Tikra legal texts

Tikra Privacy Policy

Version 2026-09-30-pilot. Last updated 28 September 2026.

1. Who we are

Tikra is provided by MB Euruvizija, a small partnership (mažoji bendrija) registered in the Republic of Lithuania, company code 307863521, registered office V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania ("we", "us").

Contact for privacy questions: privacy@tikratracking.com, MB Euruvizija, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania.

We have assessed whether Article 37 of the GDPR requires us to appoint a data protection officer. At our current size it does not. We review this assessment every year, and before we take on stores that significantly increase the number of shoppers whose orders we process. If we appoint one, we will publish the contact details here. Until then, privacy questions go to the contact above.

This is the pilot version of this policy. A lawyer has not reviewed it yet.

2. Summary

3. Shoppers: data we process for stores

3.1. If you bought from a store that uses Tikra, or visited it, the store decides how your data is used. Please read the store's privacy notice and send your requests to the store. If you contact us, we pass your request to the store.

3.2. What we process for the store, in short:

For an order paid while the store is on our free diagnosis (a Shopify store without a plan), we keep much less: only its ID and number, the payment time, the amounts, whether it is a test order, whether your country is in the EEA, the United Kingdom or Switzerland, and your consent choices, linked to the order by the checkout reference. We keep none of the other data in this list (our pixel still keeps the ad click IDs in your own browser with your marketing consent, section 14, and our server discards the identifiers it sends), send nothing to any platform, and delete these records 30 days after payment. Before a store accepts our Terms and Data Processing Agreement, we keep nothing of its orders or store events at all.

For an order that was not placed online (for example a sale at a point of sale, or a draft order marked as paid), we keep only its ID and number, the payment time, the amounts, whether it is a test order and where it came from; for a WooCommerce store also the hashed order key, used only so that an erasure or access request reaches it. We keep none of the other data in this list for it, and we send it to no platform.

3.3. We send this data only to the platforms the store connected, and only when your consent choices allow it. If the country of your order address is in the EEA, the United Kingdom or Switzerland, we send your order to advertising and e-mail marketing platforms only if you gave marketing consent, and to Google Analytics only if you gave analytics consent. If you opted out of the sale or sharing of your data through the store's Shopify privacy settings, we do not send your order or your store events to advertising or e-mail marketing platforms. Store events are sent only with marketing consent, wherever you are. Our WooCommerce plugin does not read opt-outs of the sale or sharing of data. Google Analytics never gets your contact details, your full IP address or your user agent. Where the store's agreement with us provides for it, it gets your IP address shortened to its first three parts (for an IPv6 address, its first 48 bits) and the type of your device, its operating system and your browser, so that it can show roughly where and on what kind of device you bought.

3.4. The complete list of data, recipients and retention periods is in Annex 1 of our Data Processing Agreement at https://tikratracking.com/legal/dpa.

4. Data we access in a Shopify store

When a merchant installs our Shopify app, it asks for these permissions:

PermissionWhat we use it for
read_ordersTo receive each paid order (webhook orders/paid) and to read recent orders every hour, so no order is missed. Orders include the customer's name, e-mail, phone and addresses where Shopify has approved our access to protected customer data.
write_pixelsTo add our web pixel to the store's storefront and checkout.
read_customer_eventsTo let our pixel receive the store's customer events: the checkout completion event, which carries the checkout token we use to link the order with the shopper's consent choices and advertising identifiers, and the store events of section 3.2.
read_productsTo read the product and variant IDs of the items in an order when the order data we receive does not carry them, so that a platform gets the product IDs with the purchase. No customer data.
read_privacy_settingsTo read the store's customer privacy settings (in which countries Shopify asks shoppers for consent), so that we can warn the store when consent is not asked for in the EEA, the United Kingdom or Switzerland. No customer data.

Shopify also lets our pixel read the e-mail address and phone number a shopper types at checkout, because we selected these fields as protected customer data. They are hashed on our server as soon as they arrive and sent only to the platforms the store connects, to match checkout events.

We also read the store's time zone and currency, and the currency Shopify bills the store in (shopBillingPreferences), so prices are shown in the currency of the charge; the shop owner's name and e-mail address (Shopify's shopOwnerName and email), to send service and incident notices and, on the free diagnosis, updates about it (section 7); the number of the store's paid orders in the 30 days before installation (for a store that started on the free diagnosis, before its first plan), for the before-and-after report; the store's subscription status for our app; if a guarantee credit is due, the app credits Shopify holds for our app; and, once the store allows our app to read them, the store's customer privacy settings (in which countries Shopify asks shoppers for consent) and the country of the store's address, to warn the store when consent is not asked for in the EEA, the United Kingdom or Switzerland.

