Saga StackBuilder
Saga StackBuilder (“the App,” “we,” “us,” or “our”) is a Shopify application that lets merchants group existing products into goal-based bundles (“stacks”), offer those stacks to shoppers through a storefront widget, and apply a bundle discount at checkout.
This policy explains what personal and store data the App accesses, why we process it, what it writes back to your store, how it uses artificial intelligence, how data is stored and protected, how long we keep it, and the choices and rights available to you. It applies to the App and its associated services only. It does not cover Shopify itself, the merchant store the App is installed on, or any third-party website, which are governed by their own privacy notices.
Saga StackBuilder is built and maintained by SK Labs, an independent two-person software studio based in Bengaluru, India. The App is developed and supported by Sagar S. and Sagarika S.K.
We are a small team and we handle privacy questions directly. There is no separate support desk between you and the people who wrote the code — an email to the address in Section 19 reaches us.
This policy concerns three groups of people and data:
We collect only the data needed to operate the App. The App requests the following Shopify access scopes: read products, write products, read orders, and write discounts. Sections 5 and 6 explain exactly what the two write scopes are used for. We do not request theme scopes, and we do not request customer scopes.
| Data | Purpose |
|---|---|
| Store domain and Shopify store ID | Identify your store and scope all of your data to your account. |
| Store name, contact email, primary currency, time zone | Display the App correctly, format figures, and contact you about the service. |
| Shopify access token and granted scopes | Authenticate API calls to Shopify on your behalf. Stored encrypted at rest (see Section 14). |
| Subscription & billing status | Manage your plan, trial period, and access to features. Charges are processed by Shopify Billing, not by us. |
| App settings you configure | Store your stack definitions, discount settings, widget appearance, and placement preferences. |
To render product pickers and the storefront widget quickly, the App keeps a mirror cache of your catalog: product titles, handles, images, prices, inventory availability, variants (including selling-plan and subscription indicators), and tags. Shopify remains the source of truth; the cache is kept current through product webhooks and can be rebuilt at any time.
The App receives order webhooks from Shopify and reads the fields needed to attribute revenue to stacks: the order identifier, order totals and currency, line-item prices and quantities, line-item discount allocations, and the stack identifier the widget attaches to items it adds. We do not build a full mirror of your orders and we do not store customer names, email addresses, shipping addresses, or payment details. We store order identifiers, monetary amounts, currency, and internal product references only.
On a merchant’s storefront, the widget records aggregate interaction events — impressions, clicks, and add-to-cart actions — each tied to a first-party, anonymous session identifier. This identifier is a random value used solely to connect a single visitor’s actions for attribution. It contains no name, email, address, or other directly identifying information. Its use is described further in Section 9.
The App does not only read from your store. So that a bundle discount can actually be applied at checkout, it writes in three specific places, and nowhere else:
| What | Why |
|---|---|
A product metafield in the saga_stackbuilder namespace, on each product that belongs to a discounted stack |
Records that stack’s discount rate so the checkout discount function can read it. It contains the stack identifier and a percentage — no personal data. It is removed when the stack is deactivated or deleted. |
| One automatic discount in your Discounts admin, titled after your store | Connects our discount function to your checkout. Without it, no bundle discount can be applied. It is created once, at install. |
A line-item property named _stack_id on cart lines the widget adds |
Marks which stack a shopper was completing, so the correct discount is applied and the resulting order can be attributed to that stack. It holds an internal stack identifier only. |
We do not modify your product titles, descriptions, prices, images, inventory, or any other catalog content. We do not create, modify, or cancel orders. The write scopes exist for the three purposes above.
The App uses a third-party large language model to help merchants draft stacks. This is the most significant change since the previous version of this policy, and we describe it in detail.
When you ask the App to suggest a stack, or when it prepares protocol templates for your catalog, it sends a description of your products to a language model and receives back a suggested grouping: which products belong together, a short benefit line for each, and a rationale for the grouping. These are drafts. Nothing the model produces is published to your storefront until you review it and choose to activate it.
We send product information from your catalog only — product titles, descriptions, tags, product types, and prices. We do not send:
Your data is not used to train the model. We use the model provider’s API under commercial terms that exclude API inputs and outputs from model training. We do not train any model of our own on merchant data.
