Privacy policy
Last updated: 2026-09-02
Austral Bundles is a Shopify app built by Beast Labs. This policy explains what data the app processes, what for, for how long and with whom it is shared.
Who processes the data
Beast Labs, based in Spain, is the controller for the data of the store that installs Austral Bundles. Write to [email protected] with any question about this policy.
For the store's own end-customer data, the store is the controller and Beast Labs acts as a processor, following its instructions.
What data the app processes
- Store identification: the myshopify.com domain and the access token Shopify issues when the app is installed. Without them the app cannot talk to your store.
- Bundle configuration: the packs, quantity breaks, texts, styles and templates you create in the app, and the references to the products included in each offer.
- Bundle order lines: for each new order, only the lines carrying the _beast_bundle property, with their SKU, title, quantity and already-discounted amount, plus the order name, amount and currency. This is what backs per-bundle sales attribution.
- Widget analytics: anonymous bundle view and add-to-cart events, grouped by an ephemeral session identifier. They carry no name, email, postal address or any other data identifying a person.
- What the app does not process: we store no personal data about the store's end customers beyond the above: no names, no emails, no addresses, no payment details.
Purposes and legal basis
Store data is processed to deliver the contracted service: applying the right discount at checkout, rendering the widget on the product page and giving you per-bundle sales attribution. The legal basis is performance of the contract between Beast Labs and the store.
Widget analytics are processed on the basis of our legitimate interest in measuring whether the app works and in catching errors. Being anonymous and aggregated, they identify no one.
We do not sell data, we do not share it for advertising and we do not profile anyone.
How long data is kept
For as long as the app is installed. On uninstall, Shopify sends the app/uninstalled webhook and the app deletes that store's session and access token.
The app also implements Shopify's three mandatory privacy webhooks: customers/data_request, customers/redact and shop/redact (sent by Shopify 48 hours after uninstall). shop/redact deletes that store's bundle configuration, attributed sales and analytics.
Processors and subprocessors
- Shopify: the platform the app runs on and the origin of all store and order data.
- Hetzner (Germany): hosting for the app's server and database, inside the European Union.
- Cloudflare: network and access tunnel to the server; processes traffic in transit.
- There are no other subprocessors. If we add one, we will publish it here before we start using it.
Security
Admin API access always uses the token Shopify issues for your store, with the minimum scopes the app declares. Every database query is filtered by shop domain, so one store's data is never reachable from another. Traffic is encrypted with TLS.
Your rights
You can exercise your rights of access, rectification, erasure, restriction, objection and portability by writing to [email protected]. We answer within the legal deadline. If you believe your request was not handled properly, you may complain to the Spanish Data Protection Agency (AEPD).
Changes to this policy
If something relevant changes we will publish it on this page and update the date above. When the change affects how we process your data, we will also flag it inside the app.
Contact
Beast Labs · [email protected]