For the free diagnosis we also read, with the same read_orders permission, the number of paid orders of the last 7 days, the number of orders per day that were not cancelled (to compare with what Meta counted), the total of the paid orders, and for the newest 250 of them Shopify's customer journey: the landing pages of the shopper's first and last visit before the order. We look only at whether a landing page carries an advertising click parameter (Meta fbclid, Google gclid, gbraid or wbraid, TikTok ttclid) and keep only the counts. The landing page addresses themselves, and any click ID or other value in them, are never stored, logged or passed on. We do this for the store, as its processor, under our Data Processing Agreement. The addresses are read only in memory while the diagnosis runs.

We receive Shopify's privacy notifications: customer data requests, customer erasure requests and store erasure requests. Section 9 of our Data Processing Agreement explains what we do with them.

5. Merchants and their staff: data we control

CategoryDataSource
Store and accountStore domain, store platform, plan, subscription status, time zone, currency, consent mode, settings, installation and uninstallation datesShopify or you
Acceptance of our termsWhich version of the Terms and the Data Processing Agreement was accepted, when, for which store and by which user (Shopify staff user ID or login e-mail address; for an order form, the name or e-mail address of the person who signed it and the order form's reference); no IP addressYou, our systems
Staff and loginsFor Shopify stores: the Shopify staff user ID from the session token when a staff member changes settings. For other stores: login e-mail address and role, sign-in link and session records (stored as hashes), rate-limit records (stored as keyed hashes of the e-mail address and IP address)Shopify or you
Notification contactsShopify stores: the shop owner's name and e-mail address from Shopify. Other addresses you give us. For each address, whether it receives incident e-mails and whether it receives updates about the free diagnosis and our plans. A log of the notices we sent (recipient, subject, content, delivery result).Shopify, you, our systems
Platform accessAccess keys, account IDs and connection settings for the platforms you connect, stored encrypted with your store's own keyYou
Activity and security recordsAudit log of settings changes, replays, admin actions, sign-ins, installs, uninstalls, privacy requests and billing actions, with the user who acted (login e-mail address or Shopify staff user ID) and the IP address of the request where there is oneOur systems
BillingThrough Shopify: plan, amounts, subscription and credit IDs and status. Through Stripe: your billing name, address, VAT number, e-mail and payment method are collected and held by Stripe; we store your Stripe customer ID, subscription ID and status. For a plan by agreement: the order form and our invoices.Shopify, Stripe, you
CommunicationsMessages you send us, and the e-mails we send you (sign-in links, service and incident notices)You, our systems
Operational alertsInternal alerts about your store, with its domain and delivery statistics, stay in our admin tools and our e-mail.Our systems

5A. Business contacts and prospects

If you work for a business that may use Tikra, such as an online store or a marketing agency, or if you were our client before, we may send you e-mails about Tikra.

ItemDetails
DataYour name, work e-mail address, company, role and website, our earlier messages and work with you, and whether you asked us to stop
SourceYou, your company's public website or public business listings, or our earlier work together
PurposeTelling businesses about Tikra and answering their replies
Legal basisOur legitimate interest in offering our services to businesses (Art. 6(1)(f) and Recital 47 GDPR). For e-mail we follow Article 81 of the Lithuanian Law on Electronic Communications: without consent we write only to addresses of companies and other legal entities, and to our existing clients about similar services where we gave them the choice to refuse when we collected their address. We write to anyone else only with consent, and also where the law of your country requires consent.
RecipientsCloudflare, which hosts our systems, and the provider that sends our e-mail
RetentionUntil you ask us to stop, and no longer than 24 months after our last contact with you. If you ask us to stop, we keep your e-mail address on a do-not-contact list, only so that we do not write to you again.

You can object at any time, free of charge and without giving a reason. Every such e-mail has a link that stops them. Replying "stop" works too. We never use e-mail addresses we receive from Shopify for these e-mails.

6. Visitors to our website

When you visit tikratracking.com (including the legal pages, the status page and the sign-in pages), Cloudflare processes your IP address and browser details to deliver and secure the pages. Request logs are kept for 7 days. Legal basis: our legitimate interest in operating and securing the site (Art. 6(1)(f) GDPR).

We set only the cookies the Service needs:

CookiePurposeLifetime
__Host-trk_sessionKeeps a user signed in to the web dashboard. Set only when you sign in.30 days, or until you sign out
__Host-trk_oauthLinks your browser to a Shopify installation you started, to protect that step10 minutes

Inside the Shopify admin, our app uses Shopify's session tokens instead of these cookies. We use no analytics or advertising cookies, and no other technology that reads information from your device for analytics or advertising.

