tuki
Privacy Policy
This Privacy Policy describes how tuki (“tuki”, “we”, “us”, or “our”), a Shopify loyalty and rewards application, collects, uses, stores, and shares personal data when merchants install and use the app, and when their customers interact with loyalty features powered by tuki.
tuki is a processor of customer personal data on behalf of the merchant (the controller). Merchants decide how their loyalty program works; we process data only to provide that program and related support.
This policy is not legal advice. Privacy laws vary by jurisdiction. Merchants remain responsible for their own privacy notices and for obtaining any consents required for their storefront.
1. Who this policy covers
- Merchants — store owners and staff who install and configure tuki in Shopify Admin.
- Customers — shoppers whose data merchants process through tuki for loyalty, rewards, referrals, and related features.
2. Personal data we process
2.1 From Shopify (on the merchant’s behalf)
When a merchant installs tuki and grants access scopes, we receive data through Shopify’s Admin API and webhooks as needed to run the loyalty program, including:
- Customer identifiers (Shopify customer ID), email address, first name, and last name
- Email marketing subscription state (to respect marketing consent and, where configured, newsletter earn bonuses)
- Order, refund, fulfilment, and related commerce events needed to award, delay, or claw back points
- Customer tags used for earn rules and VIP tier syncing
- Shop profile details (shop domain, currency, contact email, plan billing status)
We do not store customer phone numbers or postal addresses in tuki’s database for loyalty membership.
2.2 Provided directly by customers
- Birthday — optional, submitted via the storefront widget when the merchant enables birthday earning. Used only to grant birthday bonuses.
- Referral claim context (including IP address used for fraud controls such as velocity limits)
2.3 Generated by tuki
- Points balances, lots, ledger history, redemptions, VIP tier assignment, and referral codes
- Loyalty state mirrored to Shopify customer metafields (points balance, points value, tier, tier multiplier, birthday) so balances remain visible on the customer record
- Compliance request records for Shopify’s mandatory privacy webhooks
- Technical logs needed to operate the service (for example webhook delivery identifiers, retained briefly for deduplication)
2.4 Merchant-supplied integration credentials
If a merchant connects a third-party email provider (currently Resend) or configures outbound webhooks, we store API keys and signing secrets encrypted at rest, and never display full secrets again in the admin UI.
3. Why we process personal data
We process personal data only to:
- Provide, operate, and improve the merchant’s loyalty and rewards program (earn, redeem, tiers, referrals, product milestones)
- Send transactional loyalty emails the merchant enables (for example points earned, reward redeemed, tier upgraded), using the merchant’s own email integration when configured
- Deliver merchant-configured outbound webhooks about loyalty events
- Prevent referral abuse (self-referral checks, one-referral limits, IP and referrer velocity limits)
- Bill the merchant through Shopify’s Billing API and provide in-app support
- Comply with law and Shopify’s mandatory privacy webhooks (data access, customer erasure, shop erasure after uninstall)
We do not sell personal data. We do not use customer personal data for advertising networks, data brokerage, or unrelated profiling.
4. Legal bases (where applicable)
Depending on applicable law, we rely on:
- Performance of our contract with the merchant to provide the app
- Legitimate interests in operating a secure loyalty service and preventing fraud
- Compliance with legal obligations (including responding to erasure and access requests routed through Shopify)
- Consent, where the merchant or applicable law requires it (for example birthday collection, or marketing sends gated on Shopify marketing consent)
5. Consent and customer choices
- Marketing email: If we ever send marketing email through tuki, sends are gated on the customer’s Shopify email marketing state being subscribed. Loyalty program notifications are transactional and are not treated as marketing.
- CSV member import: Imported customers are never subscribed to marketing by tuki.
- Data sale / sharing opt-outs: We do not sell customer personal data. If a merchant must honour a sale or sharing opt-out under local law, contact us and we will support the request for data we hold.
- Automated decisions: tuki automates loyalty outcomes (points, tiers, referral fraud blocks). These do not produce legal or similarly significant effects outside the merchant’s loyalty program. Customers should contact the merchant for program-related disputes; merchants can adjust or reverse balances in admin.
6. How we share data
We share personal data only with:
- Shopify — to read and write the data needed for loyalty features (customers, orders, store credit, discounts, gift cards, metafields, billing)
- Email provider chosen by the merchant (e.g. Resend) — when the merchant connects an integration and enables email templates; content and recipients are determined by the merchant’s configuration
- Merchant-configured webhook endpoints — if the merchant enables outbound webhooks, event payloads are sent to the URL they control
- Infrastructure providers that host the app and database, under contractual confidentiality and security obligations
- Authorities when required by law, or professional advisors under confidentiality
Merchants remain responsible for any third-party tools they connect and for disclosing those tools in their own storefront privacy policy.
7. International transfers
tuki may process and store data on servers outside the merchant’s or customer’s country (including outside the EEA/UK). Where required, we rely on appropriate transfer safeguards (such as standard contractual clauses) with our processors, and merchants should ensure their own customer disclosures cover use of apps like tuki.
8. Retention
- While the loyalty program is active: Customer loyalty records (identity fields needed for the program, balances, ledger, referrals) are retained so the merchant can run rewards correctly.
- Customer erasure: On Shopify’s
customers/redactwebhook, we clear personal fields (name, email, birthday, referral code, marketing state), scrub referral PII (bound email and IPs), and delete mirrored loyalty metafields on the Shopify customer record. - Uninstall: On Shopify’s
shop/redactwebhook (after uninstall), we purge the merchant’s shop data from tuki’s database. - Webhook delivery records: Technical delivery identifiers are swept after approximately 30 days.
- Compliance request records: Kept as needed to demonstrate fulfilment of Shopify privacy webhooks and legal obligations.
9. Security
We apply technical and organisational measures including:
- Encryption in transit (HTTPS/TLS)
- Encryption of third-party integration secrets and webhook signing secrets at rest
- Shop-scoped data model so each merchant’s data is isolated in queries
- Session-token authentication for the embedded admin; no reliance on third-party cookies for app auth
- Separation of development and production apps, credentials, and databases
- Mandatory Shopify compliance webhooks for access and erasure requests
No method of transmission or storage is perfectly secure. Merchants should protect their Shopify staff accounts and API keys.
10. Customer and merchant rights
Depending on location, individuals may have rights to access, correct, erase, restrict, or object to processing, and to lodge a complaint with a supervisory authority.
- Customers should contact the merchant first. Merchants can use Shopify’s privacy tools; Shopify then notifies installed apps (including tuki) via compliance webhooks.
- Merchants can request help at workingid00@gmail.com. On a valid
customers/data_request, we prepare the customer’s loyalty export for the merchant.
11. Children’s data
tuki is not directed at children. Merchants are responsible for ensuring their store and loyalty program comply with age-related laws in their markets.
12. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes that affect merchants will be communicated through reasonable channels (for example the App Store listing or in-app notice).
13. Contact
Questions about this Privacy Policy or tuki’s data practices:
Email: workingid00@gmail.com
App: tuki — Loyalty & Rewards for Shopify
If you require a postal address for a specific jurisdiction, email us and we will provide the contact details that apply.