Privacy Policy
Last updated: 25.09.2026
1. Who we are
VIP Atelier is a Shopify app for loyalty and VIP programs, provided by:
Firat Tarti (sole proprietorship)
Welper Str. 13A
49377 Vechta
Germany
info@ombrefeu.de
2. Roles
We are the controller for data about merchants who install VIP Atelier. For data about a store's customers we act solely as a processor on behalf of the merchant (Art. 28 GDPR). The merchant is the controller towards its customers and informs them about the loyalty program in its own privacy policy.
3. Data we process
- Merchants: shop domain and name, Shopify API access token, program settings, selected plan, optionally an uploaded logo and a Klaviyo API key provided by the merchant.
- Customers (on behalf of the merchant): Shopify customer ID, first name, email address, points balance and history, order value since installation, tier, redeemed discount codes, personal referral code, birthday (day and month only, optional), completed actions (e.g. newsletter, social media) and purchased product IDs for missions.
- Apple Wallet (optional): if a customer adds the membership card to Apple Wallet, we store the device identifier and push token sent by Apple to keep the card up to date.
4. Purposes and legal bases
Providing the loyalty program (points, tiers, rewards, referrals, missions, Wallet card) under our contract with the merchant (Art. 6(1)(b) GDPR) or on the merchant's behalf (Art. 28 GDPR). Security and abuse prevention based on legitimate interests (Art. 6(1)(f) GDPR).
5. Sub-processors
- Cloudflare, Inc. – hosting and database (Cloudflare Workers, D1; stored in Western Europe). Transfers to the US are based on the EU-US Data Privacy Framework or standard contractual clauses.
- Shopify – the platform through which the app is installed and billed.
- Apple – only if a customer uses the Wallet card.
- Klaviyo – only if the merchant enables the Klaviyo integration; events (e.g. “tier reached”) with email address and points balance are then sent to the merchant's own Klaviyo account.
6. Retention and deletion
Data is stored while the app is installed. After uninstalling, we delete all store data when Shopify sends the shop/redact request, at the latest after 30 days. Customer deletion requests (customers/redact) are processed automatically; data requests (customers/data_request) are answered via the merchant.
7. Security
All connections use TLS. Requests from the storefront are signed by Shopify and verified by us; credentials and keys are never stored in source code.
8. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection, and to lodge a complaint with a supervisory authority. Customers should first contact the store in which they are a member.
VIP Atelier