Tikra Privacy Policy
Earlier versions of this text carried a version name and a date later than the day we published them. Since 2 October 2026 both are the day of publication, and the page of each earlier version shows the day it was last updated.
1. Who we are
Tikra is provided by MB Euruvizija, a small partnership (mažoji bendrija) registered in the Republic of Lithuania, company code 307863521, registered office V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania ("we", "us").
Contact for privacy questions: privacy@tikratracking.com, MB Euruvizija, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania.
We have assessed whether Article 37 of the GDPR requires us to appoint a data protection officer. At our current size it does not. We review this assessment every year, and before we take on stores that significantly increase the number of shoppers whose orders we process. If we appoint one, we will publish the contact details here. Until then, privacy questions go to the contact above.
We prepared this version with AI tools and public legal sources. A lawyer has not reviewed it.
2. Summary
- Tikra is a service for online stores. It sends each paid online order of a store (an order placed through the store's checkout) to the advertising and analytics platforms the store connects, after checking the shopper's consent choices, and shows the store what was sent. On Shopify stores it can also report the shopper's visits, product views, add to cart and checkout steps to those platforms, only when the shopper allows marketing.
- For the personal data of the store's customers and visitors (shoppers), the store is the controller and we are its processor. We process that data only on the store's instructions, under our Data Processing Agreement.
- For data about our business customers (merchants and agencies) and their staff, and about visitors to our website, we are the controller. This policy mainly covers that data.
- We do not sell personal data. We do not use shoppers' data for our own purposes.
3. Shoppers: data we process for stores
3.1. If you bought from a store that uses Tikra, or visited it, the store decides how your data is used. Please read the store's privacy notice and send your requests to the store. If you contact us, we pass your request to the store.
3.2. What we process for the store, in short:
- your e-mail address, phone number, name, city, region, postal code and customer ID, which we store only as SHA-256 hashes, apart from the postal code and country code in plain form (Google Ads requires them);
- your IP address, which we store only encrypted, and a shortened IP address from the checkout and the order confirmation page; apart from this, our hosting provider's request logs hold the IP address of each request to our servers for 7 days;
- your browser's user agent;
- advertising click and cookie identifiers (for example Meta, Google, TikTok, Pinterest and Snapchat click IDs, and a browser ID in Meta's format that our pixel makes when the store has no Meta
_fbpcookie) and a hashed form of Shopify's browser ID if you allowed marketing, and Google Analytics identifiers if you allowed analytics. On WooCommerce stores that use standard mode, we also keep them when you gave no consent signal at all and your order country is outside the EEA, the United Kingdom and Switzerland; - your consent choices for that order;
- the order: order number, amounts, currency, products and time;
- for 30 days, a copy of the order without your name, contact details or addresses (order number, amounts, products and time), so that we can send it again if a platform missed it. Only if the store connected Klaviyo, which we no longer offer, the copy also holds your e-mail address, phone number and first name, encrypted, because Klaviyo cannot use hashed data;
- on Shopify stores, only if you allowed marketing and did not opt out of the sale or sharing of your data: the pages you view, the products you view and add to your cart, and when you start checkout and enter payment information ("store events"), with the products, prices and page addresses (without their query part), a hashed form of Shopify's browser ID and customer ID, your IP address and user agent, and at checkout your e-mail address and phone number, which we hash as soon as we receive them. We keep store events only as daily counts. What you type into the store's search box is never collected; and
- if you start a checkout, the checkout reference, your consent choices and, as this section allows, the identifiers above, so that a purchase can be linked to them; if you do not complete the order, we delete them after 7 days;
- the addresses of the pages where your visits before the order started, which Shopify keeps with the order. For the store's free diagnosis we read them only to count orders that came from an ad click. With a plan, if you allowed marketing and did not opt out of the sale or sharing of your data, and our pixel did not record the ad you clicked, we take the ad click ID from the first page of your first or last visit before the order and send it with your purchase to that advertising platform. We never store these addresses.
For an order paid while the store is on our free diagnosis (a Shopify store without a plan), we keep much less: only its ID and number, the payment time, the amounts, whether it is a test order, whether your country is in the EEA, the United Kingdom or Switzerland, and your consent choices, linked to the order by the checkout reference. We keep none of the other data in this list (our pixel still keeps the ad click IDs in your own browser with your marketing consent, section 14, and our server discards the identifiers it sends), send nothing to any platform, and delete these records 30 days after payment. Before a store accepts our Terms and Data Processing Agreement, we keep nothing of its orders or store events at all.
