Privacy policy
Last updated 4 October 2026
Consignment Hub is a Shopify app made by TinyFloor ("we", "us"). It helps consignment shops ("merchants") track what they owe the people who consign items with them ("consignors"). This policy explains what information the app handles, why, and how long we keep it.
Information we handle
| What | Where it comes from | Why |
|---|---|---|
| Shop details: store domain, name, currency, timezone and contact email; Shopify access tokens | Shopify, when the merchant installs the app | To run the app for the shop and show amounts in its currency and timezone |
| Products and variants the merchant links to consignors: title, SKU, price, image link | The merchant's Shopify store | To know which items belong to which consignor, and to apply markdowns the merchant turns on |
| Orders that include consigned items: order number, line items, prices, discounts, refunds, fulfillment status | The merchant's Shopify store | To work out each consignor's share of each sale |
| Consignor records: name, email, phone, notes, items, sales, adjustments and payouts | Entered or imported by the merchant | To keep the merchant's consignment records, send statements and run the consignor portal |
| Portal sign-in: one-time invite links, sign-in codes and session cookies. There are no passwords | Created when a consignor opens an invite or signs in. With Sign in with Google, Google tells us only their verified email address, which we match to the shop's records and don't store separately | To let consignors see their own records securely |
| Item proposals: what a consignor proposes (title, details, asking price, quantity) and the shop's answer | Entered by the consignor in their portal | So the shop can review items before they come in |
| Email records: recipient, subject, type and delivery status | Created when the app sends an email | So merchants can see what was sent, and to troubleshoot delivery |
Information we don't collect
The app does not read or store the merchant's customers' names, email addresses, phone numbers or addresses. It only uses order details needed to calculate consignors' shares. It does not use advertising or analytics trackers, and the website and portal set no cookies other than the portal's sign-in cookies.
Who is responsible for consignor data
Merchants decide which consignor information to enter and how to use it, so for consignor data the merchant is the controller and we act as their processor. Consignors with questions about their data should contact the shop first; we will help the shop respond.
Service providers
We use these providers to run the app. Each only receives what it needs for its job.
- Shopify: the platform the app runs on and where merchants are billed.
- Oracle Cloud Infrastructure: hosting for the app and its database.
- Resend: sending emails such as statements, portal invites and sign-in codes.
- Google: optional Sign in with Google for consignors, which only shares their email address with us.
- Cloudflare: DNS for our domain, and hosting for this website.
We do not sell personal information or share it for advertising.
How long we keep information
- Merchant and consignor records are kept while the app is installed.
- When a merchant uninstalls the app, their consignor page closes straight away. Shopify notifies us 48 hours later and we delete all of that shop's data from our database, including consignor details and the email log.
- Backups are kept for up to 30 days, then deleted.
- Sign-in codes expire after 10 minutes and invites after 7 days; portal sessions end after 30 days of inactivity.
Security
All traffic uses HTTPS. Portal links, codes and session tokens are stored only as one-way hashes, the portal limits repeated sign-in attempts, and access to servers is restricted to our team.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, or to object to how it's used. Merchants can export and delete their data at any time, and uninstalling the app removes it. For anything else, email apps@tinyfloor.com.
Changes
If we change this policy, we'll update the date above, and tell merchants in the app about significant changes.
Contact
Questions about privacy: apps@tinyfloor.com.