Privacy Policy
Last updated: 23 August 2026
Bulkdozer (“we”, “us”) is a tool for bulk-editing invoices and bills in Xero. This policy explains, in plain English, exactly what we handle, why we handle it, where it sits, and what you can make us do about it. Bulkdozer is operated by 3D Partners Network Ltd, a company registered in England and Wales (company number 14497325), whose registered office is at Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA. We are the data controller for the purposes of UK data protection law. Questions, or want to exercise any right below? Email adam@bulkdozer.app.
The short version
We do not store your invoices or bills. They are fetched from Xero, held in your browser while you work, and written back only when you press Apply. Nothing about them is saved on our servers. What we do keep is your account details, your encrypted Xero connection, and your column layout. We never sell your data, never use it for advertising, and never use it to train AI models.
What we access from Xero
When you connect an organisation you authorise Bulkdozer through Xero’s own secure sign-in (OAuth 2.0). We never see or ask for your Xero password. The permissions we request are:
- Your identity (openid, profile, email), so you can sign in with Xero instead of creating another password.
- Staying connected(offline_access), so you don’t have to reconnect on every visit. Xero requires this of certified apps.
- Invoices and bills (accounting.invoices), to read them into the editor and write back the edits you apply.
- Payments (accounting.payments), needed to void an invoice that has already been paid, because Xero will not void a paid invoice until its payment is removed.
- Contacts, read only (accounting.contacts.read), to fill the contact picker and filter. We never create or change a contact.
- Settings, read only (accounting.settings.read), used for a single call that lists which currencies your organisation uses.
Two of these are deliberately the read-only versions. We ask for nothing beyond this list.
What we store, and why
- Your account. The name, email address and profile picture link that Xero gives us when you sign in. This is how we know who you are between visits.
- Your Xero connection tokens. The access and refresh tokens that let us talk to Xero on your behalf. These are encrypted by our app (AES-256-GCM) before they are written to the database: never stored in plain text, and never sent to your browser.
- Which organisations you have connected. For each one, its Xero identifier, its name and its type, so we can list them and let you switch between them.
- Your sign-in session. A random session token, so you stay signed in.
- Your editor layout. The order and width of your columns, which are hidden, and your row height, so the grid looks the same on your next visit and on your other devices.
What we do not store
Your invoices and bills are never saved on our servers. When you open the editor we fetch them from Xero, send them to your browser, and hold them only in that browser tab while you work. When you press Apply we send your changes to Xero. We do not keep a copy of the records, the amounts, the invoice numbers, the contact names, or anything else from your books.
We also hold no password of yours, because Bulkdozer has none. Xero is the only way in.
There is an unfinished feature that would keep a “before” copy of edited records so a mistake could be undone. It is switched off, it writes nothing, and its table is empty. If we ever turn it on it will be something you opt into, and we will update this policy first.
Why we are allowed to hold it (legal basis)
Under UK GDPR we rely on two bases, and nothing else:
- Performing our contract with you. Your account, your Xero connection, your session and your saved layout all exist because without them the service you asked for cannot work.
- Our legitimate interests. Product analytics (described below, and stripped of anything identifying), keeping the service secure, and answering the feedback you send us. We have kept these deliberately narrow so they do not override your privacy.
Product analytics
We measure how the app is used so we can improve it, and we do it without looking at your books. We use PostHog on its EU cloud.
We record which pages you visit, which features you use, and counts, such as how many rows you edited, how many records a search found, or how many contacts you ticked in a filter. We record the nameof the column you edited or filtered on, for example “reference” or “status”, and which tab you were on, invoices or bills.
We also record the choices you make from lists we put in front of you: which statuses you filtered by or changed a record to (such as “AUTHORISED” or “VOIDED”), and which currency codes you filtered by. These come from a fixed set of words that is the same for every customer, so they tell us which parts of the app are used without telling us anything about your business.
When you filter by date, we record the shapeof what you asked for and never the dates: how far back it reaches as a wide bucket (“this year”, “last year”, “two to five years” or “older”), how many days long the range is, and which month it ends in. That tells us whether people mostly tidy up the current year and whether December is a busy month for the app. No day is ever written down, so no date can be read back out of it.
