We think you deserve to know exactly what happens to your data when you use our products. This policy is a plain-English account of what we collect, why we need it, and how we keep it safe across all of our Miko Apps.
1. Who We Are
Miko Apps is the software department of Tripster Developers, a certified Shopify Plus Expert agency based in New Zealand. We build Shopify tools for merchants around the world, and this policy covers all of them: Miko Loyalty, Live Odoo Connector, B2B Wholesale Pricing, Miko AI, Miko AI Descriptions & Narrate, Miko Product Rentals, Miko Restock: Inventory & PO, Miko Bulk Image Resizer, Authentica: COA Certificates, and Miko Subscribe & Save.
2. What We Collect and Why
We only collect what each app genuinely needs to do its job. Here is what that looks like for each product.
- When any app is installed: We receive basic store details like your domain name, email address, plan tier, and primary contact. This is used purely to set up your account and keep things running smoothly.
- Miko Loyalty: We process purchase history and customer interaction events to calculate point balances and VIP tier progression. Customer identifiers are stored in our secure database so reward accounts carry over correctly between sessions.
- Live Odoo Connector: We process real-time order states and inventory levels to keep your Shopify store and Odoo instance in sync. Each merchant's sync runs in its own isolated process so your data is never mixed with anyone else's.
- B2B Wholesale Pricing: We process customer segment tags and price list metadata to apply wholesale pricing on your storefront. No payment data is stored by the app.
- Miko Product Rentals: We process product, variant, order, and customer data to manage rental bookings, availability calendars, deposit tracking, and late fees. This includes order line item details, customer contact information (name, email, phone), and product metadata. Booking records are stored in our secure Railway-hosted PostgreSQL database and linked to your Shopify orders. Customer data is used only to fulfill rental bookings and is never passed on to third parties. All rental data is permanently deleted within 48 hours of uninstalling the app.
- Miko Restock: We process product, variant, inventory, and order data to forecast demand and manage purchase orders. From your orders we read only the order date and line-item quantities, never customer names, email addresses, phone numbers, or addresses. Aggregated daily sales counts, your products, suppliers, and purchase orders are stored in our secure Railway-hosted PostgreSQL database. We use Resend to send stock alerts and reports to the merchant's own email address; shoppers never receive anything and no customer personal data is used. All data is permanently deleted when you uninstall the app.
- Miko AI: We process customer purchase history, order frequency, spend values, and timestamps to calculate RFM scores, churn risk, and lifecycle stage classifications. This data is written back to Shopify customer profiles as
miko-prefixed tags. We use the Anthropic Claude API to generate plain-English segment summaries, but only anonymised segment data is ever sent to Anthropic. No names, email addresses, or personal details leave our system. We use Resend to deliver weekly reports to the merchant's configured address. Resend does not receive raw customer data. Everything is permanently deleted when you uninstall the app or clear it from the Settings page. - Miko AI Descriptions & Narrate: We process product data only, including titles, descriptions, images, variant options, and product metafields, to generate SEO product content and a spoken product summary for the storefront Listen button. We use the Google Gemini API to generate this content; only product data is ever sent to Google, never customer names, email addresses, or personal details. Generated content is stored in our secure Railway-hosted PostgreSQL database. The storefront Listen button uses the shopper's own browser text-to-speech, so no audio is stored and no shopper data is collected. This app requests only
read_productsandwrite_productsaccess and never touches customer, order, or payment data. All generated content is permanently deleted when you uninstall the app. - Miko Bulk Image Resizer: We process product and collection images only. To resize an image we download it from your store's content delivery network, resize and recompress it, upload the new version, and remove the old one. This app requests only
read_productsandwrite_productsaccess and never touches customer, order, or payment data. We store your store domain, your own contact name and email address for service messages, your resize settings, and a record of each run including file names, dimensions, and file sizes. We also keep a copy of each original image for 30 days on an encrypted Railway-hosted volume so any run can be undone from the History screen; those copies are deleted automatically after 30 days, or immediately when you uninstall. We use Resend to send service emails to your own address; shoppers never receive anything. All of this is permanently deleted when you uninstall the app, with one deliberate exception we would rather state plainly than bury: we retain a one-way cryptographic hash of your store domain together with the