Bulkroom

Privacy Policy

Last updated 5 August 2026

Bulkroom is a wholesale and B2B portal for OpoShop stores, published by Found. This policy explains exactly what the app stores, why, and what it deliberately does not touch.

The short version. Bulkroom stores the wholesale relationship — trade accounts, price lists and quotes — for each store that installs it. It never sees or stores a card number, never sells or shares data, and never mixes one store's data with another's.

1. Merchant store data

When a merchant installs Bulkroom, OpoShop's OAuth flow grants the app an access token scoped to that one store. We use it only to:

The token is stored encrypted-at-rest in our database and never exposed to a browser, a buyer, or any third party. Uninstalling the app immediately closes the buyer portal and disables the storefront link.

2. Wholesale buyer data

A buyer who applies for a trade account provides their email, company name, and (if the merchant asks for them) contact name, phone, website and a tax or resale ID, plus anything they type in the notes field. We also store the delivery address they enter, their quotes, and the messages on those quote threads.

This information belongs to the merchant. It is visible only to that merchant and to the buyer themselves. Buyers sign in with a one-click email link — Bulkroom never asks for or stores a password for a wholesale buyer.

3. What we never collect

4. Isolation between stores

Every record — trade account, price list, quote, message, setting — is scoped to a single store and every query filters on it. If one owner installs Bulkroom on two stores, those stores get entirely separate data and neither can read the other. A boot-time audit re-verifies this on every deploy.

5. Analytics

We use PostHog for product analytics to understand which features get used. Events record actions (for example "a quote was sent"), never personal data: no buyer names, no emails, no addresses, no order contents.

6. Sub-processors

7. Retention

Data is retained while the app is installed. Uninstalling closes the portal immediately and we keep the records so a merchant who reinstalls doesn't lose their trade accounts, price lists and quote history. A merchant may ask for complete deletion at any time by emailing brandon@tryfound.io, and we will erase everything for that store within 30 days.

8. Your rights

Merchants and wholesale buyers can request access to, correction of, or deletion of their data. Buyers should contact the merchant they applied to in the first instance, since the data belongs to that merchant; we will action any verified request directly if that isn't possible.

9. Security

All traffic is HTTPS. Sessions are signed tokens with a limited lifetime. Public endpoints are rate-limited. Application and sign-in endpoints deliberately return identical responses whether or not an account exists, so they cannot be used to enumerate a merchant's stockists. See our security page for more.

10. Changes

We'll update this page and the date at the top if this policy changes. Material changes will be announced in the app's What's New page.

11. Contact

Found — brandon@tryfound.io