Skip to content

Privacy Policy

This Privacy Policy explains how TIGREN TECHNOLOGY SOLUTION COMPANY LIMITED, trading as Easify (“TIGREN COMPANY LIMITED,” “Easify,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you use our Shopify apps (collectively, the “Apps”) or visit easifyapps.com (the “Website”). It applies to every user of the Apps and the Website, individual or business, and reflects our obligations under the UK GDPR, the EU GDPR, and other applicable data protection laws.

Last updated: September 10, 2026

1. Data We Collect

1.1 Merchant data

  • Store information: Shopify domain, contact email, and store plan.
  • App settings, configurations, and the rules you define inside the app.
  • Support communications: the messages, screenshots, and store details you send us through in-app chat or email.

1.2 Access scopes

We request permission to the configured scopes during installation, in accordance with Shopify’s API and permission model, and only to the extent an app needs them to function.

1.3 Customer data processed on behalf of the merchant

Depending on the features you enable, we may process customer data strictly on your behalf:

  • Order-related data: customizations, options, or attachments tied to a customer’s order.
  • Order and product context needed to render those items correctly, such as product, variant, and order identifiers.
Our apps do not process shopper contact details. We do not collect or store a shopper’s name, email address, phone number, or shipping or billing address, and we never access payment information. Our apps comply with Shopify’s Protected Customer Data requirements and request only the access their features need.

2. How We Collect Data

2.1 Shopify API integration

When you install and authorize an Easify app, we receive data from your store through Shopify’s API based on the scopes you grant: store-level data such as domain, email, and plan; product and order data where relevant to the app; and your configuration and usage preferences. Access is limited to the scopes you approve during installation.

2.2 Merchant-provided input

You may enter additional information directly in the app, such as settings, custom rules, and manual configuration. We store it only to run the app’s features.

2.3 Customer interactions, processed on your behalf

Where an app interacts with your shoppers through product customizations, bundles, attachments, or widgets, we collect the inputs they provide during that interaction, such as option selections, uploaded files, and order-linked metadata. We do not collect their contact details. This data is processed solely on your behalf and never for an independent purpose of ours.

3. How We Use Your Data

We process personal data only as necessary to operate and improve the Apps:

  • Deliver core app functionality: run the features your store’s configuration enables.
  • Apply your settings and preferences: store and apply the rules, logic, and interface configuration you define.
  • Provide support and fix problems: access relevant store or order data when needed to investigate bugs and answer your support requests.
  • Keep the Apps secure and reliable: monitor for abuse, errors, and performance problems.

What we do not do

  • We do not use shopper data for advertising, marketing, or profiling, and we do not build profiles of your shoppers.
  • Our apps have no email, SMS, or other messaging feature, so we never contact your shoppers.
  • We do not sell, rent, or share your data with third parties for commercial purposes.
  • We do not access customer payment or billing details.

We do email you, as the merchant, about your account, billing, and app changes, and occasionally about our products. You can unsubscribe from the product emails at any time; operational messages are part of the Services.

4. Legal Bases for Processing

The data controller for that processing is TIGREN TECHNOLOGY SOLUTION COMPANY LIMITED, trading as Easify. Where we act as a data controller, for example for merchant account and billing-related data, support conversations, and website use, we rely on the following legal bases under the UK and EU GDPR: performance of our contract with you, our legitimate interests in operating and securing the Apps, compliance with legal obligations, and your consent where consent is required.

Where we process shopper data on your behalf, you are the controller and we are the processor. You decide the purpose and legal basis for that processing, and our handling of it is governed by our Data Processing Addendum.

We do not carry out automated decision-making or profiling that produces legal effects for you or for your shoppers.

5. Data Location and Security

5.1 Storage and international transfers

We store and process data on Akamai cloud infrastructure. Each app runs in a fixed region:

  • Easify Custom Product Options: London, United Kingdom
  • Easify Box Bundle Builder: Dallas, Texas, United States
  • Easify Product Attachments: Dallas, Texas, United States
  • Easify Inventory Sync: Dallas, Texas, United States

Depending on the app you use, data may therefore be stored or processed outside the United Kingdom and the European Economic Area, including in the United States. Our other providers, including our support chat provider, may also process data outside those areas. For those transfers we rely on Standard Contractual Clauses approved by the UK Information Commissioner’s Office and/or the European Commission, and on other legally recognized safeguards for cross-border transfers.

