Start building free

Privacy Policy

This Privacy Policy explains how TIGREN TECHNOLOGY SOLUTION COMPANY LIMITED, trading as Easify (“TIGREN COMPANY LIMITED,” “Easify,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you use our Shopify apps (collectively, the “Apps”) or visit easifyapps.com (the “Website”). It applies to every user of the Apps and the Website, individual or business, and reflects our obligations under the UK GDPR, the EU GDPR, and other applicable data protection laws.

1. Data We Collect

1.1 Merchant data

  • Store information: Shopify domain, contact email, and store plan.
  • Billing information: your subscription plan and billing status, provided through Shopify’s Billing API.
  • App settings, configurations, and the rules you define inside the app.
  • Support communications: the messages, screenshots, and store details you send us through in-app chat or email.

1.2 Access scopes

  • Store information: store name, store URL, contact email, plan type, and currency. Used to set up the app and identify your store.
  • Product and catalog information: product titles, variants, images, SKUs, pricing, publications, selling plans, tags, and inventory availability. Used to create and display your products, bundles, and offers.
  • Theme and storefront data: theme files and storefront content. Used to embed the app’s widgets and pages on your store, and to manage which sales channels show them.
  • Files and media: file upload and storage. Used to serve images, icons, and other assets the app needs to display correctly.
  • Inventory and locations (optional): read and update inventory levels and locations. Used to keep stock accurate for the product variants linked in the app.

1.3 Customer data processed on your behalf

To run specific features you turn on, we also process:

  • Customer tags: fetched automatically through Shopify’s API. Used for the Box Visibility feature, so you can choose who sees each box or bundle (for example, customers with a certain tag).
  • Customer name and email: read from the shopper’s own account, in real time, when they are logged in to your store. Used for the Box Visibility feature, to check the logged-in shopper against your rules so the right boxes or bundles show for them. This information is not stored in our database.
  • Order information: recent and historical orders, line items, and selected bundle or box options. We may also add a tag adn a additional detail to an order to reflect its bundle configuration. Used to process bundle orders, give you analytics on how your bundles and boxes perform, and power the Scan Catalog feature, which suggests mix-and-match product ideas, including best sellers, based on your catalog and order history.
  • AI-assisted suggestions: store and product data used by features such as the AI Setup Assistant is shared with an AI service provider solely to generate the suggestions shown to you.

We do not access customer payment card details, and we do not use customer data to contact your shoppers or for anything beyond what’s described above. The app follows Shopify’s Protected Customer Data requirements and only asks for the access its features need.

2. How We Collect Data

2.1 Shopify API integration

When you install and authorize the app, we receive data from your store through Shopify’s API based on the scopes you grant, as described in sections 1.2 and 1.3. Access is limited to the scopes you approve during installation.

2.2 Merchant-provided input

You may enter additional information directly in the app, such as settings, custom rules, and manual configuration. We store it only to run the app’s features.

2.3 Customer interactions, processed on your behalf

Where the app interacts with your shoppers through bundle or box widgets, we collect the inputs they provide during that interaction, such as option selections and order-linked metadata. Where a shopper is logged in to your store, we also read their name and email in real time, as described in section 1.3. This data is processed solely on your behalf and never for an independent purpose of ours.

3. How We Use Your Data

We process personal data only as necessary to operate the app:

  • Deliver core app functionality: run the bundle, box, and mix-and-match features your store’s configuration enables.
  • Apply your settings and preferences: store and apply the rules, logic, and interface configuration you define.
  • Determine which bundle/box offerings are visible to specific customer segments, based on your configured visibility rules (Box Visibility feature), using customer name, email, and tags.
  • Generate analytics on bundle and box performance, and power the Catalog Scan feature that suggests mix-and-match product ideas, including best sellers, using order and line-item data.
  • Provide support and fix problems: access relevant store or order data when needed to investigate bugs and answer your support requests.
  • Keep the app secure and reliable: monitor for abuse, errors, and performance problems.

What we do not do

  • We do not use shopper data for advertising or marketing, and we do not build marketing profiles of your shoppers. Sorting customers into the segments you define for Box Visibility (such as by tag or account type) is only used to control what they see in your store, never to advertise to them or build a profile of them.
  • The app has no email, SMS, or other messaging feature, so we never contact your shoppers. The name and email we process are used only to match your Box Visibility rules and are never used to reach out to a shopper.
  • We do not sell, rent, or share your data with third parties for commercial purposes.
  • We do not access customer payment card details.

We do email you, as the merchant, about your account, billing, and app changes, and occasionally about our products. You can unsubscribe from the product emails at any time; operational messages are part of the Services.

5. Data Location and Security

5.1 Storage and international transfers

We store and process data on Akamai cloud infrastructure. Easify Box Bundle Builder BYOB runs in Dallas, Texas, United States.

Our team, based in Hanoi, Vietnam, may also access this data to provide support and operate the app. Data may therefore be stored or processed outside the United Kingdom and the European Economic Area, including in the United States and Vietnam. Our other providers, including our support chat provider, may also process data outside those areas. For transfers from the EEA we rely on the European Commission’s Standard Contractual Clauses, and for transfers from the UK on the International Data Transfer Addendum issued by the UK Information Commissioner’s Office, together with other legally recognized safeguards for cross-border transfers.

