Mixly — Privacy Policy
Last updated: August 30, 2026
This Privacy Policy explains what information the Mixly app (by Solora Commerce) processes when you install it on your Shopify store, and how we protect it. By installing Mixly you agree to this policy.
1. Information we process
- Store information — your
.myshopify.comdomain, store name, Shopify plan, currency, timezone, primary locale, country, primary storefront domain, and the store’s contact email, all provided by Shopify. - App configuration — the bundles you create (name, type, discount mode and value, minimum items, priority order), the product and variant IDs and quantities they contain, and your discount-stacking settings.
- Order statistics — when an order is placed, Shopify sends us an order-created event. We record only aggregated daily totals per bundle (orders, units, revenue, and discount amount). No individual order or customer record is kept.
- Authentication tokens — a Shopify access token used to call the Shopify API on your behalf. It is encrypted at rest. Mixly requests store-level (offline) tokens, so a session identifies your store rather than a person; where Shopify supplies a staff user’s name or email alongside a session, that person is a member of your team — never one of your customers.
- Feature requests — if you post to the Feature Requests board inside the app, we store the title and description you write and a record of which stores voted. Requests we approve are shown to other Mixly merchants with your store name attached, so please do not post anything confidential.
2. What we do NOT collect
We do not store your customers’ personal data — no names, emails, phone numbers, or shipping addresses. Order events are used only to compute the aggregate numbers above and are not retained as individual customer records. Mixly does not read or evaluate customer tags, segments, or accounts anywhere in the app.
Mixly also writes very little into your store. It creates a single automatic discount and one app-owned shop metafield (mixly.bundles) that your theme blocks read in order to display bundles — plus whichever Mixly blocks you choose to add to your theme. That metafield is readable by your storefront, which is how the blocks render, and holds bundle configuration only. Mixly never creates products, variants, or SKUs, and never writes to your product catalog.
3. How we use information
- To provide the app’s functionality — applying bundle discounts at checkout and displaying bundles on your storefront.
- To show you analytics about how your bundles perform.
- To run the in-app Feature Requests board and decide what to build next.
- To operate, maintain, secure, and support the service.
We do not sell your data or use it for advertising.
4. Sharing & sub-processors
We share data only with providers strictly necessary to run the service, and never for their own purposes:
- Shopify— the platform the app runs on; discounts execute inside Shopify’s checkout.
- Our cloud hosting provider — application and database hosting.
- Object storage (S3-compatible) — holds our automated database backups, uploaded over HTTPS to a private bucket. Access tokens remain encrypted inside those backups.
- Crisp — our in-app support chat, loaded only when it is enabled. It receives your store domain, store name, contact email, Mixly plan, Shopify plan, storefront domain, and timezone so we can support you in context.
- Sentry — error monitoring, when configured; reports carry technical context, never customer data.
- Solora Tierly — if you also use our Tierly app, Mixly may ask the Tierly service whether Tierly is installed on your store, so it can show you the right discount-stacking advice. Only your store domain is sent, and both services are operated by Solora Commerce.
5. Protected customer data & GDPR
Mixly complies with Shopify’s Protected Customer Data requirements and processes only the minimum data needed for its function. We honor Shopify’s mandatory compliance webhooks:
customers/data_request— acknowledged; we hold no individual customer data to return.customers/redact— acknowledged; no customer data is stored, so there is nothing to erase.shop/redact— your store’s data is deleted (see below).
6. Data retention & deletion
We keep your bundles and aggregated statistics for as long as the app is installed. When you uninstall Mixly, we immediately delete your Shopify sessions and access token and mark the store inactive; your configuration is held a little longer so that reinstalling restores your setup.
When Shopify sends the shop/redactrequest that follows an uninstall — or when you ask us to delete sooner — we erase your store’s record in a single transaction, together with your bundles, your bundle configuration and stacking settings, your bundle statistics, your feature requests and votes, your Shopify sessions, our webhook de-duplication records, and our internal support-action log.
Database backup snapshots are retained for up to 30 days, so deleted data may remain in a backup until that snapshot ages out.
7. Security
All traffic is served over HTTPS. Shopify access tokens are encrypted at rest with AES-256-GCM. Internal access to store data is restricted to authorized operators, and the actions they take are recorded in an audit log.
8. Cookies & local storage
The embedded admin app uses a session cookie required for authentication with Shopify, plus a first-party locale cookie — and a companion localeManualflag recording whether you chose the language yourself — that remembers your admin language for a year. Because the app runs inside Shopify Admin’s iframe, these are set as SameSite=None; Secure; Partitioned.
Your browser’s local storage holds a few dismissal flags, such as whether you closed the setup checklist, the what’s-new note, the review prompt, or a product-change banner. When support chat is enabled, Crisp sets its own cookies. The Mixly storefront blocks set no cookies and no tracking of any kind.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
10. Contact
Questions about privacy or a data request? Email us at [email protected].
