Tikra legal texts

Tikra Privacy Policy

Version 2026-10-06-pilotb. Last updated 6 October 2026.

Earlier versions of this text carried a version name and a date later than the day we published them. Since 2 October 2026 both are the day of publication, and the page of each earlier version shows the day it was last updated.

1. Who we are

Tikra is provided by EURUVIZIJA, MB, a small partnership (mažoji bendrija) registered in the Republic of Lithuania, company code 307863521, registered office V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania ("we", "us").

Contact for privacy questions: privacy@tikratracking.com, EURUVIZIJA, MB, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania.

We have assessed whether Article 37 of the GDPR requires us to appoint a data protection officer. At our current size it does not. We review this assessment every year, and before we take on stores that significantly increase the number of shoppers whose orders we process. If we appoint one, we will publish the contact details here. Until then, privacy questions go to the contact above.

We prepared this version with AI tools and public legal sources. A lawyer has not reviewed it.

2. Summary

3. Shoppers: data we process for stores

3.1. If you bought from a store that uses Tikra, or visited it, the store decides how your data is used. Please read the store's privacy notice and send your requests to the store. If you contact us, we pass your request to the store.

3.2. What we process for the store, in short:

For an order paid while the store is on our free diagnosis (a Shopify store without a plan), we keep much less: only its ID and number, the payment time, the amounts, whether it is a test order, whether your country is in the EEA, the United Kingdom or Switzerland, and your consent choices, linked to the order by the checkout reference. We keep none of the other data in this list (our pixel still keeps the ad click IDs in your own browser with your marketing consent, section 14, and our server discards the identifiers it sends), send nothing to any platform, and delete these records 30 days after payment. Before a store accepts our Terms and Data Processing Agreement, we keep nothing of its orders or store events at all.

For an order that was not placed online (for example a sale at a point of sale, or a draft order marked as paid), we keep only its ID and number, the payment time, the amounts, whether it is a test order and where it came from; for a WooCommerce store also the hashed order key, used only so that an erasure or access request reaches it. We keep none of the other data in this list for it, and we send it to no platform.

3.3. We send this data only to the platforms the store connected, and only when your consent choices allow it. The platforms the Service can send to are Meta, Google Analytics 4, Google Ads, TikTok, Pinterest and Snapchat; a store connects only the ones its dashboard offers and it chooses. Store events go only to a platform that gets them (the store's terms with us, section 3.8, set the conditions) and only the events the store turned on for it. If the country of your order address is in the EEA, the United Kingdom or Switzerland, we send your order to advertising and e-mail marketing platforms only if you gave marketing consent, and to Google Analytics only if you gave analytics consent. Outside these countries, a store may choose a mode in which we send your order unless you refused: then your order is also sent when you made no choice. We never send an order to a platform whose category you refused. If you opted out of the sale or sharing of your data through the store's Shopify privacy settings, we do not send your order or your store events to advertising or e-mail marketing platforms. Store events are sent only with marketing consent, wherever you are. Our WooCommerce plugin does not read opt-outs of the sale or sharing of data. Google Analytics never gets your contact details, your full IP address or your user agent. Where the store's agreement with us provides for it, it gets your IP address shortened to its first three parts (for an IPv6 address, its first 48 bits) and the type of your device, its operating system and your browser, so that it can show roughly where and on what kind of device you bought.

3.4. The complete list of data, recipients and retention periods is in Annex 1 of our Data Processing Agreement at https://tikratracking.com/legal/dpa.

4. Data we access in a Shopify store

When a merchant installs our Shopify app, it asks for these permissions:

PermissionWhat we use it for
read_ordersTo receive each paid order (webhook orders/paid), its refunds (refunds/create) and cancellations (orders/cancelled), and to read recent orders every hour, so no order is missed. Where the store turns on customer type for a platform, we also read the order's number in the customer's order history from Shopify's customer journey summary. Orders include the customer's name, e-mail, phone and addresses where Shopify has approved our access to protected customer data.
write_pixelsTo add our web pixel to the store's storefront and checkout.
read_customer_eventsTo let our pixel receive the store's customer events: the checkout completion event, which carries the checkout token we use to link the order with the shopper's consent choices and advertising identifiers, and the store events of section 3.2.
read_productsTo read the product and variant IDs of the items in an order when the order data we receive does not carry them, so that a platform gets the product IDs with the purchase. No customer data.
read_privacy_settingsTo read the store's customer privacy settings (in which countries Shopify asks shoppers for consent), so that we can warn the store when consent is not asked for in the EEA, the United Kingdom or Switzerland. No customer data.