For an order that was not placed online (for example a sale at a point of sale, or a draft order marked as paid), we keep only its ID and number, the payment time, the amounts, whether it is a test order and where it came from; for a WooCommerce store also the hashed order key, used only so that an erasure or access request reaches it. We keep none of the other data in this list for it, and we send it to no platform.
3.3. We send this data only to the platforms the store connected, and only when your consent choices allow it. If the country of your order address is in the EEA, the United Kingdom or Switzerland, we send your order to advertising and e-mail marketing platforms only if you gave marketing consent, and to Google Analytics only if you gave analytics consent. If you opted out of the sale or sharing of your data through the store's Shopify privacy settings, we do not send your order or your store events to advertising or e-mail marketing platforms. Store events are sent only with marketing consent, wherever you are. Our WooCommerce plugin does not read opt-outs of the sale or sharing of data. Google Analytics never gets your contact details, your full IP address or your user agent. Where the store's agreement with us provides for it, it gets your IP address shortened to its first three parts (for an IPv6 address, its first 48 bits) and the type of your device, its operating system and your browser, so that it can show roughly where and on what kind of device you bought.
3.4. The complete list of data, recipients and retention periods is in Annex 1 of our Data Processing Agreement at https://tikratracking.com/legal/dpa.
4. Data we access in a Shopify store
When a merchant installs our Shopify app, it asks for these permissions:
| Permission | What we use it for |
|---|---|
read_orders | To receive each paid order (webhook orders/paid) and to read recent orders every hour, so no order is missed. Orders include the customer's name, e-mail, phone and addresses where Shopify has approved our access to protected customer data. |
write_pixels | To add our web pixel to the store's storefront and checkout. |
read_customer_events | To let our pixel receive the store's customer events: the checkout completion event, which carries the checkout token we use to link the order with the shopper's consent choices and advertising identifiers, and the store events of section 3.2. |
read_products | To read the product and variant IDs of the items in an order when the order data we receive does not carry them, so that a platform gets the product IDs with the purchase. No customer data. |
read_privacy_settings | To read the store's customer privacy settings (in which countries Shopify asks shoppers for consent), so that we can warn the store when consent is not asked for in the EEA, the United Kingdom or Switzerland. No customer data. |
Shopify also lets our pixel read the e-mail address and phone number a shopper types at checkout, because we selected these fields as protected customer data. They are hashed on our server as soon as they arrive and sent only to the platforms the store connects, to match checkout events.
We also read the store's time zone and currency, and the currency Shopify bills the store in (shopBillingPreferences), so prices are shown in the currency of the charge; the shop owner's name and e-mail address (Shopify's shopOwnerName and email), to send service and incident notices and, on the free diagnosis, updates about it (section 7); the number of the store's paid orders in the 30 days before installation (for a store that started on the free diagnosis, before its first plan), for the before-and-after report; the store's subscription status for our app; if a guarantee credit is due, the app credits Shopify holds for our app; and, once the store allows our app to read them, the store's customer privacy settings (in which countries Shopify asks shoppers for consent) and the country of the store's address, to warn the store when consent is not asked for in the EEA, the United Kingdom or Switzerland.
For the free diagnosis we also read, with the same read_orders permission, the number of paid orders of the last 7 days, the number of orders per day that were not cancelled (to compare with what Meta counted), the total of the paid orders, and for the newest 250 of them Shopify's customer journey: the landing pages of the shopper's first and last visit before the order. We look only at whether a landing page carries an advertising click parameter (Meta fbclid, Google gclid, gbraid or wbraid, TikTok ttclid) and keep only the counts. The landing page addresses themselves, and any click ID or other value in them, are never stored, logged or passed on. We do this for the store, as its processor, under our Data Processing Agreement. The addresses are read only in memory while the diagnosis runs.
We receive Shopify's privacy notifications: customer data requests, customer erasure requests and store erasure requests. Section 9 of our Data Processing Agreement explains what we do with them.
