Bonde privacy policy
1. Introduction
This Privacy Policy explains how Conspire LLC ("Conspire," "we," "us," or "our") collects, uses, shares, and protects information in connection with the Bonde Shopify application and related services (collectively, "Bonde" or the "App"). Bonde is installed by Shopify merchants (each a "Merchant") on their Shopify stores to provide subscriptions, upsells, free gifts, bundling, merchandising, order tracking pages, transactional email, and analytics features.
Bonde processes two broad categories of information: (a) information about Merchants and their personnel (the "Merchant Data"), for which Conspire is the data controller; and (b) information about Merchants' end customers (the "End-Customer Data"), for which the Merchant is the data controller and Conspire acts as a data processor or service provider on the Merchant's behalf.
If you are an end customer of a Merchant who uses Bonde and have questions about how your personal information is used, please contact the Merchant directly. The Merchant's own privacy policy governs the collection and use of your personal information.
2. Who We Are
Bonde is operated by:
Conspire LLC 7040 Weller St. San Diego, CA 92122 United States Email: support@conspireagency.com
3. Information We Collect
3.1 Merchant Data
When a Merchant installs and uses Bonde, we collect:
Account and store information: Shopify shop domain, store name, store ID, primary contact name and email, country, currency, timezone, plan type, and similar account-level metadata provided by Shopify during installation.
Authentication and authorization data: OAuth access tokens issued by Shopify, the scopes granted to the App, and session identifiers used to authenticate the Merchant within the embedded admin.
Configuration data: Settings, preferences, page builder content, themes, templates, targeting rules, discount configurations, and other content the Merchant creates or uploads while using the App.
Billing data: Information necessary to process App subscription charges through Shopify's billing system. We do not collect or store payment card numbers.
Support communications: Information you provide when you contact us for support, including your name, email address, and the contents of your messages.
3.2 End-Customer Data
Bonde processes information about the Merchant's end customers solely to provide the App's features to the Merchant. The categories of End-Customer Data we may process include:
Customer identity: Name, email address, phone number, billing and shipping addresses, and Shopify customer ID, where this information is required to fulfill an order, render an order tracking page, send a transactional email, or compute analytics for the Merchant.
Order and transaction data: Order IDs, line items, quantities, prices, discounts applied, fulfillment status, tracking numbers, carrier information, and timestamps.
Subscription data: Selling plans, subscription contracts, billing attempts, retry state, and subscription lifecycle events.
Cart and behavioral data: Cart line attributes used to attribute upsells, free gifts, and bundles; product impressions, clicks, and add-to-cart events generated by Bonde widgets and tracking pages.
Tracking page subscribers: When an end customer voluntarily enters an email address (or other contact information) into the "Subscribe to delivery updates" block on a Merchant's tracking page, we store that contact information together with the associated order and an unsubscribe token in order to send delivery-status update emails on the Merchant's behalf.
Derived analytics: Aggregated and customer-level rollups computed from the above data for the App’s analytics (e.g., lifetime value, order frequency, basket composition, and similar metrics).
We do not knowingly collect government-issued identification numbers, payment card numbers, precise geolocation, biometric data, or special categories of personal data from end customers.
3.3 Information Collected Automatically
Log and device data: IP address, browser type, operating system, referring URL, pages viewed, and timestamps, collected when Merchants use the embedded admin or when end customers load Merchant-hosted Bonde surfaces such as tracking pages.
Cookies and similar technologies: Session cookies used by Shopify App Bridge to authenticate Merchants in the embedded admin, and first-party identifiers used to measure tracking page views and engagement events. Bonde does not set advertising cookies and does not sell personal information.
Error and performance data: Diagnostic information collected through our error monitoring provider (Sentry) when the App encounters errors, including stack traces, request metadata, and a redacted snapshot of the application state.
4. How We Use Information
We use the information described above to:
Provide, operate, maintain, and improve the App's features for Merchants and their end customers;
Authenticate Merchants and authorize requests through Shopify;
Send transactional communications, including order tracking delivery-update emails to opted-in subscribers on the Merchant's behalf;
Compute analytics and recommendations for Merchants;
Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms;
Respond to support requests and Merchant inquiries;
Comply with legal obligations and enforce our agreements;
Bill Merchants for the App through Shopify's billing system.
We do not use End-Customer Data to advertise to end customers, to build cross-Merchant profiles, or to train third-party machine learning models on identifiable personal data.
5. Legal Bases for Processing (EEA, UK, and Similar Jurisdictions)
Where the General Data Protection Regulation (GDPR), UK GDPR, or a similar law applies, we rely on the following legal bases to process personal data:
Performance of a contract: to provide the App to the Merchant under our terms of service, and to process End-Customer Data on the Merchant's documented instructions.
Legitimate interests: to secure, maintain, and improve the App; to detect and prevent fraud and abuse; and to communicate with Merchants about the App.
Consent: where required (for example, when an end customer opts in to receive delivery-update emails through a tracking page subscribe block). Consent can be withdrawn at any time.
Legal obligation: to comply with applicable law, including responding to lawful requests from public authorities.