Shopify also lets our pixel read the e-mail address and phone number a shopper types at checkout, because we selected these fields as protected customer data. They are hashed on our server as soon as they arrive and sent only to the platforms the store connects, to match checkout events.

We also read the store's time zone and currency, and the currency Shopify bills the store in (shopBillingPreferences), so prices are shown in the currency of the charge; the shop owner's name and e-mail address (Shopify's shopOwnerName and email), to send service and incident notices and, on the free diagnosis, updates about it (section 7); the number of the store's paid orders in the 30 days before installation (for a store that started on the free diagnosis, before its first plan), for the before-and-after report; the store's subscription status for our app; if a guarantee credit is due, the app credits Shopify holds for our app; and, once the store allows our app to read them, the store's customer privacy settings (in which countries Shopify asks shoppers for consent) and the country of the store's address, to warn the store when consent is not asked for in the EEA, the United Kingdom or Switzerland.

For the free diagnosis we also read, with the same read_orders permission, the number of paid orders of the last 7 days, the number of orders per day that were not cancelled (to compare with what Meta counted), the total of the paid orders, and for the newest 250 of them Shopify's customer journey: the landing pages of the shopper's first and last visit before the order. We look only at whether a landing page carries an advertising click parameter (Meta fbclid, Google gclid, gbraid or wbraid, TikTok ttclid) and keep only the counts. The landing page addresses themselves, and any click ID or other value in them, are never stored, logged or passed on. We do this for the store, as its processor, under our Data Processing Agreement. The addresses are read only in memory while the diagnosis runs.

We receive Shopify's privacy notifications: customer data requests, customer erasure requests and store erasure requests. Section 9 of our Data Processing Agreement explains what we do with them.

Once a day, for a store with a running plan and Meta connected, we also read the store's public home page to find the pixel of its Facebook & Instagram app, and the names of the store's Meta pixels with the saved key, to check that orders go to the right pixel (the Meta pixel notice, Terms section 8.12). We keep only the pixel IDs, names and result of the last two checks, for 4 days. This reads no customer data.

