Tikra Privacy Policy
1. Who we are
Tikra is provided by MB Euruvizija, a small partnership (mažoji bendrija) registered in the Republic of Lithuania, company code 307863521, registered office V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania ("we", "us").
Contact for privacy questions: privacy@tikratracking.com, MB Euruvizija, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania.
We have assessed whether Article 37 of the GDPR requires us to appoint a data protection officer. At our current size it does not. We review this assessment every year, and before we take on stores that significantly increase the number of shoppers whose orders we process. If we appoint one, we will publish the contact details here. Until then, privacy questions go to the contact above.
This is the pilot version of this policy. A lawyer has not reviewed it yet.
2. Summary
- Tikra is a service for online stores. It sends each paid order of a store to the advertising and analytics platforms the store connects, after checking the shopper's consent choices, and shows the store what was sent. On Shopify stores it can also report the shopper's visits, product views, add to cart and checkout steps to those platforms, only when the shopper allows marketing.
- For the personal data of the store's customers and visitors (shoppers), the store is the controller and we are its processor. We process that data only on the store's instructions, under our Data Processing Agreement.
- For data about our business customers (merchants and agencies) and their staff, and about visitors to our website, we are the controller. This policy mainly covers that data.
- We do not sell personal data. We do not use shoppers' data for our own purposes.
3. Shoppers: data we process for stores
3.1. If you bought from a store that uses Tikra, or visited it, the store decides how your data is used. Please read the store's privacy notice and send your requests to the store. If you contact us, we pass your request to the store.
3.2. What we process for the store, in short:
- your e-mail address, phone number, name, city, region, postal code and customer ID, which we store only as SHA-256 hashes, apart from the postal code and country code in plain form (Google Ads requires them);
- your IP address, which we store only encrypted, and a shortened IP address from the order confirmation page; apart from this, our hosting provider's request logs hold the IP address of each request to our servers for 7 days;
- your browser's user agent;
- advertising click and cookie identifiers (for example Meta, Google, TikTok, Pinterest and Snapchat click IDs, and a browser ID in Meta's format that our pixel makes when the store has no Meta
_fbpcookie) and a hashed form of Shopify's browser ID if you allowed marketing, and Google Analytics identifiers if you allowed analytics. On WooCommerce stores that use standard mode, we also keep them when you gave no consent signal at all and your order country is outside the EEA, the United Kingdom and Switzerland; - your consent choices for that order;
- the order: order number, amounts, currency, products and time;
- for 30 days, a copy of the order without your name, contact details or addresses (order number, amounts, products and time), so that we can send it again if a platform missed it. Only if the store connected Klaviyo, which we no longer offer, the copy also holds your e-mail address, phone number and first name, encrypted, because Klaviyo cannot use hashed data;
- on Shopify stores, only if you allowed marketing and did not opt out of the sale or sharing of your data: the pages you view, the products you view and add to your cart, and when you start checkout and enter payment information ("store events"), with the products, prices and page addresses (without their query part), a hashed form of Shopify's browser ID and customer ID, your IP address and user agent, and at checkout your e-mail address and phone number, which we hash as soon as we receive them. We keep store events only as daily counts. What you type into the store's search box is never collected; and
- for the store's free diagnosis, the addresses of the pages where your visits before the order started, which Shopify keeps with the order. We read them only to count orders that came from an ad click, and we never store them.
For an order paid while the store is on our free diagnosis (a Shopify store without a plan), we keep much less: only its ID and number, the payment time, the amounts, whether it is a test order, whether your country is in the EEA, the United Kingdom or Switzerland, and your consent choices, linked to the order by the checkout reference. We keep none of the other data in this list (our pixel still keeps the ad click IDs in your own browser with your marketing consent, section 14, and our server discards the identifiers it sends), send nothing to any platform, and delete these records 30 days after payment. Before a store accepts our Terms and Data Processing Agreement, we keep nothing of its orders or store events at all.
3.3. We send this data only to the platforms the store connected, and only when your consent choices allow it. If the country of your order address is in the EEA, the United Kingdom or Switzerland, we send your order to advertising and e-mail marketing platforms only if you gave marketing consent, and to Google Analytics only if you gave analytics consent. If you opted out of the sale or sharing of your data through the store's Shopify privacy settings, we do not send your order or your store events to advertising or e-mail marketing platforms. Store events are sent only with marketing consent, wherever you are. Our WooCommerce plugin does not read opt-outs of the sale or sharing of data.
