1. Terms of service
By installing Badgely (“the App”) you agree to these terms. The App is provided by MB „Liūto media", a company registered in Lithuania (“we”, “the Provider”).
- The App sends reorder reminders on your behalf. You remain responsible for the content you write in the email template and for having a lawful basis to contact your customers.
- Paid plans are billed through Shopify. You can cancel at any time; billing stops at the end of the current period.
- We aim for continuous availability but do not guarantee uninterrupted service. We are not liable for indirect losses arising from delayed or undelivered reminders.
- We may update the App and these terms. Material changes are announced on this page.
- These terms are governed by the laws of the Republic of Lithuania.
2. Data processing agreement
This section forms the data processing agreement (DPA) between you (the data controller) and us (the data processor) under GDPR Article 28. It applies automatically when you install the App.
| Item | Detail |
|---|
| Subject matter | Scanning theme files for leftover app code and removing it on request |
| Duration | For as long as the App is installed |
| Categories of data subjects | None — Badgely does not process customer personal data |
| Types of personal data | Theme file contents, theme names and scan results. Optionally the merchant email address for monitoring alerts. |
| Sub-processors | Hetzner (EU hosting). No other third parties receive any data. |
As processor we commit to:
- Process personal data only on your documented instructions and for the purpose above.
- Keep the data confidential and limit access to authorised personnel.
- Apply the security measures described below.
- Assist you with data subject requests and with Shopify's mandatory GDPR webhooks.
- Delete all personal data when the App is uninstalled.
- Notify you without undue delay if a personal data breach affects your store.
3. Security measures
- In transit: all traffic is encrypted with HTTPS/TLS.
- At rest: databases are stored on an encrypted volume (LUKS2, AES-256-XTS); the storage is unlocked only by the server at boot.
- Access control: server access is limited to the developer and uses SSH key authentication; password login for the app account is not used.
- Access logging: server authentication and application request logs are retained, so access to the system is traceable.
- Backups: databases are backed up daily and the backup files are encrypted (AES-256) before storage; backups are retained for 7 days.
- Separation: development and testing are done with development stores, never with real merchant data.
- Minimisation: we store only the fields needed to send a reminder and to show statistics.
4. Security incident response
If we detect or are informed of a security incident, we follow this procedure:
- Contain — isolate the affected component, revoke exposed credentials and stop further data flow.
- Assess — determine what data was involved and which stores are affected, using server and application logs.
- Notify — inform affected merchants without undue delay and, where the incident constitutes a personal data breach, notify the supervisory authority within 72 hours as required by GDPR.
- Remediate — fix the root cause, deploy the correction and verify it.
- Review — document what happened and what changed to prevent recurrence.
Report a suspected vulnerability or incident to app@liutomedia.lt. We answer security reports first, usually the same day.
MB „Liūto media", Lithuania · app@liutomedia.lt · liutomedia.lt
See also our privacy policy.