7. How We Share Information
7.1 Sub-processors
We share information with the following third-party service providers ("sub-processors") that help us operate the App. Each sub-processor is bound by contractual obligations to protect personal data and to process it only on our instructions:
Shopify Inc. (Canada): the platform on which the App runs; source of Merchant authentication and the originating system for most Merchant Data and End-Customer Data.
Vercel Inc. (United States): application hosting and content delivery for the App's web surfaces.
Neon Inc. (United States): managed PostgreSQL database hosting for the App's primary data store.
Inngest Inc. (United States): background job orchestration for webhooks, scheduled tasks, and asynchronous workflows.
Resend (Resend, Inc., United States): transactional email delivery, including delivery-update emails sent to tracking page subscribers.
Sentry (Functional Software, Inc., United States): error monitoring and diagnostics.
Meta Platforms, Inc. (United States): Conversions API event delivery, used only when the Merchant explicitly enables and configures Meta CAPI integration in the App.
We may update this list from time to time. The current list reflects the sub-processors in use as of the effective date above.
7.2 Other Disclosures
We may also disclose information:
To Merchants, with respect to their own End-Customer Data and configuration;
To comply with applicable law, regulation, legal process, or governmental request;
To enforce our terms of service or to protect the rights, property, or safety of Conspire, our Merchants, end customers, or others;
In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets, in which case personal data may be transferred as part of the transaction, subject to the protections of this Privacy Policy.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
8. International Data Transfers
Conspire is based in the United States, and our sub-processors are located in the United States, Canada, and other jurisdictions. If you access the App from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries whose data protection laws may differ from those in your country.
Where required by applicable law, we rely on appropriate safeguards for cross-border transfers of personal data, including the European Commission's Standard Contractual Clauses and equivalent mechanisms used by Shopify and our other sub-processors.
9. Data Retention
We retain Merchant Data and End-Customer Data for as long as the Merchant's installation of the App is active and for a limited period thereafter to satisfy legal, accounting, or operational requirements. When a Merchant uninstalls the App, Shopify sends us a 48-hour shop redact webhook; upon receipt, we delete the Merchant's data from our active systems in accordance with Shopify's mandatory data protection requirements.
When Shopify sends us a customer redact webhook on behalf of an end customer, we delete or anonymize that end customer's personal data from our active systems, including their customer identity records, analytics rollups, and tracking page subscriber entries.
End customers who opted into tracking delivery-update emails may unsubscribe at any time using the unsubscribe link included in every email; doing so suppresses further sends and removes their contact information from our active subscriber list.
Aggregated, de-identified data that cannot reasonably be used to identify an individual may be retained indefinitely for analytics, model evaluation, and product improvement.
10. Your Rights
10.1 Rights of Merchants
Merchants may access, correct, export, or delete most of their data directly through the App's admin interface or by uninstalling the App. For requests we cannot fulfill through the App, contact us at support@conspireagency.com.
10.2 Rights of End Customers (GDPR, UK GDPR, and Similar Laws)
If you are an end customer of a Merchant that uses Bonde and you reside in the European Economic Area, the United Kingdom, or another jurisdiction with similar laws, you may have the right to:
Access the personal data we hold about you;
Request correction of inaccurate or incomplete personal data;
Request deletion of your personal data;
Object to or restrict our processing of your personal data;
Request that we transfer your personal data to another service (data portability);
Withdraw any consent you previously gave (such as consent to receive delivery-update emails);
Lodge a complaint with your local data protection authority.
Because we process End-Customer Data on the Merchant's behalf, we generally direct end customers to contact the Merchant to exercise these rights. We will assist the Merchant in responding to verified requests, and we will respond directly where required by law.
10.3 Rights of California Residents (CCPA/CPRA)
California residents have the right to know what personal information we collect, the right to request deletion, the right to correct inaccurate information, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights. We do not sell personal information and do not share personal information for cross-context behavioral advertising.
California residents may submit requests through their Merchant or by emailing us at support@conspireagency.com. We will verify requests and respond within the timeframes required by law.
11. Security
We implement administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These safeguards include encryption of data in transit using TLS, encryption of data at rest in our managed database, scoped OAuth tokens, signed app proxy and webhook requests, principle-of-least-privilege access controls for our personnel, and continuous error and anomaly monitoring.
No method of transmission or storage is completely secure. If you have reason to believe that your interaction with the App is no longer secure, please contact us immediately at support@conspireagency.com.
12. Children's Privacy
Bonde is intended for use by businesses and is not directed to children under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child without verified parental consent, we will delete that information.
13. Third-Party Sites and Services
The App may contain links to or integrate with third-party websites, services, or platforms (including Shopify itself). This Privacy Policy does not apply to those third parties, and we are not responsible for their content, privacy practices, or terms. We encourage you to review the privacy policies of any third-party services you use.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the App, or applicable law. When we make material changes, we will update the "Effective date" at the top of this Policy and, where appropriate, provide additional notice to Merchants through the App or by email. Your continued use of the App after the updated Policy takes effect constitutes acceptance of the changes.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our handling of personal data, please contact us at:
Conspire LLC Attn: Privacy 7040 Weller St. San Diego, CA 92122 United States Email: support@conspireagency.com
