Bow — Privacy Policy
Last updated: 2026-09-06
Bow (“the app”) helps Shopify merchants offer gift wrapping, gift messages, and gift analytics. This policy explains what data we process and why.
Data we process
- Store configuration you create (wrap styles, prices, placement, message settings).
- Order analytics: for each order we store whether gift wrap was used, whether a gift message was present (a yes/no flag, not its text), the gift-wrap fee, and the order total. No customer name, email or address is stored here.
- A short-lived hand-off for the post-purchase offer: if a buyer adds gift wrapping after paying, their gift message is held against the checkout token just long enough to attach it to the order, then deleted after 7 days by our retention job.
- Corporate recipient lists, on plans that include bulk gifting: the recipients the merchant enters — name, and optionally email, address and message — so they can reorder. They belong to the merchant and are deleted with the account.
- Anonymous widget events (impressions/selections) using a hashed, non-identifying session value.
- Support messages you send us from the Help screen: what you wrote, the screen you were on, your store address and plan, and the reply address if you choose to give one. Nothing about your customers or their orders is attached — not the order you happen to be looking at, and not the gift message a buyer wrote.
Message suggestions
Suggested gift messages come from a library built into the app. Nothing is sent to any third party to produce them, and no external service is involved.
Data sharing
We do not sell data. We use standard hosting and storage providers as processors. API keys are stored server-side only.
Your store address, plan, and any support message you send are also recorded on our own support console, which runs on the same infrastructure as Bow itself — it is not a third-party service. It is the reason we can answer you and see that you are still waiting. It never receives customer data of any kind.
Retention & deletion
We honor Shopify’s GDPR webhooks: customer data request, customer redact, and shop redact. On uninstall we disable the app and remove sessions; on the shop-redaction request (~48h later) we delete all store data, including any corporate recipient lists.
The post-purchase hand-off above is pruned on a schedule regardless of any request, and the gift message a buyer writes also lives on the order itself, in Shopify, as an order attribute and an order note — the same as any other order data the merchant already holds.
Contact
Questions: support@hullara.com