5.2 Security measures

  • Industry-standard encryption in transit and at rest.
  • Individual accounts with multi-factor authentication for systems that hold data.
  • Least-privilege access, restricted to authorized personnel and reviewed periodically.
  • Regular backups with restoration testing, and documented recovery procedures.
  • Logical separation of data per store.
  • Ongoing monitoring and auditing of our data infrastructure.
  • Internal data handling policies, confidentiality obligations, and staff training.

We review these practices regularly against Shopify’s platform standards and applicable legal requirements. The full set of measures is set out in Appendix 2 of our Data Processing Addendum.

6. Sub-processors

We work with a limited number of trusted providers that process personal data on our behalf, strictly to run our infrastructure and answer your support requests:

  • Cloud infrastructure: Akamai, used for hosting and computing.
  • Server management: RunCloud, used to manage and maintain our hosting environment.
  • Customer support: Crisp, used for support conversations between merchants and our team.

Every sub-processor is bound by a written agreement, including a Data Processing Agreement where required, by obligations under the UK and EU GDPR, and by appropriate technical and organizational security measures. We review our sub-processors periodically and share data with them only to the extent their function requires. The list above is complete and current; we update it here when it changes.

We give you at least 14 days’ notice by email before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. The full process, including what happens if we cannot provide a feature without that provider, is set out in section 9 of our Data Processing Addendum.

7. Data Retention and Deletion

We retain personal and store-related data only for as long as we need it to provide the Apps, comply with legal obligations, and resolve disputes or enforce our agreements. Once it is no longer needed, it is securely deleted or anonymized.

Merchant control and deletion requests

  • Uninstalling an app from your Shopify store starts the deletion process for that store’s data.
  • You can also contact us directly to request deletion of stored data.

All four Easify apps implement Shopify’s mandatory privacy webhooks, so deletion is triggered automatically: Shopify sends us a store redaction request 48 hours after you uninstall an app, and a customer redaction request when a shopper asks for erasure. We complete the deletion within 30 days of receiving the request, and provide requested shopper data to you within 30 days, keeping only what we are legally required to retain.

8. Your Rights

Subject to the conditions and limits set out in the UK and EU GDPR, you may exercise the following rights over your personal data:

  • Access: request a copy of the personal data we hold about you and how we use it.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure: ask us to delete data where it is no longer necessary, where you withdraw consent, or where you object and we have no overriding legitimate grounds.
  • Restriction: ask us to limit processing in specific circumstances, such as while accuracy is being verified.
  • Portability: receive your data in a structured, commonly used, machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: withdraw consent at any time, without affecting processing already carried out lawfully.

To exercise a right, email support@tigren.com. We respond within 30 days. We may need to keep certain data where the law requires it. If you are a shopper of a store using our apps, please contact that store: the merchant is the controller of your data and we act on their instructions. Because we do not hold shopper contact details, we cannot identify you from your name or email address alone. You also have the right to complain to your data protection authority, such as the ICO in the United Kingdom.

If you are a California resident, you also have rights under the CCPA as amended. We do not sell personal information and do not share it for cross-context behavioural advertising. Where we process shopper data for a merchant, we act as that merchant’s service provider and use the data only to provide the Apps.

9. Cookies and the Website

Our website uses cookies that are necessary for it to function. You can control or clear cookies in your browser at any time; blocking necessary cookies may affect how parts of the site work.

Our apps run inside your Shopify admin and storefront and use only the session and functional storage they need to operate. We do not use advertising or cross-site tracking cookies in our apps.

10. Children’s Data

The Apps and the Website are business tools and are not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us at support@tigren.com and we will delete it.

11. Data Processing Addendum

If you need processor terms under Article 28 of the UK or EU GDPR, our Data Processing Addendum sets out the roles of the parties, the scope and purpose of processing, our security measures, our sub-processor commitments, and the safeguards that apply to international transfers.

It applies whenever we process personal data on your behalf and is available at our Data Processing Addendum page. If you need a countersigned copy, email support@tigren.com and we will send our standard DPA for review and signature.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our data processing practices, updates to applicable laws and regulatory guidance, or improvements to our services and infrastructure.

When a change is material we will give notice by email to your store contact address, or through a prominent notice in the app or on our website, before it takes effect. The date at the top of this page always shows when it was last revised.

13. Contact Us

For privacy questions, data access or deletion requests, or documentation you need for your own compliance work, contact us at:

TIGREN TECHNOLOGY SOLUTION COMPANY LIMITED (TIGREN COMPANY LIMITED), trading as Easify.
Registered address: No. 2, Alley 113, Giap Bat Street, Tuong Mai Ward, Hanoi, Vietnam.
Business registration number: 0105887692.