Tikra legal texts

Tikra sub-processors and data recipients

Version 2026-10-04-pilot. Last updated 4 October 2026.

Earlier versions of this text carried a version name and a date later than the day we published them. Since 2 October 2026 both are the day of publication, and the page of each earlier version shows the day it was last updated.

Provider: MB Euruvizija, a small partnership (mažoji bendrija) registered in the Register of Legal Entities of the Republic of Lithuania, company code 307863521, registered office V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania, e-mail support@tikratracking.com ("we").

This page is part of the Data Processing Agreement (DPA, section 8 and Annex 3) at https://tikratracking.com/legal/dpa. It has three parts:

This is the pilot version of this page. A lawyer has not reviewed it yet.

Part A. Sub-processors for the merchant's customer data

Sub-processorService it provides to usPersonal data it processesWhere the data isTransfer safeguards
Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USARuns the Service: application code (Workers), database (D1), job queues (Queues, including the queue that carries store events for at most 1 day), object storage (R2) for order copies, nightly backups and data export files, and request logs (7 days)All categories in DPA Annex 1: hashed identifiers, encrypted IP addresses, user agents, click and cookie identifiers, consent flags, order data, store events while they wait in the queue, counts of store events, and for up to 30 days a minimal order copy for re-sending (no addresses and no IP addresses; the e-mail address, phone number and first name only for stores with Klaviyo connected, encrypted with the store's own key)Stored data: D1 database and R2 buckets in Cloudflare's EU jurisdiction (data stored in the EU). The queue that carries store events (at most 1 day) may be processed outside that jurisdiction, and the request logs (7 days) are stored in the United States (DPA section 14.1). Processing in memory: Cloudflare data centres worldwide, usually the one nearest to the sender of each request (Shopify's servers, the shopper's browser).Cloudflare's certification under the EU-U.S. Data Privacy Framework; where that does not apply, the Cloudflare Customer DPA version 6.4 of 3 April 2026, part of Cloudflare's subscription agreement: EU Standard Contractual Clauses (Module 3, processor to processor), UK Addendum and Swiss amendments
Anthropic Ireland, Limited, Ireland, with its affiliate Anthropic, PBC, San Francisco, CA, USAAI-assisted operator sessions (Claude) for monitoring, incident work, engineering and support (DPA section 6.2)Order-level records returned by our admin API: order IDs and numbers, payment times, amounts, consent decisions, delivery statuses and platform error texts, and store domains; support messages that our AI-assisted sessions read and draft replies to. No contact data of shoppers, hashes, IP addresses or stored order copies.Ireland and USAAnthropic's Commercial Terms of Service, which incorporate Anthropic's Data Processing Addendum with the EU Standard Contractual Clauses (Modules 2 and 3). Anthropic may not train models on this data and must keep it confidential. Sessions run only under these terms, never under a consumer plan.

Cloudflare's own sub-processors are listed at https://www.cloudflare.com/gdpr/subprocessors/. Anthropic's own sub-processors are listed at https://trust.anthropic.com/subprocessors.

Security of the data held at Cloudflare is described in DPA Annex 2. In short: D1 and R2 encrypt all stored data with AES-256-GCM (keys managed by Cloudflare). On top of that, the Service stores e-mail addresses, phone numbers, names, cities, regions and postal codes only as SHA-256 hashes in the database, encrypts IP addresses and platform credentials with a separate key per store (AES-256-GCM), and encrypts backups with its own key. Store events are not stored as such: only daily counts are, with no personal data.

Since 2026-09-28 the order copy in R2 is minimal; copies stored before then are deleted within 30 days.

Part B. Service providers for merchant account, login, billing and support data

For this data we are the controller. The providers below never receive personal data of the merchant's customers. The list is here so merchants see every party involved.