5. Merchants and their staff: data we control
| Category | Data | Source |
|---|---|---|
| Store and account | Store domain, store platform, plan, subscription status, time zone, currency, consent mode, settings, installation and uninstallation dates | Shopify or you |
| Acceptance of our terms | Which version of the Terms and the Data Processing Agreement was accepted, when, for which store and by which user (Shopify staff user ID or login e-mail address; for an order form, the name or e-mail address of the person who signed it and the order form's reference); no IP address | You, our systems |
| Staff and logins | For Shopify stores: the Shopify staff user ID from the session token when a staff member changes settings. For other stores: login e-mail address and role, sign-in link and session records (stored as hashes), rate-limit records (stored as keyed hashes of the e-mail address and IP address) | Shopify or you |
| Notification contacts | Shopify stores: the shop owner's name and e-mail address from Shopify. Other addresses you give us. For each address, whether it receives incident e-mails and whether it receives updates about the free diagnosis and our plans. A log of the notices we sent (recipient, subject, content, delivery result). | Shopify, you, our systems |
| Platform access | Access keys, account IDs and connection settings for the platforms you connect, stored encrypted with your store's own key. When you connect Meta with your Meta login (Connect with Meta): the access token Meta issues to us for your business, your Meta business ID, the pixel you chose, and the list of pixels with their names that you gave us access to (kept only until you choose one; unusable after 1 hour and deleted within 2 hours); and a keyed hash of the ID Meta gives this connection, so that we can act on Meta's notices about it. We receive nothing else about you from Meta: not your name, e-mail address or Facebook profile. | You; Meta, when you connect with your Meta login |
| Activity and security records | Audit log of settings changes, replays, admin actions, sign-ins, installs, uninstalls, privacy requests and billing actions, with the user who acted (login e-mail address or Shopify staff user ID) and the IP address of the request where there is one | Our systems |
| Billing | Through Shopify: plan, amounts, subscription and credit IDs and status. Through Stripe: your billing name, address, VAT number, e-mail and payment method are collected and held by Stripe; we store your Stripe customer ID, subscription ID and status. For a plan by agreement: the order form and our invoices. | Shopify, Stripe, you |
| Communications | Messages you send us, and the e-mails we send you (sign-in links, service and incident notices, reports) | You, our systems |
| Product analytics | A record of the steps each store takes in our service (installed, accepted our terms, connected a platform, started or changed a plan, finished the setup questions, uninstalled or reinstalled), with the date, a coarse install source (the App Store, an advertisement, a partner or a direct link) and the plan name. The store appears only as a code made with a secret key; no store name, domain, person's name, e-mail address or IP address. | Our systems |
| App review test orders | Test orders placed on Shopify development stores that connected one of our own test accounts, for example during Shopify's review of our app: the order data typed into the test checkout, hashed as for any order, reaches our own Google Analytics 4 property and Meta test pixel. We use it only to show that sending works and delete it where the platform allows. | Shopify development stores |
| Operational alerts | Internal alerts about your store and its deliveries. Our admin tools show them with the store's domain. The alerts that reach our on-call person name the store only by a reference code (section 8). | Our systems |
5A. Business contacts and prospects
If you work for a business that may use Tikra, such as an online store or a marketing agency, or if you were our client before, we may send you e-mails about Tikra.
| Item | Details |
|---|---|
| Data | Your name, work e-mail address, company, role and website, our earlier messages and work with you, and whether you asked us to stop |
| Source | You, your company's public website or public business listings, or our earlier work together |
| Purpose | Telling businesses about Tikra and answering their replies |
| Legal basis | Our legitimate interest in offering our services to businesses (Art. 6(1)(f) and Recital 47 GDPR). For e-mail we follow Article 81 of the Lithuanian Law on Electronic Communications: without consent we write only to addresses of companies and other legal entities, and to our existing clients about similar services where we gave them the choice to refuse when we collected their address. We write to anyone else only with consent, and also where the law of your country requires consent. |
| Recipients | Cloudflare, which hosts our systems, and the provider that sends our e-mail |
| Retention | Until you ask us to stop, and no longer than 24 months after our last contact with you. If you ask us to stop, we keep your e-mail address on a do-not-contact list, only so that we do not write to you again. |
You can object at any time, free of charge and without giving a reason. Every such e-mail has a link that stops them. Replying "stop" works too. We never use e-mail addresses we receive from Shopify for these e-mails.
6. Visitors to our website
When you visit tikratracking.com (including the legal pages, the status page and the sign-in pages), Cloudflare processes your IP address and browser details to deliver and secure the pages. Request logs are kept for 7 days. Legal basis: our legitimate interest in operating and securing the site (Art. 6(1)(f) GDPR).
We set only the cookies the Service needs:
| Cookie | Purpose | Lifetime |
|---|---|---|
__Host-trk_session | Keeps a user signed in to the web dashboard. Set only when you sign in. | 30 days, or until you sign out |
__Host-trk_oauth | Links your browser to a Shopify installation you started, to protect that step | 10 minutes |
Inside the Shopify admin, our app uses Shopify's session tokens instead of these cookies. We use no analytics or advertising cookies, and no other technology that reads information from your device for analytics or advertising.
