Privacy
Privacy
As of 11 October 2026. A product description of the data flows. Not legal advice; the controller’s postal address is still missing.
Scope
This page covers bulkmax.pixelpropaganda.io and the processing inside the Shopify app BulkMax. Buyers do not get a BulkMax account. The merchant stays controller toward their customers.
This website
No analytics, no ad pixel. Language is stored in a bulkmax_lang cookie (de or en) so “/” opens the same language next time. The shop-domain form sends the domain with GET to https://bulkmax.pixelpropaganda.app/auth/login.
App database
PostgreSQL on Hetzner in Nuremberg: shop domain, OAuth session (tokens, optional Shopify staff name and email), plan, credit counter, encrypted BYOK key, discount rules including customer-tag names, optional roast-share text. No buyer emails, addresses, or order histories.
Checkout and theme
The Discount Function runs at Shopify. The theme reads metafields. The widget does not call the BulkMax admin API from a buyer’s browser.
AI
Optional in the admin. Text: OpenAI, Google Gemini, or Anthropic, with a house key or BYOK. Images: Ideogram, server-side, then a file in the merchant’s Shopify Files. Competitor spy: a public URL the merchant supplies, SSRF-filtered.
Deletion
Uninstall deletes sessions and detaches Shopify discounts. The “keep data” checkbox is on by default. shop/redact deletes that shop’s BulkMax rows. customers/data_request and customers/redact are acknowledged; there is no customer file to export.
Contact
Access, erasure, objection: support@pixelpropaganda.com. The controller’s postal address is not on this page yet. You can still lodge a complaint with a supervisory authority.