Privacy Policy
Last updated: March 28, 2026
1. Introduction
Bulk Product Editor Pro ("we," "our," or "us") is committed to protecting the privacy of the BigCommerce merchants and users who interact with our Bulk Product Editor application and related services, including this website at bulkedit.novastack.co (collectively, the "Service").
This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and what rights you have in relation to it. It applies to all users of the Service, including merchants who install the Bulk Product Editor Pro app on their BigCommerce store and visitors to our website.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of the Service.
2. Data We Collect
We collect the minimum amount of data necessary to provide our Service. The categories of data we may collect include:
2.1 Account and Authentication Data
- BigCommerce store hash (a unique identifier for your store)
- OAuth access token (encrypted at rest) issued by BigCommerce to authorize the app
- Store owner email address and BigCommerce user ID (provided by BigCommerce during installation)
- Installed and uninstalled timestamps
2.2 Product Catalog Data
- Product names, descriptions, SKUs, prices, inventory levels, and other catalog fields
- Product images (references and cached metadata)
- Categories, brands, and custom field definitions
- Variant data including options, option values, and variant-level pricing and inventory
This data is fetched from the BigCommerce API on your behalf and stored in our database as a synchronized cache. It belongs to you and your store.
2.3 Usage and Operational Data
- Bulk edit operations and change history logs (what was changed, when, and by whom)
- App configuration and preferences
- Error logs and application performance metrics (no personally identifiable information in logs)
2.4 Contact Form Data
- Name, email address, subject, and message content submitted via our contact form
2.5 Automatically Collected Data
- IP address and browser type (for security and fraud prevention, retained for 30 days)
- HTTP request logs (standard web server access logs)
We do not collect end-customer data from your BigCommerce store. We do not access order history, customer records, payment information, or any data outside the product catalog scope.
3. How We Use Your Data
We use the data we collect for the following purposes:
- Providing the Service: Synchronizing your product catalog, processing bulk edit operations, and writing changes back to your BigCommerce store via the API.
- Change History & Rollback: Storing snapshots of product data before edits to enable the undo and rollback feature.
- Support: Responding to contact form submissions and diagnosing technical issues.
- Billing: Communicating plan status to BigCommerce's billing infrastructure (we do not process payment information directly).
- Security: Detecting and preventing fraudulent or unauthorized use of the Service.
- Service improvements: Analyzing aggregate, anonymized usage patterns to improve the app's features and performance.
We do not sell your data to third parties. We do not use your product catalog data for advertising or marketing purposes.
4. Data Storage and Security
All data is stored on servers hosted by Infomaniak Network SA, located in Switzerland (Geneva). Infomaniak is certified ISO 27001 and ISO 14001 and operates exclusively within the European Union and Switzerland, ensuring compliance with GDPR.
We implement the following security measures:
- OAuth access tokens are encrypted at rest using AES-256 encryption before being stored in the database.
- All data transmission between your browser, BigCommerce, and our servers uses TLS 1.2 or higher (HTTPS).
- Database access is restricted to application servers only and is not publicly accessible.
- Regular automated backups with encrypted storage.
- Access to production systems is limited to authorized personnel only.
5. Third-Party Services
The Bulk Product Editor Pro Service integrates with or relies on the following third-party services:
- BigCommerce, Inc. — The platform on which your store operates. Your relationship with BigCommerce is governed by the BigCommerce Privacy Policy and Terms of Service. We are bound by the BigCommerce App Partner Agreement.
- Infomaniak Network SA — Our hosting provider. Data processed by Infomaniak is subject to their Data Processing Agreement and Swiss/EU privacy law.
- Google Fonts — Used to load the Inter typeface on our website. Google may collect IP addresses and browser data when loading fonts. See Google's Privacy Policy for details. You can disable font loading by using a content blocker.
We do not use analytics services such as Google Analytics, Mixpanel, or equivalent tracking tools on our application or website.
6. Data Retention
We retain data for the following periods:
- Product catalog cache: Retained while your app is installed. Deleted within 30 days of app uninstallation.
- Change history logs: Retained for 90 days from the date of the operation, then automatically purged.
- Store account data (store hash, access token, owner info): Retained indefinitely while installed, and for 30 days after uninstallation to support reinstallation. Deleted on written request.
- Contact form messages: Retained in our email system for up to 2 years for support continuity, then deleted.
- Access logs: Retained for 30 days, then deleted.
7. Your Rights
If you are located in the European Union, European Economic Area, Switzerland, or the United Kingdom, you have the following rights under GDPR and applicable privacy law:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right of Rectification: You may request correction of inaccurate or incomplete data.
- Right of Erasure: You may request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Right of Portability: You may request your data in a structured, commonly used, machine-readable format.
- Right to Object: You may object to processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email us at support@novastack.co with the subject line "Privacy Request". We will respond within 30 days. Note that uninstalling the app from your BigCommerce store will initiate automatic deletion of your data per the retention schedule above.
8. Cookies
Our website (bulkedit.novastack.co) does not use tracking cookies or advertising cookies. The Bulk Product Editor Pro app embedded in your BigCommerce dashboard uses strictly necessary session cookies to maintain your authenticated session within the iframe. These cookies are not used for tracking or analytics.
If you access our website directly, your browser may cache static resources (CSS, JavaScript) using standard HTTP cache headers — this is a standard browser behavior and does not constitute cookie-based tracking.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last updated" date at the top of this page. For material changes, we will provide notice through the app interface.
Your continued use of the Service after any update constitutes your acceptance of the revised policy. We encourage you to review this page periodically.
10. Contact
If you have questions, concerns, or requests related to this Privacy Policy, please contact us:
- Email: support@novastack.co
- Subject line: Privacy Inquiry
- Response time: Within 30 days for privacy-related requests; within 24 hours for general support.