Shopify App, last updated on 20th September, 2026
This Privacy Policy explains how RadiusTheme (“we,” “our,” “us”) collects, uses, stores, and shares information when you install and use the Shopify app (the “App”). We’ve written this in plain language so you know exactly what data we touch, why, and what control you have over it.
By installing the App, you agree to the practices described below.
1. Who We Are
- App publisher: RadiusTheme
- Website: https://www.radiustheme.com
- General support & inquiries: support@radiustheme.com
RadiusTheme is the data controller for the merchant account data described in section 2.1. For data about your customers (section 2.2), you, the merchant, are the controller and we process it on your behalf to provide the App.
2. Information We Collect
When you install our app, the App accesses the following data through the Shopify Admin API and webhooks. We’ve grouped it by category so you can see exactly what’s involved.
2.1 Merchant store information
- Shop domain (e.g. your-store.myshopify.com), shop name, currency, plan, locale, country, and time zone.
- The store owner’s email address, as set in your Shopify store settings (Shopify’s account email, not the customer-facing contact email). We receive it when you install the App and keep it up to date when you change it in Shopify.
- App installation status, subscription status, and trial dates.
- Encrypted Shopify access tokens (used to call the Shopify Admin API on your behalf).
We do not store the names or email addresses of your staff accounts
2.2 Your customer information
The App does not store your customers’ names, email addresses, phone numbers, postal addresses, or payment details.
It does process the following, only to run bundle analytics:
- Shopify customer ID of logged-in shoppers. When a shopper who is logged in to your store views a bundle, the storefront widget sends their Shopify customer ID (a number Shopify already exposes on your storefront) so that each bundle view is counted once per customer per day. We store that ID with the bundle and the date and time of the view. For shoppers who are not logged in, the widget sends no identifier.
- Customer ID on orders. For orders that include a bundle, we use the order’s customer ID to ask Shopify whether it is that customer’s first order in your store. We keep only the number of new and returning customer purchases per bundle. The customer ID is not stored.
A Shopify customer ID can be linked to a person by the store that issued it, so we treat it as personal data. See section 6 for how it is deleted.
2.3 Product and catalogue data
- Product IDs, titles, descriptions, vendors, types, variants, prices, compare-at prices, SKUs, and inventory status
- Product images and media URLs
- Collections and tags
2.4 Order and analytics data
- Order data received through the orders/create webhook (line items, totals, currency) — used solely to track conversion performance
- Aggregated app metrics: views, add-to-cart events, purchases, and revenue
- Anonymous session identifiers — used only to deduplicate analytics. We do not store names, emails, phone numbers, addresses, or payment details.
2.5 App configuration data
- Bundle definitions (name, type, products, pricing rules, schedule, status).
- Widget appearance settings (layout, colours, typography, custom CSS) and storefront labels.
- Translations of your storefront labels, when you use automatic label translation (section 5).
- App preferences and feature toggles
2.6 What we never collect
- Buyer payment details, credit card numbers, or banking information
- Buyer email addresses, phone numbers, or postal addresses
- Customer account passwords or authentication credentials
- Any data outside the OAuth scopes listed in our App Store listing
3. How We Use Your Information
Here’s a straightforward breakdown of why we use what we collect:
- Run the App — deliver core functionality on your storefront and at checkout
- Show the widget — fetch product details to render the App’s interface for your customers
- Power your analytics — track key metrics for your reporting dashboard
- Authenticate securely — communicate with Shopify on your behalf using encrypted tokens
- Process billing — manage subscription charges through Shopify’s Billing API
- Contact you about the App: use the store owner email for support, service and security notices, and important changes to the App or this policy
- Keep a merchant record: when you install, we copy the store owner email, shop domain, country and time zone into our own customer-relationship system (section 5), and we record there whether the App is currently installed. This is how we know who is using the App and how to reach you about it.
- Marketing emails: only if you have opted in to receive them; every marketing email includes an unsubscribe link, and unsubscribing does not affect the service and security notices above
- Provide support — diagnose issues when you contact us
- Meet legal obligations — respond to GDPR data requests, tax/audit requirements, and lawful authority requests
We do not sell, rent, or trade your data to third parties for advertising or marketing purposes.
Legal bases (GDPR)
- Contract: running the App you installed, including the widget, discounts, analytics and billing.
- Legitimate interests: counting bundle views once per customer, measuring conversions, keeping the App secure, and sending service, security and important product emails to the store owner.
- Consent: marketing emails. You can withdraw consent at any time with the unsubscribe link or by emailing us.
- Legal obligation: responding to data requests and lawful authority requests.
4. Where Your Data Lives
- Database: PostgreSQL on Amazon Web Services (AWS), deployed in Asia Pacific (Mumbai, India)
- Application servers: AWS EC2
- File uploads: Stored through Shopify’s Files API (MediaImage) — not on our servers
- Customer-relationship system: FluentCRM on our own WordPress site at radiustheme.com, hosted by SiteGround on Google Cloud infrastructure in Council Bluffs, Iowa, USA. It holds only the merchant record described in section 5; no customer, order, or bundle data.
