Privacy Policy
BulkSheet ("we", "our", "us") builds tools for Shopify merchants. This policy explains what data we access, how we use it, and the choices merchants have. We follow Shopify's Partner Program requirements and the principle of least privilege.
1. Data we access
With the merchant's consent during install, BulkSheet requests these Shopify Admin API scopes:
read_products- Read product fields, tags, and related media so we can display them in the bulk editor.write_products- Apply bulk updates the merchant explicitly initiates to products and tags.read_inventory- Read variant inventory levels at each location for display in the grid.write_inventory- Apply inventory adjustments the merchant initiates via bulk edit.read_locations- Resolve Shopify locations when editing inventory by location.
We do not request or access customer data, orders, or financial records.
2. How we use the data
- To render the bulk editor and display product and tag data in the embedded app.
- To apply bulk updates the merchant explicitly initiates, via Shopify's Admin GraphQL API and bulk operation APIs.
- To store limited draft undo history in the bulk editor (cross-session on paid plans: 30 days on Starter, 90 days on Growth, 180 days on Pro, up to 50 steps) and, when enabled, a per-field log of changes saved to Shopify for view and Pro revert. Free plan: in-session undo only; no saved change log.
3. Data we do not collect
- Customer personal data
- Order history or financial data
- Payment information
4. Storage and security
Session credentials and edit-history records are stored in an encrypted database on infrastructure we control. We encrypt data in transit over TLS and at rest. Access to production data is limited to the smallest number of personnel necessary.
Per-field audit logs (shop, product ID, field name, prior and new values, timestamp) may be stored when bulk edits are successfully saved to Shopify. They are not used for marketing and do not include customer personal data. When stored, retention follows your plan window (30 days on Starter, 90 days on Growth, 180 days on Pro) and rows are deleted on uninstall or Shopify shop/redact (within 48 hours). Draft cross-session undo uses a separate store with the same plan windows; see section 2.
5. Subprocessors
We rely on the following vetted subprocessors:
- Hosting provider
- Database hosting
- Error monitoring (Sentry)
- PostHog - behavior analytics and session recording, hosted in the United States (PostHog Privacy Policy)
6. GDPR webhooks
BulkSheet processes Shopify's mandatory compliance webhooks: customers/data_request, customers/redact, and shop/redact. Because we do not store customer data, customers/data_request and customers/redact are acknowledged with no records to return or redact. On shop/redact (48 hours after uninstall), we delete all data associated with that shop.
7. Uninstall and data deletion
On app uninstall, we delete session tokens immediately and all remaining shop data within 48 hours. You may request earlier deletion at any time by emailing [email protected].
8. Analytics and session recording
We use PostHog to understand how merchants interact with the app. PostHog records session interactions (mouse movements, clicks, scrolls) and produces aggregated usage insights. Analytics state is kept in memory only - no analytics cookies or persistent browser storage are used. Each merchant session is identified by the store's .myshopify.com domain, which is transmitted to and stored by PostHog (on servers in the United States; PostHog Inc. is certified under the EU-U.S. Data Privacy Framework) as the user identifier. No Shopify customer personal data, order data, or financial data is captured or transmitted to PostHog. Session recordings are retained for a limited period before automatic deletion. You can review PostHog's data practices at PostHog Privacy Policy.
Our marketing site embeds a product demo video hosted on YouTube. The player loads only after you click play, using YouTube's privacy-enhanced (no-cookie) mode; until then, no data is sent to Google. See the Google Privacy Policy for how Google handles playback data.
9. Contact
Questions about this policy or your data: [email protected].