Privacy Policy | ConvertIQ AI Bundles App
Last Updated: May 25, 2026
1. Introduction
This Privacy Policy explains how ConvertIQ - AI Bundles App ("ConvertIQ," "we," "us," or "our") collects, uses, stores, shares, and deletes personal and store-related information when merchants install and use our Shopify app.
This policy applies to information processed through the app, including the embedded Shopify admin interface, bundle creation and editing features, storefront bundle interactions, cart transform and discount functionality, theme app extension features, analytics features, and AI-assisted bundle workflows.
ConvertIQ is designed for Shopify merchants who want to create, publish, manage, and analyze product bundles, bundle offers, and related storefront purchase experiences.
Because this service involves merchant store data and may process end-customer interaction and cart-related data, we process data as described below.
By installing or using the app, you acknowledge this Privacy Policy. If you do not agree, do not install or use the app.
2. Who This Policy Covers
This policy covers two categories of data subjects:
- Merchants – Shopify store owners, staff, and collaborators who install and use ConvertIQ in Shopify admin.
- End Customers – Store visitors or customers who interact with bundles, bundle blocks, bundle offers, cart experiences, or discount functionality published by a merchant on that merchant's storefront.
For Shopify compliance and privacy law purposes, the merchant is generally the controller of their customer data, and ConvertIQ generally acts as a processor/service provider on the merchant's behalf.
3. Information We Collect
3.1 Merchant and Store Information
When a merchant installs and uses ConvertIQ, we may collect and process:
- Shopify store domain and shop identifier
- Shopify app installation and session details
- Access scopes and authentication/session metadata
- Merchant plan/subscription and app entitlement status
- Bundle configurations, bundle rules, bundle templates, and settings created by merchant users
- Bundle layout, design, display, and storefront placement preferences
- Product and variant data needed to create and run bundles, such as product IDs, variant IDs, titles, descriptions, handles, tags, product type, vendor, collection references, category, prices, images, inventory-related fields, and variant options
- Discount, cart transform, validation, and runtime configuration data needed to apply bundle behavior in Shopify
- Theme app extension configuration and storefront rendering settings
- Bundle analytics, dashboard, and performance metrics associated with the merchant's store
- Operational logs needed to support reliability, debugging, security, and fraud prevention
3.2 End-Customer Bundle and Storefront Interaction Information
When an end customer interacts with a bundle or related storefront/cart experience, we may collect and process:
- Bundle session identifiers
- Bundle views, selections, option choices, and configuration progress
- Products, variants, quantities, and bundle combinations selected by the customer
- Bundle add-to-cart events, cart update events, discount application events, and checkout-related bundle events
- Recommendation, upsell, or bundle offer results shown during the session, where applicable
- Customer interaction events with bundle widgets, bundle blocks, and bundle offers
- Session context and analytics metadata such as locale, device type, browser type, referrer, UTM tags, viewport size, timestamps, and storefront page context
3.3 Optional Customer Contact Fields
A merchant may configure bundle-related experiences to request customer contact details or other information for lead capture, follow-up, personalization, or customer service purposes.
If enabled by the merchant, such data is submitted through the merchant's storefront experience and processed under the merchant's instructions.
3.4 Shopify Customer and Order-Related Data
Depending on the merchant's configuration and the app features used, ConvertIQ may process limited Shopify customer, cart, checkout, or order-related data needed to support bundle analytics, troubleshoot bundle behavior, validate discount application, or respond to Shopify compliance webhooks.
3.5 Data We Do Not Intend to Collect
ConvertIQ is not intended for collecting sensitive personal information, such as health data, government identification numbers, financial account credentials, payment card numbers, or special-category data.
Merchants should avoid requesting sensitive data through any bundle-related storefront experience.
4. How We Use Information
We use collected information to:
- Provide app functionality, including bundle creation, bundle editing, bundle publishing, bundle rendering, cart transform behavior, and discount functionality
- Generate and maintain bundle runtime configuration, manifests, and storefront bundle behavior
- Apply bundle rules, bundle pricing logic, bundle validation, and related Shopify Function behavior
- Display bundle blocks, bundle layouts, and bundle offers on merchant storefronts
- Deliver analytics and reporting to merchants about bundle performance, customer interactions, conversion behavior, and revenue impact
- Build, maintain, and improve product and bundle configuration data used for merchant workflows
- Provide AI-assisted bundle generation, content drafting, layout suggestions, or optimization workflows when requested by merchants
- Maintain app security, performance, reliability, and fraud prevention
- Respond to support requests and operational incidents
- Meet legal and contractual obligations, including Shopify App Store requirements
- Process required Shopify privacy/compliance webhooks and related deletion/redaction events
We do not sell personal information.