ProviderWhat it does for usMerchant data it processesWhereSafeguards
Google (Google Workspace), with Cloudflare Email Routing forwarding our addresses support@, privacy@ and ops@ to it and delivering our alert e-mails to itSupport mailbox, and our own mailbox for internal alerts that our alert messenger could not deliverMessages merchants send us, with the sender's name and e-mail address. Alert e-mails: the alert's type and severity and its text, which names a store only by a reference code (never its name or domain) and can include the platform concerned, delivery counts, a plan a store chose, an error message, a privacy request's reference and due date, and times; an incident about a store's deliveries is e-mailed as its headline only, with a link to our admin console (its delivery figures, cause and clock stay there); any other alert with its text; no customer dataPer Google's terms, including the USAGoogle Cloud Data Processing Addendum
Anthropic Ireland, Limited, with Anthropic, PBC (Claude API)Writes the short fix plan shown with the free diagnosisThe diagnosis findings of one store: codes, counts, percentages and UTC dates. No store name or domain, no customer data, no access keys. Without an API key, or when the call fails, a fixed template is used instead.Ireland and USAAnthropic's Commercial Terms of Service with its Data Processing Addendum (EU Standard Contractual Clauses). Anthropic may not train models on this data and must keep it confidential. These terms also cover the per-store figures, which are Merchant Data under Shopify's API terms.
Stripe Payments Europe, Limited (Ireland), with Stripe, Inc. (USA), when a merchant pays through StripeSubscriptions, invoices, tax calculation and payments for merchants that are not billed through Shopify (WooCommerce, custom stores, direct contracts). Card and SEPA Direct Debit.Name, billing address, VAT number, e-mail, payment method details, invoices. We store only the Stripe customer ID, subscription ID and subscription status.EEA and USAStripe DPA (updated 18 November 2025): Stripe acts as our processor for billing, and as an independent controller for fraud prevention, loss prevention and legal compliance. EU-U.S. Data Privacy Framework, EU Standard Contractual Clauses, UK Addendum.
Plus Five Five, Inc. (trading as Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA, when the Service sends e-mailSends e-mail: dashboard sign-in links, and service and incident notices to merchant contactsRecipient e-mail address, message content (sign-in link, store name, incident details), delivery logsUSA. Resend states that customer data is stored in the United States.Resend DPA (2025-12-31): EU Standard Contractual Clauses Module 2, UK Addendum, EU-U.S. Data Privacy Framework and UK Extension
Telegram (operator of the Telegram messenger)Wakes our on-call person with short alerts, and sends us a daily summary of themThe alert's type and severity and its text. A store is named only by a reference code, never by its name or domain. An alert can include the platform concerned, delivery counts and percentages, the cause and the times of an incident, a plan a store chose, billing details (a plan, its status, the billing provider and its subscription identifier), an error message, a privacy request's reference and due date, and a link to our admin console. No customer data and no contact details.Telegram states that data of EEA users is stored in the NetherlandsTelegram offers no data processing terms. For that reason our alerts carry no customer data and never a store's name, domain or e-mail address: the reference code is made with a key only we hold, so it cannot be linked to a store outside our systems, and every alert text passes a filter that replaces store identifiers and the domain names and e-mail addresses it recognises before it is sent.
Pushover, LLC, USARings our on-call person's phone for urgent alertsThe urgent alerts that also go to Telegram (not the daily summary), with the same content and the same limits as in the Telegram row. No customer data and no contact details.USA. Pushover states that it processes data on servers in the United States and deletes a message from them once it reached the phone, or after 21 days when that cannot be confirmed.Pushover offers no data processing terms. For that reason these alerts carry no personal data of customers and never a store's name, domain or e-mail address, with the same safeguards as the Telegram row: the reference code is made with a key only we hold, so it cannot be linked to a store outside our systems, and every alert text passes a filter that replaces store identifiers and the domain names and e-mail addresses it recognises before it is sent.

Part C. Parties that are not our sub-processors

Shopify

Shopify is the merchant's commerce platform. The merchant installs Tikra from Shopify and authorises it to read orders and to run our web pixel. Shopify then sends us each paid order (webhook orders/paid), lets us read orders through its Admin API, and passes the store's customer events to our pixel. Shopify also bills App Store subscriptions through the Shopify Billing API. We do not engage Shopify to process the merchant's customer data for us. Shopify's own terms with the merchant govern Shopify's processing.

Advertising and analytics platforms

The Service sends a purchase event for each eligible order, and, once a platform gets them (Terms, section 3.8), store events, to the platforms the merchant connects in the dashboard. The merchant chooses these platforms, holds the accounts, accepts each platform's terms and gives us the access keys. We send data to a platform only while the merchant keeps it connected, and only when the shopper's consent allows it (DPA section 5 and Annex 1).

The platforms are recipients that the merchant chooses (Art. 4(9) GDPR). The merchant contracts with each of them. We do not engage them to process the merchant's customer data for us, so they are not our sub-processors. Each platform's terms set its role towards the merchant. For example, Meta and the business are joint controllers for the collection and transmission of event data, and Meta is a controller for what it does with the data afterwards (Meta Controller Addendum). Other platforms act as the merchant's processor or as a controller under their own terms.

This table lists the platforms merchants can connect today. When we add a platform, we add it here, with the date, before it appears in the dashboard. No data reaches a platform until a merchant connects it.

