Privacy Policy — BubbleCrossSell
Last updated: August 31, 2026
1. What the app does
BubbleCrossSell lets Shopify merchants create cross-sell offers (complementary products) that are shown in a popup when the customer adds a product to the cart. The merchant configures trigger products, offered products, discounts, and attribute inheritance from the app's admin panel.
2. Data we process
Store (merchant) data:
- Store identifier (domain) and installation session data.
- Offers configured by the merchant: trigger products, offered products, discounts, and attribute inheritance settings.
Product data:
productId, title, handle, and image of the products the merchant selects when configuring their offers. This data is stored as a cache so the popup can be shown on the storefront without additional Admin API calls.
End customer data:
BubbleCrossSell does not collect end customers' personal data directly. The popup is rendered on the merchant's storefront and cart additions use Shopify's native AJAX Cart API. The app does not access the cart or shoppers' personal data.
Usage data:
Technical logs (IP address for abuse-limiting purposes, audit logs).
Subscription and billing data:
The premium plan ($5.99/month) is managed entirely through Shopify's Billing API. BubbleCrossSell does not store or process credit card or billing data: charging, subscription status, and cancellation are handled by Shopify on the merchant's behalf. The app only checks the subscription status (active or free plan) to decide which features to show.
3. Purpose and legal basis
- Displaying cross-sell offers configured by the merchant (merchant's legitimate interest).
- Creating automatic discount codes for the offered products.
- Maintaining the security and operation of the app.
We do not sell personal data. We do not use data for advertising or for profiling customers.
4. How the app obtains data
The app requests only the read_products (to search for and display products when configuring offers), write_discounts (to create automatic discount codes), and read_themes (to detect whether the app's App Embed is enabled on the store's theme and show that status in the panel) scopes. It queries the Shopify Admin API of the store where it is installed. Data is used only within the corresponding store and is never shared between stores.
5. Storage and retention
- Data is stored in a secure database managed by the developer (PostgreSQL in production).
- Offers and associated data are retained while active or until the merchant deletes them from the admin panel.
- When the app is uninstalled, the store's data is automatically deleted (app/uninstalled webhook).
6. Children's data
The app is not directed at children under 13 and does not knowingly collect data from children.
7. Security
- Webhook (HMAC) and session (OAuth / App Bridge) validation.
- HMAC signature validation on the App Proxy that serves offers to the storefront.
- Database access restricted via environment credentials.
8. Contact
For privacy questions or to request data deletion:
- Email: info@bytebubbles.com
- Data controller: ByteBubbles SL
9. Changes to this policy
We will notify any material change by updating the date on this page.