To avoid re-asking the same question and to keep the App responsive, we cache the model’s suggestions against a fingerprint of the catalog they were generated from. When your catalog changes materially, the cache is invalidated and suggestions are regenerated. Cached suggestions are stored with your store’s data and deleted with it (Section 15).
AI-generated content is a starting point, not a decision. You review every suggestion before it goes live, you can edit any part of it, and you can build stacks entirely by hand without using the AI features at all. No AI-generated text reaches a shopper unless you activate the stack containing it.
We use the information above to:
We do not sell personal information, and we do not use it for advertising or cross-context behavioral advertising.
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
For storefront shopper data, the merchant is the controller and determines the applicable legal basis; we process this data on the merchant’s documented instructions.
The anonymous session identifier described in Section 4.4 is a behavioral attribution identifier. Although it stores no directly identifying details, we treat it as subject to privacy and consent rules rather than claiming it is exempt.
The widget respects the merchant’s existing consent signal where one is exposed (for example, through Shopify’s Customer Privacy API or a consent banner). If analytics consent has not been given, the widget still renders and can still add items to the cart, but it suppresses the tracking beacon rather than firing it. In that case, attribution simply undercounts — metrics are treated as a meaningful lower bound.
We do not claim to store no personal data of any kind. We claim that we store no customer personal information and use only an anonymous, consent-respecting attribution identifier. Merchants are responsible for displaying any consent mechanism their jurisdiction requires and for disclosing the App’s analytics in their own storefront privacy notice.
Order data accessed through Shopify falls under Shopify’s Protected Customer Data requirements. We access order data only with the required Shopify approval in place, limit our use of it to the attribution features described in this policy, retain only the minimal fields listed in Section 4.3, and apply the security and retention controls in Sections 14 and 15. We do not use order data to identify individual shoppers, we do not send it to any language model, and we do not use it for any purpose unrelated to the merchant’s analytics.
| Provider | Function | Data involved |
|---|---|---|
| Shopify Inc. | Platform, authentication, webhooks, App Proxy, checkout discount function, billing | Store, catalog, order, and subscription data |
| Railway Corp. (application hosting & PostgreSQL database) | Runs the App and stores its database | All App data described in Section 4 |
| Groq | Language model that drafts stack suggestions (Section 6) | Product titles, descriptions, tags, types, and prices only. No customer, order, or account data. |
We require each provider to safeguard data consistent with this policy and applicable law.
We are based in India. Our service providers may process data in countries where they operate, including the United States and other countries. Where personal data is transferred outside jurisdictions with applicable data transfer restrictions (such as the EEA or the UK), we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses or equivalent legal mechanisms provided by our service providers.
We apply technical and organizational measures appropriate to the data we hold, including:
No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security.
We keep data only as long as needed for the purposes in this policy:
We may retain limited records longer where required for legal, accounting, or security purposes, kept to the minimum necessary.
Depending on where you live, you may have rights over your personal information, including to access, correct, delete, port, or restrict its processing, to object to processing, and to withdraw consent. Where the CCPA/CPRA applies, you have rights to know, delete, and correct, and a right not to be discriminated against for exercising them; note that we do not sell or share personal information for cross-context behavioral advertising.
Merchants can exercise many of these rights directly by managing their data in the App or by uninstalling it. For storefront shoppers, the merchant is the controller and is the primary point of contact; we will assist merchants in responding to such requests. To make a request to us directly, contact us using Section 19. We may need to verify your identity, and we will respond within the timeframe required by applicable law.
The App is a business tool intended for merchants and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us so we can delete it.
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify merchants through the App or by email. Your continued use of the App after an update takes effect constitutes acceptance of the revised policy.
For privacy questions or to exercise your rights, contact:
SK Labs
Cauvery Bhavana, 9/B Palace Road
Ambedkar Veedhi, Majestic
Bengaluru, Karnataka 560009
India
Email: sa39in12th@gmail.com
If you are in the EEA or UK and believe we have not addressed your concern, you may lodge a complaint with your local data protection authority.