3.4. The complete list of data, recipients and retention periods is in Annex 1 of our Data Processing Agreement at https://tikratracking.com/legal/dpa.
4. Data we access in a Shopify store
When a merchant installs our Shopify app, it asks for these permissions:
| Permission | What we use it for |
|---|---|
read_orders | To receive each paid order (webhook orders/paid) and to read recent orders every hour, so no order is missed. Orders include the customer's name, e-mail, phone and addresses where Shopify has approved our access to protected customer data. |
write_pixels | To add our web pixel to the store's storefront and checkout. |
read_customer_events | To let our pixel receive the store's customer events: the checkout completion event, which carries the checkout token we use to link the order with the shopper's consent choices and advertising identifiers, and the store events of section 3.2. |
read_products | To read the product and variant IDs of the items in an order when the order data we receive does not carry them, so that a platform gets the product IDs with the purchase. No customer data. |
Shopify also lets our pixel read the e-mail address and phone number a shopper types at checkout, because we selected these fields as protected customer data. They are hashed on our server as soon as they arrive and sent only to the platforms the store connects, to match checkout events.
We also read the store's time zone and currency, and the currency Shopify bills the store in (shopBillingPreferences), so prices are shown in the currency of the charge; the shop owner's name and e-mail address (Shopify's shopOwnerName and email), to send service and incident notices and, on the free diagnosis, updates about it (section 7); the number of the store's paid orders in the 30 days before installation (for a store that started on the free diagnosis, before its first plan), for the before-and-after report; the store's subscription status for our app; and, if a guarantee credit is due, the app credits Shopify holds for our app.
For the free diagnosis we also read, with the same read_orders permission, the number of paid orders of the last 7 days, the number of orders per day that were not cancelled (to compare with what Meta counted), the total of the paid orders, and for the newest 250 of them Shopify's customer journey: the landing pages of the shopper's first and last visit before the order. We look only at whether a landing page carries an advertising click parameter (Meta fbclid, Google gclid, gbraid or wbraid, TikTok ttclid) and keep only the counts. The landing page addresses themselves, and any click ID or other value in them, are never stored, logged or passed on. We do this for the store, as its processor, under our Data Processing Agreement. The addresses are read only in memory while the diagnosis runs.
We receive Shopify's privacy notifications: customer data requests, customer erasure requests and store erasure requests. Section 9 of our Data Processing Agreement explains what we do with them.
5. Merchants and their staff: data we control
| Category | Data | Source |
|---|---|---|
| Store and account | Store domain, store platform, plan, subscription status, time zone, currency, consent mode, settings, installation and uninstallation dates | Shopify or you |
| Acceptance of our terms | Which version of the Terms and the Data Processing Agreement was accepted, when, for which store and by which user (Shopify staff user ID or login e-mail address; for an order form, the name or e-mail address of the person who signed it and the order form's reference); no IP address | You, our systems |
| Staff and logins | For Shopify stores: the Shopify staff user ID from the session token when a staff member changes settings. For other stores: login e-mail address and role, sign-in link and session records (stored as hashes), rate-limit records (stored as keyed hashes of the e-mail address and IP address) | Shopify or you |
| Notification contacts | Shopify stores: the shop owner's name and e-mail address from Shopify. Other addresses you give us. For each address, whether it receives incident e-mails and whether it receives updates about the free diagnosis and our plans. A log of the notices we sent (recipient, subject, content, delivery result). | Shopify, you, our systems |
| Platform access | Access keys, account IDs and connection settings for the platforms you connect, stored encrypted with your store's own key | You |
| Activity and security records | Audit log of settings changes, replays, admin actions, sign-ins, installs, uninstalls, privacy requests and billing actions, with the user who acted (login e-mail address or Shopify staff user ID) and the IP address of the request where there is one | Our systems |
| Billing | Through Shopify: plan, amounts, subscription and credit IDs and status. Through Stripe: your billing name, address, VAT number, e-mail and payment method are collected and held by Stripe; we store your Stripe customer ID, subscription ID and status. For a plan by agreement: the order form and our invoices. | Shopify, Stripe, you |
| Communications | Messages you send us, and the e-mails we send you (sign-in links, service and incident notices) | You, our systems |
| Operational alerts | Internal alerts about your store, with its domain and delivery statistics, stay in our admin tools and our e-mail. | Our systems |
5A. Business contacts and prospects
If you work for a business that may use Tikra, such as an online store or a marketing agency, or if you were our client before, we may send you e-mails about Tikra.