7. Why we use merchant data and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the Service: running your account, sending your orders to your platforms, monitoring, the service guarantee, support | Performance of our contract with you (Art. 6(1)(b) GDPR). For staff of a company that is our customer: our legitimate interest in providing the Service to their employer (Art. 6(1)(f)). |
| Recording the acceptance of our Terms and Data Processing Agreement | Performance of our contract with you, and our legal obligation to have a written processing agreement (Art. 6(1)(b) and (c), Art. 28(9) GDPR) |
| Billing, accounting and tax records | Legal obligation (Art. 6(1)(c)) under Lithuanian accounting and tax law |
| Security of the Service, audit logs, abuse and fraud prevention | Legitimate interest in keeping the Service and our customers' data secure (Art. 6(1)(f)) |
| Service messages: incidents, guarantee credits, changes to the Service or to our terms and a weekly report about your store's tracking while your store is on a plan and you keep the report on (orders sent to each platform, orders skipped and why, incidents, how many orders carried each advertising identifier; it contains no offers, and you can stop it from any report with one click) | Performance of contract, and legitimate interest (Art. 6(1)(b) and (f)) |
| Offers for our plans and updates on your free diagnosis: the 12-hour offer e-mail and the weekly summary, sent only while your store is on the free diagnosis | Your consent (Art. 6(1)(a) GDPR and Art. 81 of the Lithuanian Law on Electronic Communications), given by the holder of the address by ticking an unticked box in the app. You can withdraw it at any time: every such e-mail has a link that stops them with one click, and mail apps that show an unsubscribe button stop them with that button. Service and incident e-mails are not affected. |
| Product analytics: which steps stores complete and which listing sources bring installs (section 5); not used for advertising and not shared | Legitimate interest in improving the Service (Art. 6(1)(f)) |
| Improving the Service, using operating data without personal data where possible | Legitimate interest (Art. 6(1)(f)) |
You need to give us a working contact e-mail address, and for stores outside Shopify your billing details, to use the Service. Without them we cannot provide or bill the Service. Shopify gives us the shop owner's name and e-mail address when the app is installed. The rest of the data is created as you use the Service.
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
8. Who receives merchant data
- Our service providers: Cloudflare (hosting, database, storage, forwarding of e-mail sent to our addresses, and delivery of our internal alert e-mails to our own mailbox), Google (Google Workspace, which holds our support mailbox and our own mailbox for internal alerts), Stripe (billing for merchants not billed through Shopify, when used), the provider that sends our e-mail (Resend, when used) and Anthropic, under its commercial terms (AI-assisted operations sessions, which see store domains, delivery figures, order-level records and support messages; and the fix plan shown with the free diagnosis, for which the Claude API receives only the diagnosis findings: counts, percentages and dates, without the store's name or domain and without any personal data). The full list is at https://tikratracking.com/legal/subprocessors.
- Our on-call person is alerted through Telegram, and for urgent alerts also through Pushover (Pushover, LLC, United States), which rings a phone. Such an alert names a store only by an internal reference code, never by its name or domain, and contains no customer data. It can include the platform concerned, delivery counts and percentages, the cause and the times of an incident, a plan a store chose, billing details (a plan, its status, the billing provider and its subscription identifier), an error message, a privacy request's reference and due date, and a link to our admin tools. Telegram also gets a daily summary of the alerts, with the same limits. If Telegram cannot deliver an urgent alert, the alert is sent by e-mail to our own mailbox instead, with the same limits: an incident about your store's deliveries is e-mailed as its headline only (its type, the reference code and the platform concerned) with a link to our admin tools, and its delivery figures, cause and clock stay there; any other alert is e-mailed with its text.
- Shopify, for stores that use our Shopify app, including for billing through Shopify.
- The platforms you connect, which receive the access keys you gave us, or that Meta issued to us when you connected with your Meta login, when we send your orders to them.
- Our professional advisers (accountant, lawyer) and insurers, under confidentiality.
- Authorities, when the law requires it.
9. International transfers
Cloudflare, Google, Stripe, Resend and Anthropic may process data outside the EEA, including in the United States. Where they do, the transfer is covered by the EU-U.S. Data Privacy Framework certification of the provider or by the EU Standard Contractual Clauses. You can ask us for a copy of the clauses at privacy@tikratracking.com.