PlatformAPIConsent neededData sent
Meta (Facebook, Instagram)Conversions API v26.0MarketingPurchases: SHA-256 hashes of e-mail, phone, first name, last name, city, region, postal code, country and customer ID, and the hashed visitor ID when our pixel sent it; Meta browser IDs (_fbp, or our own browser ID in Meta's format when the store has no _fbp, and _fbc); full IP address; user agent; page URL; order ID, value, currency, product IDs, quantities, prices; when the store turns on customer type, whether the customer is new or returning and, if the store chooses it, a second event PurchaseNewCustomer. Store events, once Meta gets them: event name, event ID and time, page address without query, product IDs, quantities, prices, value, currency; SHA-256 hashes of the shopper's browser ID and customer ID, and at checkout of the e-mail address and phone number; full IP address; user agent; Meta browser IDs or our own browser ID in Meta's format. Search terms are never sent.
Google Analytics 4Measurement Protocol, through Google's EU collection endpointAnalyticsPurchases, and refunds of purchases it received: GA client ID and session ID (or an ID made from the order ID and payment time when there is no GA cookie); order ID, value (the items' prices after discounts, without tax and shipping), tax, shipping, currency, items (SKU or product ID, name, quantity, price after discounts, discount); consent signals ad_user_data and ad_personalization (DENIED unless the shopper gave marketing consent and did not opt out of the sale or sharing of data); for stores whose accepted DPA lists them (Annex 1, F.2), the shopper's IP address shortened to its first three parts (IPv4) or first 48 bits (IPv6), and the device type, operating system and browser name read from the user agent. For a refund: the order ID, the refunded value, tax, shipping, currency and refunded items. When the store turns on customer type: whether the customer is new or returning. No e-mail, phone, name, address, full IP address or user agent.

Notes:

Platforms connected earlier

A store that connected one of these platforms before this version keeps it until it disconnects it. They receive purchases only:

PlatformAPIConsent neededData sent
Google AdsData Manager API v1MarketingSHA-256 hashes of e-mail, phone, first name and last name; postal code and country code without hashing (Google requires them in plain form); one click ID (gclid, wbraid or gbraid); user agent; IP address only for buyers outside the EEA, UK and Switzerland; order ID, value, currency; consent flags
TikTokEvents API v1.3MarketingSHA-256 hashes of e-mail, phone and customer ID (the hashed visitor ID when the order has no customer ID); TikTok click ID and the _ttp cookie ID; IP address; user agent; page URL; order ID, value, currency, product IDs, quantities, prices
PinterestConversions API v5MarketingSHA-256 hashes of e-mail, phone, first name, last name, city, country and customer ID (region and postal code only for US addresses), and the hashed visitor ID when our pixel sent it; Pinterest click ID (from the landing page or the _epik cookie); IP address; user agent; page URL; order ID, the order subtotal as value, currency, product IDs, quantities, prices
SnapchatConversions API v3MarketingSHA-256 hashes of e-mail, phone, first name, last name, city, region, postal code, country and customer ID (the hashed visitor ID when the order has no customer ID); Snap click ID and the _scid cookie ID; IP address; user agent; page URL; order ID, value, currency, product IDs, quantities, prices
KlaviyoCreate Event API (revision 2026-07-15)MarketingE-mail address, phone number and first name in plain text (Klaviyo cannot match hashes), order ID and number, item names, SKUs, quantities, prices, value, currency. For a store with Klaviyo connected, the Service keeps these three fields in the order copy, encrypted with the store's own key, and decrypts them only at the moment of sending.

Planned changes

These are not in use. Each would be added to this page, with notice under DPA section 8 where Part A changes, before any data reaches it.

ProviderPurposeStatus
Anthropic Ireland, Limited, with Anthropic, PBC (Claude API)In-app assistant that answers merchants' questions about their store's trackingPlanned. Before launch we add it to Part B, and to Part A with 30 days' notice if it sees order-level data.
Sentry (Functional Software, Inc.)Error trackingPlanned in the design, not integrated. It would be configured to receive no personal data.
Backblaze B2 or Amazon S3 (Frankfurt region)Second, encrypted copy of backups outside CloudflarePlanned in the design (weekly copy), not built

Changes to this list

We tell merchants about a new or replaced sub-processor in Part A at least 30 days before it starts processing their customers' data, by e-mail to the account contacts and by a notice in the dashboard. The notice names the sub-processor, its address, what it will do, where it will process the data and the transfer safeguards. A merchant may object within 15 days after the notice, as described in DPA section 8.4. Our sub-processors notify changes to their own sub-processors under their own terms, and we pass these changes on without undue delay. Changes to Part B and to the platforms in Part C are made on this page, with the date. Shopify merchants: notices go to the shop owner's e-mail address, which the Service reads from Shopify, and to any other address the merchant gives us.

MB Euruvizija, company code 307863521, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania. support@tikratracking.com