PurposeLegal basis
Providing the Service: running your account, sending your orders to your platforms, monitoring, the service guarantee, supportPerformance of our contract with you (Art. 6(1)(b) GDPR). For staff of a company that is our customer: our legitimate interest in providing the Service to their employer (Art. 6(1)(f)).
Recording the acceptance of our Terms and Data Processing AgreementPerformance of our contract with you, and our legal obligation to have a written processing agreement (Art. 6(1)(b) and (c), Art. 28(9) GDPR)
Billing, accounting and tax recordsLegal obligation (Art. 6(1)(c)) under Lithuanian accounting and tax law
Security of the Service, audit logs, abuse and fraud preventionLegitimate interest in keeping the Service and our customers' data secure (Art. 6(1)(f))
Service messages: incidents, guarantee credits, changes to the Service or to our termsPerformance of contract, and legitimate interest (Art. 6(1)(b) and (f))
Updates on your free diagnosis and offers for our plans: the e-mails of the 12-hour offer and the weekly summary, sent only while your store is on the free diagnosisLegitimate interest in offering our Service to a business that installed it (Art. 6(1)(f) GDPR). You can object at any time: every such e-mail has a link to a page where one click stops them, and mail apps that show an unsubscribe button stop them with that button; service and incident e-mails are not affected.
Improving the Service, using operating data without personal data where possibleLegitimate interest (Art. 6(1)(f))

You need to give us a working contact e-mail address, and for stores outside Shopify your billing details, to use the Service. Without them we cannot provide or bill the Service. Shopify gives us the shop owner's name and e-mail address when the app is installed. The rest of the data is created as you use the Service.

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

8. Who receives merchant data

9. International transfers

Cloudflare, Google, Stripe, Resend and Anthropic may process data outside the EEA, including in the United States. Where they do, the transfer is covered by the EU-U.S. Data Privacy Framework certification of the provider or by the EU Standard Contractual Clauses. You can ask us for a copy of the clauses at privacy@tikratracking.com.

10. How long we keep merchant data

DataRetention
Store, account and settings dataWhile you use the Service. Deleted when you uninstall the Shopify app (an interrupted deletion is finished within the hour). For other stores, deleted within 30 days after your subscription ends.
Record of the acceptance of our termsWhile the store's other records are kept; deleted with them at uninstall
Platform access keysDeleted when you disconnect the platform, when you uninstall the Shopify app, or, for other stores, within 30 days after your subscription ends
Notification contactsWhile you use the Service. A shop owner address that changes in Shopify is replaced at our next weekly check. Deleted with the store's other records when you uninstall the app.
Log of notices we sent90 days, or sooner when the store's records are deleted after uninstall. A notice about an incident is kept while the incident is open and for 90 days after it closes. A notice about a platform key problem is kept while the problem lasts, so the same notice is not sent twice. Daily digests and system alerts that are not linked to a store: 30 days.
Audit log24 months
Sign-in linksValid for 15 minutes, single use, deleted within about a day after they expire
Login sessionsEnd after 30 days, or at once when you log out or the user is removed
Rate-limit recordsAbout a day
Website request logs7 days
Billing recordsInvoices, payment records and other accounting documents: 10 years. Our contract with you and the records that prove it: 10 years after the contract ends. These are the minimum periods of the Lithuanian Internal Administration Documents Retention Index (items 3.15, 3.19 and 3.24). The Stripe and Shopify IDs and statuses we keep in the Service, and the Service's own billing rows (charges for extra orders, guarantee credits, monthly order counts and the invoice lines of a plan by agreement), are deleted with your store's other records; the audit log keeps the entries about each charge and credit for 24 months.
Support e-mails3 years after the conversation ends. If a dispute needs them, we keep them until it is settled.
Encrypted database backups20 days
Restore journal (records of erasures, uninstalls and reinstalls, disconnected platforms with their emptied encrypted settings, consent mode changes and removed logins, applied again if a backup is ever restored; a removed login only as the SHA-256 hash of its e-mail address)28 days
Our database provider's point-in-time history30 days; it cannot be shortened. Every copy of deleted data is gone within 30 days after the deletion.

11. Your rights

Your right to object. Where we rely on our legitimate interests (section 7), you can object at any time for reasons related to your situation. We then stop, unless we have compelling legitimate grounds or need the data for legal claims. You can object to direct marketing at any time, without giving a reason, and we then stop.

