updated: 27 September 2026. Separate policies apply to Scaly Visual Product Builder and to Scaly Advent & Deal Calendar.

The short version

The app does not read, store or process personal data of your customers. It does not use cookies, and it does not track anyone. The storefront part of the app talks only to your store's own Shopify cart and makes no request to our servers.

What the app can access

When you install the app, Shopify grants it these permissions:

None of these permissions reaches customer data. The app does not request access to protected customer data, and Shopify would not grant it.

Where your configuration lives

Your setup (which products belong to which step, prices, discount settings, your gift promotions and their codes) is stored in your own shop, in the shop metafield bundle_builder.config. It stays with Shopify. The app has no product database of its own.

Promotion codes are not published in your storefront's page source. The storefront only receives a checksum (SHA-256) of each code, enough to recognise a code a shopper enters, not to reveal it.

What we store on our own infrastructure

The app runs on Cloudflare Workers. For operating and supporting it, we keep the following per store, in Cloudflare KV:

We do not store a copy of your configuration, your product data, your prices or your access token. Access to your shop's API is requested from Shopify when needed and only held briefly in memory, never written to storage.

Support chat

The app's admin pages show a chat bubble in the bottom right corner. When you open it and write to us, our support service (support.scalyapp.de, also on Cloudflare Workers) stores the conversation: your messages and our replies with timestamps, your .myshopify.com domain, your store's name, the app you wrote from, your admin language and an email address (by default the store owner's email from Shopify, or the one you enter in the chat). We use this only to answer you. If we are offline, your message is forwarded to our support mailbox by email, and replies you have not read in the chat are sent to you by email.

Nothing is stored until you send a message. Conversations are deleted 400 days after the last message, when you uninstall the app (see Deletion), or earlier on request.

Your customers

The configurator and the gift code field in your store are rendered by a Shopify theme app extension. They read your setup directly from the shop metafield through Liquid and change the cart only through Shopify's own cart API on your store's domain. They never contact our servers, set no cookies and collect no analytics. We therefore have no data about your customers, not even in aggregate.

Sub-processors

No other party receives data from the app or the support chat. Billing for paid plans is handled by Shopify; we receive only which plan your store is on.

Deletion

The app answers Shopify's mandatory compliance webhooks. When you uninstall the app and Shopify sends shop/redact, we delete the registry entry and the event log for your store. Because we hold no customer data, customers/data_request and customers/redact have nothing to return or erase.

On shop/redact we also delete your support chat conversation, if there is one.

What the app created in your store remains there after uninstalling: the set products, the discount codes of your promotions and the collection “All products (Bundle Builder)”. They are ordinary Shopify items; you can delete them in the Shopify admin at any time.

Contact

Questions about this policy, or a request regarding your data: support@scalyapp.de. Postal address and legal details: Impressum.

Also by Scaly