Tikra sub-processors and data recipients
Provider: MB Euruvizija, a small partnership (mažoji bendrija) registered in the Register of Legal Entities of the Republic of Lithuania, company code 307863521, registered office V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania, e-mail support@tikratracking.com ("we").
This page is part of the Data Processing Agreement (DPA, section 8 and Annex 3) at https://tikratracking.com/legal/dpa. It has three parts:
- Part A lists the sub-processors that process personal data of the merchant's customers and store visitors on our behalf.
- Part B lists service providers that process data about merchants themselves (account, login, billing and support data), where we are the controller.
- Part C explains Shopify and the advertising and analytics platforms. They receive or provide data in the Service but are not our sub-processors.
This is the pilot version of this page. A lawyer has not reviewed it yet.
Part A. Sub-processors for the merchant's customer data
| Sub-processor | Service it provides to us | Personal data it processes | Where the data is | Transfer safeguards |
|---|---|---|---|---|
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA | Runs the Service: application code (Workers), database (D1), job queues (Queues, including the queue that carries store events for at most 1 day), object storage (R2) for order copies, nightly backups and data export files, and request logs (7 days) | All categories in DPA Annex 1: hashed identifiers, encrypted IP addresses, user agents, click and cookie identifiers, consent flags, order data, store events while they wait in the queue, counts of store events, and for up to 30 days a minimal order copy for re-sending (no addresses and no IP addresses; the e-mail address, phone number and first name only for stores with Klaviyo connected, encrypted with the store's own key) | Stored data: D1 database and R2 buckets in Cloudflare's EU jurisdiction (data stored in the EU). The queue that carries store events (at most 1 day) may be processed outside that jurisdiction, and the request logs (7 days) are stored in the United States (DPA section 14.1). Processing in memory: Cloudflare data centres worldwide, usually the one nearest to the sender of each request (Shopify's servers, the shopper's browser). | Cloudflare's certification under the EU-U.S. Data Privacy Framework; where that does not apply, the Cloudflare Customer DPA version 6.4 of 3 April 2026, part of Cloudflare's subscription agreement: EU Standard Contractual Clauses (Module 3, processor to processor), UK Addendum and Swiss amendments |
| Anthropic Ireland, Limited, Ireland, with its affiliate Anthropic, PBC, San Francisco, CA, USA | AI-assisted operator sessions (Claude) for monitoring, incident work, engineering and support (DPA section 6.2) | Order-level records returned by our admin API: order IDs and numbers, payment times, amounts, consent decisions, delivery statuses and platform error texts, and store domains; support messages that our AI-assisted sessions read and draft replies to. No contact data of shoppers, hashes, IP addresses or stored order copies. | Ireland and USA | Anthropic's Commercial Terms of Service, which incorporate Anthropic's Data Processing Addendum with the EU Standard Contractual Clauses (Modules 2 and 3). Anthropic may not train models on this data and must keep it confidential. Sessions run only under these terms, never under a consumer plan. |
Cloudflare's own sub-processors are listed at https://www.cloudflare.com/gdpr/subprocessors/. Anthropic's own sub-processors are listed at https://trust.anthropic.com/subprocessors.
Security of the data held at Cloudflare is described in DPA Annex 2. In short: D1 and R2 encrypt all stored data with AES-256-GCM (keys managed by Cloudflare). On top of that, the Service stores e-mail addresses, phone numbers, names, cities, regions and postal codes only as SHA-256 hashes in the database, encrypts IP addresses and platform credentials with a separate key per store (AES-256-GCM), and encrypts backups with its own key. Store events are not stored as such: only daily counts are, with no personal data.
Since 2026-09-28 the order copy in R2 is minimal; copies stored before then are deleted within 30 days.
