Privacy Policy

Effective date: March 12, 2026

This Privacy Policy describes how Only Super Apps ("we", "us", or "our") collects, uses, and shares information when you install and use the Super Bundle application ("the App") from the Shopify App Store. By installing the App, you agree to this policy.

1. Information We Collect

Shop Data

When you install the App, we collect basic store information through the Shopify API, including your store name, store owner email address, store domain, and Shopify plan information. This data is required to authenticate your account and provide the service.

Bundle Configuration Data

We store the bundle configurations you create within the App, including product selections, discount rules, display settings, A/B test variants, and subscription settings.

Analytics Events

The App collects anonymized analytics events from your storefront, including bundle views, add-to-cart actions, and conversion events. These events are used to power the analytics dashboard and A/B testing features. No personally identifiable customer information is collected through analytics events.

Customer Data

We process minimal customer data. When you enable the Subscribe & Save feature, we collect the customer's email address solely for the purpose of matching subscription contracts. We do not collect or store any other customer personal information such as names, addresses, or payment details.

2. How We Use Your Data

We use the information we collect for the following purposes:

  • To provide, operate, and maintain the bundle builder service
  • To display analytics and A/B test results on your dashboard
  • To process billing through Shopify's billing system
  • To communicate with you about your account, updates, and support requests
  • To improve the App and develop new features

3. Data Storage and Security

Your data is stored in a PostgreSQL database hosted on Neon, located in the AWS us-east-1 (US East, N. Virginia) region. All data is encrypted at rest. We use industry-standard security measures to protect your information, including encrypted connections (TLS/SSL) for all data in transit.

4. Third-Party Services

We use the following third-party services to operate the App:

  • Shopify -- We access your store data through the Shopify API and process billing through Shopify's subscription billing system. Shopify's privacy policy governs their handling of your data.
  • Neon -- Our database provider. Neon hosts the PostgreSQL database where your bundle configurations and analytics data are stored.
  • Vercel -- Our hosting provider. Vercel serves the App's web interface and API endpoints.
  • Crisp -- Our live chat provider. Crisp may collect information when you interact with the chat widget, subject to Crisp's own privacy policy.

We do not sell, rent, or share your data with any other third parties for marketing or advertising purposes.

5. GDPR Compliance

If you are located in the European Economic Area (EEA), you have certain data protection rights under the General Data Protection Regulation (GDPR). These include:

  • Right to Access -- You may request a copy of the personal data we hold about you.
  • Right to Rectification -- You may request that we correct any inaccurate data.
  • Right to Erasure -- You may request that we delete your personal data.
  • Right to Data Portability -- You may request your data in a structured, machine-readable format.
  • Right to Restrict Processing -- You may request that we limit how we use your data.

To exercise any of these rights, please contact us at support@onlysuperapps.com. We will respond to your request within 30 days.

6. Data Retention

We retain your data for as long as the App is installed on your Shopify store. When you uninstall the App, we receive a notification from Shopify via the shop/redact webhook. All associated shop data, bundle configurations, and analytics data are permanently deleted within 48 hours of receiving the uninstall notification.

7. Customer Data Handling

We process minimal customer data on behalf of your store. Customer email addresses are used only for subscription contract matching when the Subscribe & Save feature is enabled. We do not use customer data for any other purpose.

Upon receiving a customer data redaction request from Shopify (via the customers/redact webhook), we anonymize or delete all customer-identifiable information associated with that customer within 48 hours.

8. Cookies

The App uses only essential session cookies for authentication within the Shopify Admin. We do not use tracking cookies or advertising cookies.

Our live chat provider, Crisp, uses its own cookies to maintain chat sessions and improve chat functionality. Please refer to Crisp's privacy policy for details on their cookie usage.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or by email. Your continued use of the App after any changes constitutes your acceptance of the updated policy.

10. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Only Super Apps
Email: support@onlysuperapps.com
Website: onlysuperapps.com