Privacy Policy

Last updated: 10 July 2026

This Privacy Policy explains how Siuntora (available at siuntora.com, the "Service") collects, uses and protects personal data. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the laws of the Republic of Lithuania.

1. Who is responsible for your data

Digitasodas, MB
Company code: 305676811
VAT code: LT100016563313
K. Čerbulėno g. 17-2, LT-47266 Kaunas, Lithuania
Email: [email protected]

Our role depends on whose data is being processed:

  • For your account data (you as a Siuntora user), we are the data controller.
  • For your customers' data (people whose orders, addresses and contact details you manage through the Service), you are the data controller and we are your data processor — we process that data only on your instructions, as described in Section 8.

2. What data we collect

2.1 Account data (you as a user)

  • Name and email address
  • Password (stored as a cryptographic hash — we cannot see it)
  • Optional two-factor authentication and passkey details
  • Company details you provide (company name, VAT code, address)
  • Billing information for paid plans (plan, invoices, payment status; card details are held by our payment provider, not by us)
  • Support correspondence

2.2 Business data you enter (your customers' data)

  • Customer names, email addresses, phone numbers and delivery addresses
  • Customer company and VAT details
  • Orders, order notes, products, inventory records and invoices

2.3 Integration data

  • Shopify: when you connect a Shopify store, we access data only within the scopes you explicitly approve (reading and writing orders, reading products, writing inventory levels).
  • Shipping carriers: API credentials you provide for carriers (DPD, Omniva, LP Express, Venipak) are stored encrypted and used only to create shipments and print labels on your instruction.

2.4 Technical data

  • Server logs (IP address, timestamp, requested pages) kept for security and troubleshooting
  • Session information needed to keep you logged in securely

We do not use advertising trackers, and we do not sell personal data to anyone.

3. Why we process data and on what legal basis

PurposeDataLegal basis (GDPR Art. 6)
Providing the Service (accounts, orders, inventory, shipping, invoicing)Account data, business data, integration dataPerformance of a contract (6(1)(b))
Billing and subscription managementAccount and billing dataPerformance of a contract (6(1)(b)); legal obligation (6(1)(c))
Tax and accounting compliance (retention of invoices)Invoicing recordsLegal obligation (6(1)(c)) under Lithuanian accounting and tax law
Security, fraud prevention, troubleshootingTechnical data, logsLegitimate interest (6(1)(f)) in keeping the Service secure
Service communications (renewal notices, material changes, security alerts)Email addressPerformance of a contract (6(1)(b)); legitimate interest (6(1)(f))
Third-party integrations you enableIntegration dataPerformance of a contract (6(1)(b)); your explicit action connecting the service

4. Cookies

Siuntora uses only cookies that are strictly necessary for the Service to function: session cookies to keep you signed in and security cookies (for example, CSRF protection). Because we use no analytics or marketing cookies, no cookie consent banner is required. If this changes, we will update this policy and ask for consent where required.

5. Who we share data with

We share personal data only with the following categories of recipients, and only to the extent necessary:

  • Hosting provider: our infrastructure is located in the European Union.
  • Payment provider: processes subscription payments on our behalf; card data is handled by the provider under PCI-DSS and is not stored by us.
  • Shopify: if and only if you connect a Shopify store, data is exchanged with Shopify under the scopes you approve.
  • Shipping carriers: if you create shipments, the recipient's name, address and contact details are transmitted to the carrier you selected — this is necessary to deliver the parcel.
  • Public authorities: where we are legally required to disclose data (for example, tax authorities).

All processors acting on our behalf are bound by data processing agreements consistent with Article 28 GDPR.

6. International transfers

Personal data is stored on servers within the European Economic Area (EEA). We do not transfer personal data outside the EEA. If a future integration you enable requires such a transfer (for example, a third-party platform operating outside the EEA), it will occur only under appropriate safeguards such as adequacy decisions or EU Standard Contractual Clauses.

7. How long we keep data

  • Account data: kept while your account is active. When you delete your account, personal data is deleted within 30 days, except data we must retain by law.
  • Invoices and accounting records: retained for the period required by Lithuanian accounting and tax law (generally 10 years).
  • Server logs: retained for a short period (up to 12 months) for security purposes.
  • Backups: encrypted backups are rotated on a fixed schedule; deleted data disappears from backups within that cycle (maximum 30 days).

8. Our commitments as your data processor

When you use Siuntora to manage your customers' personal data, we commit to the following, which forms the data processing arrangement between you (controller) and us (processor):

  • We process your customers' data only to provide the Service to you and on your documented instructions.
  • All personnel with access to data are bound by confidentiality.
  • We implement appropriate technical and organisational measures, including encryption in transit, encrypted storage of credentials, access controls, two-factor authentication and audit trails.
  • We will assist you, insofar as reasonably possible, in responding to your customers' requests to exercise their GDPR rights.
  • We will notify you without undue delay after becoming aware of a personal data breach affecting your data.
  • We engage sub-processors (hosting, payments) only under contracts imposing equivalent data protection obligations, and will inform you of changes to sub-processors.
  • Upon account deletion, we delete or return your customers' data as described in Section 7.

8.1 Shopify data requests

For connected Shopify stores, we automatically honour Shopify's mandatory privacy webhooks: customer data requests (data compiled and provided within 30 days), customer redaction (data erased, with encrypted backups purged within 30 days), and shop redaction after app uninstallation.

9. Your rights

If we hold personal data about you, you have the right to:

  • Access — obtain a copy of your personal data;
  • Rectification — correct inaccurate data (most account data can be edited directly in your profile);
  • Erasure — delete your data (self-service account deletion is available in profile settings);
  • Portability — receive your data in a machine-readable format (CSV export is built in);
  • Restriction and objection — restrict or object to certain processing;
  • Complaint — lodge a complaint with a supervisory authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt. You may also complain to the authority of your country of residence.

To exercise any right that is not self-service, email [email protected]. We respond within one month.

If you are a customer of a business that uses Siuntora, please direct privacy requests to that business — they control your data, and we will assist them in fulfilling your request.

10. Security

We protect data using industry-standard measures: TLS encryption in transit, hashed passwords, encrypted storage of API credentials, role-based access control, optional two-factor authentication and passkeys, and audit trails for inventory operations. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the supervisory authority as required by Articles 33–34 GDPR.

11. Children

The Service is intended for business use and is not directed at children under 18. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top shows the current version. For material changes we will notify you by email or in-app notice before they take effect.

13. Contact

Privacy questions and requests: [email protected]
Postal address: Digitasodas, MB, K. Čerbulėno g. 17-2, LT-47266 Kaunas, Lithuania