Bulk Find & Replace

Privacy Policy

This policy explains how Bulk Find & Replace handles information when merchants use the app with Shopify.

Overview

Bulk Find & Replace helps merchants preview and review find-and-replace changes to supported Shopify product fields before any change is requested. Preview is read-only. Product changes are requested only after a merchant reviews and confirms an execution.

Information We Access

We access Shopify store information needed to operate the app, including the shop domain, installation status, granted scopes, and Shopify authentication and session information. Session storage can include Shopify-provided account details associated with a session, such as a user identifier, name, email, locale, and account role where Shopify provides them.

We read product information selected by the merchant or returned by a store-wide preview. This can include product titles, product descriptions, SEO titles, SEO descriptions, product handles, statuses, and update timestamps. To support the preview, confirmed execution, conflict protection, History, and Undo workflows, the app stores the matching original and replacement values, operation settings, and related operation outcomes.

How We Use Information

We use store and product information solely to provide the app: authenticate the store, display products, create read-only previews, show review results, request confirmed changes, protect changes made in Shopify after preview, support Undo where available, and show operation history. Preview itself does not modify products.

When a merchant confirms an execution, the app requests updates only to the supported product fields and values included in that confirmed operation. We do not sell product data, use it for advertising, or use it to build unrelated profiles.

Shopify Data

The app uses Shopify Admin API access to read the product data required for previews and guarded checks. It uses Shopify webhooks for app lifecycle, scope updates, bulk preview completion, and Shopify privacy compliance topics. Webhook audit records contain operational metadata such as a webhook identifier, shop domain, topic, processing status, and timestamps.

Shopify remains the source of truth for the merchant's store. The app does not expose Shopify credentials, product identifiers, snapshots, hashes, or Shopify request details in the browser interface.

Data Storage and Retention

App data is stored in the app's PostgreSQL database. This includes store records, Shopify sessions, subscription verification records, operation settings, Preview snapshots, execution and Undo outcomes, and privacy or webhook audit records. Redis and BullMQ are used for background delivery of internal operation identifiers; product content is not placed in queue payloads.

The current lifecycle policy evaluates certain standalone terminal Preview records for removal after a 30-day window. The current implementation does not run an automatic deletion scheduler. Execute and Undo records, and snapshots required for conflict protection, auditability, and Undo, remain stored while they are needed for those purposes or until a valid deletion request is processed.

Data Security

We use tenant-scoped server-side access checks, Shopify authentication, guarded product reads before writes, idempotency controls, and redacted application logging. Access to app infrastructure and stored data is limited to systems operating the app. No internet transmission or storage system can be guaranteed to be completely secure.

Data Sharing

We share information with Shopify only as needed to provide the app through Shopify APIs and webhooks. We do not sell merchant product data, and we do not share it with unrelated third parties for advertising or marketing purposes. Technical infrastructure used to operate the app processes data only as necessary to provide and secure the service.

Data Deletion

Merchants may request deletion of their app data through the support contact published with the Bulk Find & Replace Shopify App Store listing. Shopify can also send a shop redaction request. When the app receives a valid Shopify shop/redact webhook, it deletes the shop's sessions, webhook audit records, subscription record, and shop-scoped operation data, including related Preview, Execute, Undo, and queue records. A minimal privacy-request audit record is retained to document completion of the compliance request.

Uninstalling the app marks the shop as uninstalled and deletes its stored sessions. It does not by itself delete all operation history and snapshots; merchants who want complete deletion should submit a data deletion request.

Merchant Rights

Depending on applicable law, merchants may request access to, correction of, or deletion of their app data. Merchants may also use Shopify's privacy request process. We will respond through the app's published support contact and process valid requests in accordance with applicable requirements.

Changes to This Privacy Policy

We may update this policy when the app or applicable requirements change. The current version will remain available at this URL. Material changes will be reflected in the updated policy text.

Contact Us

For privacy questions, access requests, or deletion requests, contact Bulk Find & Replace through the support email or support URL published in the app's Shopify App Store listing.