What this app accesses, what it stores, how long it keeps it, and how to have it removed.
Last updated 26 August 2026Falco Bundles is a Shopify app that lets merchants sell products together — as fixed bundles, mix-and-match sets, assembled outfits, and shoppable looks — and shows them how those offers perform.
This policy is written for the merchants who install the app and for their customers. Falco Bundles is operated by Aramega Digital Solutions, aramega.com. The app's own site is falco1.com.
The app requests only the access it needs to function. Its current permissions are:
| Permission | Why |
|---|---|
write_products | Create and update the shell products that represent a bundle, and read the products a merchant chooses for one |
read_orders | Attribute completed sales to the merchant's bundles |
read_publications, write_publications | Publish bundle products to the merchant's Online Store |
read_cart_transforms, write_cart_transforms | Apply the merchant's bundle discount in the cart |
unauthenticated_read_product_inventory | Show shoppers when a size or colour is unavailable |
write_files | Store cutout images a merchant uploads for the outfit canvas |
When an order is paid, Shopify sends us the order. We read four things from it: the order ID, the currency, the date, and the line items — product ID, variant ID, quantity, price.
We do not read the customer object, the email address, the phone number, the billing address, or the shipping address. Those fields arrive in Shopify's payload and are discarded unread; they are never written to our database.
We have not requested and do not hold Shopify's read_customer_name, read_customer_email, read_customer_phone, or read_customer_address permissions.
The app's storefront blocks record when a shopper reaches a stage of a bundle — viewing it, adding to it, reaching checkout. Each record contains only which bundle, which stage, and a timestamp.
There is no customer ID, no session ID, no device identifier, no IP address, and no cookie. These records cannot be traced to an individual and are not used to build a profile of anyone.
The app sets one item in the shopper's own browser storage: the outfit they are assembling, so it survives a page reload. It stays on their device, is never transmitted to us, and contains only product references.
Customer names, email addresses, phone numbers, postal addresses, payment details, IP addresses, or any identifier that resolves to an individual shopper.
The single purpose is providing the app's functionality to the merchant: displaying their bundles on their storefront, applying their discounts, and reporting how those bundles performed.
We do not use this data for anything else. We do not sell it, share it for advertising, use it to build profiles, or use it for automated decision-making. We do not use it to train models.
| Data | Retained | Then |
|---|---|---|
| Sales records | 2 years from the sale | Deleted automatically |
| Storefront interaction events | 90 days | Deleted automatically |
| Bundle configuration | While the app is installed | Deleted on uninstall or erasure request |
| Session / access token | While the app is installed | Deleted on uninstall |
Deletion runs automatically and continuously; it does not depend on anyone requesting it.
Two years for sales records is chosen so a merchant can compare a season against the same season last year, which is the longest look-back the app's reporting offers. Interaction events are kept for a shorter period because they exist only to show a recent trend.
Merchants can have everything we hold for their store deleted by uninstalling the app, or by contacting us. We also respond automatically to Shopify's shop/redact request, which erases every record associated with that store in a single operation.
Customers of a merchant's store: because we hold no personal data about individual shoppers, there is nothing about you for us to return, correct or delete. We implement Shopify's customers/redact and customers/data_request webhooks, and both correctly report that we hold no data for the customer.
If you believe we hold data about you and would like it removed, contact us at the address below and we will investigate and respond.
The app runs on Render, and its database is hosted in Frankfurt, Germany (EU).
| Sub-processor | Role |
|---|---|
| Shopify | The platform the app runs on and the source of all data |
| Render | Application hosting and managed PostgreSQL |
We do not send merchant or customer data to any analytics service, advertising network, or other third party.
If we change what we process or why, we will update this page and the date above. Material changes affecting merchants will also be communicated through the app listing.
Questions about this policy, or requests relating to data we hold:
Aramega Digital Solutions
Company: aramega.com
App: falco1.com
Email: privacy@falco1.com
We aim to respond within 30 days. Merchants can also reach us through the support contact on the Falco Bundles listing in the Shopify App Store.