SERVICE & DATA

Merchant agreement

Version 2026-09-17 · Effective September 17, 2026

These terms are between Frequent & Vigorous LLC, the operator of Tillgrove, and the merchant accepting them. The person accepting must be authorized to act for the merchant.

1. What Tillgrove provides

Tillgrove tracks vendor earnings from supported Shopify sales and refunds, applies your vendor agreements, produces statements, records payments made outside the app, and gives vendors private access to their records. The service supports USD settlements for one Shopify store with up to one physical location plus online sales.

Tillgrove does not hold or transfer money, file taxes, or replace your accounting and legal responsibilities. Some order edits and exchanges need review and are unsupported. Review reported issues and payment totals before paying vendors.

2. Your account and records

You are responsible for the accuracy of vendor agreements, ownership assignments, starting balances and payment records. Keep Shopify access secure, invite the correct vendor recipients, and include only necessary personal information in notes and descriptions. You retain ownership of your data.

You may use Tillgrove for your store’s business. Do not attempt to access another store’s records, bypass access controls, interfere with the service, or use it unlawfully. Export the records you need before uninstalling.

3. Price and cancellation

Standard is $39 USD every 30 days, with a 60-day trial for eligible shops. Shopify shows the exact charge, taxes, trial eligibility and billing dates before you approve a subscription. Previously used trial days may reduce a returning shop’s trial. Accepting this agreement does not authorize a charge.

Shopify bills your subscription. Uninstalling ends access and cancels future recurring app charges under Shopify’s billing rules. It does not reverse charges already incurred. Contact us about billing errors or refund requests.

4. Support, changes and availability

Contact erik@tillgrove.com for support. We use reasonable care to operate and secure Tillgrove and correct reported defects. Maintenance and failures at Tillgrove or its providers can interrupt service. We do not promise uninterrupted or error-free operation.

We may update the app to fix issues or meet platform requirements. We give notice of material service or agreement changes. If a change requires your agreement or payment approval, we obtain that before it applies. We may restrict access for misuse, security incidents or nonpayment, with notice when practical. Nothing in these terms removes rights or duties that applicable law does not allow the parties to exclude.

5. Instructions for personal data

The following data-processing terms form part of this agreement. For personal data in your store and vendor records, you determine the purposes of processing and we process on your documented instructions. If you process data for another controller, you authorize us as your subprocessor. App configuration, authorized actions and verified support or privacy requests provide those instructions. We tell you if an instruction appears to violate applicable data-protection law, unless the law prohibits that notice.

Processing covers collecting, organizing, storing, retrieving, calculating, disclosing to authorized users and deleting information needed for the service. Data subjects include merchant users, vendors and shoppers. Data includes store and account identifiers; product, order and refund references, descriptions, amounts and dates; vendor names, email addresses and agreements; payment notes, statements and access records. We do not request shopper names, email addresses, phone numbers or addresses in our order queries. Shopify notifications and merchant-entered text can contain additional personal information. The privacy policy describes these fields and their use.

6. Limited use and safeguards

We use this data only to provide, support and secure Tillgrove, follow your instructions, or comply with law. We do not sell it, use it for targeted advertising, combine it for unrelated commercial purposes, or use it to train AI models. People authorized to access personal data must be bound to confidentiality and receive only the access required for their work.

We maintain appropriate safeguards, including access controls, authenticated requests, encryption in transit and at rest, limited vendor sessions, backups and procedures for privacy requests and incidents. We assist with your applicable privacy obligations, including requests from individuals, security assessments and data-protection impact assessments, taking account of the service and information available to us.

7. Providers and international processing

You authorize the service providers identified in the privacy policy. We use written data-protection obligations for providers processing your personal data on our behalf and remain responsible for their performance of the obligations we delegate. Before adding or replacing such a provider, we give reasonable advance notice and an opportunity to raise a substantiated data-protection objection. If we cannot resolve the objection, you may stop the affected service and export your records.

The application server is in Virginia, United States. Backup storage is in Falkenstein, Germany. Resend stores email data in the United States. Other provider locations are described in the privacy policy. Where applicable law requires a transfer agreement or other protection, it must be in place before the affected personal data is transferred. This agreement does not assert a certification or replace any separately required transfer clauses.

8. Requests, incidents and verification

We assist with verified access, correction, restriction, export and deletion requests. We work through the merchant for shopper requests and follow Shopify’s required request process. We notify you without undue delay after becoming aware of a personal-data breach affecting your store, and provide available facts and mitigation updates so you can meet your obligations.

We provide reasonable information needed to demonstrate these obligations and allow proportionate audits or inspections required by applicable data-protection law, subject to confidentiality, security and protection of other merchants’ data.

9. Return and deletion

Processing continues while needed for the service, followed by the deletion process in the privacy policy. You may export available records or instruct us to return or delete personal data when the service ends. We delete remaining copies unless law requires retention, in which case we restrict their use and explain the requirement where permitted.

Routine backups expire within the published retention period. If a backup is restored, completed erasures and redactions must be reapplied before the affected data becomes available. Records you or vendors have downloaded remain under the recipient’s control.

10. Contact

Frequent & Vigorous LLC
Tillgrove
erik@tillgrove.com