If our processing of your data is covered by the GDPR, you also have the right to:

To use these rights, write to privacy@tikratracking.com. We answer within one month. We may extend this by two further months for complex requests and will tell you why.

12. Complaints

You may complain to the Lithuanian supervisory authority:

Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate)
L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
E-mail: ada@ada.lt
Telephone: +370 5 271 2804
Website: https://vdai.lrv.lt

You may also complain to the supervisory authority where you live or work, or where you think the infringement took place. We would like to hear from you first, so we can try to solve the problem.

13. Security

We protect data with encryption in transit and at rest, a separate encryption key for each store, hashing of shoppers' contact details, admin tools that require both a secret key and a separate login through Cloudflare Access, an audit log and a written incident response plan. If a personal data breach affects your data, we inform you as the law and our Data Processing Agreement require.

On Shopify stores our web pixel sets no cookies. With the shopper's consent it reads existing cookies: _fbp, _fbc, _gcl_aw, _ttp, _epik and _scid with marketing consent, and _ga and _ga_<property> with analytics consent (to find the _ga_<property> cookies it reads the browser's cookie string and uses nothing else from it). With marketing consent it keeps these items in the browser's storage:

KeyBrowser storagePurposeHow long it is usedCategory
tikra_clicksLocal storageKeeps the ID of the ad the shopper clicked, so that a later purchase can be reported to that advertising platform90 days from the click; an older click is ignoredMarketing
tikra_fbpLocal storageA browser ID in Meta's format, made only when the store has no Meta _fbp cookie, so that the shopper's store events and purchase can be matched in Meta90 days from its creation; then a new one is madeMarketing
tikra_icLocal storageRemembers, without the checkout token itself, that a checkout was already reported, so that it is reported once24 hours per entryMarketing

Browser storage has no expiry of its own: the pixel ignores an entry past its time and removes or replaces it the next time it reads that key (tikra_clicks at the next ad click, at checkout, and on every page of a store that gets store events; tikra_fbp when it needs a browser ID, otherwise it stays until a page opens without marketing consent; tikra_ic at the next checkout step). It deletes all three when the shopper withdraws marketing consent and when a page opens without marketing consent (for example after a Global Privacy Control opt-out). On a store's free diagnosis the pixel keeps tikra_clicks and reads the cookies above in the same way; our server then keeps only the shopper's consent decision.

On WooCommerce stores our plugin sets first-party cookies on your domain. _tikra_gclid, _tikra_gbraid, _tikra_wbraid, _tikra_ttclid, _tikra_epik, _tikra_sccid and _tikra_fbc hold the advertising click ID from the landing page for 90 days. They are set with marketing consent and, in standard mode, also on stores without a supported consent tool, for every visitor. _tikra_consent keeps a copy of the consent tool's choices for 180 days. With the matching consent the plugin also reads _fbp, _fbc, _gcl_aw, _epik, _ga and _ga_<stream>. Section I of Annex 1 to our Data Processing Agreement has the details.

Describe this in your cookie notice under the purposes your consent banner uses.

15. Children

The Service is for businesses. It is not directed at children, and we do not knowingly process children's data as a controller.

16. Changes

We may update this policy. We tell merchants about material changes by e-mail and in the dashboard before they apply. The version and date at the top show the latest version. Earlier versions stay readable at https://tikratracking.com/legal/privacy followed by a slash and the version name.

17. Notice for residents of US states

Shoppers: we process your data for the store, on its instructions. To use your rights, including the right to opt out of the sale or sharing of your data or of targeted advertising, use the store's privacy settings or contact the store. When you opt out through a Shopify store's privacy settings, we stop sending your orders and store events to advertising and e-mail marketing platforms (section 3.3).

Merchants and their staff: in the last 12 months we collected the categories of data in section 5: identifiers (such as name, e-mail address, IP address and account IDs), commercial information (plan and billing records), internet activity (sign-in and audit records) and professional information (your store and role). We collected them from the sources in section 5, used them for the purposes in section 7, and disclosed them for those purposes to the recipients in section 8. We do not sell or share this data, as the California Consumer Privacy Act defines those words, and we did not do so in the last 12 months. We use sensitive data, such as the access keys to your platform accounts, only to provide the Service. We keep the data for the periods in section 10.

You may ask to know, correct or delete your data. Write to privacy@tikratracking.com from the e-mail address on your account, or through an authorised agent with your signed permission. We check that the request comes from you before we act on it. We will not treat you differently for using these rights.

MB Euruvizija, company code 307863521, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania. support@tikratracking.com