Skip to content

New: ask Claude, ChatGPT or Cursor about your Bulkvane jobs and catalog. See how

Bulkvane

Legal

Privacy policy

What the Bulkvane app and website collect, why, who we share it with, how long we keep it, and your rights.

Last updated

1. The short version

Bulkvane is a Shopify app for bulk importing, exporting and editing store data. To do that it reads and writes the products, customers and collections you choose, keeps job files so you can preview and undo changes, and deletes them after 30 days. We don't sell personal data, we don't use it for advertising, and we don't use it to train AI models. When you uninstall the app, everything we hold about your store is deleted.

2. Who we are and what this policy covers

This policy explains how Bulkvane (“Bulkvane”, “we”, “us”) handles personal data in the Bulkvane app for Shopify (the “App”) and on bulkvane.com (the “Website”).

For store data that merchants process with the App — including their customers' personal data — the merchant is the controller and Bulkvane acts as a processor (a “service provider” under US state laws), processing it only on the merchant's instructions. Our Data Processing Addendum sets out those terms. For merchants' account details and for Website visitors, Bulkvane is the controller.

3. Information we collect through Shopify's APIs

When you install the App, Shopify gives us access only to the permissions you approve. We use them as follows:

DataWhy we need it
Store details: shop domain, plan and store emailTo run the App, apply your plan's limits and send the emails you turn on.
Staff account details from your Shopify session: name, email, locale and whether you're the account ownerTo sign you in to the App securely. We don't use them for marketing.
Products, variants, images, SEO fields, product metafields and collectionsTo export, import, preview and undo the changes you ask for (read/write products and files permissions).
Inventory levels and locationsTo export and update stock per location (read/write inventory, read locations).
Customer data: name, email, phone, note, tags, tax-exempt status, default address, company, email/SMS marketing consent status, orders count, amount spent and datesOnly when you export or import customers. Consent, orders count and amount spent are read for reference and never changed.

We do not access orders, payment details or checkout data.

4. Information you give us

  • Files you upload, and links you import from (Google Sheets, Google Drive, Dropbox or direct file links).
  • Edits you make in the spreadsheet editor, saved export templates and your settings, including the email address for notifications.
  • Names you give to AI assistant tokens. We store only a one-way hash of each token, never the token itself.
  • Messages you send to support or through the Website's contact form, and your email address if you subscribe to the newsletter.

5. Information collected automatically

  • Job records: type, data type, file name, status, counts and dates of each import and export.
  • An audit log of every AI assistant (MCP) request and signed download: the tool used, the token that made it and when.
  • A log of job emails sent, used to count your plan's monthly allowance.
  • Standard server logs (IP address, browser type, time of request), used to keep the App and Website secure and working.

The Website doesn't use advertising or tracking cookies. It stores your light/dark theme choice in your own browser. If we add analytics, we'll use a privacy-friendly service and ask for consent first where the law requires it.

6. How we use information

  • To provide the App's features: exports, imports, previews, the spreadsheet editor, undo, templates and job history.
  • To send the job and account emails you turn on in Settings.
  • To manage your subscription through Shopify's billing system.
  • To answer support requests and tell you about important changes to the App.
  • To keep the App secure, prevent abuse and enforce rate limits.
  • To meet legal obligations.

We don't sell or “share” personal data (as defined by US state privacy laws), don't use it for targeted advertising, don't make automated decisions with legal or similarly significant effects, and don't use store or customer data to train AI models. We process customer data only for the purposes above.

7. AI assistants

Bulkvane doesn't send your data to any AI model on its own. If you connect an AI assistant (for example Claude, ChatGPT or Cursor) to Bulkvane's MCP server, the assistant receives the answers to the requests you make — such as job results, record counts, a catalog health report or a download link. That assistant's provider handles the data under its own privacy policy.

You decide whether to connect an assistant. Assistant access is read-only for your store, every request is logged, download links expire after 15 minutes, and you can revoke a token at any time under Settings → AI assistants.

8. Who we share information with

We share personal data only with service providers that help us run Bulkvane (“sub-processors”), under contracts that require them to protect it and use it only to provide their service to us:

ProviderPurposeLocation
ShopifyApp platform, sign-in and billingCanada, United States and others
Cloud hosting providerRuns the app, its database and job filesRegion available on request
BrevoSends job and account emails you turn onEuropean Union
ResendDelivers website contact form messages and newsletter sign-upsUnited States
CloudflareSpam protection (Turnstile) on website formsGlobal network

We may also disclose information if the law requires it, to protect the rights and safety of our users or others, or as part of a merger or acquisition, in which case this policy continues to apply. We'll update the list above before adding a new sub-processor.

9. How long we keep it

DataKept for
Uploaded files, export and results files, row data and undo snapshots (including any customer data in them)30 days after the job finishes — the end of the undo window. Unapplied previews are cancelled then.
Job history (counts, dates and status, no row data)365 days
AI assistant audit log and job email log365 days
Store settings, templates, tokens and sessionsUntil you uninstall the App
Website contact messagesAs long as needed to answer, and no longer than 24 months
Newsletter email addressUntil you unsubscribe

When you uninstall the App, we delete all sessions, jobs, snapshots, templates, tokens, logs and files for your store straight away. We also act on Shopify's privacy requests: a shop redaction request deletes everything we hold for the store, and a customer redaction request deletes the files, row data and undo snapshots of the store's customer jobs.

10. How we protect it

  • All data is encrypted in transit (HTTPS/TLS) and stored on encrypted disks and backups.
  • Access to production systems and customer data is limited to the staff who need it, with strong passwords and two-factor authentication, and is logged.
  • Production data is kept separate from test and development data.
  • AI assistant tokens and OAuth tokens are stored only as SHA-256 hashes.
  • Imports from links refuse private and internal network addresses.
  • We have an incident response plan and will notify affected merchants without undue delay if a breach affects their data.

More detail is on our Security & data page.

11. Where data is processed

Bulkvane and its sub-processors may process data in countries other than yours, including outside the European Economic Area and the United Kingdom. Where the law requires it, we protect those transfers with appropriate safeguards such as the European Commission's Standard Contractual Clauses.

12. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to restrict or object to its processing, and to withdraw consent. Residents of US states such as California also have the right to know what we collect and to not be discriminated against for using their rights. You can also complain to your local data protection authority.

Merchants and Website visitors can use these rights by emailing support@bulkvane.com. We'll reply within 30 days and may need to verify your identity first.

If you're a customer of a store that uses Bulkvane, please contact that store: it controls your data. When a store asks us to help with a request — including through Shopify's customer data request and redaction webhooks — we do so promptly. Bulkvane keeps no separate customer profiles; customer details exist only in a store's job files, for at most 30 days.

13. Children

Bulkvane is a business tool and isn't directed at children. We don't knowingly collect personal data from anyone under 16.

14. Changes to this policy

We'll post any changes on this page and update the date at the top. If a change is significant, we'll tell merchants in the App or by email before it takes effect.

15. Contact

Questions or requests about privacy: support@bulkvane.com. Post: Bulkvane.