Bundle App Privacy
Last updated: 23 July 2026
Yoke Bundle Discount ("the App") applies automatic bundle pricing to a merchant's cart using pricing the merchant configures on their own products. This policy explains what the App does and does not do with data.
Who this covers
This policy is for the Shopify merchant who installs the App and for the customers who shop on that merchant's store.
What the App does
When a shopper's cart is evaluated at checkout, Shopify runs the App's discount function inside Shopify's own infrastructure. The function reads the cart contents (products, quantities, the merchant's custom.bundle_pricing metafield, and whether the cart belongs to a B2B/company buyer) and returns a discount. This evaluation happens entirely within Shopify and is not sent to, or stored by, any Yoke server.
Data the App collects and stores
The App's backend stores one item per store: an offline Shopify access token, used solely to create the automatic discount in the merchant's admin on the merchant's request. It is stored in Cloudflare Workers KV and is deleted when the App is uninstalled.
The App does not collect, store, sell, or share: customer names, emails, addresses, or contact details; order contents or order history; payment or financial information; browsing or analytics data.
Because the App holds no customer personal data, requests received on the mandatory Shopify compliance webhooks (customers/data_request, customers/redact, shop/redact) are acknowledged but return no personal data and have no personal data to erase. On shop/redact and on app uninstall, the store's stored access token is deleted.
Data processors
Shopify: runs the discount function and provides the Admin API. Cloudflare: hosts the App backend (Workers) and the token store (KV).
Data retention
The per-store access token is retained only while the App is installed and is deleted on uninstall or on a shop/redact request.
Security
All traffic to the App backend is over HTTPS. All Shopify webhooks are verified with HMAC-SHA256 before being processed; requests failing verification are rejected.
Changes
Material changes to this policy will be reflected here with an updated date.
Contact
Yoke Apparel, it@yokeapparelmanufacturing.com