Privacy Policy: Bulk Edit Everything
Last updated: 27 September 2026
Bulk Edit Everything ("the app") is a Shopify app published by Dixon App Studio LLC ("we", "us"). This policy explains what the app collects when a merchant installs it, why, how long it is kept, and how to have it deleted.
What we collect and why
| Data | Why | Kept |
|---|---|---|
| Your store's myshopify domain, currency, and the Shopify access token Shopify issues at install | To read and edit the records you ask the app to edit | Until you uninstall. The token is deleted at uninstall; the store record is deleted 48 hours later when Shopify sends shop/redact. |
| Bulk-edit tasks you create: the filter, the changes, and each changed record's ID with its value before and after | To show you a preview, run the task in the background, and let you undo it | Up to 97 days after the task finishes (the longest undo window on any plan, plus a week), then deleted automatically |
| Saved presets (a filter and a set of changes you named) | So you can re-run a task | Until you delete them or uninstall |
| An access log: for each task, undo, import or export, the Shopify staff user ID that ran it, the record type, how many records, and when. No field values. | So access to your store's data, including customer data, can be accounted for | 97 days, then deleted automatically; deleted at uninstall with everything else |
| CSV files you import | Parsed in your browser; only the rows are uploaded, staged for the task | Deleted with the task history, as above |
Customer and order data. The app only reads customer or order records when you run a task on customers, orders or draft orders. If you do, the before and after values of the fields you edited (for example a customer's name, email address, phone number or tags) are stored with that task so it can be undone. They are never used for anything else, never shared, and never sold.
We do not use cookies or tracking pixels, and we do not collect any information from your store's shoppers or visitors. The app adds nothing to your storefront.
Where the data is stored
On Cloudflare (Workers and D1), which encrypts data at rest and in transit. All traffic between the app, Shopify and your browser uses HTTPS. Access to production data is limited to the app's operator for support you request.
Sharing
We do not sell, rent or share store, customer or order data with anyone. Our only processors are Shopify (the platform) and Cloudflare (hosting). Payments for paid plans are handled entirely by Shopify's billing; we never see card details.
Data protection terms
These terms apply between Dixon App Studio LLC and every merchant who installs the app, alongside Shopify's Partner Program and API terms.
- Roles. You (the merchant) control your store's data. We process it only on your instructions, that is, only to run the tasks you create in the app, and for no other purpose. We do not sell it, use it for advertising, profiling or analytics, or use it to train any model.
- Purpose limitation. The data listed above is used only to preview, run, schedule and undo your tasks and to provide support you ask for.
- No automated decisions. The app makes no automated decisions about your customers. It changes a record only when you run a task that says to.
- Consent. Only a customer can give marketing consent, so the app never subscribes anyone: a task, CSV import or undo that would move a customer to "subscribed" skips that change and reports it as "skipped (consent)". Unsubscribing, when you choose to, is allowed. The app never changes consent on its own.
- Security. Data is encrypted in transit (HTTPS/TLS) and at rest, including Cloudflare D1's point-in-time recovery copies. Requests to the app are authenticated with Shopify session tokens and webhooks with HMAC signatures, and each store can only ever reach its own records. Secrets are held as Cloudflare Worker secrets and never stored in source code. Production data is reached only by the deployed app and, for support you request, by the app's operator (a single named person), and to nobody else. Access to personal data is logged: the access log above records each task, undo, import and export, and Cloudflare keeps a log of every request to the app for up to 7 days.
- Test data. Automated tests and local development use separate, synthetic data and never the production database.
- Sub-processors. Shopify (platform and billing) and Cloudflare (hosting and database). We will update this page before adding another.
- Security incidents. We keep a written incident response procedure. If a security incident affects your data we will tell you by email without undue delay, and within 72 hours of confirming it, with what happened, what data was affected and what we have done about it.
- End of processing. On uninstall, and on Shopify's
shop/redactrequest, everything we hold for your store is deleted as described below.
Your rights and deletion
- Uninstall removes the app's access immediately and triggers deletion of everything above within 48 hours.
- Customer data requests and erasure (GDPR / CCPA). We honour Shopify's
customers/data_request,customers/redactandshop/redactrequests. Acustomers/redactrequest deletes every task record that holds that customer's or their orders' values. - You can ask for a copy of the data held for your store, or its deletion, at any time by emailing support@dixonappstudio.com. We answer within 30 days.
Changes
If this policy changes materially we will update the date above and tell installed merchants in the app.
Contact
Dixon App Studio LLC · support@dixonappstudio.com · dixonappstudio.com