Bespoke Products

Privacy policy

Effective 6 September 2026

Who we are

Bespoke Products is operated by O'Donnell Technologies Ltd. We provide a Shopify app that lets merchants add product options, stocked extras, cart summaries, and checkout checks.

For privacy questions or rights requests, email support@odtech.uk or use the support channel in the installed app.

What data we handle

  • Merchant and shop data: the Shopify shop domain, Shopify session information, access scope information, and the product, variant, shop, and metafield data needed to configure the app.
  • Configuration data: templates, option labels, conditions, prices, linked variants, checkout rules, and storefront settings. These are stored in Shopify metafields. A legacy workspace record can also remain in the app database while migration support is needed.
  • App subscription status: we check the shop’s active app subscription through Shopify’s Partner API to control access to the app management tools. This includes private free plans. We keep a short access result in server memory for up to 15 minutes. Shopify handles app billing; this check does not request payment card details or billing addresses.
  • App usage events: the shop domain, the name of an action in the app (for example “product saved” or “app opened”), and the time. We use them to see which parts of the app merchants use and to support merchants. They do not include staff names, product data, option values, customer data, tokens, or page addresses.
  • Storefront selections: the app places a shopper's selections in Shopify cart line properties so the merchant can see them with the order. The app backend does not use Shopify Customer or Order API scopes to copy this data into its own database.

The app does not provide customer file uploads. It does not use advertising identifiers, session replay, or an analytics profile.

Why we use the data

We use merchant and shop data to authenticate the merchant, load and save product options, resolve Shopify prices and stock, create managed service charges when requested, and run checkout protection. Our legal bases are performance of the app agreement, legitimate interests in operating and securing the service, and legal obligations such as Shopify privacy requests and redaction.

The Shopify merchant controls the customer information in the merchant's store. The merchant should provide its own customer privacy information for order and cart processing.

Service providers and storage

Shopify hosts the merchant store, Admin data, cart, checkout, order, and storefront metafields. The app runs on Cloudflare Workers Paid and uses a Cloudflare D1 database configured in the EU for app session and migration data. Shopify and Cloudflare may process information in other countries under their own terms and operational policies. Applicable transfer safeguards depend on the provider and service configuration.

We do not sell personal data or use it for advertising. We do not configure application request or Shopify HTTP request logging. The Worker has provider observability and Logpush disabled. Shopify, Cloudflare, or other infrastructure providers may still create operational logs under their own privacy notices and service terms.

Retention and deletion

Shopify keeps store, cart, order, and product metafield data under the merchant's Shopify account and retention settings. The app keeps an offline session while the shop is installed and keeps configuration data while it is needed to provide the service.

When Shopify sends an uninstall or shop-redact request, the app deletes its database session and workspace records for that shop. App usage events are deleted after 90 days, and all usage events for a shop are deleted when Shopify sends the shop-redact request. Product and shop metafields already written to Shopify remain in the merchant's Shopify store unless the merchant removes them or Shopify removes them. The app does not set a separate retention period for Shopify records.

Your rights

Depending on the law that applies, you can ask for access, correction, deletion, restriction, portability, or objection to processing. Where processing relies on consent, you can withdraw consent. Contact us through the support channel above. For customer cart or order data, contact the Shopify merchant first; Shopify's privacy tools and the merchant's privacy notice may also apply.

You can complain to the data protection authority where you live or work. In the UK, this is the Information Commissioner's Office.

Changes

We may update this policy when the app, law, or data handling changes. We will publish the new version at this URL and update the effective date.