5. Merchants and their staff: data we control

CategoryDataSource
Store and accountStore domain, store platform, plan, subscription status, time zone, currency, consent mode, settings, installation and uninstallation datesShopify or you
Acceptance of our termsWhich version of the Terms and the Data Processing Agreement was accepted, when, for which store and by which user (Shopify staff user ID or login e-mail address; for an order form, the name or e-mail address of the person who signed it and the order form's reference); no IP addressYou, our systems
Staff and loginsFor Shopify stores: the Shopify staff user ID from the session token when a staff member changes settings. For other stores: login e-mail address and role, sign-in link and session records (stored as hashes), rate-limit records (stored as keyed hashes of the e-mail address and IP address). For Shopify stores, when you connect Google Ads from the Shopify admin, we ask Shopify which staff member is signed in; Shopify's answer includes a name, an e-mail address and a short-lived access token. We compare only the staff ID with the ID of the person who clicked, and keep nothing else; the short-lived token is dropped at onceShopify or you
API tokensWhen a store makes a read-only API token: its label, a hash of the token, who made it and when it was last used.You
Notification contactsShopify stores: the shop owner's name and e-mail address from Shopify. Other addresses you give us. For each address, whether it receives incident e-mails and whether it receives updates about the free diagnosis and our plans. A log of the notices we sent (recipient, subject, content, delivery result).Shopify, you, our systems
Platform accessAccess keys, account IDs and connection settings for the platforms you connect, stored encrypted with your store's own key. When you connect Meta with your Meta login (Connect with Meta): the access token Meta issues to us for your business, your Meta business ID, the pixel you chose, and the list of pixels with their names that you gave us access to (kept only until you choose one; unusable after 1 hour and deleted within 2 hours); and a keyed hash of the ID Meta gives this connection, so that we can act on Meta's notices about it. We receive nothing else about you from Meta: not your name, e-mail address or Facebook profile. When you connect Google Ads with your Google account (Connect with Google): a refresh token that Google issues to us for the Data Manager API, and the Google Ads account ID, the manager account ID (if you have one) and the conversion action ID that you enter; the token and the IDs are stored encrypted with your store's own key. We ask Google for this one permission only and receive no name, e-mail address or other data about your Google account (section 5C).You; Meta, when you connect with your Meta login; Google, when you connect with your Google account
Activity and security recordsAudit log of settings changes, replays, admin actions, sign-ins, installs, uninstalls, shared diagnosis links made or turned off, privacy requests, changes approved in the support chat, and billing actions, with the user who acted (login e-mail address or Shopify staff user ID) and the IP address of the request where there is oneOur systems
BillingThrough Shopify: plan, amounts, subscription and credit IDs and status. Through Stripe: your billing name, address, VAT number, e-mail and payment method are collected and held by Stripe; we store your Stripe customer ID, subscription ID and status. For a plan by agreement: the order form and our invoices.Shopify, Stripe, you
CommunicationsMessages you send us, and the e-mails we send you (sign-in links, service and incident notices, reports)You, our systems
Support chatYour messages in the support chat, with e-mail addresses, phone numbers and card numbers masked before they are stored; the assistant's replies; a short summary of each conversation (the issue, what was checked, the outcome and open items, without names or contact data); support tickets when a conversation is handed to a person. If you type details about your customers, we process them for your store as its processor (Data Processing Agreement, section 6.2 and Annex 1); please do not type them.You, our systems
Product analyticsA record of the steps each store takes in our service (installed, accepted our terms, connected a platform, started or changed a plan, finished the setup questions, uninstalled or reinstalled), with the date, a coarse install source (the App Store, an advertisement, a partner with the partner's code, or a direct link) and the plan name. The store appears only as a code made with a secret key; no store name, domain, person's name, e-mail address or IP address.Our systems
Shared diagnosis linksWhen you share the free diagnosis: a hash of the link, the snapshot it shows (order counts, findings, the 7-day period, your store's domain and time zone), who made it (login e-mail address or Shopify staff user ID), and when it was made, expires and was turned off.Our systems
App review test ordersTest orders placed on Shopify development stores that connected one of our own test accounts, for example during Shopify's review of our app: the order data typed into the test checkout, hashed as for any order, reaches our own Google Analytics 4 property and Meta test pixel. We use it only to show that sending works and delete it where the platform allows.Shopify development stores
Operational alertsInternal alerts about your store and its deliveries. Our admin tools show them with the store's domain. The alerts that reach our on-call person name the store only by a reference code (section 8).Our systems

5A. Business contacts and prospects

If you work for a business that may use Tikra, such as an online store or a marketing agency, or if you were our client before, we may send you e-mails about Tikra.

ItemDetails
DataYour name, work e-mail address, company, role and website, our earlier messages and work with you, and whether you asked us to stop
SourceYou, your company's public website or public business listings, or our earlier work together
PurposeTelling businesses about Tikra and answering their replies
Legal basisOur legitimate interest in offering our services to businesses (Art. 6(1)(f) and Recital 47 GDPR). For e-mail we follow Article 81 of the Lithuanian Law on Electronic Communications: without consent we write only to addresses of companies and other legal entities, and to our existing clients about similar services where we gave them the choice to refuse when we collected their address. We write to anyone else only with consent, and also where the law of your country requires consent.
RecipientsCloudflare, which hosts our systems, and the provider that sends our e-mail
RetentionUntil you ask us to stop, and no longer than 24 months after our last contact with you. If you ask us to stop, we keep your e-mail address on a do-not-contact list, only so that we do not write to you again.

You can object at any time, free of charge and without giving a reason. Every such e-mail has a link that stops them. Replying "stop" works too. We never use e-mail addresses we receive from Shopify for these e-mails.

5B. The support assistant

The support chat in the dashboard is answered by an AI system. The chat says so at the start of every conversation, and you can ask for a person at any time. To answer you it reads your store's state in the Service: your settings, connected platforms, delivery counts, incidents, diagnosis, health checks, plan and store event counts, and the delivery state of an order whose number you give; never data that describes your customers, unless you type it into the chat (section 5). The assistant is switched on for a store only after the store accepts a Data Processing Agreement version that describes it (DPA section 19.3). Its replies are checked by rules and by a second AI check before you see them. A change to your settings or a repair (for example sending failed orders again) happens only when an owner or admin approves it on a card in the chat; we record who approved it and when. The assistant does not take decisions about you on its own.

