Needly Bundle Break Alerts
Privacy policy
Effective July 18, 2026
Needly Bundle Break Alerts processes the minimum Shopify store and inventory data needed to warn merchants about broken bundles.
Information the app reads
Shopify store domain, store name and contact email; merchant-selected product and variant identifiers, titles and optional SKUs; inventory-item identifiers, inventory-tracking state, and aggregate available quantities.
Information the app stores
The app stores the shop domain, display name and configured alert email; bundle-to-component mappings and thresholds; current component snapshots, bundle status, cause and check times; alert delivery state and bounded non-secret errors; coalesced inventory-refresh jobs and retry state; and Shopify authentication sessions. Online Shopify sessions can include staff identity and role fields supplied by Shopify for authentication.
How information is used
Data is used only to authenticate the installed app, evaluate mapped bundle health, display current status, retry operational work, and send merchant-configured transactional bundle alerts.
Data leaving Shopify
The listed data reaches the app through Shopify's authenticated GraphQL API and signed webhooks. Application data is processed by the hosted app and managed PostgreSQL database. Alert recipient, bundle/component names, quantity, threshold, and message metadata pass through Resend for transactional email. Open and link tracking are disabled. No data is sent to advertising, analytics, or marketing services.
Storage and deletion
The prepared production topology uses Render for application hosting and PostgreSQL in Frankfurt, Germany. A merchant can remove mappings and uninstall to revoke Shopify access. After Shopify sends the mandatory signed shop-redaction webhook, the shop, mappings, snapshots, alerts, refresh jobs, and sessions are deleted. Encrypted backup copies expire under the final documented provider retention window.
Customer privacy requests
Needly Bundle Break Alerts does not read or store customer or order data. It authenticates Shopify's mandatory customer data-request and redaction webhooks and acknowledges that no customer record is held.
Service providers
The prepared release uses Shopify for commerce APIs and authentication, Render for app hosting and PostgreSQL, and Resend for transactional email. Needly Labs will update this policy before adding a provider that processes merchant data.
Questions
Email needlylabs@gmail.com. Merchants may include their store domain and approximate UTC time, but must not email access tokens, passwords, payment details, customer exports, or database copies.