Privacy Policy for Custoset

Last updated: May 2025

Custoset ("we", "our", or "us") is a Shopify application that allows merchants to create and manage product bundles in their online stores. This Privacy Policy explains how we collect, use, and protect information when you install and use the Custoset app.

1. Information We Collect

When you install Custoset, we collect and store the following information:

  • Shop information: Your Shopify store domain, shop name, and currency.
  • Bundle configuration data: Product selections, pricing rules, discount codes, and banner settings you create within the app.
  • Order and sales data: Aggregate statistics (total sales, revenue, cart additions) associated with your bundles, used solely to display analytics within the app dashboard.
  • Session tokens: OAuth access tokens required by Shopify to authenticate API requests on your behalf.

2. How We Use Your Information

  • To provide and operate the Custoset service within your Shopify store.
  • To render your configured bundles on your storefront via the app block.
  • To display usage analytics (sales, cart events) in your app dashboard.
  • To process Shopify webhooks related to your store (order creation, app uninstall, scope updates).
  • To improve the app's functionality and fix issues.

We do not sell, rent, or share your data with third parties for marketing purposes.

3. Data Storage and Security

Your bundle configurations and session data are stored in a secure database. We use industry-standard security practices including encrypted connections (HTTPS/TLS) and access controls. Session tokens are stored and managed in accordance with Shopify's requirements.

4. Shopify API Access

Custoset requests the following Shopify API scopes to function correctly:

  • read_products — to let merchants browse and select products for bundles.
  • write_script_tags / app blocks — to render the bundle widget on your storefront.
  • read_orders — to track bundle-related sales for analytics.

We only access data that is strictly necessary to provide the service.

5. Customer Data

Custoset does not directly collect or store end-customer (shopper) personal information. The bundle selection widget on your storefront communicates with Shopify's native cart API. No shopper names, emails, or payment details pass through our servers.

6. Data Retention and Deletion

When you uninstall Custoset, we receive a Shopify webhook and revoke the associated session. Your bundle configuration data is retained for 30 days after uninstallation to allow for reinstallation, after which it is permanently deleted. You may request immediate deletion of all your data by contacting us at the email below.

7. Third-Party Services

Custoset is hosted on infrastructure provided by trusted cloud providers. These providers process data on our behalf and are bound by appropriate data processing agreements. We do not use third-party analytics or advertising services that would have access to your store data.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Shopify Partner dashboard or within the app. Continued use of Custoset after changes constitutes your acceptance of the updated policy.

9. Contact Us

If you have any questions about this Privacy Policy or wish to request data deletion, please contact us at:

Email: supportcustoset@gmail.com