Your messages and the store facts the assistant reads are processed by Anthropic Ireland, Limited, with its affiliate Anthropic, PBC in the United States, as our processor. Anthropic may not train its models on this data. It deletes the inputs and outputs from its systems within 30 days, unless it has to keep them to enforce its usage policy (inputs and outputs up to 2 years, its trust and safety classification scores up to 7 years) or by law. The transfer to the United States is covered by the EU Standard Contractual Clauses in Anthropic's Data Processing Addendum.

5C. Google user data

This section applies when you connect Google Ads with your Google account (Connect with Google). It describes how Tikra accesses, uses, stores and shares data it receives from Google.

What we ask for and receive. We ask Google for one permission only: the Data Manager API (https://www.googleapis.com/auth/datamanager), which lets us send conversions to your Google Ads account. We do not ask for your name, e-mail address or profile. What we receive is a refresh token, from which we obtain the short-lived access tokens each send needs. Google's Data Manager API cannot list your Google Ads accounts, so you enter your Google Ads account ID, the manager account ID if you have one, and the conversion action ID yourself.

What we use it for. Only to send the paid orders of your store to the Google Ads account and conversion action you entered, as conversions, with the data that Annex 1, section F.2 of our Data Processing Agreement lists for Google Ads; and to check that the connection works, with a test request that Google validates and does not record as a conversion, when you connect and once an hour. We do not create, change or pause ads, audiences or campaigns, and we do not read your Google Ads data.

How we store it. The token, with the account ID, the manager account ID and the conversion action ID, is stored encrypted with your store's own key. Our dashboard and admin tools never show it; only the service decrypts it, to send your orders. A token from a connection attempt that fails is not stored.

Who receives it. We do not sell it and we do not pass it to anyone, except as needed to run this connection (our hosting provider, Cloudflare, stores it encrypted; section 8), to comply with the law, or, with your explicit prior consent, as part of a merger, acquisition or sale of assets of our business. We do not use it for advertising. People at Tikra read it only with your express agreement, for security purposes or to comply with the law. The orders we send to Google Ads are your store's data, sent on your instruction; Google Ads receives them as the platform you chose, not as our processor (sections 8 and 9).

Disconnecting and deletion. When you disconnect Google Ads in the dashboard, or your store's records are deleted after you uninstall the app, we ask Google to revoke the token and delete our copy. If Google cannot be reached we still delete our copy, and you can remove Tikra yourself in your Google Account under Third-party apps and services (https://myaccount.google.com/permissions). If you remove our access there first, the token stops working at once; we then hold your orders for Google Ads until you connect again, and we delete the token when you disconnect or uninstall.

Tikra's use of information received from Google APIs will adhere to [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

6. Visitors to our website

When you visit tikratracking.com (including the legal pages) or the status page and the sign-in pages at app.tikratracking.com, Cloudflare, our hosting provider, processes your IP address and browser details to deliver and secure the pages. We keep no request logs of these visits: our logs record only our service's own error and job lines, without IP addresses or browser details, for 7 days. Legal basis: our legitimate interest in operating and securing the site (Art. 6(1)(f) GDPR).

We set only the cookies the Service needs:

CookiePurposeLifetime
__Host-trk_sessionKeeps a user signed in to the web dashboard. Set only when you sign in.30 days, or until you sign out
__Host-trk_oauthLinks your browser to a Shopify installation you started, to protect that step10 minutes
__Host-trk_gbindLinks your browser to a Connect with Google step you started, in the web dashboard or in the window Connect with Google opens from the Shopify admin, to protect that step. Set only when you connect Google Ads25 minutes
trk_home_banner_dismissedBrowser storage (local storage) on the dashboard: remembers that you closed a notice on Home7 days

These are strictly necessary for the service you asked for, so they need no consent (Article 5(3) of the ePrivacy Directive as implemented in the Lithuanian Law on Electronic Communications).

Inside the Shopify admin, our app uses Shopify's session tokens instead of these cookies, except __Host-trk_gbind in the window Connect with Google opens. We use no analytics or advertising cookies, and no other technology that reads information from your device for analytics or advertising.

When you open a shared diagnosis link that a store gave you, the page sets no cookies. We keep a keyed hash of your IP address for about a day, to limit how often the page can be opened.

