Security

How we protect merchant and customer data when you use Bunk Shipments. We describe practices that are in place today—not certifications we do not claim.

How data is protected

Bunk Shipments runs as an embedded Shopify app. Merchants sign in through Shopify. Application data for your shop is stored in our production database and is scoped to your store. Staff access the app only through Shopify Admin for shops that have installed it.

HTTPS

Public traffic to the application uses HTTPS. Communication with Shopify and with connected carriers also uses HTTPS endpoints provided by those services.

Access control

Merchant authentication uses Shopify OAuth. There is no separate consumer login for buyers. Production servers are limited to authorized administrators. Application secrets (such as Shopify API credentials and database connection settings) are kept in environment configuration on the server, not in the public website or the app listing.

Data minimization

We request only the Shopify permissions needed to run shipping workflows. We store order and shipping fields required to create shipments, show operators the right context, and keep your settings. Carrier passwords entered in Settings are not returned to the browser after save.

Protected customer data

To create labels and carrier shipments, the app may process customer name, shipping address, phone, email, and order identifiers when Shopify provides them for that order. We use this information only to operate shipping for your shop—not to sell data or build unrelated marketing lists.

Field-level purposes are listed in our Privacy Policy.

Backups

Shop data lives in PostgreSQL on our production host. Operators take database backups before significant updates and can restore from those backups if a release causes problems. Backup copies are handled by administrators on the server; retention is managed operationally rather than by a separate product UI.

Incident response

If we detect a security or availability incident, we assess severity, contain the issue, investigate, and restore service. Affected merchants are notified when their shop or data may be impacted. Shopify is notified when platform rules require it.

Data retention

We keep personal and operational data only as long as needed to provide the service, meet legal obligations, or process privacy requests from Shopify. After you uninstall, Shopify’s compliance process triggers deletion workflows on their schedule.

GDPR

You remain responsible for your customer relationships in Shopify. Bunk Shipments processes data to provide shipping features you enable. We implement Shopify’s mandatory privacy webhooks for customer data requests, customer redaction, and shop redaction.

  • Customer data request — prepare information related to a customer when Shopify asks
  • Customer redact — remove app-stored data tied to requested orders
  • Shop redact — remove shop-scoped app data after uninstall

You can also contact support@gudle.lt for privacy questions.

What we do not claim

We do not claim SOC 2, ISO 27001, or third-party penetration-test certifications on this site. Carrier credentials in the current product version are stored in the application database without additional application-layer encryption. We will update this page when those practices change.