Privacy policy
Bundle & Multi Discount is a Shopify app published by JLX InnoTech. This policy covers what the app receives from a merchant’s store, what it keeps, and for how long.
Last updated 5 August 2026
The short version
The app exists to apply bundle and multibuy discounts and to report on what they earned. To do the reporting it reads orders. It does not read, request or store any customer’s name, email address, phone number or postal address, and it does not sell or share data with anyone.
What the app receives
When an order is placed, updated or cancelled, Shopify sends the app a webhook containing that order. The app reads only these parts of it:
- the order’s Shopify id and order number,
- when it was processed, and whether it was cancelled,
- its currency, total, and the number of items on it,
- each line’s product, variant, title, quantity and price, and
- the title and amount of each discount that applied, so the app can tell which of its own offers earned what.
The rest of the payload — including everything identifying the buyer — is ignored and never written down.
What the app stores
The app keeps its own records in its own database, hosted in the United States:
- The offers a merchant configures: titles, prices, currencies and the products, collections or tags they cover.
- One row per order: the fields listed above. Orders with no offer on them are kept too, because the reports compare orders that used an offer against orders that did not.
- A staff record for the merchant: Shopify’s session, which carries the name and email address of the person who installed or opened the app. This is the merchant’s own staff data, not a shopper’s, and it is used only to keep them signed in.
Shopify treats an order and its total as data that can be linked back to a person even when no name is attached, and this policy treats it the same way. What the app holds cannot be turned into a shopper’s identity on its own.
What the app never collects
- Customer names, email addresses, phone numbers or addresses.
- Payment details of any kind.
- Browsing behaviour. The app’s storefront blocks read the offers the merchant configured and render text. They set no cookies, load no third-party scripts and follow no one around.
Why the app holds it
To show merchants what their offers did: how many orders used one, what those orders sold, how much was given away, and which products moved. The data is used for nothing else. It is never sold, rented, shared for advertising, or used to train anything.
How long it is kept
Order records are deleted automatically once they are two years old. This is enforced by the app on every write, not by anyone remembering to run it.
Everything belonging to a shop — offers, order records and the session — is deleted when the app is uninstalled. One thing outlives that: a short record that the shop installed and uninstalled the app, with the dates and the shop’s country and Shopify plan. It identifies no person, and it is what lets us tell a shop coming back from one arriving for the first time. It is erased when Shopify sends its shop erasure request, 48 hours after the uninstall. Nothing is kept as a backup copy afterwards.
Who else can see it
The app runs on Heroku (Salesforce) and stores its data in Heroku Postgres. Heroku hosts the data; it does not use it. No other company receives any of it. Inside JLX InnoTech, access to the production database is limited to the people who operate the app.
Security
Data is encrypted in transit (TLS) and at rest. Every webhook Shopify sends is verified against its signature before the app acts on it, so a forged request cannot write to the database.
Requests about personal data
Shopify passes customer data requests, customer erasure requests and shop erasure requests to the app automatically, and the app answers all three. Because the app holds no customer identity, there is nothing to return or erase for an individual shopper; a shop erasure removes everything belonging to that shop.
A merchant, or a shopper through their merchant, can also write to info.jltechconsulting@gmail.com to ask what is held, to have it corrected, or to have it deleted. Requests are answered within 30 days.
Changes
If what the app does with data changes, this page changes with it and the date at the top moves. Merchants on the app when a material change is made are told through the app.
Contact
JLX InnoTech — info.jltechconsulting@gmail.com