| Item | Details |
|---|---|
| Data | Your name, work e-mail address, company, role and website, our earlier messages and work with you, and whether you asked us to stop |
| Source | You, your company's public website or public business listings, or our earlier work together |
| Purpose | Telling businesses about Tikra and answering their replies |
| Legal basis | Our legitimate interest in offering our services to businesses (Art. 6(1)(f) and Recital 47 GDPR). For e-mail we follow Article 81 of the Lithuanian Law on Electronic Communications: without consent we write only to addresses of companies and other legal entities, and to our existing clients about similar services where we gave them the choice to refuse when we collected their address. We write to anyone else only with consent, and also where the law of your country requires consent. |
| Recipients | Cloudflare, which hosts our systems, and the provider that sends our e-mail |
| Retention | Until you ask us to stop, and no longer than 24 months after our last contact with you. If you ask us to stop, we keep your e-mail address on a do-not-contact list, only so that we do not write to you again. |
You can object at any time, free of charge and without giving a reason. Every such e-mail has a link that stops them. Replying "stop" works too. We never use e-mail addresses we receive from Shopify for these e-mails.
6. Visitors to our website
When you visit tikratracking.com (including the legal pages, the status page and the sign-in pages), Cloudflare processes your IP address and browser details to deliver and secure the pages. Request logs are kept for 7 days. Legal basis: our legitimate interest in operating and securing the site (Art. 6(1)(f) GDPR).
We set only the cookies the Service needs:
| Cookie | Purpose | Lifetime |
|---|---|---|
__Host-trk_session | Keeps a user signed in to the web dashboard. Set only when you sign in. | 30 days, or until you sign out |
__Host-trk_oauth | Links your browser to a Shopify installation you started, to protect that step | 10 minutes |
Inside the Shopify admin, our app uses Shopify's session tokens instead of these cookies. We use no analytics or advertising cookies, and no other technology that reads information from your device for analytics or advertising.
7. Why we use merchant data and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the Service: running your account, sending your orders to your platforms, monitoring, the service guarantee, support | Performance of our contract with you (Art. 6(1)(b) GDPR). For staff of a company that is our customer: our legitimate interest in providing the Service to their employer (Art. 6(1)(f)). |
| Recording the acceptance of our Terms and Data Processing Agreement | Performance of our contract with you, and our legal obligation to have a written processing agreement (Art. 6(1)(b) and (c), Art. 28(9) GDPR) |
| Billing, accounting and tax records | Legal obligation (Art. 6(1)(c)) under Lithuanian accounting and tax law |
| Security of the Service, audit logs, abuse and fraud prevention | Legitimate interest in keeping the Service and our customers' data secure (Art. 6(1)(f)) |
| Service messages: incidents, guarantee credits, changes to the Service or to our terms | Performance of contract, and legitimate interest (Art. 6(1)(b) and (f)) |
| Updates on your free diagnosis and offers for our plans: the e-mails of the 12-hour offer and the weekly summary, sent only while your store is on the free diagnosis | Legitimate interest in offering our Service to a business that installed it (Art. 6(1)(f) GDPR). You can object at any time: every such e-mail has a link to a page where one click stops them, and mail apps that show an unsubscribe button stop them with that button; service and incident e-mails are not affected. |
| Improving the Service, using operating data without personal data where possible | Legitimate interest (Art. 6(1)(f)) |
You need to give us a working contact e-mail address, and for stores outside Shopify your billing details, to use the Service. Without them we cannot provide or bill the Service. Shopify gives us the shop owner's name and e-mail address when the app is installed. The rest of the data is created as you use the Service.
