Montie | Bundles & Deals - Privacy Policy

Last updated:

Montie | Bundles & Deals
Last updated: 15 September 2026

Montie | Bundles & Deals ("Montie", "the App", "we", "us", or "our") is a Shopify app provided by Montagne Group V.O.F., trading as Montagne Agency. Montie enables merchants to create and sell bundles, build-a-box products, quantity breaks, free gifts, add-ons, and Buy X Get Y offers.

This Privacy Policy explains what information Montie processes, why we process it, where it is processed, how long it is kept, and how merchants can contact us about privacy.

Who this policy applies to

This policy applies to:

  • Merchants who install or use Montie in their Shopify stores.

  • Information about a merchant’s Shopify store that is processed to provide the App.

  • Limited technical information that may be processed when a shopper interacts with a Montie storefront widget.

For personal data processed on behalf of a merchant’s store, the merchant is generally the data controller and Montagne Group V.O.F. acts as the processor. The merchant remains responsible for its own customer-facing privacy notices and for handling customer requests under applicable privacy law. Where we process our own business-contact, account, security, or billing information, Montagne Group V.O.F. may act as an independent controller.

Information we process

Information read from Shopify

Montie reads the following information from a merchant’s Shopify store only as needed to provide its bundle and offer functionality:


Information

Why we use it

Product and variant data, including titles, handles, images, options, prices, availability, and publication status

To create bundles and offers and display them correctly on the storefront

Metafields and metaobjects created by Montie, and a merchant-selected product metafield for linked colour products

To store and deliver bundle contents, offer rules, and storefront styling

Automatic discounts and Cart Transform resources created by Montie

To apply the merchant’s offer rules and prices in cart and checkout

Order data: order ID, order creation date, and, for each relevant line item, product ID, quantity, discounted total, currency, and bundle grouping

To attribute revenue to Montie-created bundles and offers, provide in-app analytics, and calculate usage-based app billing

Store currency and language

To format storefront text and prices correctly

Shop identifier and shop domain

To associate the App, its configuration, billing records, and deletion requests with the correct store

Information provided by merchants

We process information a merchant provides while using the App, including:

  • The selected pricing plan.

  • Bundle, build-a-box, quantity-break, gift, add-on, and Buy X Get Y configurations.

  • Storefront-widget styling and display settings.

  • Product titles and image URLs retained as configuration snapshots where necessary for the App to function.

  • Support messages and information a merchant voluntarily sends to us at the contact address below.

Customer and buyer information

Montie is not designed to request or persist customer names, email addresses, telephone numbers, postal addresses, or customer IDs.

Shopify order webhook payloads can contain buyer information. Where Montie receives such a webhook, it uses only the order identifier needed to retrieve and process the relevant order line-item information described in this policy. We do not intentionally store customer contact details or customer identifiers from these payloads.

We do store limited order-level and line-item-level commercial information for the merchant’s store: order ID, date, product ID, quantity, discounted total, currency, and bundle grouping. An order ID can be personal data in some contexts. We therefore protect it and handle it as store data subject to this policy and applicable privacy obligations.

Storefront visitors and browser storage

Montie’s storefront scripts read the current cart in the visitor’s browser to display relevant tiers, add earned gifts or rewards, and remove gifts or rewards when the cart no longer qualifies.

  • Montie does not use advertising or analytics cookies through its storefront widgets.

  • Montie does not intentionally send customer identifiers, contact details, or a complete identifiable cart profile to our application through those widgets.

  • The App’s cart endpoint receives the product identifiers needed to determine applicable bundle contents or offer responses.

  • The widget uses browser session storage to remember when a visitor intentionally removes a gift. This session-storage entry is cleared when the browser tab or session closes.

  • When a request reaches our services, Vercel may process limited technical request metadata and our own operational log entries, such as IP address, browser or device metadata, request timestamp, request path, status information, and error information. We do not store request or response bodies in these logs. We use this information only for security, fraud prevention, debugging, and reliable service operation. We do not use it for advertising or cross-site behavioural tracking.

How we use information

We use the information described above to:

  • Provide, operate, maintain, and support Montie.

  • Create and administer merchant-configured offers, discounts, bundles, and storefront widgets.

  • Apply bundle and offer logic in the cart and checkout through Shopify-supported functionality.

  • Display analytics relating to Montie-created offers and calculate usage-based billing.

  • Format prices and content for the merchant’s configured currency and language.

  • Authenticate and secure the App, prevent misuse, diagnose errors, and maintain service reliability.

  • Respond to merchant support requests and privacy requests.

  • Meet applicable legal, accounting, tax, and regulatory obligations.

We do not sell personal information. We do not use merchant, buyer, or visitor information for advertising, retargeting, profiling, or cross-site tracking. We do not use the information to train public or third-party AI models.

Legal bases for processing

Where the General Data Protection Regulation (GDPR) or similar law applies, our processing is based on one or more of the following grounds:

  • Processing necessary to perform our agreement with the merchant and provide the App.

  • Processing necessary for our legitimate interests in securing, operating, improving, and troubleshooting the App, provided those interests are not overridden by an individual’s rights and interests.

