Bundle GuardBack to home

Legal

Privacy policy

Version 1.0 — 10 August 2026

Who is responsible

Bundle Guard is operated by 2SMART4YOU, a French SASU registered under SIRET 999 276 835 00017, at 16 rue de la Treille, 13170 Les Pennes-Mirabeau, France. Privacy requests can be sent to admin@2smart4you.fr.

Data processed

  • Shopify shop domain, OAuth credentials and app-session metadata required to install, authenticate and operate the app.
  • Product identifiers and titles, component status and imagery, variant inventory policy and aggregate inventory quantities for native fixed bundles, requested from Shopify during a health scan.
  • The latest health-scan snapshot, including detected issues and summary counts, so the merchant can review the last result.
  • Subscription status supplied by Shopify Billing to decide whether health scans may run.
  • Support messages and limited technical logs needed to secure and troubleshoot the service.
  • A random installation identifier and onboarding milestones such as opening the app, starting billing, completing a scan, detecting an issue or opening support. The event record does not contain the shop domain, customer data or catalogue data.
  • Visits to the Bundle Guard listing in the Shopify App Store, clicks on the install button and completed installations. Shopify sends these events to our Google Analytics 4 property. Depending on the event, this can include the referring App Store surface, shop identifier, shop name and shop URL.

Bundle Guard does not request or store customer, order, payment or checkout data and does not use merchant data for advertising or AI training.

Purposes and legal bases

App sessions, catalogue scans, saved health results and subscription checks are processed to perform the merchant contract. Security logs are processed for the legitimate interest of protecting and maintaining the service. The short-lived onboarding milestones and App Store listing analytics are processed for our legitimate interest in measuring whether merchants can activate the app successfully. Billing records are processed by Shopify under its own terms and legal obligations.

Retention and deletion

  • App sessions are deleted when the app is uninstalled and again when Shopify sends its shop-redaction request.
  • Only the latest bundle-health snapshot is kept and it is replaced by the next successful scan.
  • The latest bundle-health snapshot is deleted when the app is uninstalled and again on Shopify's final shop-redaction request.
  • Onboarding milestones are retained for no more than 30 days. Their random installation identifier is no longer linked to a shop after the app session is deleted.
  • Operational logs are retained for no more than 30 days unless a security incident requires longer preservation.
  • Support correspondence is retained for up to three years after the last exchange.

Processors and transfers

Shopify provides installation, authentication, APIs and billing. OVH SAS, 2 rue Kellermann, 59100 Roubaix, France, hosts the application in the European Union. Google Ireland Limited provides analytics for the Shopify App Store listing. Where Shopify or Google processes data outside the European Economic Area, their published contractual and transfer safeguards apply.

Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability by emailing admin@2smart4you.fr. You may also lodge a complaint with the CNIL or your local data protection authority. Requests are answered within the legally applicable period.

Cookies

Bundle Guard does not run on the merchant storefront and does not add advertising or analytics cookies to the embedded app. The Shopify App Store is operated by Shopify and applies its own cookie and privacy controls. Listing events are sent to our Google Analytics property only through the tracking integration provided by Shopify.