Last updated on 29.06.2026

This privacy policy explains how the Shopify app Tierly (Tiered Quantity Discounts) ("the App") handles data. It applies to the App only. For our general website privacy policy, see the Privacy Policy.

Controller

Martin Becker
Becker Software
Blockkamp 13
29351 Eldingen, Germany

Phone: 05145 3479490
E-mail: [email protected]

What the App does

The App lets merchants configure quantity-based ("tiered") discounts that are applied automatically at checkout and at the point of sale through Shopify Functions. It is installed by a merchant onto their own Shopify store.

Data the App accesses

To provide its functionality, the App requests the following Shopify access scopes:

  • read_products – to read product types, vendors, and SKUs so the merchant can choose which products a discount applies to.
  • read_discounts / write_discounts – to create, read, and update the discounts the merchant configures.

The App reads this store data on demand to render the configuration interface and to calculate discounts. It does not copy your product catalog into its own database.

Data the App stores

  • Discount configuration – the rules a merchant sets up (tiers, percentages, product-type/vendor targeting, etc.) are stored in the merchant's own Shopify store as an app-owned metafield. This data lives in the merchant's Shopify account, not in a separate product database.
  • Authentication sessions – for the embedded admin interface, the App stores the Shopify session/OAuth token required to authenticate the merchant's store. This is used solely to operate the App.

Customer (buyer) personal data

The App does not collect, store, sell, or share the personal data of a store's customers. Discounts are calculated on the contents of the cart, server-side and transiently, at the moment of checkout or sale. No buyer names, addresses, emails, or payment details are retained by the App.

Mandatory compliance webhooks

The App implements Shopify's mandatory privacy webhooks:

  • customers/data_request and customers/redact – because the App stores no customer personal data, there is no customer data to return or erase; these requests are acknowledged with no data to act on.
  • shop/redact – when a store is removed, any stored authentication session for that store is deleted.

When the App is uninstalled, its stored session for that store is deleted.

Subprocessors

  • Shopify Inc. – the platform the App runs on; all store data is processed within Shopify's infrastructure.
  • Cloudflare, Inc. – the App's backend runs as a Cloudflare Worker (Cloudflare Workers), which acts as our hosting and infrastructure subprocessor. The Worker serves the App's embedded admin page and receives Shopify webhooks (app/uninstalled and the mandatory GDPR compliance webhooks). It verifies webhook HMAC signatures and Shopify session tokens. The Worker makes no Admin API calls and uses no database; requests are processed transiently in memory and are not persisted. No customer personal data is sent to or stored by the Worker.

We do not use buyer data for advertising, profiling, or analytics.

Data location and transfers

Store data remains within the merchant's Shopify account. Any limited operational data (authentication sessions) is processed on the basis of our legitimate interest in operating the App and fulfilling our agreement with the merchant (Art. 6(1)(b) and 6(1)(f) GDPR).

Your rights

Merchants have the rights granted under the GDPR, including access, rectification, erasure, restriction, and portability of their data, and the right to lodge a complaint with a supervisory authority. To exercise any of these rights, or for any data protection question about the App, contact us at [email protected].

Changes

We may update this policy as the App evolves. The current version and its date are shown above.