★ Parkly← Back to home

Legal

Privacy Policy

Last updated: June 4, 2026

Parkly (“Parkly”, “we”, “us”) is a Shopify app provided by Trionex Pvt Ltd that connects a merchant’s Shopify store to the merchant’s own Odoo loyalty program. It lets the merchant’s customers view their loyalty points and redeem them for discounts at checkout. This policy explains what data Parkly processes, why, who it is shared with, and how it is protected.

1. Who controls the data

The merchant (the store that installs Parkly) is the data controller for their customers’ personal data. Parkly acts as a data processor on the merchant’s behalf, moving loyalty data between Shopify and the merchant’s Odoo instance.

2. Data we process

From the merchant

  • Shopify store domain and Shopify session / access tokens.
  • The merchant’s Odoo instance URL and Odoo API token (the API token is encrypted at rest).
  • Loyalty program configuration synced from the merchant’s Odoo.

From customers

  • Email address and name.
  • Loyalty points balance, lifetime totals, and points history.
  • Order references, cart / checkout tokens, redemption codes, points redeemed, and discount amounts.

3. How we use the data

  • Display a customer’s loyalty balance and history in their customer account and during checkout.
  • Redeem points: deduct the points in the merchant’s Odoo system and create a matching single-use Shopify discount for that order.
  • Release or reconcile redemptions for abandoned or refunded orders so points are not lost or double-counted.

We do not use customer data for advertising, profiling, or any purpose unrelated to operating the loyalty program, and we do not sell personal data.

4. Who we share data with

  • Shopify — to authenticate requests and apply discounts to orders.
  • The merchant’s Odoo instance — the merchant’s own system of record for loyalty points. Customer email and redemption details are sent there to look up balances and record redemptions.

We do not share personal data with any other third parties except where required by law.

5. How we protect data

  • Odoo API tokens are encrypted at rest using AES-256-GCM.
  • Storefront and webhook requests from Shopify are verified with HMAC signatures.
  • Customer-account requests are authenticated with signed Shopify session tokens.
  • All data is transmitted over HTTPS.

6. Data retention and deletion

  • When a merchant uninstalls Parkly, we delete that store’s stored settings and redemption records.
  • We honor Shopify’s mandatory privacy webhooks: customers/data_request, customers/redact, and shop/redact.
  • Loyalty balances and history are held in the merchant’s Odoo system and are governed by the merchant’s own retention policy.

7. Customer rights

Customers may request access to, correction of, or deletion of their personal data by contacting the merchant whose store they shopped with, or by contacting us at the address below. Requests received through Shopify’s privacy webhooks are actioned automatically.

8. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.

9. Contact

Questions about this policy or your data can be sent to Trionex Pvt Ltd at irhan@trionex.pk.

© 2026 Parkly by TrionexHome