Yeli is installed by online store owners (“Merchants”) to collect, display, and manage product reviews from their customers (“Reviewers” or “you,” when this policy addresses an end customer).
Yeli’s processing of Merchant Data on a Merchant’s behalf is additionally governed by our Data Processing Addendum, which forms part of the agreement between Yeli and every Merchant using the app.
From Reviewers, via the Merchant’s store
We do not collect phone numbers or physical mailing addresses.
From Merchants
Shop name, contact email, Shopify shop id and domain, store currency and timezone, plan/billing status, and the app’s configuration settings (branding, moderation rules, email templates, etc.).
What we don’t do
Unlike some apps in this category, Yeli does not run any third-party analytics, tracking pixel, or session-replay tool (no Google Analytics, no Hotjar, no Meta/X pixel) in the admin app or the storefront widgets, and does not use tracking cookies — see Section 10.
We do not sell personal data, and we do not use Reviewer data for advertising or marketing unrelated to the review the Reviewer submitted.
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Displaying reviews, verifying purchases, applying Merchant settings | Performance of our contract with the Merchant |
| Sending review-request/reminder emails, incentive discounts | Performance of our contract with the Merchant; the Merchant’s legitimate interest in soliciting reviews |
| Preventing duplicate votes/flags | Legitimate interest in the integrity of the review system |
| Automated review-text analysis (Section 5) | Legitimate interest in improving review quality signals for the Merchant |
| Fulfilling data-subject requests and legal obligations | Legal obligation |
| Billing the Merchant | Performance of our contract with the Merchant |
We use a small number of service providers (“sub-processors”) to operate Yeli, each contractually restricted to using data only to provide their service to us, not for their own purposes. These fall into a few categories:
For the specific sub-processors we use and where they’re located, see Section 5 of our Data Processing Addendum.
We may also disclose data where required by law, to enforce our terms, or to protect the rights, property, or safety of Yeli, our Merchants, or others. If Yeli is involved in a merger, acquisition, or asset sale, data may be transferred as part of that transaction, subject to this policy (or a policy providing at least equivalent protection).
We retain personal data only for as long as it serves the purpose it was collected for — specifically, for as long as the Merchant’s relationship with Yeli and the Reviewer’s relationship with the Merchant’s store remain active. We do not run an arbitrary time-based auto-delete on active data, because a review still needs its author’s name to remain meaningfully displayed for as long as it’s live.
Retention ends, and personal data is erased, in two cases:
customers/redact process): their reviews are unpublished, their photos and videos are permanently deleted, and their name/email/Shopify customer id are irreversibly anonymized. Any pending review-request emails addressed to them are anonymized the same way.shop/redact process): every Reviewer’s identity for that store is anonymized, all review media is permanently deleted, all reviews are unpublished, and all email-request history for that store is anonymized.Depending on where you live, you may have some or all of the following rights over your personal data:
Because Yeli acts as a Data Processor for Reviewer data, the fastest way to exercise these rights is usually through the store where you left a review — Merchants can submit Shopify’s standard customer data-request and erasure requests, which Yeli fulfills automatically. You are also welcome to contact us directly (Section 13) and we will either action the request or route it to the relevant Merchant. We may ask for reasonable proof of identity before acting on a request.
If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection supervisory authority (in the UK, the Information Commissioner’s Office, ico.org.uk) — though we’d appreciate the chance to resolve your concern directly first.
We do not sell personal data, so there is nothing to opt out of in that regard.
If you are a resident of California or another US state with its own privacy law, you have the right to know what categories of personal data we collect about you and why (Section 2 and 3), to request deletion or correction of that data, and not to be discriminated against for exercising these rights. We do not sell personal data and have not done so in the past 12 months, and we do not share personal data for cross-context behavioral advertising. To exercise any of these rights, contact us using the details in Section 13; you may also designate an authorized agent to act on your behalf, subject to us verifying both your identity and the agent’s authorization.
The Service is not directed to, and we do not knowingly collect personal data from, anyone under the age of 16. If you believe a child has provided us with personal data, please contact us (Section 13) and we will take steps to remove it.
We do not use tracking or advertising cookies. The storefront widgets use browser local/session storage only for functional purposes (e.g., remembering an in-progress review draft), never for advertising or cross-site tracking, and we do not run third-party analytics or session-replay tools (Section 2). Because we don’t track you across sites, we do not respond differently to browser “Do Not Track” signals — there is nothing to opt out of.
We use industry-standard safeguards appropriate to the data we hold, including encrypted connections (TLS) between our services and our database, encryption at rest and for backups (provided by our database host), and access to production systems restricted to authorized personnel only. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we maintain an internal incident response process and will notify affected Merchants without undue delay if we become aware of a breach affecting their data.
Our infrastructure and sub-processors (Section 5) are located in and may process data in the United States. Where required, we rely on appropriate safeguards for transfers of personal data out of the UK/EEA. Contact us for more information about the specific mechanism relevant to your data.
Questions about this policy, or requests relating to your personal data, can be sent to support@yeli.thunder-team.com.
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above; where required by law, we will provide additional notice.