Privacy Policy
Trackly: Order Tracking Page · Last updated September 14, 2026
Trackly: Order Tracking Page (“Trackly”, “the App”, “we”) is a Shopify app provided by SolApp. It adds an order tracking page to a merchant’s Shopify store. This policy explains what information the App accesses, how it is used, and the choices merchants and their customers have.
Information we collect from merchants
When a merchant installs the App, Shopify gives us:
- The store’s myshopify domain and an access token limited to reading orders (
read_ordersandread_all_orders, so shoppers can also track orders placed more than 60 days ago). The App has no write access to the store. - The tracking page settings the merchant enters: display name, brand color, logo URL, support email and support message.
Information about customers
When a shopper uses the tracking page, they enter an order number and the email address used at checkout. The App uses these only to look up that order through the Shopify Admin API at the moment of the request and to confirm the email matches the order. It then shows the order’s fulfillment status, carrier, tracking number and delivery events.
We do not store customer names, email addresses, addresses, phone numbers or order details. Email addresses are never written to our logs. We do not use customer data for marketing, advertising, profiling or analytics, and we do not sell or share it.
How we use information
- To show the merchant’s branded tracking page and answer order lookups.
- To authenticate the merchant inside the Shopify admin.
- To provide support when the merchant contacts us.
Sharing
Information is processed only by Shopify and by Google Cloud / Firebase, which hosts the App. We do not share information with any other third party.
Security and retention
Data is transmitted over HTTPS and stored encrypted at rest in Google Cloud. Access is limited to the people who operate the App. Order lookups are rate-limited and return no information unless both the order number and the matching email are provided.
When a merchant uninstalls the App, the access token is deleted immediately. Within 48 hours of uninstalling, Shopify sends a shop/redact request and we delete all remaining store settings. Because we store no customer data, customer data requests and deletion requests (customers/data_request, customers/redact) have no stored data to return or remove.
Your rights
Merchants and their customers may request access to, correction of, or deletion of their information at any time. Customers of a store should contact that store; merchants can contact us directly.
Changes
We may update this policy and will change the date above when we do.
Contact
Questions about this policy: linhnguyenvan1902@gmail.com