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
8. Who receives merchant data
- Our service providers: Cloudflare (hosting, database, storage, and forwarding of e-mail sent to our addresses), Google (Google Workspace, which holds our support mailbox), Stripe (billing for merchants not billed through Shopify, when used), the provider that sends our e-mail (Resend, when used) and Anthropic, under its commercial terms (AI-assisted operations sessions, which see store domains, delivery figures, order-level records and support messages; and the fix plan shown with the free diagnosis, for which the Claude API receives only the diagnosis findings: counts, percentages and dates, without the store's name or domain and without any personal data). The full list is at https://tikratracking.com/legal/subprocessors.
- Our on-call person is alerted through Telegram with a short signal that contains no store names, store figures or customer data. The details stay in our admin tools.
- Shopify, for stores that use our Shopify app, including for billing through Shopify.
- The platforms you connect, which receive the access keys you gave us when we send your orders to them.
- Our professional advisers (accountant, lawyer) and insurers, under confidentiality.
- Authorities, when the law requires it.
9. International transfers
Cloudflare, Google, Stripe, Resend and Anthropic may process data outside the EEA, including in the United States. Where they do, the transfer is covered by the EU-U.S. Data Privacy Framework certification of the provider or by the EU Standard Contractual Clauses. You can ask us for a copy of the clauses at privacy@tikratracking.com.
10. How long we keep merchant data
| Data | Retention |
|---|---|
| Store, account and settings data | While you use the Service. Deleted when you uninstall the Shopify app (an interrupted deletion is finished within the hour). For other stores, deleted within 30 days after your subscription ends. |
| Record of the acceptance of our terms | While the store's other records are kept; deleted with them at uninstall |
| Platform access keys | Deleted when you disconnect the platform, when you uninstall the Shopify app, or, for other stores, within 30 days after your subscription ends |
| Notification contacts | While you use the Service. A shop owner address that changes in Shopify is replaced at our next weekly check. Deleted with the store's other records when you uninstall the app. |
| Log of notices we sent | 90 days, or sooner when the store's records are deleted after uninstall. A notice about an incident is kept while the incident is open and for 90 days after it closes. A notice about a platform key problem is kept while the problem lasts, so the same notice is not sent twice. Daily digests and system alerts that are not linked to a store: 30 days. |
| Audit log | 24 months |
| Sign-in links | Valid for 15 minutes, single use, deleted within about a day after they expire |
| Login sessions | End after 30 days, or at once when you log out or the user is removed |
| Rate-limit records | About a day |
| Website request logs | 7 days |
| Billing records | Invoices, payment records and other accounting documents: 10 years. Our contract with you and the records that prove it: 10 years after the contract ends. These are the minimum periods of the Lithuanian Internal Administration Documents Retention Index (items 3.15, 3.19 and 3.24). The Stripe and Shopify IDs and statuses we keep in the Service, and the Service's own billing rows (charges for extra orders, guarantee credits, monthly order counts and the invoice lines of a plan by agreement), are deleted with your store's other records; the audit log keeps the entries about each charge and credit for 24 months. |
| Support e-mails | 3 years after the conversation ends. If a dispute needs them, we keep them until it is settled. |
| Encrypted database backups | 20 days |
| Restore journal (records of erasures, uninstalls and reinstalls, disconnected platforms with their emptied encrypted settings, consent mode changes and removed logins, applied again if a backup is ever restored; a removed login only as the SHA-256 hash of its e-mail address) | 28 days |
| Our database provider's point-in-time history | 30 days; it cannot be shortened. Every copy of deleted data is gone within 30 days after the deletion. |
11. Your rights
Your right to object. Where we rely on our legitimate interests (section 7), you can object at any time for reasons related to your situation. We then stop, unless we have compelling legitimate grounds or need the data for legal claims. You can object to direct marketing at any time, without giving a reason, and we then stop.
If our processing of your data is covered by the GDPR, you also have the right to:
- access your data and receive a copy;
- have incorrect data corrected;
- have your data erased;
- restrict the processing;
- receive your data in a portable format; and
- withdraw consent where we rely on it, without affecting earlier processing.
To use these rights, write to privacy@tikratracking.com. We answer within one month. We may extend this by two further months for complex requests and will tell you why.
12. Complaints
You may complain to the Lithuanian supervisory authority:
Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate)
L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
E-mail: ada@ada.lt
Telephone: +370 5 271 2804
Website: https://vdai.lrv.lt
You may also complain to the supervisory authority where you live or work, or where you think the infringement took place. We would like to hear from you first, so we can try to solve the problem.