Pushover processes our urgent alerts in the United States and offers no data processing terms. These alerts carry no customer data and never a store's name, domain or e-mail address. They name a store only by a reference code made with a key that only we hold, and every alert text passes a filter that replaces store identifiers and the domain names and e-mail addresses it recognises before it is sent (section 8).
10. How long we keep merchant data
| Data | Retention |
|---|---|
| Store, account and settings data | While you use the Service. Deleted when you uninstall the Shopify app (an interrupted deletion is finished within the hour). For other stores, deleted within 30 days after your subscription ends. |
| Record of the acceptance of our terms | While the store's other records are kept; deleted with them at uninstall |
| Platform access keys | Deleted when you disconnect the platform, when you uninstall the Shopify app, or, for other stores, within 30 days after your subscription ends. An access token Meta issued through Connect with Meta, with the Meta IDs we keep for it, is also deleted at once when Meta sends us a data deletion request for it. After you disconnect a Meta connection made with Connect with Meta, we keep your Meta business ID and the keyed hashes (never the token), so the Meta card can link to Connected apps in your Meta business and we can act on Meta's notices about it. Connecting with Connect with Meta again replaces them. They are deleted when Meta tells us that access was removed or sends a data deletion request, or with your store's other records (at uninstall, or for other stores within 30 days after your subscription ends). |
| Pixel list from Connect with Meta | Until you choose a pixel; unusable after 1 hour and deleted within 2 hours |
| Notification contacts | While you use the Service. A shop owner address that changes in Shopify is replaced at our next weekly check. Deleted with the store's other records when you uninstall the app. |
| Log of notices we sent | 90 days, or sooner when the store's records are deleted after uninstall. A notice about an incident is kept while the incident is open and for 90 days after it closes. A notice about a platform key problem is kept while the problem lasts, so the same notice is not sent twice. Daily digests and system alerts that are not linked to a store: 30 days. |
| Audit log | 24 months |
| Sign-in links | Valid for 15 minutes, single use, deleted within about a day after they expire |
| Login sessions | End after 30 days, or at once when you log out or the user is removed |
| Rate-limit records | About a day |
| Website request logs | 7 days |
| Product analytics records (section 5) | While the app is installed. Within 30 days after uninstall, the store's records are turned into monthly totals without any store code, and deleted. The totals are kept 36 months. |
| Billing records | Invoices, payment records and other accounting documents: 10 years. Our contract with you and the records that prove it: 10 years after the contract ends. These are the minimum periods of the Lithuanian Internal Administration Documents Retention Index (items 3.15, 3.19 and 3.24). The Stripe and Shopify IDs and statuses we keep in the Service, and the Service's own billing rows (charges for extra orders, guarantee credits, monthly order counts and the invoice lines of a plan by agreement), are deleted with your store's other records; the audit log keeps the entries about each charge and credit for 24 months. |
| Support e-mails | 3 years after the conversation ends. If a dispute needs them, we keep them until it is settled. |
| Encrypted database backups | 20 days |
| Restore journal (records of erasures, uninstalls and reinstalls, disconnected platforms and Meta access deleted on Meta's request, with their emptied encrypted settings, consent mode changes and removed logins, applied again if a backup is ever restored; a removed login only as the SHA-256 hash of its e-mail address) | 28 days |
| Our database provider's point-in-time history | 30 days; it cannot be shortened. Every copy of deleted data is gone within 30 days after the deletion. |
11. Your rights
Your right to object. Where we rely on our legitimate interests (section 7), you can object at any time for reasons related to your situation. We then stop, unless we have compelling legitimate grounds or need the data for legal claims. You can object to direct marketing at any time, without giving a reason, and we then stop.
If our processing of your data is covered by the GDPR, you also have the right to:
- access your data and receive a copy;
- have incorrect data corrected;
- have your data erased;
- restrict the processing;
- receive your data in a portable format; and
- withdraw consent where we rely on it, without affecting earlier processing.
To use these rights, write to privacy@tikratracking.com. We answer within one month. We may extend this by two further months for complex requests and will tell you why.
If you connected Meta with your Meta login, you can also remove our access in Meta: in your business settings, open Integrations, then Connected apps, and remove Tikra. When Meta tells us that access was removed, we treat the saved key like any key that stops working: your orders for Meta are held until the key works again or you connect again. When Meta sends us a data deletion request, we delete the access token and the Meta IDs we kept for it at once, and Meta shows you a link where you can check that the request was done.
