Legal Center

Legal

Privacy Policy

Last updated: 2026-09-04

This Privacy Policy explains what information Nestio - Bundle Add-Ons ("Nestio", "we", "us", "our") collects when you install and use the Nestio app on your Shopify store, how we use that information, and your rights regarding that data.

1. Who This Policy Applies To

This policy applies to Shopify merchants who install and use Nestio. Nestio is a merchant-facing tool — your store's customers do not create accounts in our app, and the app does not collect their personal information. Section 2.7 describes what the storefront bundle widget does and does not do in your customers' browsers.

2. Information We Collect

2.1 Shop & Account Information

When you install Nestio, we receive and store the following information about your store:

We do not store your shop's contact email address or shop name in our application records.

2.2 Campaign & Bundle Configuration

When you build bundles inside the app, we store the configuration you create. This is catalog and pricing configuration, not personal data:

2.3 Order & Refund Data

To show you how your bundles perform, Nestio subscribes to Shopify's orders/create, orders/cancelled, and refunds/create webhooks. For orders that contain a bundle purchase, we record:

We do not collect customer names, email addresses, shipping or billing addresses, payment details, or any other customer personal information from orders. When the app reads an order from Shopify's Admin API, it requests only the order's ID, name, creation and cancellation timestamps, currency, and its line items (ID, quantity, line-item properties, and discounted total). The customer object on the order is never requested.

Note that Shopify limits the read_orders scope to the last 60 days of order history, so the app cannot see or backfill orders placed before that window.

2.4 Onboarding Progress

We store your progress through the app's setup guide: the current step, the list of steps you have completed, whether onboarding is finished, and the timestamps for when it started and completed.

2.5 Session & Authentication Data

Shopify's OAuth session records are stored in our database by Shopify's official session storage library. In addition to the access and refresh tokens used to authenticate API requests on your behalf, these records may contain the first name, last name, email address, and locale of the merchant or staff account that authenticated the app, as supplied by Shopify. This is the only place in the app where personal data about a person is stored. These records are used solely to authenticate and operate the app.

2.6 Operational Logs & Webhook Records

Our infrastructure writes operational logs for monitoring and debugging, which may include your shop domain and error details. We also keep a record of each webhook delivery the app has processed — the Shopify webhook ID, the topic, the ID of the resource it concerned, the processing status, attempt count, and any error message. These records exist so that Shopify's at-least-once webhook delivery does not cause an event to be counted twice.

2.7 Storefront Bundle Widget

Nestio includes a theme app extension that renders the bundle picker on your product pages, plus an optional "Cart Integrity" app embed. In your customers' browsers:

3. How We Use This Information

4. Sharing of Information

We do not sell, rent, or trade your data. We may share data only in the following limited circumstances:

No customer personal information is shared with any third party.

5. Shopify API Permissions

Nestio requests the following Shopify API access scopes, which are necessary for the app to function:

6. Data Retention

When you uninstall Nestio, Shopify sends an app/uninstalled webhook and we begin the process of removing your shop data in accordance with Shopify's partner requirements.

7. GDPR & Shopify Compliance Webhooks

Nestio implements Shopify's mandatory compliance webhooks:

Because Nestio does not collect customer personal data, responses to customer data requests will typically confirm that no customer personal data is held.

8. Security

We implement reasonable technical and organizational measures to protect the data we hold, including encrypted database connections and secure token storage. However, no system is perfectly secure and we cannot guarantee absolute security.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last updated" date above. Continued use of the app after changes are posted constitutes your acceptance of the updated policy.

10. Contact

If you have any questions or requests regarding this Privacy Policy or your data, please contact us at [email protected].