5.2 Security measures

  • Industry-standard encryption in transit and at rest.
  • Individual accounts with multi-factor authentication for systems that hold data.
  • Least-privilege access, restricted to authorized personnel and reviewed periodically.
  • Regular backups with restoration testing, and documented recovery procedures.
  • Logical separation of data per store.
  • Ongoing monitoring and auditing of our data infrastructure.
  • Internal data handling policies, confidentiality obligations, and staff training.

We review these practices regularly against Shopify’s platform standards and applicable legal requirements. The full set of measures is set out in Appendix 2 of our Data Processing Addendum.

6. Sub-processors

We work with a limited number of trusted providers that process personal data on our behalf, strictly to run our infrastructure and answer your support requests:

  • Cloud infrastructure: Akamai, used for hosting and computing.
  • Server management: RunCloud, used to manage and maintain our hosting environment.
  • Customer support: Crisp, used for support conversations between merchants and our team.
  • AI service providers: used to power AI-assisted features, such as the AI Setup Assistant and Catalog Scan, which generate suggestions from your store and product data.

Every sub-processor is bound by a written agreement, including a Data Processing Agreement where required, by obligations under the UK and EU GDPR, and by appropriate technical and organizational security measures. We review our sub-processors periodically and share data with them only to the extent their function requires. The list above is complete and current; we update it here when it changes.

We give you at least 14 days’ notice by email before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. The full process, including what happens if we cannot provide a feature without that provider, is set out in section 9 of our Data Processing Addendum.

7. Data Retention and Deletion

We retain personal and store-related data only for as long as we need it to provide the app, comply with legal obligations, and resolve disputes or enforce our agreements. Once it is no longer needed, it is securely deleted or anonymized.

Merchant control and deletion requests

  • Uninstalling the app from your Shopify store starts the deletion process for that store’s data.
  • You can also contact us directly to request deletion of stored data.

The app implements Shopify’s mandatory privacy webhooks (shop/redact, customers/redact, and customers/data_request), so deletion is triggered automatically: Shopify sends us a store redaction request 48 hours after you uninstall the app, and a customer redaction request when a shopper asks for erasure. We complete the deletion within 30 days of receiving the request, and provide requested shopper data to you within 30 days, keeping only what we are legally required to retain.

8. Your Rights

Subject to the conditions and limits set out in the UK and EU GDPR, you may exercise the following rights over your personal data:

  • Access: request a copy of the personal data we hold about you and how we use it.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure: ask us to delete data where it is no longer necessary, where you withdraw consent, or where you object and we have no overriding legitimate grounds.
  • Restriction: ask us to limit processing in specific circumstances, such as while accuracy is being verified.
  • Portability: receive your data in a structured, commonly used, machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: withdraw consent at any time, without affecting processing already carried out lawfully.

To exercise a right, email support@tigren.com. We respond within 30 days. We may need to keep certain data where the law requires it. If you are a shopper of a store using this app, please contact that store directly: the merchant is the controller of your data and we act on their instructions, so we will direct any request you send us back to the relevant store. Your name, email, and tags are processed as described in section 1.3. You also have the right to complain to your data protection authority, such as the ICO in the United Kingdom.

If you are a California resident, you also have rights under the CCPA as amended. We do not sell personal information and do not share it for cross-context behavioural advertising. Where we process shopper data for a merchant, we act as that merchant’s service provider and use the data only to provide the app.

9. Cookies and the Website

Our website uses cookies that are necessary for it to function. You can control or clear cookies in your browser at any time; blocking necessary cookies may affect how parts of the site work.

The app runs inside your Shopify admin and storefront and uses only the session and functional storage it needs to operate. We do not use advertising or cross-site tracking cookies in the app.

10. Children’s Data

The app and the Website are business tools and are not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us at support@tigren.com and we will delete it.

11. Data Processing Addendum

If you need processor terms under Article 28 of the UK or EU GDPR, our Data Processing Addendum sets out the roles of the parties, the scope and purpose of processing, our security measures, our sub-processor commitments, and the safeguards that apply to international transfers.

It applies whenever we process personal data on your behalf and is available at our Data Processing Addendum page. If you need a countersigned copy, email support@tigren.com and we will send our standard DPA for review and signature.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our data processing practices, updates to applicable laws and regulatory guidance, or improvements to our services and infrastructure.

When a change is material we will give notice by email to your store contact address, or through a prominent notice in the app or on our website, before it takes effect. The date at the top of this page always shows when it was last revised.

13. Contact Us

For privacy questions, data access or deletion requests, or documentation you need for your own compliance work, contact us at:

TIGREN TECHNOLOGY SOLUTION COMPANY LIMITED (TIGREN COMPANY LIMITED), trading as Easify.

Registered address: No. 2, Alley 113, Giap Bat Street, Tuong Mai Ward, Hanoi, Vietnam.

Business registration number: 0105887692.

Privacy requests support@tigren.com
App support In-app live chat, 24/7

Related policies

Terms of service The terms that govern your use of our apps, this website, and our support.
Still have a question? A real person on our team reads every message and answers. Contact us