We never record your keystrokes, anything you type into a filter or a cell, any amount, any invoice or bill number, any reference, any contact name, any date, or the names of your organisations. When we write down a reason Xero refused a change, every number is stripped out of it first, because Xero sometimes quotes your own figures back at us. Automatic click-and-text capture is off, session replay is off, heatmaps and surveys are off, and all text is masked. You are identified only by a random internal id, never by your name or email. Your IP address is not stored: PostHog reads a rough country from it and then discards it. Activity in the public demo on our home page is flagged as demo, so it is never mistaken for real work.
Feedback and email
If you use the feedback form, we email ourselves your message together with the name and email address on your account, so we know who to reply to. If you attach a screenshot, we receive that too, and a screenshot of the grid will contain whatever was on your screen, so please only attach what you’re happy for us to see. We also email ourselves a one-line alert with your name and email when a new account is created.
These emails are sent through Resend and land in a Google Workspace mailbox. They are not used for marketing and you will not be added to any list.
Who else handles it, and where it sits
To run the service we use a small number of providers. They act on our instructions only, and none of them is permitted to use your data for their own purposes.
- Xero: the source of the data, under the connection you authorised.
- Supabase: our database, hosted in London (eu-west-2). Everything listed under “What we store” lives here.
- Vercel: hosts and serves the application.
- PostHog: product analytics, on their EU cloud.
- Resend: sends the feedback and new-account emails, in the EU.
- Google (Workspace): the mailbox those emails arrive in.
Our database and our analytics are in the UK and the EU. Where any provider processes data outside the UK, that transfer is covered by the safeguards in that provider’s standard data processing terms.
We never sell it, and never train AI on it
We do not sell your data, share it with data brokers, or use it for advertising or profiling of any kind. We do not pass your Xero data to any other app.
We also do not use any data from Xero to train, fine-tune or improve artificial intelligence or machine learning models, and we never will. Xero’s developer terms forbid it, and we agree with them.
How long we keep it
- Your account, tokens, connections and layout: until you delete your account, at which point they are erased immediately. Deleting an organisation’s connection removes that connection straight away.
- Your sign-in session: until it expires or you sign out.
- Feedback emails: kept in our mailbox while they are useful for support. Ask us and we will delete yours.
- Analytics events: held by PostHog under their standard retention. They contain no name, email or IP address, only a random id.
Because we never store your invoices or bills, there is no retention period for them. There is nothing to retain.
Security
Your Xero tokens are encrypted by the app with AES-256-GCM before they are saved, using a key held only in our server environment, and they are never sent to your browser. All traffic is over HTTPS. Only your own signed-in account can act on the organisations you have connected. We do not use shared hosting.
No system is perfect. If we ever discover a breach affecting your data, we will tell you and the Information Commissioner’s Office as the law requires.
Cookies and local storage
We keep this to a minimum. There are two kinds:
- Essential. One cookie holds your sign-in session. A few short-lived cookies are also set during the trip to Xero and back, to keep that sign-in secure. Without these you cannot stay signed in.
- Analytics.PostHog stores your random analytics id in a cookie and in your browser’s local storage, so repeat visits can be counted as one person rather than several. It holds an id and nothing else.
We use no advertising cookies and no third-party tracking cookies. You can clear or block these in your browser; the analytics one can go without affecting the app.
Your rights
Under UK GDPR you can ask us to do any of the following, free of charge, and we will respond within one month:
- See it: get a copy of the personal data we hold about you.
- Correct it: have anything inaccurate fixed.
- Delete it: have it erased. You can also do this yourself, instantly, from the Organisations screen.
- Take it with you: receive it in a common, machine-readable format, or have it sent to someone else.
- Object, or ask us to pause: object to anything we do on the basis of legitimate interests, including analytics, or ask us to restrict our use of your data while a question is resolved.
To use any of these, email adam@bulkdozer.app. If you think we have got something wrong you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first so we can put it right.
Disconnecting and deleting your account
You are in charge, and both of these take effect immediately:
- Disconnect an organisation: go to the Organisations screen and press Disconnect. This revokes our access to that organisation at Xero, not just on our side, and removes our record of it.
- Delete your account: also on the Organisations screen. This revokes every Xero connection and permanently erases your account, your encrypted tokens, your session, your organisation list and your saved layout. It cannot be undone.
You can also remove Bulkdozer from inside Xero at any time, under Settings then Connected apps. Note that this stops our access but does not by itself delete the account details listed above. Use Delete account, or email us, for that.
Children
Bulkdozer is a business tool and is not intended for anyone under 16. We do not knowingly collect data about children.
Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects how we handle your data, we will tell you before it takes effect.