12. Complaints
You may complain to the Lithuanian supervisory authority:
Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate)
L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
E-mail: ada@ada.lt
Telephone: +370 5 271 2804
Website: https://vdai.lrv.lt
You may also complain to the supervisory authority where you live or work, or where you think the infringement took place. We would like to hear from you first, so we can try to solve the problem.
13. Security
We protect data with encryption in transit and at rest, a separate encryption key for each store, hashing of shoppers' contact details, admin tools that require both a secret key and a separate login through Cloudflare Access, an audit log and a written incident response plan. If a personal data breach affects your data, we inform you as the law and our Data Processing Agreement require.
14. For your store's cookie notice
On Shopify stores our web pixel sets no cookies. With the shopper's consent it reads existing cookies: _fbp, _fbc, _gcl_aw, _ttp, _epik and _scid with marketing consent, and _ga and _ga_<property> with analytics consent (to find the _ga_<property> cookies it reads the browser's cookie string and uses nothing else from it). With marketing consent it keeps these items in the browser's storage:
| Key | Browser storage | Purpose | How long it is used | Category |
|---|---|---|---|---|
tikra_clicks | Local storage | Keeps the ID of the ad the shopper clicked, so that a later purchase can be reported to that advertising platform | 90 days from the click; an older click is ignored | Marketing |
tikra_fbp | Local storage | A browser ID in Meta's format, made only when the store has no Meta _fbp cookie, so that the shopper's store events and purchase can be matched in Meta | 90 days from its creation; then a new one is made | Marketing |
tikra_ic | Local storage | Remembers, without the checkout token itself, that a checkout was already reported, so that it is reported once | 24 hours per entry | Marketing |
Browser storage has no expiry of its own: the pixel ignores an entry past its time and removes or replaces it the next time it reads that key (tikra_clicks at the next ad click, at checkout, and on every page of a store that gets store events; tikra_fbp when it needs a browser ID, otherwise it stays until a page opens without marketing consent; tikra_ic at the next checkout step). It deletes all three when the shopper withdraws marketing consent and when a page opens without marketing consent (for example after a Global Privacy Control opt-out). On a store's free diagnosis the pixel keeps tikra_clicks and reads the cookies above in the same way; our server then keeps only the shopper's consent decision.
On WooCommerce stores our plugin sets first-party cookies on your domain. _tikra_gclid, _tikra_gbraid, _tikra_wbraid, _tikra_ttclid, _tikra_epik, _tikra_sccid and _tikra_fbc hold the advertising click ID from the landing page for 90 days. They are set with marketing consent and, in standard mode, also on stores without a supported consent tool, for every visitor. _tikra_consent keeps a copy of the consent tool's choices for 180 days. With the matching consent the plugin also reads _fbp, _fbc, _gcl_aw, _epik, _ga and _ga_<stream>. Section I of Annex 1 to our Data Processing Agreement has the details.
Describe this in your cookie notice under the purposes your consent banner uses.
15. Children
The Service is for businesses. It is not directed at children, and we do not knowingly process children's data as a controller.
16. Changes
We may update this policy. We tell merchants about material changes by e-mail and in the dashboard before they apply. The version and date at the top show the latest version. Earlier versions stay readable at https://tikratracking.com/legal/privacy followed by a slash and the version name.
17. Notice for residents of US states
Shoppers: we process your data for the store, on its instructions. To use your rights, including the right to opt out of the sale or sharing of your data or of targeted advertising, use the store's privacy settings or contact the store. When you opt out through a Shopify store's privacy settings, we stop sending your orders and store events to advertising and e-mail marketing platforms (section 3.3).
Merchants and their staff: in the last 12 months we collected the categories of data in section 5: identifiers (such as name, e-mail address, IP address and account IDs), commercial information (plan and billing records), internet activity (sign-in and audit records) and professional information (your store and role). We collected them from the sources in section 5, used them for the purposes in section 7, and disclosed them for those purposes to the recipients in section 8. We do not sell or share this data, as the California Consumer Privacy Act defines those words, and we did not do so in the last 12 months. We use sensitive data, such as the access keys to your platform accounts, only to provide the Service. We keep the data for the periods in section 10.
You may ask to know, correct or delete your data. Write to privacy@tikratracking.com from the e-mail address on your account, or through an authorised agent with your signed permission. We check that the request comes from you before we act on it. We will not treat you differently for using these rights.
MB Euruvizija, company code 307863521, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania. support@tikratracking.com