Privacy Policy
BulkMsg is a Shopify app that sends WhatsApp and SMS messages on behalf of the stores that install it. This policy explains what data we handle, why, who we share it with, and how long we keep it.
1. Who is responsible for what
BulkMsg is operated by PantherCodx (“BulkMsg”, “we”, “us”). You can reach us at info@panthercodx.com.
Two different relationships matter here, and they carry different obligations:
- Merchants. For the account data of the Shopify merchant who installs BulkMsg, we act as a data controller. We decide what we collect and why.
- The merchant’s customers. For the shopper data that flows through the app — phone numbers, order details, message history — we act as a data processor on the merchant’s instructions. The merchant is the controller. They choose who to message and what to say; we deliver it.
If you are a shopper who received a message from a store using BulkMsg, the store is the right first point of contact. You can also write to us and we will route your request to them.
2. What we collect
| Category | What it includes | Why we have it |
|---|---|---|
| Store profile | Store domain, store name, contact email, owner name, store phone, country, currency, timezone and Shopify plan | To identify the account, price messages in the right currency, and send at a sane local hour |
| Shopify order events | Orders, checkouts, draft orders, fulfilments and inventory levels received through Shopify webhooks | To trigger the automations the merchant has switched on |
| Recipient data | Customer phone number, the message sent, delivery status, any reply, click timestamps and the provider’s error code when a send fails | To deliver messages, show delivery history and attribute revenue |
| Channel credentials | The WhatsApp Business access token issued to us during Embedded Signup, and SMS subaccount credentials | To send on the merchant’s behalf. Stored encrypted at rest with AES-256-GCM, never displayed back and never shared |
| Usage and billing | Message counts, per-message cost, plan and spend-cap settings | To bill the subscription and show what sending actually cost |
We do not collect payment card numbers. Subscription billing runs through Shopify’s billing API and card details never reach us.
3. What we do with it
We use data to:
- Deliver the messages a merchant has configured, over WhatsApp or SMS
- Show delivery status, message history and revenue attribution in the app
- Calculate usage against the merchant’s plan and spend cap
- Provide support when a merchant asks for it
- Detect abuse, debug failures and keep the service running
- Meet our legal obligations, including WhatsApp Business Platform policy
We do not sell personal data. We do not use a merchant’s customer data to advertise to those customers, to build profiles across stores, or to train machine learning models.
4. Legal basis (GDPR and similar laws)
Where GDPR or UK GDPR applies, we rely on contract to provide the service a merchant signed up for, legitimate interests to secure and improve it, and legal obligation where retention or disclosure is required of us. For shopper data we process on a merchant’s instruction, the merchant is responsible for having a lawful basis — in practice, for holding valid opt-in before messaging anyone.
6. International transfers
Our processors operate globally, so data may be processed outside the country a merchant or their customer is in. Where data leaves the EEA or the UK, transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent safeguard.
7. How long we keep it
- Message records — retained while the app is installed, so merchants can see delivery history and attribution.
- On uninstall — we receive Shopify’s
app/uninstalledwebhook, stop all sending immediately, and revoke the stored channel credentials. - Shop erasure — Shopify sends a
shop/redactrequest 48 hours after uninstall. We erase the store’s data on receipt. - Customer erasure — a
customers/redactrequest erases that individual’s data. See Data deletion. - Billing records — retained as long as tax and accounting law requires, typically seven years, independent of the above.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict processing of your personal data, to object to processing, and to withdraw consent. Under California law you may also ask what we collect and disclose, and we do not sell or share personal information as those terms are defined there.
Write to info@panthercodx.com and we will respond within the period the applicable law allows — 30 days under GDPR. Shoppers should contact the store that messaged them; we will forward requests we receive directly. You also have the right to complain to your local data protection authority.
9. Security
Data is encrypted in transit with TLS and at rest. Third-party access tokens are encrypted separately with AES-256-GCM before they are written to the database. Every inbound webhook — from Shopify, Meta and our SMS providers — is signature-verified before it is processed. Access to production data is limited to people who need it to operate the service.
No system is perfectly secure. If a breach affects a merchant’s data, we will notify them and the relevant regulator within the timeframes the law requires.
10. Children
BulkMsg is a business tool and is not directed at anyone under 16. We do not knowingly collect their data. If you believe we have, contact us and we will delete it.
11. Changes to this policy
We will update this page when our practices change and revise the date at the top. Material changes will be notified to merchants by email or in the app before they take effect.
12. Contact
PantherCodx
info@panthercodx.com