Privacy policy
Last updated October 1, 2026
Mint Bulk Editor is a Shopify app made by Mint Labs ("we", "us"). It lets merchants change many products at once — prices, tags, titles, stock and other product fields — with a preview before anything changes and an undo afterwards, and exports and imports product spreadsheets. This policy explains what the app handles, why, and when it's deleted.
The short version
- The app works only with the store's own product data — products, variants, their prices, stock and other fields. It has no access to orders or customers and never reads, stores or processes any customer's personal data.
- To make undo possible it keeps, for each job, the value every changed field had before and after the change — for as long as the merchant's undo history (24 hours on Free, 30 days on Pro).
- We never sell or share data, use it for advertising, or combine it across stores. The app adds nothing to the storefront and sets no cookies there.
Information we handle
| Information | Why | Kept |
|---|---|---|
| Store domain and a Shopify access token | To read products and make the changes the merchant runs. | Token: until uninstall |
| Store name, time zone, currency and weight unit from Shopify | To schedule edits in the store's time zone and show values in its currency and units. | Until the store is deleted |
| Bulk edits the merchant sets up (which products, which changes, schedule) | To preview and run them. | With the job (see below) |
| For each field a job changes: product and variant IDs, product and variant titles, the field's value before and after, and the value found if someone else changed it | To show the preview and results, and to undo the job exactly. | Undo history: 24 hours after the job finishes (Free) or 30 days (Pro); previews that are never run: 24 hours |
| Export files (CSV / Excel) of the store's products and variants | So the merchant can download them through a private link that expires after 30 minutes. | 7 days |
| Uploaded import files (CSV or Excel) and the row-by-row check report | To check and run the import and show what couldn't be imported. | With the import job (as above) |
| The store's locations, product tags, vendors and product types | Shown as choices and suggestions in the forms. Read from Shopify when a form opens; location names used in a job are stored with it. | With the job, otherwise not stored |
| Activity log (e.g. "Autumn price update finished: 1,240 changes applied") | So the merchant can see what the app did and when. | With the job; export entries 30 days |
| Plan and subscription status | Read from Shopify to decide which features apply. Payments are handled entirely by Shopify. | Until the store is deleted |
| Customer names, email addresses, phone numbers, addresses, orders, payments | Not requested from Shopify — the app has no permission to read them. | Never held |
Customer privacy requests
Because the app holds no information about customers, Shopify's customer data requests (customers/data_request) and erasure requests (customers/redact) have nothing to return or delete; we acknowledge them. When a store is deleted (shop/redact, sent 48 hours after a merchant uninstalls), we permanently delete everything we hold for it, including export and import files.
Where data is processed and how it's protected
The app runs on Cloudflare (hosting, database, file storage and job queue) and connects to Shopify's APIs. Data is encrypted in transit (TLS) and at rest. Export downloads use signed links that work for one file, for one store, for 30 minutes. Access is limited to Mint Labs staff who need it to provide support. We use no other sub-processors, analytics or trackers. See our security policy.
Retention
Access tokens are deleted as soon as the app is uninstalled. Job records are kept until their undo history ends, so a merchant who reinstalls within 48 hours can still undo a recent job; everything for the store is deleted when Shopify sends the store deletion request 48 hours after uninstalling. Moving from Pro to Free shortens the undo history to 24 hours.
Your rights
Merchants can ask us to access, correct or delete the information above at any time — deleting a job in the app deletes it and its records immediately. We respond to requests within 30 days.
Changes
If we change this policy we'll update the date above and, for significant changes, notify merchants in the app.
Contact
Mint Labs — support@stickermint.com