  • Processing necessary to comply with legal obligations, including accounting, tax, and record-keeping obligations.

  • Processing carried out on the merchant’s documented instructions where Montagne Group V.O.F. acts as processor for the merchant.

Where information is processed and shared

Montie uses the following service providers to provide the App:





Provider

Purpose

Processing location

Shopify

App installation, Shopify API access, store resources, checkout and billing functionality, and required privacy webhooks

Shopify’s applicable infrastructure locations

Vercel

Hosting and delivery of the App, its endpoints, and operational request logs

Application functions: Frankfurt, Germany (fra1); operational logs: United States, retained for one day

Neon

Hosted Postgres database and point-in-time recovery

Frankfurt, Germany, on AWS eu-central-1

We use these providers only to operate Montie and under appropriate contractual and security arrangements. Our database is encrypted at rest, and data exchanged between browsers, Shopify, the App, and the database is encrypted in transit.

For usage-based billing, Montie sends Shopify the revenue amount attributed to Montie offers for the relevant order together with the merchant’s store identifier, so Shopify can place the usage charge on the merchant’s Shopify invoice.

We do not share information with advertising networks, data brokers, or third-party analytics providers. We do not use Sentry, PostHog, Resend, Intercom, Crisp, Clerk, Supabase, Cloudflare, or Vercel Analytics for the App. GitHub is used solely for source-code hosting and does not receive merchant, buyer, or visitor data through the App’s normal operation.

Vercel’s processing of operational logs in the United States may constitute a transfer of personal data outside the European Economic Area. Where required, we rely on legally recognised safeguards used by our providers for those transfers, such as an adequacy decision or the European Commission’s Standard Contractual Clauses.

Security

We use reasonable technical and organisational measures designed to protect the information we process. These include encryption in transit, encryption at rest for our database, access controls, and limiting internal access to people who need the information to operate or support the App.

Shopify Admin API offline access tokens are treated as confidential credentials. Tokens are stored in our Neon database, which uses encryption at rest. They are revoked or replaced when required, including when the App is uninstalled or reinstalled and when credentials are rotated. They are not exposed in storefront code and are not intentionally included in application logs. We do not currently apply separate application-level encryption to tokens before they are stored in the database.

No internet service or storage system is completely secure. Merchants should also protect their Shopify accounts and control access to their Shopify store.

Retention and deletion

We retain merchant and store information only for as long as needed to operate Montie, provide analytics and billing, resolve support requests, maintain security, or meet legal obligations.

  • While the App is installed, we retain the information described in this policy so that merchant configurations, storefront functionality, analytics, and billing can operate.

  • Shopify generally sends a shop/redact request approximately 48 hours after a merchant uninstalls the App. After receiving that request, we delete or anonymise store information associated with the shop without undue delay and, unless a legal retention obligation applies, no later than 30 days after receiving the request.

  • This deletion includes the store’s access tokens, settings, bundles, offers, rules, sales rows, billing ledger entries that are not required to be retained, and other store-specific App records.

  • Neon provides point-in-time recovery for up to six hours in the same Frankfurt region. There is no separate backup provider. Deleted information may remain in this protected and isolated recovery window and is overwritten as part of that recovery process. It is not restored except where necessary for disaster recovery.

  • Vercel operational request logs are retained for one day.

  • We may retain limited information where legally required, such as records required for tax, accounting, fraud prevention, security, or dispute resolution. We retain it only for the period required for that purpose.

Shopify privacy webhooks and data requests

Montie subscribes to Shopify’s mandatory privacy compliance webhook topics:

  • customers/data_request

  • customers/redact

  • shop/redact

We verify Shopify webhook requests and respond to valid requests with an appropriate 2xx status code. We complete required access, deletion, or redaction actions within 30 days of receiving a request, unless applicable law requires us to retain particular information.

Because Montie is not designed to retain identifiable customer names, email addresses, telephone numbers, postal addresses, or customer IDs, we normally have no such customer personal data to provide or erase. If customer personal data is identified in our systems, we provide, delete, or redact it as applicable law and the request require.

Rights and choices

Depending on applicable law, merchants and other individuals may have rights to request access to, correction of, deletion of, restriction of, or objection to the processing of their personal data. They may also have a right to data portability and a right to complain to a relevant data-protection authority.

Store customers should normally submit privacy requests to the merchant whose store they used. We will assist merchants with valid requests where required, including through Shopify’s mandatory privacy webhooks.

A merchant can request information about the store data Montie holds, ask for correction, or request deletion before automated uninstall deletion by contacting us using the details below.

Contact

Montie is provided by:

Montagne Group V.O.F., trading as Montagne Agency
Ebro 107
1423 AP Uithoorn
The Netherlands
KVK / Chamber of Commerce number: 92891403
VAT number: NL866207375B01
Privacy and support email: Dev@montagneagency.com

If you are unsatisfied with our response, you may have the right to lodge a complaint with the supervisory authority responsible for privacy matters in your jurisdiction. In the Netherlands, this is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Changes to this policy

We may update this Privacy Policy to reflect changes to Montie, our processing practices, or applicable law. We will publish the updated policy at this page and change the “Last updated” date. Where a change is material, we will provide merchants with additional notice where required by law.