Part B. Service providers for merchant account, login, billing and support data
For this data we are the controller. The providers below never receive personal data of the merchant's customers. The list is here so merchants see every party involved.
| Provider | What it does for us | Merchant data it processes | Where | Safeguards |
|---|---|---|---|---|
| Google (Google Workspace), with Cloudflare Email Routing forwarding our addresses support@, privacy@ and ops@ to it | Support mailbox | Messages merchants send us, with the sender's name and e-mail address | Per Google's terms, including the USA | Google Cloud Data Processing Addendum |
| Anthropic Ireland, Limited, with Anthropic, PBC (Claude API) | Writes the short fix plan shown with the free diagnosis | The diagnosis findings of one store: codes, counts, percentages and UTC dates. No store name or domain, no customer data, no access keys. Without an API key, or when the call fails, a fixed template is used instead. | Ireland and USA | Anthropic's Commercial Terms of Service with its Data Processing Addendum (EU Standard Contractual Clauses). Anthropic may not train models on this data and must keep it confidential. These terms also cover the per-store figures, which are Merchant Data under Shopify's API terms. |
| Stripe Payments Europe, Limited (Ireland), with Stripe, Inc. (USA), when a merchant pays through Stripe | Subscriptions, invoices, tax calculation and payments for merchants that are not billed through Shopify (WooCommerce, custom stores, direct contracts). Card and SEPA Direct Debit. | Name, billing address, VAT number, e-mail, payment method details, invoices. We store only the Stripe customer ID, subscription ID and subscription status. | EEA and USA | Stripe DPA (updated 18 November 2025): Stripe acts as our processor for billing, and as an independent controller for fraud prevention, loss prevention and legal compliance. EU-U.S. Data Privacy Framework, EU Standard Contractual Clauses, UK Addendum. |
| Plus Five Five, Inc. (trading as Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA, when the Service sends e-mail | Sends e-mail: dashboard sign-in links, and service and incident notices to merchant contacts | Recipient e-mail address, message content (sign-in link, store name, incident details), delivery logs | USA. Resend states that customer data is stored in the United States. | Resend DPA (2025-12-31): EU Standard Contractual Clauses Module 2, UK Addendum, EU-U.S. Data Privacy Framework and UK Extension |
| Telegram (operator of the Telegram messenger) | Wakes our on-call person with a short alert | Only an internal alert number, its type and its severity. No store name or domain, platform, figures or customer data. The details stay in our admin console. | Telegram states that data of EEA users is stored in the Netherlands | Telegram offers no data processing terms. For that reason our alerts through Telegram carry no Merchant Data and no personal data of merchants or their customers. |
Part C. Parties that are not our sub-processors
Shopify
Shopify is the merchant's commerce platform. The merchant installs Tikra from Shopify and authorises it to read orders and to run our web pixel. Shopify then sends us each paid order (webhook orders/paid), lets us read orders through its Admin API, and passes the store's customer events to our pixel. Shopify also bills App Store subscriptions through the Shopify Billing API. We do not engage Shopify to process the merchant's customer data for us. Shopify's own terms with the merchant govern Shopify's processing.
Advertising and analytics platforms
The Service sends a purchase event for each eligible order, and, once a platform gets them (Terms, section 3.8), store events, to the platforms the merchant connects in the dashboard. The merchant chooses these platforms, holds the accounts, accepts each platform's terms and gives us the access keys. We send data to a platform only while the merchant keeps it connected, and only when the shopper's consent allows it (DPA section 5 and Annex 1).
The platforms are recipients that the merchant chooses (Art. 4(9) GDPR). The merchant contracts with each of them. We do not engage them to process the merchant's customer data for us, so they are not our sub-processors. Each platform's terms set its role towards the merchant. For example, Meta and the business are joint controllers for the collection and transmission of event data, and Meta is a controller for what it does with the data afterwards (Meta Controller Addendum). Other platforms act as the merchant's processor or as a controller under their own terms.
This table lists the platforms merchants can connect today. When we add a platform, we add it here, with the date, before it appears in the dashboard. No data reaches a platform until a merchant connects it.
