Privacy Policy
1. Scope
This Privacy Policy describes how Upthink Solutions OÜ collects, uses, stores, and deletes information in connection with GiftTier, our Shopify application that provides tiered free-gift progress bars on merchant storefronts.
GiftTier is an embedded Shopify app. We process merchant store data as needed to provide the Service and to comply with Shopify’s App Store and privacy requirements, including mandatory compliance webhooks.
This Policy is intended to meet Shopify’s App Store privacy disclosure requirements. It is not legal advice. Applicable privacy laws (including GDPR and US state privacy laws) may impose additional obligations depending on your location.
2. Information we collect through Shopify’s APIs
When a merchant installs GiftTier, we access Shopify Admin APIs with the scopes granted during OAuth. We collect and store:
- Shop identifiers — shop domain (e.g.
example.myshopify.com) and related install metadata. - Offline access credentials — OAuth access token (and refresh token when provided) required to sync automatic discounts and validate billing.
- Product / variant identifiers — IDs and titles of products or variants selected as free gifts, plus optional product image URLs.
- Discount identifiers — Shopify Automatic Discount IDs created or updated by GiftTier for free-gift rules.
- Billing subscription metadata — plan status, Shopify app subscription IDs, and charge confirmation state (via Shopify Billing API).
- Theme context — limited information needed to deep-link merchants to Theme Customizer / App embeds (no theme source code is uploaded by GiftTier).
We do not request or store Shopify Protected Customer Data such as customer names, emails, phone numbers, shipping addresses, or order line-item personal details.
3. Information we collect directly from merchants
Through the GiftTier Admin UI, merchants provide configuration such as:
- Reward tier thresholds, reward names, and gift product selections
- Progress bar styling (colors, messages, placement preferences)
- Enable/disable and plan upgrade/downgrade actions
We may also process technical logs related to app usage (for example API errors, webhook delivery acknowledgements, and authentication failures) for reliability and security. We do not ask merchants to upload customer contact lists.
4. Information from merchants’ customers (storefront)
GiftTier’s Theme App Extension runs on the merchant’s storefront to show progress toward free gifts and to reconcile free-gift cart lines.
What we process on-store
- Cart subtotal / line totals needed to evaluate tier thresholds (processed in the shopper’s browser and via Shopify’s Cart Ajax API on the merchant’s domain).
- Cart line properties GiftTier adds to mark free-gift items (e.g.
_gifttier_reward).
What we store on our servers from storefront traffic
- Aggregated analytics events such as bar impressions and gift unlock counts, keyed by shop domain only. We do not store any session, device, or visitor identifier alongside them, nor customer names, emails, IP addresses, or Shopify customer IDs — an event row records the shop, the event type, and which reward tier it related to.
Cookies & tracking
- GiftTier does not drop third-party advertising cookies.
- The storefront script may use browser sessionStorage / local cache on the merchant’s domain solely for UI performance (e.g. restoring bar state). This is not used to track shoppers across sites.
- We do not sell shopper personal information or use storefront data for cross-context behavioral advertising.
5. How we use information
We use the information described above to:
- Provide, operate, and improve GiftTier features (progress bar, gift auto-add, discount sync)
- Authenticate the embedded Admin using Shopify session tokens and maintain the merchant’s installation
- Process freemium / Pro billing through the Shopify Billing API
- Show merchant-facing analytics about GiftTier performance
- Maintain security, prevent abuse, debug failures, and comply with law and Shopify requirements
We do not use merchant or shopper data to build unrelated marketing profiles, and we do not sell personal data.
7. Retention
- While installed: shop settings and access tokens are retained to provide the Service.
- Storefront analytics events: individual event rows (shop domain, event type, reward tier) are deleted automatically after 30 days. The merchant dashboard only ever reads the most recent 14 days. The aggregate per-shop counters shown in that dashboard — total impressions, unlocks and checkout clicks — are running totals and are kept for the life of the install; they contain no shopper, session or device identifier.
- On uninstall: we revoke offline access tokens and disable the app for that shop. Tier configuration may be retained temporarily so a merchant who reinstalls can recover their setup.
- Shop redact (mandatory webhook): after Shopify sends
shop/redact(typically 48 hours after uninstall), we permanently delete the shop’s GiftTier records, including settings, analytics, and remaining credentials. - Customer redact / data request: GiftTier does not store customer PII outside Shopify; we acknowledge these webhooks and have no customer-level records to export or erase.
8. International transfers
Upthink Solutions OÜ is established in Estonia (European Union). Depending on the merchant’s location and our infrastructure, information may be processed in the EU and/or other regions where our processors (including Supabase and Vercel) operate.
Where personal data is transferred internationally, we rely on appropriate safeguards recognized under applicable law (such as Standard Contractual Clauses or equivalent mechanisms provided by our processors).
9. Your rights & Shopify compliance webhooks
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of personal data, and to object to certain processing. Merchants can contact us using the details below. Shoppers should typically contact the merchant first for storefront privacy requests; we support merchants through Shopify’s mandatory webhooks:
customers/data_requestcustomers/redactshop/redact
These endpoints are HMAC-verified and acknowledged in accordance with Shopify’s requirements.
10. Security
We use industry-standard safeguards appropriate to the data we process, including HTTPS/TLS in transit, restricted service-role access to our database, Shopify session-token authentication for Admin API calls, and webhook HMAC verification. No method of transmission or storage is 100% secure; we continuously improve our controls as the Service evolves.
11. Children
GiftTier is designed for use by Shopify merchants in a business context. We do not knowingly collect personal information from children under 16.
12. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be reflected at this URL, which is also linked from the GiftTier Shopify App Store listing.
13. Contact
For privacy questions, data requests, or concerns about GiftTier:
- Controller: Upthink Solutions OÜ
- Jurisdiction: Estonia, European Union
- Email: privacy@upthink.ee
- App: GiftTier — Tiered Free Gifts (Shopify App Store)
If you need a postal address for a jurisdiction-specific request, email us and we will provide our registered office details promptly.