Privacy Policy

thunder-team · Last updated September 5, 2026

This Privacy Policy explains how Yeli (“Yeli,” “we,” “us,” or “our”) collects, uses, and protects personal data when a merchant installs the Yeli app on their Shopify store (the “Service”), and when that merchant’s customers interact with Yeli-powered review features on the merchant’s storefront.

1. Who This Policy Applies To, and Our Role

Yeli is installed by online store owners (“Merchants”) to collect, display, and manage product reviews from their customers (“Reviewers” or “you,” when this policy addresses an end customer).

Yeli’s processing of Merchant Data on a Merchant’s behalf is additionally governed by our Data Processing Addendum, which forms part of the agreement between Yeli and every Merchant using the app.

2. What We Collect

From Reviewers, via the Merchant’s store

We do not collect phone numbers or physical mailing addresses.

From Merchants

Shop name, contact email, Shopify shop id and domain, store currency and timezone, plan/billing status, and the app’s configuration settings (branding, moderation rules, email templates, etc.).

What we don’t do

Unlike some apps in this category, Yeli does not run any third-party analytics, tracking pixel, or session-replay tool (no Google Analytics, no Hotjar, no Meta/X pixel) in the admin app or the storefront widgets, and does not use tracking cookies — see Section 10.

3. How We Use This Data

We do not sell personal data, and we do not use Reviewer data for advertising or marketing unrelated to the review the Reviewer submitted.

4. Legal Basis for Processing (EU/UK Visitors)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Displaying reviews, verifying purchases, applying Merchant settingsPerformance of our contract with the Merchant
Sending review-request/reminder emails, incentive discountsPerformance of our contract with the Merchant; the Merchant’s legitimate interest in soliciting reviews
Preventing duplicate votes/flagsLegitimate interest in the integrity of the review system
Automated review-text analysis (Section 5)Legitimate interest in improving review quality signals for the Merchant
Fulfilling data-subject requests and legal obligationsLegal obligation
Billing the MerchantPerformance of our contract with the Merchant

5. Who We Share Data With

We use a small number of service providers (“sub-processors”) to operate Yeli, each contractually restricted to using data only to provide their service to us, not for their own purposes. These fall into a few categories:

For the specific sub-processors we use and where they’re located, see Section 5 of our Data Processing Addendum.

We may also disclose data where required by law, to enforce our terms, or to protect the rights, property, or safety of Yeli, our Merchants, or others. If Yeli is involved in a merger, acquisition, or asset sale, data may be transferred as part of that transaction, subject to this policy (or a policy providing at least equivalent protection).

6. Data Retention

We retain personal data only for as long as it serves the purpose it was collected for — specifically, for as long as the Merchant’s relationship with Yeli and the Reviewer’s relationship with the Merchant’s store remain active. We do not run an arbitrary time-based auto-delete on active data, because a review still needs its author’s name to remain meaningfully displayed for as long as it’s live.

Retention ends, and personal data is erased, in two cases:

7. Your Rights

Depending on where you live, you may have some or all of the following rights over your personal data:

Because Yeli acts as a Data Processor for Reviewer data, the fastest way to exercise these rights is usually through the store where you left a review — Merchants can submit Shopify’s standard customer data-request and erasure requests, which Yeli fulfills automatically. You are also welcome to contact us directly (Section 13) and we will either action the request or route it to the relevant Merchant. We may ask for reasonable proof of identity before acting on a request.

If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection supervisory authority (in the UK, the Information Commissioner’s Office, ico.org.uk) — though we’d appreciate the chance to resolve your concern directly first.

We do not sell personal data, so there is nothing to opt out of in that regard.

8. Additional Notice for California and Other US Residents

If you are a resident of California or another US state with its own privacy law, you have the right to know what categories of personal data we collect about you and why (Section 2 and 3), to request deletion or correction of that data, and not to be discriminated against for exercising these rights. We do not sell personal data and have not done so in the past 12 months, and we do not share personal data for cross-context behavioral advertising. To exercise any of these rights, contact us using the details in Section 13; you may also designate an authorized agent to act on your behalf, subject to us verifying both your identity and the agent’s authorization.

9. Children’s Privacy

The Service is not directed to, and we do not knowingly collect personal data from, anyone under the age of 16. If you believe a child has provided us with personal data, please contact us (Section 13) and we will take steps to remove it.

10. Cookies and Tracking

We do not use tracking or advertising cookies. The storefront widgets use browser local/session storage only for functional purposes (e.g., remembering an in-progress review draft), never for advertising or cross-site tracking, and we do not run third-party analytics or session-replay tools (Section 2). Because we don’t track you across sites, we do not respond differently to browser “Do Not Track” signals — there is nothing to opt out of.

11. Security

We use industry-standard safeguards appropriate to the data we hold, including encrypted connections (TLS) between our services and our database, encryption at rest and for backups (provided by our database host), and access to production systems restricted to authorized personnel only. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we maintain an internal incident response process and will notify affected Merchants without undue delay if we become aware of a breach affecting their data.

12. International Data Transfers

Our infrastructure and sub-processors (Section 5) are located in and may process data in the United States. Where required, we rely on appropriate safeguards for transfers of personal data out of the UK/EEA. Contact us for more information about the specific mechanism relevant to your data.

13. Contact Us

Questions about this policy, or requests relating to your personal data, can be sent to support@yeli.thunder-team.com.

thunder-team #207/1/1, Road#2, North Shyamoli, Dhaka - 1207, Bangladesh

14. Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above; where required by law, we will provide additional notice.