Privacy Policy — Custom Bike Builder
Last updated: July 26, 2026
This Privacy Policy describes how the Custom Bike Builder app ("the App", "we",
"us") collects, uses, and protects information when a merchant installs and uses
it on their Shopify store.
1. Who we are
The App is provided by Christopher Lind. Contact:
chris@yosoymilk.com.
2. Data we access
When installed, the App accesses the following through the Shopify Admin API,
limited to what is required for it to function:
- Store catalog data — products, product metafields, and
metaobjects used to build and price bike configurations.
- Order line-item data — on order creation, the App reads the
component build-spec (component types, names, and SKUs) that the customer
selected, in order to generate a dealer parts list saved to the order.
- Shopify session data — access tokens and session identifiers
required to authenticate the App with your store.
The App does not access, store, or process customer personal
data — no names, email addresses, phone numbers, or billing/shipping addresses.
3. How we use data
- To render the storefront bike builder and apply correct pricing.
- To generate a dealer parts list (component SKUs) on each order for
fulfillment and purchasing.
- To authenticate and operate the embedded admin.
We use data only for these stated purposes. We do not sell data or share it
for advertising.
4. Data storage & retention
- Only Shopify session tokens are stored by the App, in a
database on our hosting provider (Render, United States).
- The parts list is written to the merchant's own Shopify order metafield;
the App keeps no separate copy of order data.
- Session data is deleted when the App is uninstalled (within 48 hours, via
Shopify's
shop/redact webhook).
5. Security
- All data is transmitted over HTTPS (encrypted in transit).
- Incoming webhooks are verified via HMAC signature.
- Access to production systems is limited to authorized personnel.
6. Compliance webhooks
The App implements Shopify's mandatory privacy webhooks:
customers/data_request, customers/redact, and
shop/redact. Because the App stores no customer personal data,
data-request and customer-redaction requests return no personal data; shop
redaction deletes stored session data.
7. Changes
We may update this policy; the "Last updated" date reflects the latest
revision.
8. Contact
Questions: chris@yosoymilk.com.