5. Legal Basis and Role Allocation
Where required by law, our legal basis may include contractual necessity, legitimate interests such as security and service reliability, merchant instructions, consent where applicable, and legal compliance.
For merchant customer data submitted through storefront bundle experiences, carts, or related flows, merchants are responsible for establishing an appropriate legal basis and for providing notices to their customers.
6. How and When We Share Information
We share information only as needed to operate the service and comply with law, including with:
- Shopify, when required for app operation, authentication, API access, Shopify Functions, billing, webhook processing, and compliance workflows
- Infrastructure providers for hosting, storage, monitoring, logging, and service reliability
- Database and indexing infrastructure providers used to store and query app, bundle, analytics, and product data
- AI service providers used for merchant-requested AI bundle generation, drafting, or optimization workflows
- Professional advisors or authorities when legally required
We require service providers to process data under contractual restrictions and to use appropriate safeguards.
7. AI and Automated Processing Disclosure
ConvertIQ may use AI-assisted features to help merchants create bundles, draft bundle content, suggest bundle structures, generate product grouping ideas, improve layout workflows, or support related merchant-requested functionality.
AI generation requests may be processed through an external LLM or AI service provider.
AI outputs may be probabilistic and may require merchant review.
Merchants remain responsible for reviewing bundle content, pricing, discount rules, product selections, and customer-facing claims before publishing and for ensuring their storefront content is accurate and compliant.
8. Data Retention
We retain data only as long as necessary for the purposes in this policy, including service operation, analytics, legal obligations, security, and dispute resolution.
Typical retention behavior:
- Active store data is retained while the app remains installed and in use.
- Bundle configuration, design, runtime, and analytics data are retained while bundle features are active for the store.
- Merchants can delete certain bundle, analytics, or configuration records through app controls where provided.
- Product and variant data used for bundle configuration are retained while related features are active for the store.
- Operational logs are retained as needed for reliability, debugging, security, and compliance.
9. Uninstall and Deletion Commitment
When a merchant uninstalls ConvertIQ, we initiate deletion of associated store data from our systems, including bundle configuration data, bundle rules, bundle templates, bundle design settings, storefront bundle interaction records, bundle cart events, bundle discount events, runtime configuration data, product indexing or product reference data, analytics records, and related operational data associated with that store.
We also process Shopify-mandated compliance webhooks, including customers/data_request, customers/redact, and shop/redact, and handle related data export, redaction, and deletion workflows according to Shopify requirements.
Please note that limited backup or log copies may persist temporarily for disaster recovery, security, or legal compliance purposes, after which they are deleted according to our retention lifecycle.
10. Customer Data Requests, Redaction, and Deletion
For merchant customer data, the merchant is the primary contact for data subject rights requests.
If you are a customer of a merchant using ConvertIQ and want to access, correct, or delete your information, please contact the merchant directly first.
If we receive a valid request directly, we may route or coordinate it with the relevant merchant unless law requires otherwise.
We support Shopify compliance processes and merchant instructions for customer redaction and store-level redaction.
11. Security
We use reasonable technical and organizational measures to protect data against unauthorized access, loss, misuse, or alteration.
Measures may include access controls, data isolation controls, encryption in transit, secure credential handling, least-privilege access practices, and operational monitoring.
Merchants should also implement strong internal access controls and protect their Shopify admin credentials.
12. International Data Transfers
Depending on hosting and service provider locations, information may be processed in countries other than the country where the merchant or customer is located.
Where required, we use appropriate transfer safeguards under applicable law.
13. Children's Privacy
ConvertIQ is a business tool for merchants and is not directed to children. We do not knowingly collect personal information directly from children for our own purposes.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect operational, legal, or product changes.
When we make material changes, we will update the "Last Updated" date and may provide additional notice where required.
15. Contact Information
For privacy-related questions, requests, or complaints, contact:
- Support Contact: raja@optiexperts.co.uk
- Company: OptiExperts, London, United Kingdom
- Registered Office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, UK
- Website: optiexperts.co.uk
If you are submitting a Shopify compliance-related privacy request, include your Shopify store domain and relevant details so we can respond efficiently.
16. Merchant Responsibilities
Because merchants configure bundle content, choose bundled products, define bundle rules, and decide whether to request customer details, merchants are responsible for:
- Providing customer-facing notices and obtaining any required consent
- Ensuring bundle offers, pricing, discounts, claims, and storefront messaging are lawful and appropriate for their market
- Ensuring bundle rules and discount behavior comply with applicable laws, Shopify requirements, and merchant policies
- Responding to customer rights requests as controller
- Not collecting sensitive personal data unless legally permitted and properly disclosed