PurposeLegal basis
Providing the Service: running your account, sending your orders to your platforms, monitoring, the service guarantee, support, including the support assistant (section 5B)Performance of our contract with you (Art. 6(1)(b) GDPR). For staff of a company that is our customer: our legitimate interest in providing the Service to their employer (Art. 6(1)(f)).
Recording the acceptance of our Terms and Data Processing AgreementPerformance of our contract with you, and our legal obligation to have a written processing agreement (Art. 6(1)(b) and (c), Art. 28(9) GDPR)
Billing, accounting and tax recordsLegal obligation (Art. 6(1)(c)) under Lithuanian accounting and tax law
Security of the Service, audit logs, abuse and fraud preventionLegitimate interest in keeping the Service and our customers' data secure (Art. 6(1)(f))
Service messages: incidents, guarantee credits, changes to the Service or to our terms and a weekly report about your store's tracking while your store is on a plan and you keep the report on (orders sent to each platform, orders skipped and why, incidents, how many orders carried each advertising identifier; it contains no offers, and you can stop it from any report with one click)Performance of contract, and legitimate interest (Art. 6(1)(b) and (f))
Offers for our plans and updates on your free diagnosis: the 12-hour offer e-mail and the weekly summary, sent only while your store is on the free diagnosisYour consent (Art. 6(1)(a) GDPR and Art. 81 of the Lithuanian Law on Electronic Communications), given by the holder of the address by ticking an unticked box in the app. You can withdraw it at any time: every such e-mail has a link that stops them with one click, and mail apps that show an unsubscribe button stop them with that button. Service and incident e-mails are not affected.
Product analytics: which steps stores complete and which listing sources bring installs (section 5); not used for advertising and not sharedLegitimate interest in improving the Service (Art. 6(1)(f))
Improving the Service, using operating data without personal data where possibleLegitimate interest (Art. 6(1)(f))

You need to give us a working contact e-mail address, and for stores outside Shopify your billing details, to use the Service. Without them we cannot provide or bill the Service. Shopify gives us the shop owner's name and e-mail address when the app is installed. The rest of the data is created as you use the Service.

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

8. Who receives merchant data

9. International transfers

Cloudflare, Google, Stripe, Resend and Anthropic may process data outside the EEA, including in the United States. Where they do, the transfer is covered by the EU-U.S. Data Privacy Framework certification of the provider or by the EU Standard Contractual Clauses (for Anthropic, the Standard Contractual Clauses in its Data Processing Addendum). You can ask us for a copy of the clauses at privacy@tikratracking.com.

Pushover processes our urgent alerts in the United States and offers no data processing terms. These alerts carry no customer data and never a store's name, domain or e-mail address. They name a store only by a reference code made with a key that only we hold, and every alert text passes a filter that replaces store identifiers and the domain names and e-mail addresses it recognises before it is sent (section 8).

Telegram stores our alerts in the Netherlands; Healthchecks.io processes the pings in the EU.

What we send to the platforms you connect (Meta, Google Analytics 4, Google Ads, TikTok, Pinterest and Snapchat) goes on your instruction. Each platform may process it outside the EEA under its own terms with you, not under ours.

