Tierly — Privacy Policy
Last updated: September 8, 2026
This Privacy Policy explains what information the Tierly app (by Solora Commerce) processes when you install it on your Shopify store, and how we protect it. By installing Tierly you agree to this policy.
1. Information we process
- Store information — your
.myshopify.comdomain, store name, plan, currency, and the store owner’s email, provided by Shopify at install. - App configuration — the pricing offers, tiers, targeting, and settings you create in the app.
- Order statistics — when an order is placed, Shopify sends us an order-created event. We record only aggregated figures (order count, units sold, discount amounts, order totals) for your analytics dashboard.
- Authentication tokens — a Shopify access token used to call the Shopify API on your behalf. It is encrypted at rest.
2. What we do NOT collect
We do not store your customers’ personal data — no names, emails, phone numbers, or shipping addresses. Order events are used only to compute the aggregate numbers above and are not retained as individual customer records.
If wholesale (B2B) features are enabled in the future, Tierly may evaluate customer tags during checkout to determine pricing eligibility. Tags are evaluated in the moment and are not stored by the app.
3. How we use information
- To provide the app’s functionality — applying volume discounts at checkout and displaying pricing on your storefront.
- To show you analytics about how your volume pricing performs.
- To operate, maintain, secure, and support the service.
We do not sell your data or use it for advertising.
4. Sharing & sub-processors
We share data only with providers strictly necessary to run the service, and never for their own purposes:
- Shopify— the platform the app runs on; discounts execute inside Shopify’s checkout.
- Hugging Face — application hosting, and the storage bucket that holds our database backups. Backups contain everything described in section 1; they are transferred over HTTPS, and the Shopify access tokens inside them stay encrypted (see section 7).
- Crisp — our in-app support chat; receives your store domain, store name, owner email, and plan so we can support you in context.
- Sentry — error monitoring; reports carry technical context such as your store domain and the action that failed, never customer data.
5. Protected customer data & GDPR
Tierly complies with Shopify’s Protected Customer Data requirements and processes only the minimum data needed for its function. We honor Shopify’s mandatory compliance webhooks:
customers/data_request— we hold no individual customer data to return.customers/redact— no customer data is stored, so there is nothing to erase.shop/redact— when you uninstall, your store’s data is deleted (see below).
6. Data retention & deletion
We keep your store’s configuration and aggregated statistics for as long as the app is installed.
When you uninstall, your Shopify session and the access tokens it holds are deleted immediately, and your store is marked uninstalled. Your offers, settings and statistics are kept for a short period so that reinstalling restores what you had.
When Shopify sends shop/redact — normally about 48 hours after uninstall — everything belonging to your store is erased from our live database in a single transaction: offers, pricing configuration, daily statistics, per-offer statistics, feature requests and votes, settings, webhook records, our internal support-action log, sessions, and the store record itself.
Backups.Dated database snapshots are retained for up to 30 days, so an erased store’s data can persist in a backup until the last snapshot taken before erasure ages out. Backups exist for disaster recovery and are not used for any other purpose.
To request deletion sooner than the schedule above, contact us at the address below.
7. Security
All traffic is served over HTTPS. Shopify access tokens are encrypted at rest with AES-256-GCM, and stay encrypted inside database backups. We restrict internal access to store data to authorized operators, and every support action an operator takes against a store is written to an audit log.
8. Cookies
The embedded admin app uses a session cookie required for authentication with Shopify. The storefront components set no tracking cookies.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
10. Contact
Questions about privacy or a data request? Email us at [email protected].
