Who we are
BulkSync ("the app") is developed and operated by Kanagalingam Pirinthan, Via Monte Gran Sasso 4/3, 46042 Castel Goffredo (MN), Italy. Tax code: KNGPN97L05Z209Y.
For any question about this policy or how your data is processed, write to pirinthankanagalingam@gmail.com.
This policy describes what data BulkSync collects from the Shopify stores that install it, how it is used, who it is shared with and what rights you have.
1. Who this policy is for
BulkSync is a tool for merchants who run a Shopify store. The data processed concerns the store and its product catalog.
BulkSync does not collect, store or access data about your store's end customers. We do not process orders, customer records, shipping addresses or payment data. The permissions the app requests cover only products, inventory, locations, publishing channels and metaobjects.
2. What data we collect
2.1 Store data
When you install BulkSync, Shopify provides us with, and we store:
- your store domain (e.g.
yourstore.myshopify.com) - an access token that lets the app act on the store on your behalf
- the permissions (scopes) you granted
- if you use per-user authentication: first name, last name, email address and language of the logged-in user, provided by Shopify
2.2 Settings you create in the app
- Mapping templates: the column names of your files and how they map to Shopify fields
- Metaobject mappings: the same, for structured content
- Schedules: name, frequency, data source and status of the last run
- Suppliers: name and alignment settings
2.3 FTP / SFTP server credentials
If you set up a connection to an FTP or SFTP server, we store the server address, port, protocol, username, file path and password.
The password is encrypted with AES-256-GCM before it is saved and is never sent back to the browser, shown in the interface or written to logs. It is decrypted only when needed to connect to the server you specified.
2.4 Imported files and catalog data
- The
.xlsxand.csvfiles you upload, or that the app downloads from a URL or FTP server, are kept temporarily to build the preview and complete the import, then deleted. - We keep a log of each import: file name, date, number of rows, row-by-row result with SKU and error messages.
- We keep a cryptographic fingerprint (hash) of each synced product, used to detect what changed and avoid unnecessary updates. Product data cannot be reconstructed from the hash.
2.5 Technical data
We record operational logs (errors, runs, response times) needed to run the service and diagnose problems. They may contain the store domain and technical references to the operations performed.
3. Why we process this data
| Purpose | Legal basis |
|---|---|
| Providing the app's features | Performance of a contract |
| Authenticating requests to Shopify | Performance of a contract |
| Connecting to the FTP servers you specify | Performance of a contract |
| Diagnosing errors and providing support | Legitimate interest |
| Keeping the service secure | Legitimate interest |
| Meeting tax and legal obligations | Legal obligation |
We do not use your data for marketing, we do not sell it and we do not hand it to third parties for advertising. We do not profile you or make automated decisions with legal effects on you.
4. Who we share data with
We rely on the following providers, acting as data processors:
| Provider | Role | Region |
|---|---|---|
| Shopify Inc. | Platform the app runs on | Global |
| Render Services, Inc. | Application hosting, database and queues | Frankfurt, Germany (EU) |
Where data is stored. The infrastructure hosting BulkSync (application, database and queues) is located in Frankfurt, Germany. The data described in this policy is therefore stored within the European Economic Area.
Render Services, Inc. is a US company: to the extent the provider may access data from its own premises, such access is governed by the Standard Contractual Clauses approved by the European Commission, supplemented by the technical measures described in section 6.
Shopify Inc. operates globally and processes your store's data under its own privacy policy.
We may also disclose data to the competent authorities where required by law.
FTP connections: when you use this feature, the app connects to the server you specified. That server is run by you or your supplier and is outside our control. Please check the data processing terms of whoever runs it.
5. How long we keep data
| Data | Retention |
|---|---|
| Session and access token | Until the app is uninstalled |
| Templates and mappings | Until you delete them or uninstall |
| FTP credentials | Until you delete them or uninstall |
| Files waiting to be imported | Until the import is complete |
| Import logs | Until uninstall |
| Product hashes | Until manually reset or uninstall |
| Technical logs | Up to 30 days |
When you uninstall, the session and access token are deleted immediately. All other data linked to the store is permanently deleted within 48 hours, following Shopify's procedure for store data deletion.
You can request earlier deletion by writing to pirinthankanagalingam@gmail.com.
6. How we protect data
- All communication uses encrypted connections (HTTPS/TLS)
- FTP server passwords are encrypted with AES-256-GCM and the key is stored separately from the database
- Data access is restricted to the store that generated it: every query is bound to the store domain
- The app verifies the cryptographic signature of every webhook received from Shopify
- URL download features are protected against requests to internal networks (SSRF)
- Access to production systems is limited to authorized personnel
No system is perfectly secure. If a data breach poses a risk to your rights, we will inform you and notify the supervisory authority within the legal deadlines.
7. Your rights
Under Regulation (EU) 2016/679 (GDPR) you have the right to:
- access the data concerning you
- request its rectification or erasure
- request restriction of processing
- object to processing based on legitimate interest
- receive your data in a structured format (portability)
- lodge a complaint with a supervisory authority (in Italy: Garante per la protezione dei dati personali, www.garanteprivacy.it)
To exercise these rights, write to pirinthankanagalingam@gmail.com. We reply within 30 days.
If you are in California, Virginia or other US states with equivalent laws, you have similar rights: to know what data we collect, to request its deletion and not to be discriminated against for doing so. We do not sell personal data as defined by the CCPA.
8. Cookies
The app runs inside the Shopify admin and uses only the technical cookies needed to keep the authenticated session. We do not use profiling, behavioral analytics or third-party advertising cookies.
9. Children
BulkSync is a professional tool for merchants. It is not intended for anyone under 16 and we do not knowingly collect data from minors.
10. Changes to this policy
We may update this policy to reflect changes to the app or to legal requirements. The date at the top shows the last update. For material changes, we will inform active merchants by email or with a notice in the app.
11. This website
bulksync.kanagalingam.it presents the app and hosts its guide. It does not use cookies, analytics tools, or fonts and scripts loaded from external services.
The "Install BulkSync" form stores nothing on the website: the store name you enter is sent directly to the app, which starts the installation on Shopify. The website's hosting provider may record IP addresses and requested pages in its server logs for security purposes.
Contact
Kanagalingam Pirinthan
Via Monte Gran Sasso 4/3, 46042 Castel Goffredo (MN), Italy
Email: pirinthankanagalingam@gmail.com