10. How long we keep merchant data

DataRetention
Store, account and settings dataWhile you use the Service. Deleted when you uninstall the Shopify app (an interrupted deletion is finished within the hour). For other stores, deleted within 30 days after your subscription ends.
Record of the acceptance of our termsWhile the store's other records are kept, and in the audit log for 24 months after uninstall (version, time and user)
Platform access keysDeleted when you disconnect the platform, when you uninstall the Shopify app, or, for other stores, within 30 days after your subscription ends. An access token Meta issued through Connect with Meta, with the Meta IDs we keep for it, is also deleted at once when Meta sends us a data deletion request for it. After you disconnect a Meta connection made with Connect with Meta, we keep your Meta business ID and the keyed hashes (never the token), so the Meta card can link to Connected apps in your Meta business and we can act on Meta's notices about it. Connecting with Connect with Meta again replaces them. They are deleted when Meta tells us that access was removed or sends a data deletion request, or with your store's other records (at uninstall, or for other stores within 30 days after your subscription ends). A refresh token that Google issued through Connect with Google is deleted when you disconnect Google Ads and when your store's records are deleted after you uninstall the app; at both times we ask Google to revoke it, and we delete our copy even if Google cannot be reached.
Pixel list from Connect with MetaUntil you choose a pixel; unusable after 1 hour and deleted within 2 hours
Notification contactsWhile you use the Service. A shop owner address that changes in Shopify is replaced at our next weekly check. Deleted with the store's other records when you uninstall the app.
Log of notices we sent90 days, or sooner when the store's records are deleted after uninstall. A notice about an incident is kept while the incident is open and for 90 days after it closes. A notice about a platform key problem is kept while the problem lasts, so the same notice is not sent twice. Daily digests and system alerts that are not linked to a store: 30 days.
Audit log24 months, also after you uninstall the app. After an uninstall we keep only the audit log entries about the store (who acted, what and when; no customer data) and the records of privacy requests we handled (type, dates and counts; 24 months after the request was closed), as evidence that we met our obligations, and the product analytics record under the store's code until it is turned into totals (within 30 days, see the row below).
Sign-in linksValid for 15 minutes, single use, deleted within about a day after they expire
Login sessionsEnd after 30 days, or at once when you log out or the user is removed
API tokensUntil the store revokes the token. Deleted with the store's records.
Rate-limit recordsAbout a day
Error logs of our service (no IP addresses or browser details)7 days
Product analytics records (section 5)While the app is installed. Within 30 days after uninstall, the store's records are turned into monthly totals without any store code, and deleted. The totals are kept 36 months.
Shared diagnosis links (section 5)7 days after the link ends (30 days after it was made, or when it is turned off or replaced by a new link). Deleted at once when you uninstall.
Billing recordsInvoices, payment records and other accounting documents: 10 years. Our contract with you (the order or plan record and invoices): 10 years after the contract ends. These are the minimum periods of the Lithuanian Internal Administration Documents Retention Index (items 3.15, 3.19 and 3.24). The Stripe and Shopify IDs and statuses we keep in the Service, and the Service's own billing rows (charges for extra orders, guarantee credits, monthly order counts and the invoice lines of a plan by agreement), are deleted with your store's other records; the audit log keeps the entries about each charge and credit for 24 months.
Support chat conversations30 days after the conversation ends (when you close it, or after 24 hours without a message). If it was handed to a person: 90 days after the last ticket closes. You can delete a conversation in the chat. We keep them to answer you, to continue an open case and to show what was said if there is a question about a change made in the chat. Deleted with the store's other records at uninstall.
Support chat summaries90 days. The store owner can clear them in the chat (Forget). Deleted with the store's other records at uninstall.
Support e-mails3 years after the conversation ends. If a dispute needs them, we keep them until it is settled.
Encrypted database backups20 days
Restore journal (records of erasures, uninstalls and reinstalls, disconnected platforms and Meta access deleted on Meta's request, with their emptied encrypted settings, consent mode changes and removed logins, applied again if a backup is ever restored; a removed login only as the SHA-256 hash of its e-mail address)28 days
Our database provider's point-in-time history30 days; it cannot be shortened. Every copy of deleted data, including the data of a store that uninstalled the app, is gone within 30 days after the deletion.

11. Your rights

Your right to object. Where we rely on our legitimate interests (section 7), you can object at any time for reasons related to your situation. We then stop, unless we have compelling legitimate grounds or need the data for legal claims. You can object to direct marketing at any time, without giving a reason, and we then stop.

Under the GDPR (and the UK GDPR for people in the United Kingdom) you also have the right to:

To use these rights, write to privacy@tikratracking.com. We answer within one month. We may extend this by two further months for complex requests and will tell you why.

If you connected Meta with your Meta login, you can also remove our access in Meta: in your business settings, open Integrations, then Connected apps, and remove Tikra. When Meta tells us that access was removed, we treat the saved key like any key that stops working: your orders for Meta are held until the key works again or you connect again. When Meta sends us a data deletion request, we delete the access token and the Meta IDs we kept for it at once, and Meta shows you a link where you can check that the request was done.

If you connected Google Ads with your Google account, you can also remove our access in Google: in your Google Account, open Third-party apps and services (https://myaccount.google.com/permissions) and remove Tikra. The token then stops working at once, and your orders for Google Ads are held until you connect again.

12. Complaints

You may complain to the Lithuanian supervisory authority:

Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate)
L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
E-mail: ada@ada.lt
Telephone: +370 5 271 2804
Website: https://vdai.lrv.lt

You may also complain to the supervisory authority where you live or work, or where you think the infringement took place. We would like to hear from you first, so we can try to solve the problem.

13. Security

We protect data with encryption in transit and at rest, a separate encryption key for each store, hashing of shoppers' contact details, admin tools that require both a secret key and a separate login through Cloudflare Access, an audit log and a written incident response plan. If a personal data breach affects your data, we inform you as the law and our Data Processing Agreement require.

