BulkPilot is a Shopify app that adds quantity-break "Buy 2 for X" / "Buy 3 for Y" buttons to a store's product and cart pages, and applies the tier price automatically at checkout. This policy explains exactly what it stores, why, and for how long.

Who we are

BulkPilot is operated by Boldnsmart (boldnsmart.com), based in Lithuania, which acts as the data controller for the data described in this policy. Lithuania is in the European Union, so the GDPR applies. You can reach the controller at [email protected].

What we do not collect

BulkPilot stores no personal data about your customers. It does not read, request or retain shopper names, email addresses, shipping addresses or payment details. When an order is placed, it does read that order's line items — product id, quantity and the discount amount applied — solely to determine whether a bulk-pricing tier was used; the record it keeps of that contains order and product identifiers and amounts only — never a customer identifier.

BulkPilot contains no analytics, advertising or tracking scripts, and sets no cookies beyond the session cookie Shopify itself requires to keep you signed in to the embedded app.

What we store

  • Your store's domain — to associate your bulk-pricing tiers with your shop and no one else's.
  • Your Shopify staff account details, as provided by Shopify when you install and sign in: your name, email address, locale, Shopify user id, and whether you are the account owner or a collaborator.
  • Access and refresh tokens issued by Shopify, used to read your products and manage the checkout Discount Function on your behalf. They are credentials, not personal data, and are never shared.
  • The tiers you configure — which products have bulk pricing, the qty-2 and qty-3 prices, and whether pricing is calculated from the current or original price.
  • A count of orders that used a tier — product id, quantity, which tier applied, and the discount amount. No customer or shopper identifier.

What we read from an order, and what we do not

When an order is placed, BulkPilot reads that order's line items — product id, quantity, and the discount amount applied — solely to determine whether a bulk-pricing tier was used, for the count described above. No customer personal field on the order (name, email, address, payment details, or any other shopper-identifying data) is ever read or stored.

Why we store it

Solely to provide the service: to show the right bulk-pricing buttons, to apply the right price at checkout, and to show you how often tiers are used. We do not sell data, and we do not use it for advertising or profiling.

Where it is stored

Data is held in a PostgreSQL database hosted by Neon, and the application runs on Railway. Both act as processors on our behalf. Product and order data is also read from and written to Shopify through their Admin API.

How long we keep it

When you uninstall BulkPilot, Shopify notifies us and we erase your store's data — every tier rule, tier-order record and setting, along with your session. Shopify sends this notification 48 hours after uninstall, so erasure happens then rather than instantly.

Your rights

If you are in the EEA or UK you have the right to access, correct, export, restrict or erase your personal data, and to object to its processing. Because BulkPilot holds so little, uninstalling the app already triggers erasure of everything tied to your store. For anything else, email [email protected] and we will respond within 30 days.

Requests that Shopify forwards on a shopper's behalf are answered automatically. customers/redact deletes our tier-order record for every order id the request names. customers/data_request reports which of the named order ids we hold such a record for. As set out above, that record is an order id, product id, quantity and discount amount only — not personal data — so there is no shopper personal data to return.

Changes

If this policy changes materially we will update the date at the top of this page. Continued use of the app after a change means the updated policy applies.

Contact

Questions about this policy or about your data: [email protected].