13. Security
We protect data with encryption in transit and at rest, a separate encryption key for each store, hashing of shoppers' contact details, admin tools that require both a secret key and a separate login through Cloudflare Access, an audit log and a written incident response plan. If a personal data breach affects your data, we inform you as the law and our Data Processing Agreement require.
14. For your store's cookie notice
On Shopify stores our web pixel sets no cookies. With the shopper's consent it reads existing cookies: _fbp, _fbc, _gcl_aw, _ttp, _epik and _scid with marketing consent, and _ga and _ga_<property> with analytics consent (to find the _ga_<property> cookies it reads the browser's cookie string and uses nothing else from it). With marketing consent it keeps these items in the browser's storage:
| Key | Browser storage | Purpose | How long it is used | Category |
|---|---|---|---|---|
tikra_clicks | Local storage | Keeps the ID of the ad the shopper clicked, so that a later purchase can be reported to that advertising platform | 90 days from the click; an older click is ignored | Marketing |
tikra_fbp | Local storage | A browser ID in Meta's format, made only when the store has no Meta _fbp cookie, so that the shopper's store events and purchase can be matched in Meta | 90 days from its creation; then a new one is made | Marketing |
tikra_ic | Local storage | Remembers, without the checkout token itself, that a checkout was already reported, so that it is reported once | 24 hours per entry | Marketing |
Browser storage has no expiry of its own: the pixel ignores an entry past its time and removes or replaces it the next time it reads that key (tikra_clicks at the next ad click, at checkout, and on every page of a store that gets store events; tikra_fbp when it needs a browser ID, otherwise it stays until a page opens without marketing consent; tikra_ic at the next checkout step). It deletes all three when the shopper withdraws marketing consent and when a page opens without marketing consent (for example after a Global Privacy Control opt-out). On a store's free diagnosis the pixel keeps tikra_clicks and reads the cookies above in the same way; our server then keeps only the shopper's consent decision.
On WooCommerce stores our plugin sets first-party cookies on your domain. _tikra_gclid, _tikra_gbraid, _tikra_wbraid, _tikra_ttclid, _tikra_epik, _tikra_sccid and _tikra_fbc hold the advertising click ID from the landing page for 90 days. They are set with marketing consent and, in standard mode, also on stores without a supported consent tool, for every visitor. _tikra_consent keeps a copy of the consent tool's choices for 180 days. With the matching consent the plugin also reads _fbp, _fbc, _gcl_aw, _epik, _ga and _ga_<stream>. Section I of Annex 1 to our Data Processing Agreement has the details.
Describe this in your cookie notice under the purposes your consent banner uses.
15. Children
The Service is for businesses. It is not directed at children, and we do not knowingly process children's data as a controller.
16. Changes
We may update this policy. We tell merchants about material changes by e-mail and in the dashboard before they apply. The version and date at the top show the latest version. Earlier versions stay readable at https://tikratracking.com/legal/privacy followed by a slash and the version name.
17. Notice for residents of US states
Shoppers: we process your data for the store, on its instructions. To use your rights, including the right to opt out of the sale or sharing of your data or of targeted advertising, use the store's privacy settings or contact the store. When you opt out through a Shopify store's privacy settings, we stop sending your orders and store events to advertising and e-mail marketing platforms (section 3.3).
Merchants and their staff: in the last 12 months we collected the categories of data in section 5: identifiers (such as name, e-mail address, IP address and account IDs), commercial information (plan and billing records), internet activity (sign-in and audit records) and professional information (your store and role). We collected them from the sources in section 5, used them for the purposes in section 7, and disclosed them for those purposes to the recipients in section 8. We do not sell or share this data, as the California Consumer Privacy Act defines those words, and we did not do so in the last 12 months. We use sensitive data, such as the access keys to your platform accounts, only to provide the Service. We keep the data for the periods in section 10.
You may ask to know, correct or delete your data. Write to privacy@tikratracking.com from the e-mail address on your account, or through an authorised agent with your signed permission. We check that the request comes from you before we act on it. We will not treat you differently for using these rights.
MB Euruvizija, company code 307863521, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania. support@tikratracking.com