Privacy Policy

Last updated: 21 July 2026

1. Who we are

Bondi ("we", "us") is a Shopify application that lets merchants create product bundles, volume discounts, and BOGO offers, with associated analytics. This policy explains what data the app processes when a merchant installs it and when shoppers interact with a merchant's storefront.

Bondi acts as a data processor on behalf of the merchant (the data controller) for shopper data, and as a data controller for merchant account data.

2. What data we collect

CategoryExamplesSource
Store data Store domain, store name, plan, contact email Shopify OAuth on install
Product data Product titles, images, prices, variants used in bundles Shopify Admin API (read_products)
Order data Order line items, totals, discounts applied, refunds Shopify webhooks (orders/create, orders/cancelled, refunds/create)
Storefront events Bundle page views, builder interactions, add-to-cart events Shopify Web Pixel (product_viewed, product_added_to_cart)

What we do NOT collect: shopper names, shipping or billing addresses, payment details, or phone numbers. Storefront events are used in aggregate for bundle analytics, not to build shopper profiles.

3. How we use it

We do not sell data. We do not use one merchant's data to benefit another merchant.

4. AI processing

The AI suggestions feature sends aggregated order-pattern data from your own store (which products are bought together, at what frequency and value) to Anthropic's Claude API to generate bundle proposals. Specifics:

5. Who we share data with

ProcessorPurpose
ShopifyPlatform — all app data flows through Shopify's APIs
AnthropicAI bundle suggestions (aggregated, non-personal data only)
Hosting providerApplication and database hosting

No advertising networks, no data brokers, no analytics resellers.

6. Data retention & deletion

7. GDPR & merchant rights

Bondi implements all three of Shopify's mandatory compliance webhooks:

Merchants in the EU/EEA, UK, and similar jurisdictions may also contact us directly to exercise access, rectification, or erasure rights (§10).

8. Security

9. Changes to this policy

We may update this policy as the product evolves. Material changes will be announced in-app and the "Last updated" date above will change. Continued use of the app after changes constitutes acceptance.

10. Contact

Questions, concerns, or data requests: [email protected] — or use the contact form. We respond to privacy requests within 30 days, usually much faster.