Privacy policy — Lilya: Bulk Discount Codes
What the app accesses, what it stores, and when it is deleted.
This policy describes how Lilya: Bulk Discount Codes (“the app”) handles data when a Shopify merchant installs and uses it. The app is made by Lilya Work. Contact: support@lilya.work.
Summary
The app creates and manages discount codes in your Shopify store. It does not collect, read or store personal data of your customers, and it has no access to your orders or customers.
Data the app accesses
When you install the app you grant it the Shopify permissions read_discounts, write_discounts and read_products. With them the app:
- Creates discounts and adds, reads, counts and deletes discount codes.
- Reads how often each code was used. It never reads who used a code.
- Shows the products and collections you pick as discount targets or landing pages.
The app does not ask for access to your orders or customers.
Data the app stores
- Your store’s myshopify.com domain, the access token Shopify gives the app and the granted permissions.
- Your plan and trial status.
- Your settings: default code format and discount options, notification mode, the notification e-mail address you enter (your own address, used only for batch e-mails) and automatic cleanup days.
- Your store’s time zone, currency and primary domain, cached code counts for the store code meter, and setup guide progress.
- For each batch: its name, discount title and ID, code format, counts, status, dates and the codes Shopify rejected (at most 1,000).
- The generated or imported codes with their Shopify code IDs, the latest usage report per discount (used codes and how often each was used), export files you prepare and code lists you upload.
- For Shopify Flow: the code handed out by each action run and whether a workflow uses the app’s triggers, and a list of e-mails already sent, so nothing is sent twice.
The app does not store customer names, e-mail addresses, phone numbers, addresses or orders. When you pair codes with an Omnisend or Mailchimp contact file, the file is read and combined in your browser; it is never sent to our servers.
How the data is used
Only to provide the app’s features. We do not sell data, use it for advertising, or share it with third parties other than the service providers below.
Service providers
- Cloudflare, Inc. runs the app and stores its data (Workers, D1 database in the Eastern Europe region, R2 file storage, queues, e-mail sending from notify@lilya.work, request logs kept 7 days).
- Shopify provides the platform, billing through Shopify App Pricing, and Shopify Flow.
Retention and deletion
- Export files are deleted after 7 days; download links expire after 10 minutes.
- Uploaded code lists are deleted after 1 day.
- Deleting a batch in the app removes its code files and exports within about 5 minutes. The codes stay in Shopify.
- Only the latest usage report per discount is kept.
- When you uninstall the app, its access tokens are deleted at once. Discounts and codes created by the app stay in Shopify and keep working.
- 48 hours after you uninstall, Shopify asks us to erase your store’s data (shop/redact) and the app deletes every record and file it stored for your store. If you reinstall within those 48 hours, your data is kept.
- Shopify’s customer data requests (customers/data_request and customers/redact) are answered, but there is nothing to return or delete because the app stores no customer data.
Security
Admin requests are authenticated with Shopify session tokens. Webhooks and Shopify Flow requests are verified with Shopify’s signatures. Download links are signed, expire after 10 minutes and only open files of the store that created them. Each store can only reach its own data and files.
Your rights
You can ask for a copy of the data the app holds about your store, or ask us to delete it before you uninstall, by writing to support@lilya.work. You can also complain to the data protection authority where you live.
Changes
If we change this policy we update the date at the top of this page.
