Kolli

Privacy Policy

Last updated: 22 September 2026

Kolli is a Shopify app built by Lyro Digital. This policy explains what the app reads from your store, what it stores on our servers, and how long it keeps it.

The short version. Kolli stores your store domain, the bundles you create and daily counters per bundle. It never stores the name, email, address or payment details of your customers, and it sets no cookies on your storefront.

Who we are

The app is operated by Lyro Digital, Emaar Residence, Ünalan, Libadiye Cd. No:82 E Blok Kat:29 Daire:291, 34700 İstanbul, Türkiye. For any privacy question, write to kolli@lyrodigital.com.

What the app stores

  • Store record. Your myshopify.com domain, the access token Shopify issues at install, your store time zone and the admin language you selected.
  • Staff account. When you open the app, Shopify passes the signed-in staff account (Shopify user ID, name and email). It is kept only to keep your session valid.
  • Bundle configuration. The bundles you build: name, quantity tiers, labels, discount type and value, rounding rule and appearance settings.
  • Product references. For the products you attach to a bundle: the Shopify product ID, title and image URL, so the admin list and preview can render.
  • Daily counters. Per bundle and per day: how often the block was shown, how often a tier was picked, how often it went to cart, how many orders contained it, and the total revenue and discount of those lines.

What the app does not store

  • No customer name, email address, phone number, shipping address or payment data.
  • No raw storefront events, IP addresses or visitor identifiers.
  • No cookies, local storage or tracking pixels on your storefront.

Order data

Kolli subscribes to the orders/create webhook. From each order it reads only the line items that carry a Kolli bundle reference, together with their price, quantity and discount amount. Those numbers are added to the daily counters described above and the payload is then discarded. The rest of the order — customer, addresses, payment — is never read or written to our database.

Shopify permissions

  • read_products, write_products — to list your products and to write the bundle configuration onto the products it applies to.
  • write_discounts — to create and update the single automatic discount that applies the bundle price at checkout.
  • read_orders — to count how many orders included a bundle line, for the analytics page.

Where the data is kept

Data is stored in a PostgreSQL database on a private server operated by Lyro Digital and hosted in İstanbul, Türkiye. Traffic to the app is encrypted with TLS, and the database itself sits on an encrypted volume (LUKS2, AES-XTS), so the data is encrypted both in transit and at rest. Backups are taken daily onto a separate encrypted volume and kept for 14 days.

If your store is in the European Economic Area or the United Kingdom, this means your store data is processed outside that area. Write to us if you need a data processing agreement.

Who else sees it

Nothing is sold, rented or shared for advertising. The app uses no third-party analytics and sends data to no other service. Shopify itself is the only other party involved, because the app runs on Shopify's APIs.

How long it is kept

When you uninstall Kolli, the app receives Shopify's app/uninstalled webhook and deletes your store record, bundles, product references, counters and session immediately. Backups roll off within 14 days. You can also request deletion at any time by writing to us.

While the app is installed, fixed retention periods apply. The Shopify order identifier kept to avoid counting the same order twice is deleted after 90 days. Daily counters, which are aggregate totals and cannot be linked to a person, are deleted after 400 days. Nothing is kept longer than the period stated here.

GDPR requests

Kolli implements Shopify's mandatory compliance webhooks. A customer data request (customers/data_request) returns nothing, because the app holds no customer data. Customer redaction (customers/redact) has nothing to erase for the same reason. Store redaction (shop/redact) deletes every row belonging to your store.

Changes

If this policy changes in a way that affects what the app stores, the date at the top of this page changes with it and installed merchants are notified by email.