On Shopify stores our web pixel sets no cookies. Shopify tells the pixel what the shopper allowed. Where a store's Shopify privacy settings do not ask for consent in the shopper's region, Shopify reports the choice as allowed and the pixel works as if the shopper had consented. The store is responsible for asking where the law requires it. With the shopper's consent it reads existing cookies: _fbp, _fbc, _gcl_aw, _ttp, _epik and _scid with marketing consent, and _ga and _ga_<property> with analytics consent (to find the _ga_<property> cookies it reads the browser's cookie string and uses nothing else from it). When Shopify does not report both marketing and analytics consent as given, the pixel also reads the consent record that Shopify keeps in the shopper's browser, to learn the shopper's choice; it never changes it. With marketing consent it keeps these items in the browser's storage:

KeyBrowser storagePurposeHow long it is usedCategory
tikra_clicksLocal storageKeeps the ID of the ad the shopper clicked, so that a later purchase can be reported to that advertising platform90 days from the click; an older click is ignoredMarketing
tikra_fbpLocal storageA browser ID in Meta's format, made only when the store has no Meta _fbp cookie, so that the shopper's store events and purchase can be matched in Meta90 days from its creation; then a new one is madeMarketing
tikra_icLocal storageRemembers, without the checkout token itself, that a checkout was already reported, so that it is reported once24 hours per entryMarketing

Browser storage has no expiry of its own: the pixel ignores an entry past its time and removes or replaces it the next time it reads that key (tikra_clicks at the next ad click, at checkout, and on every page of a store that gets store events; tikra_fbp when it needs a browser ID, otherwise it stays until the pixel deletes it (below); tikra_ic at the next checkout step). It deletes all three when the shopper refuses marketing and when a page opens without marketing consent (for example after a Global Privacy Control opt-out), except where the store asks for consent, the shopper has not answered and the pixel can read the consent record when the page opens: then it neither reads nor deletes them. On a store's free diagnosis the pixel keeps tikra_clicks and reads the cookies above in the same way; our server then keeps only the shopper's consent decision.

On WooCommerce stores our plugin sets first-party cookies on your domain. _tikra_gclid, _tikra_gbraid, _tikra_wbraid, _tikra_ttclid, _tikra_epik, _tikra_sccid and _tikra_fbc hold the advertising click ID from the landing page for 90 days. They are set with marketing consent and, in standard mode on stores without a supported consent tool, only for visitors our plugin has found to be outside the EEA, the United Kingdom and Switzerland. _tikra_consent keeps a copy of the consent tool's choices for 180 days. With the matching consent the plugin also reads _fbp, _fbc, _gcl_aw, _epik, _ga and _ga_<stream>. Section I of Annex 1 to our Data Processing Agreement has the details.

Describe this in your cookie notice under the purposes your consent banner uses.

15. Children

The Service is for businesses. It is not directed at children, and we do not knowingly process children's data as a controller.

16. Changes

We may update this policy. We tell merchants about material changes by e-mail and in the dashboard before they apply. The version and date at the top show the latest version. Earlier versions stay readable at https://tikratracking.com/legal/privacy followed by a slash and the version name.

17. Notice for residents of US states

Shoppers: we process your data for the store, on its instructions. To use your rights, including the right to opt out of the sale or sharing of your data or of targeted advertising, use the store's privacy settings or contact the store. When you opt out through a Shopify store's privacy settings, we stop sending your orders and store events to advertising and e-mail marketing platforms (section 3.3).

Merchants and their staff: in the last 12 months we collected the categories of data in section 5: identifiers (such as name, e-mail address, IP address and account IDs), commercial information (plan and billing records), internet activity (sign-in and audit records) and professional information (your store and role). We collected them from the sources in section 5, used them for the purposes in section 7, and disclosed them for those purposes to the recipients in section 8. We do not sell or share this data, as the California Consumer Privacy Act defines those words, and we did not do so in the last 12 months. We use sensitive data, such as the access keys to your platform accounts, only to provide the Service. We keep the data for the periods in section 10.

You may ask to know, correct or delete your data. Write to privacy@tikratracking.com from the e-mail address on your account, or through an authorised agent with your signed permission. We check that the request comes from you before we act on it. We will not treat you differently for using these rights.

MB Euruvizija, company code 307863521, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania. support@tikratracking.com