5. Third-Party Services
The App relies on the following sub-processors.
| Provider | Purpose | Data shared |
| Shopify, Inc. | Platform hosting, OAuth, billing, webhook delivery | All app data flows through Shopify |
| Amazon Web Services (AWS) | Database hosting, application servers, infrastructure | All structured app data and server logs |
| Translated srl (Lara Translate) | Automatic translation of storefront labels | The label text you ask us to translate, and the language pair |
| Groq, Inc. | Automatic translation of storefront labels (fallback) | The label text you ask us to translate, and the language pair |
| Translated srl (MyMemory) | Automatic translation of storefront labels (fallback) | The label text you ask us to translate, and the language pair |
| SiteGround (web hosting for radiustheme.com, on Google Cloud, Council Bluffs, Iowa, USA) | Hosting for our customer-relationship system | Store owner email, shop domain, country, time zone, and whether the App is installed |
Our customer-relationship system is FluentCRM, which we run ourselves on our own WordPress site rather than on a third party’s platform. RadiusTheme remains the controller of that record; the only other party involved is the company hosting the site. It holds the fields listed above and nothing about your customers, your orders, or your bundles.
Translation providers are used only when you choose to translate your storefront labels in Settings, and they receive only that label text (for example “Add bundle to cart”). They never receive customer data, order data, or your email address. Results are cached in our database so the same text is not sent twice.
Tutorial videos in the App are hosted on YouTube (Google LLC). Their thumbnails load from YouTube when the dashboard or Support page is shown, and the player loads when you open a video, so YouTube receives your IP address and browser details at those moments. YouTube’s own privacy policy applies.
6. How Long We Keep Your Data
- While the App is installed: We retain all data needed to operate the App for as long as it’s installed on your store.
- After you uninstall: The app/uninstalled webhook immediately disables further data processing and revokes access tokens. We hold remaining shop data for 48 hours in case of accidental uninstall, then permanently delete everything.
- GDPR shop/redact webhook: Sent by Shopify 48 hours after uninstall. On receipt, we permanently delete all merchant data, including the store owner email, bundles, analytics, and configuration. The merchant record in our customer-relationship system (section 5) is deleted at the same time, unless the same store owner still runs the App on another store, in which case that record still describes a current merchant and is kept.
- GDPR customers/redact webhook: When Shopify sends this webhook, we permanently delete every bundle view record linked to that customer’s ID in your store.
- Server logs: Kept for up to 7 days for troubleshooting and security, then deleted.
7. Your Rights
Whether you’re a merchant or a shopper whose data we process, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectify — correct inaccurate personal data.
- Erase — request deletion of your personal data (“right to be forgotten”).
- Restrict — limit how we process your personal data.
- Portability — receive your personal data in a machine-readable format.
- Object — object to processing based on legitimate interests.
- Withdraw consent — at any time, where processing is based on consent.
How to exercise your rights
- Merchants: Uninstall the App from your Shopify admin. Shopify automatically sends the shop/redact webhook 48 hours later, triggering full deletion. For faster action, email support@radiustheme.com.
- Shoppers: Contact the merchant whose store you visited. They’ll forward your request to us through Shopify’s customers/data_request or customers/redact webhooks.
- Direct inquiries: Email support@radiustheme.com. We respond to all verifiable requests within 30 days.
GDPR webhook compliance
The App implements all three Shopify-mandated GDPR webhooks:
- customers/data_request — we compile and return all data we hold about a specified customer
- customers/redact — we permanently delete all data about a specified customer
- shop/redact — we permanently delete all data about a specified shop
8. Cookies and Tracking
The App uses Shopify session tokens for authentication. The App itself does not set cookies, tracking pixels, advertising identifiers, or cross-site tracking in the embedded admin app. When you play a tutorial video, YouTube may set its own cookies.
The storefront widget does not set cookies and does not store identifiers in the shopper’s browser. It reads the logged-in customer ID that Shopify already provides on your storefront, as described in section 2.2, and nothing for shoppers who are not logged in.
9. Children’s Privacy
The App is intended for Shopify merchants who are at least 18 years old. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact support@radiustheme.com and we will delete it promptly.
10. International Data Transfers
Our App infrastructure is located in Asia Pacific (Mumbai, India). Our customer-relationship system, which holds only the merchant record described in section 5, is hosted in the United States (Council Bluffs, Iowa). Our translation providers may process label text in the European Union or the United States. Depending on where you’re located, your data may be processed in a different country from yours. We protect these transfers using safeguards required by applicable data protection laws, including Standard Contractual Clauses where necessary.
11. Security
We implement industry-standard security measures to protect your data:
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption at rest for sensitive credentials
- HMAC verification on all incoming Shopify webhooks
- Token-based authentication using Shopify session tokens (no third-party cookies)
- Rate limiting on App Proxy endpoints
- Multi-tenant data isolation enforced at the database query level
- Regular dependency audits and security reviews
No system is 100% secure. If we become aware of a data breach affecting your information, we will notify affected merchants without undue delay and report to relevant authorities as required by law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the “Last updated” date at the top of this page
- Notify merchants in-app of material changes
- For significant changes, provide 30 days’ notice before they take effect
Continued use of the App after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
For any questions, requests, or complaints:
- Support & Privacy: support@radiustheme.com
- Website: https://www.radiustheme.com
If you’re not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.
Radius Bundles is a third-party app built on the Shopify platform. Shopify’s own privacy practices are described in Shopify’s Privacy Policy.