Security & data
Your store's data, handled like it's ours.
Only what's needed
Bulkvane asks only for the permissions its features use, and reads customer data only when you run a customer job.
Encrypted everywhere
HTTPS/TLS for every connection; data and backups encrypted at rest.
Deleted after 30 days
Job files, row data and undo snapshots are deleted automatically when the undo window ends.
Gone on uninstall
Uninstall and every session, job, file, template, token and log for your store is deleted straight away.
Read-only AI access
AI assistants can look things up and start exports — never change your store. Every request is logged.
Hashed tokens
AI assistant and OAuth tokens are stored only as SHA-256 hashes. Download links expire in 15 minutes.
Limited staff access
Only staff who need it can reach production data, with strong passwords and two-factor authentication.
Shopify privacy webhooks
Customer data requests, customer redaction and shop redaction are handled automatically.
The life of your data
Every job follows the same timeline. Nothing is kept “just in case”.
You start a job
The file and the rows it needs are stored for that job only.
Before any change
A snapshot of each item is saved, so you can undo.
Day 30
Files, row data and snapshots are deleted; the undo window ends.
Day 365
The job's history line (counts and dates) and API logs are deleted.
You uninstall
Everything for your store is deleted immediately.
Permissions we ask for, and why
Shopify shows these when you install. Bulkvane never reads orders or payment details.
| Permission | Used for |
|---|---|
| read_products, write_products | Export, import, edit and undo products, variants, SEO, metafields and collections. |
| read_files, write_files | Add product and collection images from the URLs in your file. |
| read_inventory, write_inventory | Export and update available stock per location. |
| read_locations | Match “Inventory: <location>” columns to your store's locations. |
| read_customers, write_customers | Export and import customers — only when you choose to. |
Sub-processors
The providers that help us run Bulkvane. Each is bound by data protection terms. See our data processing addendum and privacy policy.
| Provider | Purpose | Location |
|---|---|---|
| Shopify | App platform, sign-in and billing | Canada, United States and others |
| Cloud hosting provider | Runs the app, its database and job files | Region available on request |
| Brevo | Sends job and account emails you turn on | European Union |
| Resend | Delivers website contact form messages and newsletter sign-ups | United States |
| Cloudflare | Spam protection (Turnstile) on website forms | Global network |
Found a security issue?
Please email support@bulkvane.com with “Security” in the subject. We'll acknowledge it within 2 business days, keep you updated, and credit you if you'd like. Please don't access other merchants' data or disrupt the service while testing.