YOUR INFORMATION

Privacy policy

Effective September 17, 2026

Tillgrove is operated by Frequent & Vigorous LLC in the United States. This policy explains how we handle information when you visit tillgrove.com, contact us, or use our Shopify app and vendor portal.

We use store and vendor information to provide vendor accounting and support. We do not sell personal information, use it for targeted advertising, or use it to train AI models.

1. Information we handle

From Shopify

When a merchant installs Tillgrove, we receive the permissions needed to connect the app to that store. We handle the shop’s identifier and domain, currency and location information; product and variant identifiers and titles; and order, line-item and refund identifiers, descriptions, amounts, discounts, taxes, payment status and timestamps needed to calculate vendor earnings.

Shopify authentication can provide the authorized owner’s user identifier, name and email, together with session and access credentials. We use credentials to authenticate requests and communicate with Shopify.

We do not request shopper names, emails, addresses or payment-card details in our order queries. Shopify webhook notifications can contain additional customer fields; our order handlers use the order identifier to retrieve the accounting data needed for the app. Customer privacy requests can also contain identifiers and contact information needed to route and fulfill the request.

From merchants and vendors

Merchants provide vendor names and email addresses, product ownership, commission rates, fees, opening balances, hold periods, payout minimums, adjustments and payment references. Tillgrove creates balances, statements, access records and an accounting history from this information. Free-text notes or product descriptions may include information the merchant chooses to enter.

Vendors can provide an email address to request access to their portal. Portal access is limited to the vendor records associated with the invitation or verified session. Tillgrove records external payments; it does not need your bank-login credentials or payment-card numbers.

Website, support and technical information

If you email us, we receive your address, message and anything you attach. Our hosting, email and security providers may process ordinary request information such as IP address, browser information, request time and delivery logs to operate and protect their services.

Our public website has no advertising pixels, analytics scripts or tracking cookies added by Tillgrove. Fonts and images are served from the site itself. The app and vendor portal use necessary session storage or cookies for sign-in and security. Shopify and infrastructure providers apply their own policies to their services.

2. How we use information

For store and vendor records, we generally act on the merchant’s instructions. The merchant remains responsible for its relationship with its vendors and customers, including the information it supplies. For our website and support correspondence, we determine the purposes described in this policy. Where a legal basis is required, we rely on providing the requested service, our legitimate interests in operating and securing it, complying with applicable obligations, or consent where required.

3. Service providers and disclosures

We share information only as needed with service providers that help operate Tillgrove, the merchant and authorized users, or where required to comply with law, protect rights or complete a business transfer subject to appropriate protections.

ProviderPurpose
ShopifyStore integration, authentication, app subscription billing and platform privacy requests.
CloudflareWebsite delivery, network security and incoming support-email routing.
OpenAI SitesHosting the public information website. Store accounting data is not placed on this website.
Google / GmailReceiving and responding to support email forwarded from erik@tillgrove.com.

The app is currently in development and is not publicly available to install. Production app infrastructure and any transactional-email provider will be added here before they process live customer data. Using AI coding tools to develop Tillgrove does not mean store or vendor records are sent to an AI model as an app feature.

We are based in the United States. Providers may process information in the United States and other countries where they operate. Where applicable, transfers must use the protections required by the relevant law; this policy does not claim that data remains in one country.

4. Retention and deletion

We keep store settings and accounting records while needed to provide the installed app, including accurate statements and later refund adjustments. Ending a paid subscription does not itself erase records; the merchant can still access available history while the app remains installed.

Uninstalling disables app and vendor access. Shopify subsequently sends a store-erasure request. We process verified erasure requests within Shopify’s required period, normally within 30 days of receipt, unless retention is legally required or a later active installation must first be verified. We do not treat an old delayed request as permission to erase a newer active installation without review.

Shopper access and deletion requests are handled with the merchant. We identify relevant records, remove or anonymize personal information where appropriate, and explain any retention required by law. Financial records are protected against routine editing; that does not prevent a verified privacy request from being processed through a controlled privacy workflow.

Sign-in links expire after 30 minutes and vendor sessions normally expire after seven days; the merchant can revoke access sooner. Expiry prevents use of a credential but does not imply that every security or audit record is deleted immediately. Support messages are retained for as long as needed to resolve the request and maintain a useful support record. You may request their deletion. We keep information longer only where reasonably necessary for a documented legal, security or dispute purpose.

5. Access, correction and other choices

Email erik@tillgrove.com to request access, correction, deletion, a copy of your information, or to raise a concern. Include the shop domain and your relationship to the shop, but do not send passwords or full bank or card details. We may verify identity and work with the merchant before fulfilling a request.

Depending on your location, you may also have rights to restrict or object to processing, withdraw consent, appeal a decision or complain to your local data-protection authority. We apply Shopify’s required privacy-request process regardless of the requester’s location and do not penalize people for exercising privacy rights.

If your request concerns a purchase from a Shopify shop, contact that merchant first. Tillgrove does not operate the shop or manage its customer relationship.

6. Security and scope

We use access controls, authenticated requests and limited vendor sessions to protect information. No service can guarantee absolute security. Do not put unnecessary sensitive personal information in vendor names, product titles or payment notes.

Tillgrove is a business service for merchants and vendors; it is not intended for children. If you believe a child has provided personal information to us, contact us so we can investigate and remove it where appropriate.

7. Changes to this policy

We may update this policy as the service changes. The effective date above identifies the current version. We will provide additional notice of material changes when required.

8. Contact

Frequent & Vigorous LLC
Tillgrove
erik@tillgrove.com