Volver: Bulk Price Edit & Undo
Privacy policy
Last updated: October 10, 2026
Who we are
Volver: Bulk Price Edit & Undo ("Volver") is a Shopify app published by Swicelso OÜ. It lets merchants edit products, variants, collections, customers and orders in bulk from inside the Shopify admin, preview every change before it is written, and undo a task afterwards.
What we process
- Store identity: your myshopify domain, the store owner's email address, currency, time zone and Shopify plan name, received from Shopify when you install the app.
- Product data: the products, variants and collections you ask Volver to read or edit (titles, prices, compare-at prices, SKUs, tags and similar fields).
- Customer data (only when you open the Customers tab or a customer CSV): the customers your filter matches — name, email address, phone number, tags, note, account state, the province and country of the default address, totals and marketing consent state — read to show the preview and to write the field you chose — and, only for the CSV columns you choose, the full addresses: read into a customer export file, or added and edited by a customer CSV import. The journal keeps only the previous and new value of that field, never a copy of the customer record. A bulk edit or a CSV edit of existing customers can never subscribe a customer to marketing, and a revert never re-subscribes one; only a CSV that creates new customers may carry the marketing consent you already collected (state and opt-in level), as Shopify's own customer import does.
- Order data (only when you open the Orders tab or an order CSV): the orders your filter matches from the last 60 days — order name, dates, statuses, tags, note, line items, customer name, total, discount codes, shipping country and, only for the CSV columns you choose, the shipping address and the fulfillment tracking numbers — read to show the preview and to write the field you chose. Orders older than 60 days are never listed or modified. The journal keeps only the previous and new value of that field, never a copy of the order.
- Abandoned checkouts (only in an abandoned-checkout CSV export you start): checkout name, dates, customer name and email address, billing and shipping address, discount codes, totals and line items, written into the export file and nowhere else.
- CSV files: the files you import and the files Volver exports for you, kept with the task for its retention window and deleted with its journal; the customer and order files of a store are deleted when Shopify sends a
customers/redactrequest. - Task journals: for every edited field, the previous value, the new value, the result and Shopify's message. This is what makes a task reversible.
- Staff actions: the Shopify user ID of the staff member who starts, stops or reverts a task or changes the plan, taken from the Shopify session token (never their name or email address), kept in the audit log so a store with several staff members can tell who did what.
- Billing events: the status of your Volver subscription as reported by Shopify (plan, active, cancelled, test), never a card number — Shopify bills you.
- Technical logs: request and job logs for reliability, without personal data (email addresses are redacted from logs).
Volver reads order data only inside a task you start from the Orders tab or an order CSV, and, when you open the Revert dialog of a task that created products, the number of orders placed since then that include them (a count, not the orders) — never in the background, and does not use advertising or analytics trackers. Volver sets no cookies of its own; the embedded app relies on Shopify session tokens.
Why we process it
- To run the bulk edits you create, and only those.
- To let you preview and undo a task (the journal is the backup).
- To manage your plan through Shopify Billing and list every change, with its date and time, in the subscription history.
- To answer support requests and legal obligations.
Where the data lives
Volver runs on Fly.io in the Paris region (PostgreSQL database and application servers), keeps CSV files (the imports you upload and the exports it generates) in Tigris object storage on Fly.io, uses Upstash Redis for its job queue — a job carries what it needs to run, including the webhooks Shopify sends, and is deleted from Redis once it has run (a failed webhook job after 7 days). When you use an AI writing change (titles, descriptions, SEO), the product fields you tick and your instructions are sent to Google's Gemini API (paid service: Google does not use them to train its models); customer and order data are never sent to it. These providers act as processors on our instructions. We do not sell data and do not share it with anyone else.
How long we keep it
- Task journals and backups: for the retention window of the plan active when the task was created (Free: 30 days, Basic: 60 days, Professional: 90 days, Advanced: 180 days, Enterprise: 365 days). The window is fixed at creation; a plan change never shortens it. Expired journals are deleted by a nightly job.
- After you uninstall: journals and backups are kept 30 days so you can still revert past tasks if you reinstall, then deleted by the nightly job.
- Shopify data-erasure requests: Shopify sends a
shop/redactrequest 48 hours after an uninstall. It confirms the deletion above: everything except the billing ledger and the audit log is deleted within the 30 days Shopify allows, and never later than 30 days after the uninstall.customers/redactanonymizes any journal row about that customer and about the orders Shopify lists in the request, and deletes the customer and order export files of the store;customers/data_requestis shown to the store owner in Volver's Settings, under Customer data requests, with the journal rows that mention the customer ready to download and send to them; a copy is emailed to the store owner when email delivery is enabled. - Billing ledger and audit log: kept as evidence of what was charged and when.
Your rights and controls
From Settings inside the app you can export everything Volver holds about your store (JSON) and delete all of it at any time. You can change or cancel your plan from Plans & Pricing; every change is listed there, with its date and time, in the subscription history. Under the GDPR and similar laws you may also ask us for access, rectification, erasure or portability of your data.
Security
All traffic is encrypted (TLS). Access to the Shopify admin is authenticated with Shopify session tokens. Access tokens are stored server-side; merchant secrets are encrypted at rest (AES-256-GCM). Every write to your store is preceded by a saved copy of the previous value.
Changes
We will update this page and its date when the policy changes. Material changes are announced inside the app.
Contact
Write to contact@swicelso.com.