1. Terms of service
By installing Repeatly (“the App”) you agree to these terms. The App is provided by MB „Liūto media", a company registered in Lithuania (“we”, “the Provider”).
- The App sends reorder reminders on your behalf. You remain responsible for the content you write in the email template and for having a lawful basis to contact your customers.
- Paid plans are billed through Shopify. You can cancel at any time; billing stops at the end of the current period.
- We aim for continuous availability but do not guarantee uninterrupted service. We are not liable for indirect losses arising from delayed or undelivered reminders.
- We may update the App and these terms. Material changes are announced on this page.
- These terms are governed by the laws of the Republic of Lithuania.
2. Data processing agreement
This section forms the data processing agreement (DPA) between you (the data controller) and us (the data processor) under GDPR Article 28. It applies automatically when you install the App.
| Item | Detail |
|---|
| Subject matter | Sending reorder reminders and showing repeat-purchase statistics |
| Duration | For as long as the App is installed |
| Categories of data subjects | Your customers who placed an order |
| Types of personal data | Email address, marketing consent status, purchased products, quantity, order date and line amount |
| Sub-processors | Hetzner (EU hosting). Browser push services (Google, Mozilla, Microsoft, Apple) receive only an encrypted payload when push is enabled. |
As processor we commit to:
- Process personal data only on your documented instructions and for the purpose above.
- Keep the data confidential and limit access to authorised personnel.
- Apply the security measures described below.
- Assist you with data subject requests and with Shopify's mandatory GDPR webhooks.
- Delete all personal data when the App is uninstalled.
- Notify you without undue delay if a personal data breach affects your store.
3. Security measures
- In transit: all traffic is encrypted with HTTPS/TLS.
- At rest: databases are stored on an encrypted volume (LUKS2, AES-256-XTS); the storage is unlocked only by the server at boot.
- Access control: server access is limited to the developer and uses SSH key authentication; password login for the app account is not used.
- Access logging: server authentication and application request logs are retained, so access to the system is traceable.
- Backups: databases are backed up daily and the backup files are encrypted (AES-256) before storage; backups are retained for 7 days.
- Separation: development and testing are done with development stores, never with real merchant data.
- Minimisation: we store only the fields needed to send a reminder and to show statistics.
4. Security incident response
If we detect or are informed of a security incident, we follow this procedure:
- Contain — isolate the affected component, revoke exposed credentials and stop further data flow.
- Assess — determine what data was involved and which stores are affected, using server and application logs.
- Notify — inform affected merchants without undue delay and, where the incident constitutes a personal data breach, notify the supervisory authority within 72 hours as required by GDPR.
- Remediate — fix the root cause, deploy the correction and verify it.
- Review — document what happened and what changed to prevent recurrence.
Report a suspected vulnerability or incident to app@liutomedia.lt. We answer security reports first, usually the same day.
MB „Liūto media", Lithuania · app@liutomedia.lt · liutomedia.lt
See also our privacy policy.