Privacy Policy
Last updated: July 24, 2026
We want to be upfront with you about how your data is handled, whether you're a client working with us on a project or a merchant using one of our Miko Apps. This policy is a plain-English account of what we collect, why we need it, and how we look after it.
1. Who We Are
Tripster Developers is a web development agency and certified Shopify Plus Expert partner based in New Zealand. We work in two ways: we build custom websites, themes, and integrations for merchants as an agency, and we develop a suite of Shopify apps under the Miko brand. This policy covers both sides of what we do.
2. Our Agency Services
When you hire us to build or customise your Shopify store, here is what that means for your data.
- Custom theme development: We access your Shopify theme files and store configuration to design and build your storefront. We do not keep copies of your code after delivery. All working files are handed over and removed from our systems within 30 days of project sign-off.
- Store customisation and feature development: For ongoing work like app integrations, checkout extensions, or script modifications, we are granted collaborator access to your Shopify admin. That access is limited to the project scope and revoked as soon as the work is complete. We only look at product, order, or customer data where it is genuinely needed to build and test what you have asked for.
- Third-party integrations: When we connect your store to external platforms like ERPs, CRMs, or logistics providers, we handle API credentials with strict access controls. Credentials are stored in encrypted secrets management systems and are never committed to code or written to logs.
- Project enquiries and communication: When you get in touch for a quote or consultation, we collect your name, business email, and project details. This is used only to respond to you and manage your project. We will not add you to any marketing list without your explicit consent.
- Website analytics: We use anonymised analytics to understand how people use our website. No personally identifiable information is collected through these tools.
3. Our Miko Apps
Each Miko app collects only what it needs to work properly. All seven apps are built on Shopify's platform and follow Shopify's requirement to permanently delete all data within 48 hours of uninstallation.
Miko Loyalty and Rewards
We process customer purchase history and interaction events to calculate point balances and VIP tier progression. Customer identifiers are stored in our secure database so reward accounts stay consistent over time. Point and tier data is written back to Shopify customer profiles as metafields. Everything is deleted within 48 hours of uninstallation.
Live Odoo Connector
We process real-time order states, inventory levels, customer records, and fulfilment data to keep your Shopify store and Odoo ERP in sync. Each merchant's sync runs in an isolated process so your data cannot touch another merchant's. Your Odoo credentials are stored in encrypted form and are never exposed outside the sync process.
Miko B2B Wholesale House
We process customer segment tags, company records, and price list metadata to apply wholesale pricing on your storefront. No payment information is stored by the app at all. All data is deleted within 48 hours of uninstallation.
Miko Claude AI
We process customer purchase history, order frequency, spend values, and timestamps to calculate RFM scores, churn risk probability, and lifecycle stage classifications. This data is written back to Shopify customer profiles as miko- prefixed tags. We use the Anthropic Claude API to generate plain-English segment summaries, but only anonymised segment data is sent to Anthropic. No names, email addresses, or personal details ever leave our system. We use Resend to deliver weekly reports and CSV exports to the merchant's email address. Resend does not receive raw customer data. All data is permanently deleted within 48 hours of uninstallation or on demand from the app Settings page.
Miko AI Descriptions & Narrate
We process product data only, including titles, descriptions, images, variant options, and product metafields such as shipping and material information, to generate SEO product content and a spoken product summary for the storefront Listen button. We use the Google Gemini API to generate this content; only product data is ever sent to Google, never customer names, email addresses, or personal details. Generated content is stored in our secure Railway-hosted PostgreSQL database. The storefront Listen button uses the shopper's own browser text-to-speech, so no audio is ever stored and no shopper data is collected. This app requests only read_products and write_products access and never touches customer, order, or payment data. All generated content is permanently deleted within 48 hours of uninstallation.
Miko Product Rentals
We process product, variant, order, and customer data to manage rental bookings, availability calendars, deposit tracking, and late fees. This includes order line item details, customer contact information (name, email, phone), and product metadata. Booking records are stored in our secure Railway-hosted PostgreSQL database and linked to your Shopify orders. Customer data is used only to fulfil rental bookings and is never passed on to third parties. All rental data is permanently deleted within 48 hours of uninstallation.
Miko Restock
We process product, variant, inventory, and order data to forecast demand and manage purchase orders. From your orders we read only the order date and line item quantities, never customer names, email addresses, phone numbers, or addresses. Aggregated daily sales counts, your products, suppliers, and purchase orders are stored in our secure Railway-hosted PostgreSQL database. We use Resend to send stock alerts and reports to the merchant's own email address; shoppers never receive anything and no customer personal data is ever used. All data is permanently deleted within 48 hours of uninstallation.
4. Our Akira Theme
Akira is a Shopify OS 2.0 theme we sell through the Shopify Theme Store. Purchasing and installing Akira does not give us any access to your store, your customer data, or your Shopify admin. The theme runs entirely inside your own Shopify store using Shopify's standard theme infrastructure. We do not collect, receive, or process any data through the theme itself.
The only data we collect in relation to Akira is what you choose to share directly with us: enquiries submitted through our contact page about the theme, or support requests you send us by email. That information is handled the same way as any other project enquiry, described in section 2 above.
Our Akira documentation site uses the same anonymised website analytics as the rest of tripsterdevelopers.com. No personally identifiable information is collected there either.
5. How We Use Your Data
Across both our agency work and our apps, your data is used only for:
- Delivering the service or feature you have asked for or installed.
- Responding to support requests, project questions, and technical issues.
- Keeping our systems secure and running well.
- Meeting our obligations under Shopify's platform requirements.
- Internal quality improvement. Never for advertising or resale.
We do not sell, rent, or trade your data or your customers' data. Data is shared only with infrastructure partners that are necessary to run the service, and every partner is bound by equivalent data protection obligations.
6. Security
Security is a baseline requirement across everything we build. Here is what we have in place.
- Encryption: All data is encrypted at rest using AES-256 and in transit via TLS 1.3 or higher.
- Access control: Production system access is limited to senior engineers with multi-factor authentication. Shopify collaborator access is revoked immediately on project completion.
- Isolation: Each merchant's data is kept separate. High-throughput processes like the Odoo sync run on isolated workers so there is no risk of cross-merchant data leakage.
- Secrets management: API keys, credentials, and tokens are stored in encrypted secrets management systems and are never committed to code or written to logs.
7. How Long We Keep Your Data
- Miko Apps: All app data is permanently deleted within 48 hours of uninstallation. Where a Settings-based data clear is available, deletion happens as soon as you trigger it.
- Agency projects: Working files and project data are removed from our internal systems within 30 days of project sign-off. Collaborator access to your Shopify admin is revoked at project completion.
- Enquiry records: Contact and project enquiry records are kept for up to 24 months for project history and support continuity, then permanently deleted.
You can request a copy of the data we hold about you, ask for corrections, or request immediate deletion at any time by getting in touch with us.
8. Legal Compliance
We comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the New Zealand Privacy Act 2020. Where our services involve processing data of EU or UK residents, we act as a data processor on behalf of the merchant and process data only as instructed.
9. Get in Touch
If you have any questions about this policy, want to know what data we hold, or would like to request deletion, please get in touch at [email protected]. We will get back to you within five business days.