Privacy Policy
How the TierUp app handles data (last updated June 12, 2026)
1. Who we are
TierUp is developed and operated by GrünerBaum GmbH, Vorstädter Str. 32, 55276 Oppenheim, Germany. For any privacy question, contact hello@gbdesign.art.
2. What the app does
TierUp lets Shopify merchants configure quantity-tier discounts, bundles, BOGO offers and free gifts. Discounts are applied by a Shopify Function at checkout; the storefront widgets read the merchant's discount configuration from shop metafields.
3. Data we process
We deliberately process the minimum data required to provide the service to merchants:
- Shop data:the shop's myshopify.com domain, an API access token, and the discount configuration the merchant creates in the app.
- Order-level aggregates: for the analytics dashboard we store order totals, currency, line-item counts and discount amounts per order, keyed by shop domain and Shopify order ID.
We never store customer names, e-mail addresses, postal addresses, phone numbers, IP addresses or any other personal customer fields. Analytics are aggregate and shop-level by design.
4. Where data lives
All app data is stored on Cloudflare infrastructure (Workers KV and D1), encrypted at rest and in transit, with EU-region placement where available. A data-processing agreement pursuant to Art. 28 GDPR is in place with Cloudflare, Inc., including the EU Standard Contractual Clauses for third-country transfers.
5. Retention & deletion
When a merchant uninstalls TierUp, the shop's session tokens are deleted immediately. We honour Shopify's mandatory GDPR webhooks: on a customers/data_request we can confirm that no personal customer data is held; on customers/redact and shop/redact all data associated with the shop is deleted within 30 days.
6. Legal basis
Processing is carried out to perform the contract with the merchant (Art. 6 (1)(b) GDPR) and on the basis of our legitimate interest in providing secure, reliable analytics without personal data (Art. 6 (1)(f) GDPR).
7. Your rights
Merchants and data subjects have the rights of access, rectification, erasure, restriction, portability and objection under Chapter III GDPR, and the right to lodge a complaint with a supervisory authority. Requests can be sent to hello@gbdesign.art and are answered within 30 days.