number of images left in the app's one-time free allowance, solely to stop that allowance being claimed repeatedly by uninstalling and reinstalling. It holds no store domain, no contact details and nothing personal, cannot be reversed, and is never used for marketing, analytics, or profiling. - Authentica: We process order, line-item, and product data to issue Certificates of Authenticity, including product titles, images, variant details, and order quantities. To name a certificate correctly we also access protected customer data (the buyer's name and email); no payment data is ever stored. Certificates, their serial numbers, verification records, and an app-wide cryptographic signing key are stored in our secure Railway-hosted PostgreSQL database. Buyers may optionally record an ownership transfer or report a problem from the public verification page; transfer details (a new owner's name and, if provided, email) are stored to maintain the certificate's provenance trail. We use Resend to send certificate emails to buyers when this is enabled, and optionally forward certificate events to Klaviyo or a merchant-configured webhook URL, sending only the certificate and order data needed for that integration. All of the above is permanently deleted within 48 hours of uninstallation, with one exception inherent to the product: certificates already shared with buyers (for example, printed, emailed, or scanned via QR) remain independently verifiable by design until the merchant revokes them, since a Certificate of Authenticity that vanishes on uninstall would defeat its purpose for buyers who already own the certified item.
- Miko Subscribe & Save: A subscription app necessarily handles more customer data than most, so here is the whole of it. We process your subscription contracts (products, variants, prices, delivery schedule and status), protected customer data (the subscriber's name, email address and, where present, phone number) so the subscriber can be shown on their own subscription, sign in to the self-serve customer portal, and receive subscription and payment-recovery messages, and order data (order date, line items and fulfillment status) so the portal can show the real status of each past delivery. We read the status of the payment method behind a subscription, so a failed charge can be attributed correctly, but we never receive, process or store card or bank details: payment data stays with Shopify and its payment providers, and a subscriber who needs to update a failing card does so on Shopify's own secure page, reached through a link Shopify sends them. We also read your theme and files, solely to detect where the storefront block sits and to resolve your logo for the portal. Subscriptions, subscribers, billing cycles, dunning attempts, cancel reasons, churn scores and agent activity logs are stored in our secure Railway-hosted PostgreSQL database. We use the Google Gemini API for the AI retention features; only behavioral signals are ever sent (risk band, risk factors, number of deliveries so far, the value of one delivery) and never names, email addresses, phone numbers, order contents or payment information. We use Resend to send subscription and payment-recovery emails, which means Resend receives the recipient's email address in order to deliver them, and merchant reports to your own address. The optional AI-assistant feature never gives an assistant standing access to your store: a subscriber issues a key for their own single subscription, it expires by itself after 30 days, it can be revoked, and it cannot read or change any other subscription, customer or order. We implement Shopify's mandatory privacy webhooks for customer data requests, customer redaction and shop redaction, and all subscription data is permanently deleted within 48 hours of uninstalling the app.
3. How We Keep Your Data Safe
Security is a baseline requirement across everything we build, not something we bolt on later. Here is what we have in place.
- Encryption: All data is encrypted at rest using AES-256 and in transit via TLS 1.3 or higher.
- Isolation: High-volume processes like the Odoo sync run in isolated worker threads so one merchant's data can never touch another's.
- Access control: Only senior engineers with multi-factor authentication can access production environments, and only for authorized maintenance tasks.
4. Who We Share Data With
We do not sell, rent, or trade your data or your customers' data. The only parties we share data with are infrastructure providers like Shopify, our hosting platforms, and services like Anthropic, Google and Resend, and only where this is genuinely necessary to run the app you have installed. Every provider is bound by equivalent data protection obligations.
We comply with the GDPR, CCPA, and the New Zealand Privacy Act 2020.
5. How Long We Keep It
All app data is permanently deleted within 48 hours of uninstallation, as required by Shopify's platform policies. For apps with a Settings-based data clear, deletion happens the moment you trigger it. You can contact us at any time to request a copy of your data, ask for corrections, or have everything deleted immediately.
Questions or Requests
For any data-related inquiries or compliance requests across the Miko ecosystem, get in touch with our privacy team.
Email Privacy Team