Who we are
Complement Bridge (“the App”) is a Shopify embedded admin app that helps merchants keep Search & Discovery complementary products filled from living collection, tag, or product_type rules, so new SKUs do not sit with an empty “Pair it with” block. We write the native complementary-products metafield (shopify--discovery--product_recommendation.complementary_products) where the API allows. You still own Search & Discovery config and add the Complementary products theme block yourself.
Contact for privacy questions: molyneuxnicky@gmail.com. Physical address: UK (operator is UK-based).
What this App does not do
- We do not run storefront pixels, cookies, or buyer tracking.
- We do not send marketing emails to shoppers.
- We do not sell personal data.
- We do not use AI, purchase-history, or “frequently bought together” recommendations.
- We do not write Search & Discovery filter config, and we do not add the Complementary products theme block for you (theme checklist only — no theme extension).
- We do not read checkout, customers, or orders.
Information we collect through Shopify’s APIs
When a merchant installs the App and grants access, we process shop data needed to provide the service, including:
- Shop identifiers (shop domain, shop ID)
- OAuth / session tokens for the embedded admin
- Product data needed to match rules and fill complements: product IDs, handles, status, gift-card flag,
product_type, tags, inventory /availableForSale, and collection membership - Complementary-products metafield values (JSON lists of product GIDs, Shopify cap 10) that we dry-run, apply, and undo
- Collection listings used as a source matcher or complement pool
- Billing subscription state via Shopify Billing API (
appSubscriptionCreateand related)
Granted Admin API scopes: read_products, write_products, read_inventory, read_locations. We do not request customers, orders, checkout, themes, or write-inventory.
We aim to store only: shop identity, living rules (max 5), last-run / drift state, and undo snapshots of previous complementary GID lists. We do not need customer checkout profiles, payment instruments, or order PII to provide the core job.
If a future version touches additional Shopify resources, this policy will be updated before those scopes go live.
Information we collect directly from the merchant
- Rule choices (source = collection, tag, or product_type → pool = collection or tag; max N; prefer in-stock; exclude self, gift cards, drafts)
- Optional support emails they send us about drift or first-rule-wins collisions
- Routine operational logs (install/uninstall, webhook delivery IDs, error logs) tied to the shop, not to individual shoppers
We do not ask merchants for their customers’ contact lists as a product feature.
Information we collect from merchants’ customers
The App is admin-only. We do not drop cookies on the storefront, and we do not intentionally collect shopper personal data for analytics or ads.
Product titles, handles, tags, types, and complementary GID lists are merchant catalog content used to fill the native complementary metafield. We treat that as merchant content used to provide the App, not as a shopper profile we build. We do not store customer identities, emails, or order history.
How we use the information
We use the data solely to:
- Provide Complement Bridge (enable complementary metafield, rules, dry-run, apply, undo last write, drift, theme checklist)
- Bill via Shopify Billing API ($29 USD / month after a 14-day trial; no separate Stripe checkout)
- Respond to support requests the merchant opens
- Meet Shopify mandatory compliance webhooks and legal obligations
We do not use this data for advertising, resale, AI training, or unrelated products.
Sharing and subprocessors
- Shopify — platform APIs, Billing, and compliance webhook delivery.
- Hosting / database — the App’s production host and datastore (names to be filled when production hosting is chosen; currently Origin-built Remix app, not yet production-hosted under a public merchant URL).
We do not share merchant data with AI vendors. If we add a named subprocessor later, we will update this policy and the listing.
International transfers
The operator is UK-based. Hosting region will be stated here once production infrastructure is fixed. Where UK/EEA personal data is processed outside those regions, we will use appropriate safeguards (for example standard contractual clauses) as required.
Retention
- While installed: shop + rules + last-run / drift state + undo GID snapshots for as long as needed to run the App.
- On uninstall /
shop/redact: we delete or anonymize shop data per Shopify’s mandatory compliance webhooks within the required window. customers/data_requestandcustomers/redact: we respond per Shopify’s webhook process. If we hold no customer personal data for that request, we still acknowledge and complete the webhook handling.- Support email threads: retained only as long as needed to resolve the ticket, then deleted or minimized.
Mandatory Shopify compliance webhooks
The App implements (or will implement before listing submit):
customers/data_requestcustomers/redactshop/redact- plus
app/uninstalled
Operational product webhooks (products/create, products/update, collections/update) are used only to keep complementary lists filled as catalog and pools change. Requests are HMAC-verified (401 on invalid HMAC). Handling is idempotent where Shopify retries.
Your rights
Merchants (and, where applicable, individuals) may request access, correction, deletion, or restriction of personal data we hold. Contact us via the listing support channel. Shopify’s compliance webhooks are the primary path for shop- and customer-scoped redaction when the platform initiates them.
Children
The App is for business merchants on Shopify. It is not directed at children.
Changes
We will update this page when practices change and refresh the “Last updated” date. Material changes that affect merchants will also be reflected in the App Store listing materials where required.
Contact
Privacy / support contact: molyneuxnicky@gmail.com
Operator: Nicky Molyneux (UK)