Falco Bundles

Privacy Policy

What this app accesses, what it stores, how long it keeps it, and how to have it removed.

Last updated 26 August 2026

Falco Bundles is a Shopify app that lets merchants sell products together — as fixed bundles, mix-and-match sets, assembled outfits, and shoppable looks — and shows them how those offers perform.

This policy is written for the merchants who install the app and for their customers. Falco Bundles is operated by Aramega Digital Solutions, aramega.com. The app's own site is falco1.com.

The short version

1Data we access from Shopify

The app requests only the access it needs to function. Its current permissions are:

PermissionWhy
write_productsCreate and update the shell products that represent a bundle, and read the products a merchant chooses for one
read_ordersAttribute completed sales to the merchant's bundles
read_publications, write_publicationsPublish bundle products to the merchant's Online Store
read_cart_transforms, write_cart_transformsApply the merchant's bundle discount in the cart
unauthenticated_read_product_inventoryShow shoppers when a size or colour is unavailable
write_filesStore cutout images a merchant uploads for the outfit canvas

What we take from an order

When an order is paid, Shopify sends us the order. We read four things from it: the order ID, the currency, the date, and the line items — product ID, variant ID, quantity, price.

We do not read the customer object, the email address, the phone number, the billing address, or the shipping address. Those fields arrive in Shopify's payload and are discarded unread; they are never written to our database.

We have not requested and do not hold Shopify's read_customer_name, read_customer_email, read_customer_phone, or read_customer_address permissions.

2Data we store

For the merchant

From the storefront

The app's storefront blocks record when a shopper reaches a stage of a bundle — viewing it, adding to it, reaching checkout. Each record contains only which bundle, which stage, and a timestamp.

There is no customer ID, no session ID, no device identifier, no IP address, and no cookie. These records cannot be traced to an individual and are not used to build a profile of anyone.

The app sets one item in the shopper's own browser storage: the outfit they are assembling, so it survives a page reload. It stays on their device, is never transmitted to us, and contains only product references.

What we never store

Customer names, email addresses, phone numbers, postal addresses, payment details, IP addresses, or any identifier that resolves to an individual shopper.

3Why we process it

The single purpose is providing the app's functionality to the merchant: displaying their bundles on their storefront, applying their discounts, and reporting how those bundles performed.

We do not use this data for anything else. We do not sell it, share it for advertising, use it to build profiles, or use it for automated decision-making. We do not use it to train models.

4How long we keep it

DataRetainedThen
Sales records2 years from the saleDeleted automatically
Storefront interaction events90 daysDeleted automatically
Bundle configurationWhile the app is installedDeleted on uninstall or erasure request
Session / access tokenWhile the app is installedDeleted on uninstall

Deletion runs automatically and continuously; it does not depend on anyone requesting it.

Two years for sales records is chosen so a merchant can compare a season against the same season last year, which is the longest look-back the app's reporting offers. Interaction events are kept for a shorter period because they exist only to show a recent trend.

5Deletion and your rights

Merchants can have everything we hold for their store deleted by uninstalling the app, or by contacting us. We also respond automatically to Shopify's shop/redact request, which erases every record associated with that store in a single operation.

Customers of a merchant's store: because we hold no personal data about individual shoppers, there is nothing about you for us to return, correct or delete. We implement Shopify's customers/redact and customers/data_request webhooks, and both correctly report that we hold no data for the customer.

If you believe we hold data about you and would like it removed, contact us at the address below and we will investigate and respond.

6Where the data lives, and who else touches it

The app runs on Render, and its database is hosted in Frankfurt, Germany (EU).

Sub-processorRole
ShopifyThe platform the app runs on and the source of all data
RenderApplication hosting and managed PostgreSQL

We do not send merchant or customer data to any analytics service, advertising network, or other third party.

7Security

8Changes to this policy

If we change what we process or why, we will update this page and the date above. Material changes affecting merchants will also be communicated through the app listing.

9Contact

Questions about this policy, or requests relating to data we hold:

Aramega Digital Solutions
Company: aramega.com
App: falco1.com
Email: privacy@falco1.com

We aim to respond within 30 days. Merchants can also reach us through the support contact on the Falco Bundles listing in the Shopify App Store.