| Platform | API | Consent needed | Data sent |
|---|---|---|---|
| Meta (Facebook, Instagram) | Conversions API v26.0 | Marketing | Purchases: SHA-256 hashes of e-mail, phone, first name, last name, city, region, postal code, country and customer ID, and the hashed visitor ID when our pixel sent it; Meta browser IDs (_fbp, or our own browser ID in Meta's format when the store has no _fbp, and _fbc); full IP address; user agent; page URL; order ID, value, currency, product IDs, quantities, prices. Store events, once Meta gets them: event name, event ID and time, page address without query, product IDs, quantities, prices, value, currency; SHA-256 hashes of the shopper's browser ID and customer ID, and at checkout of the e-mail address and phone number; full IP address; user agent; Meta browser IDs or our own browser ID in Meta's format. Search terms are never sent. |
| Google Analytics 4 | Measurement Protocol | Analytics | Purchases only: GA client ID and session ID (or an ID made from the order ID and payment time when there is no GA cookie); order ID, the order subtotal as value, tax, shipping, currency, items (SKU or product ID, name, quantity, price); consent signals ad_user_data and ad_personalization (DENIED unless the shopper gave marketing consent and did not opt out of the sale or sharing of data). No e-mail, phone, name, address or IP. |
Notes:
- Test orders are never sent to live platform accounts.
- On the date of this version, no platform gets store events yet: the Service counts them for Meta first and compares the counts with Meta's own before it sends any.
Platforms connected earlier
A store that connected one of these platforms before this version keeps it until it disconnects it. They receive purchases only:
| Platform | API | Consent needed | Data sent |
|---|---|---|---|
| Google Ads | Data Manager API v1 | Marketing | SHA-256 hashes of e-mail, phone, first name and last name; postal code and country code without hashing (Google requires them in plain form); one click ID (gclid, wbraid or gbraid); user agent; IP address only for buyers outside the EEA, UK and Switzerland; order ID, value, currency; consent flags |
| TikTok | Events API v1.3 | Marketing | SHA-256 hashes of e-mail, phone and customer ID (the hashed visitor ID when the order has no customer ID); TikTok click ID and the _ttp cookie ID; IP address; user agent; page URL; order ID, value, currency, product IDs, quantities, prices |
| Conversions API v5 | Marketing | SHA-256 hashes of e-mail, phone, first name, last name, city, country and customer ID (region and postal code only for US addresses), and the hashed visitor ID when our pixel sent it; Pinterest click ID (from the landing page or the _epik cookie); IP address; user agent; page URL; order ID, the order subtotal as value, currency, product IDs, quantities, prices | |
| Snapchat | Conversions API v3 | Marketing | SHA-256 hashes of e-mail, phone, first name, last name, city, region, postal code, country and customer ID (the hashed visitor ID when the order has no customer ID); Snap click ID and the _scid cookie ID; IP address; user agent; page URL; order ID, value, currency, product IDs, quantities, prices |
| Klaviyo | Create Event API (revision 2026-07-15) | Marketing | E-mail address, phone number and first name in plain text (Klaviyo cannot match hashes), order ID and number, item names, SKUs, quantities, prices, value, currency. For a store with Klaviyo connected, the Service keeps these three fields in the order copy, encrypted with the store's own key, and decrypts them only at the moment of sending. |
Planned changes
These are not in use. Each would be added to this page, with notice under DPA section 8 where Part A changes, before any data reaches it.
| Provider | Purpose | Status |
|---|---|---|
| Anthropic Ireland, Limited, with Anthropic, PBC (Claude API) | In-app assistant that answers merchants' questions about their store's tracking | Planned. Before launch we add it to Part B, and to Part A with 30 days' notice if it sees order-level data. |
| Sentry (Functional Software, Inc.) | Error tracking | Planned in the design, not integrated. It would be configured to receive no personal data. |
| Backblaze B2 or Amazon S3 (Frankfurt region) | Second, encrypted copy of backups outside Cloudflare | Planned in the design (weekly copy), not built |
Changes to this list
We tell merchants about a new or replaced sub-processor in Part A at least 30 days before it starts processing their customers' data, by e-mail to the account contacts and by a notice in the dashboard. The notice names the sub-processor, its address, what it will do, where it will process the data and the transfer safeguards. A merchant may object within 15 days after the notice, as described in DPA section 8.4. Our sub-processors notify changes to their own sub-processors under their own terms, and we pass these changes on without undue delay. Changes to Part B and to the platforms in Part C are made on this page, with the date. Shopify merchants: notices go to the shop owner's e-mail address, which the Service reads from Shopify, and to any other address the merchant gives us.
MB Euruvizija, company code 307863521, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania. support@tikratracking.com