1. General Provisions
1.1. This Privacy Policy (the "Policy") governs the processing of personal data by UAB "OrderKrab" (the "Company") via the website orderkrab.com, the OrderKrab Web Application (admin.orderkrab.com), and all associated e-commerce connectors/plugins (collectively, the "Platform").
1.2. We are committed to the highest standards of data protection and process all personal data in strict accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Law on Legal Protection of Personal Data of the Republic of Lithuania.
1.3. This Policy applies to all Users (Merchants) who register an account, as well as the data of End-Customers processed through our Platform's fulfillment infrastructure.
2. Data Controller and Contact Information
2.1. The Data Controller for User account data is:
UAB "OrderKrab"
Registration Number: 307409974
Legal Address: Perkūnkiemio g. 19, LT-12120 Vilnius, Lithuania
Email: info@orderkrab.com
2.2. For all inquiries regarding data protection, data subjects may contact our designated privacy officer at the email address provided above.
3. Identification of Roles: Controller vs. Processor
3.1. Company as Controller: The Company is the Data Controller for the personal data of its Users (Merchants), including account credentials, billing details, and carrier API secrets.
3.2. Company as Processor: The Company acts strictly as a Data Processor regarding the personal data of End-Customers (shipment recipients) imported from e-commerce platforms. The User remains the Data Controller for their customers' data and warrants that they have a valid legal basis for transferring such data to the Company.
4. Categories of Personal Data Processed
4.1. Account Metadata: Full name, business email, phone number, company registration number, VAT code, and physical business address.
4.2. Integration & API Data: OAuth tokens, API keys, and secret credentials for e-commerce platforms (Shopify, WooCommerce, etc.) and shipping carriers.
4.3. Shipment Information: Full name of recipient, granular delivery address, contact phone number, email address, package weight, dimensions, and declared value/contents.
4.4. Financial Data: Payment method details (including card brand, last four digits, and expiry where applicable) and transaction metadata processed through Stripe, our payment service provider; we do not store full primary account numbers on our own systems. Subscription and invoice records, transaction history, tax identifiers relevant to billing, and billing logs.
4.5. Technical Logs: IP addresses, device fingerprints, browser versions, clickstream data, and session identifiers.
4.6. Debt Collection & Legal Enforcement: Where a User fails to pay subscription or other fees, we may share with debt collectors or legal representatives the data necessary to pursue the debt—including contact details, account identifiers, billing history, and related documentation—in accordance with applicable law.
5. Purposes and Legal Bases for Processing
5.1. Contract Performance (Art. 6(1)(b) GDPR): To provide the fulfillment hub services, synchronize orders, and facilitate the generation of shipping labels via User-provided carrier contracts.
5.2. Legal Compliance (Art. 6(1)(c) GDPR): To comply with Lithuanian and EU tax, accounting, and anti-money laundering (AML) regulations.
5.3. Legitimate Interest (Art. 6(1)(f) GDPR): To maintain Platform security, prevent API abuse, troubleshoot technical errors, and defend legal claims.
5.4. Consent (Art. 6(1)(a) GDPR): For the use of non-essential cookies and the distribution of marketing communications.
5.5. Debt Collection & Legal Enforcement (Art. 6(1)(b)/(f) GDPR): To enforce payment obligations and recover unpaid subscription fees, we may disclose relevant personal data to debt collection agencies or legal representatives. This processing is necessary for the performance of the contract and our legitimate interest in recovering sums owed.
5.6. Business Restructuring (Art. 6(1)(f) GDPR): In the event of a merger, acquisition, sale of assets, or other corporate restructuring, we may transfer the database (including personal data) to the successor or acquirer. Such transfers are carried out with appropriate safeguards and do not require renewed consent from each User, as the processing remains necessary for the same services under the new controller.
5.7. Billing & payments (Art. 6(1)(b) GDPR): To charge for subscription or usage-based fees, apply taxes, maintain billing records, and process payments through our payment service provider (Stripe), including fraud-related signals we receive in connection with successful or failed charges.
6. Billing, Pricing & Payment Processing
6.1. Plans and charges: If you use paid features or subscription plans, we process personal data needed to set up and administer billing—such as your selected plan or tier, billing cycle, applicable taxes, currency, invoice details, payment status, and (where relevant) usage or volume metrics tied to pricing. Pricing, upgrades, downgrades, and renewals are governed by your agreement with us (including our Terms of Service) and by the information presented at checkout or in your account.
6.2. Stripe as payment processor: We use Stripe (Stripe, Inc. and its affiliates) to collect payments, manage payment methods, and process refunds and chargebacks. When you pay us, Stripe receives the payment information you provide (for example, card details or other payment method data) and processes it on our behalf in accordance with applicable law and industry security standards (including PCI DSS). We do not receive or store your full card number on OrderKrab infrastructure; we may receive limited identifiers from Stripe (such as payment method type, last four digits, expiry, and Stripe customer or payment IDs) to operate subscriptions and support you.
6.3. Stripe's own processing: Stripe also processes personal data under its own policies and for its own purposes (for example, fraud prevention and compliance). How Stripe uses data is described in Stripe's privacy materials, including stripe.com/privacy.
6.4. International transfers: Payment data may be processed by Stripe in countries outside the European Economic Area. Stripe provides appropriate safeguards as described in its documentation and agreements.
7. Carrier Integrations & Data Transfers
7.1. User-Owned Contracts: The Platform functions as a technical interface. When a User initiates a shipment, the Company transmits the necessary data to the Carrier associated with the User's own contract.
7.2. Third-Party Controllers: Upon successful transmission of data to a Carrier's API, that Carrier becomes an independent Data Controller. The Company is not responsible for the data processing practices of third-party Carriers.
7.3. International Transfers: Data may be transferred outside the EEA only when:
- (a) The User selects a Carrier located outside the EEA;
- (b) The shipment destination is outside the EEA;
- (c) Transfers are protected by Standard Contractual Clauses (SCCs) or Adequacy Decisions.
7.4. Identity Verification: Before processing certain data subject requests (including requests for access, rectification, erasure, or data portability), we may require the requester to verify their identity. This measure protects against fraudulent or malicious requests and ensures that personal data is disclosed only to the data subject or their duly authorised representative.
8. Data Retention Policy
8.1. Active Accounts: Data is retained for the duration of the service agreement.
8.2. Statutory Retention: Financial and tax-related documents are retained for 10 years in accordance with Lithuanian Law on Archives.
8.3. System Logs: Technical logs are retained for a period of up to 12 months unless required for ongoing security investigations.
8.4. Carrier Secrets: API keys are purged from our active databases within 30 days of account termination or integration removal.
9. Data Security and Encryption
9.1. Encryption at Rest: All sensitive API credentials and carrier secrets are stored using AES-256 encryption.
9.2. Encryption in Transit: All data moving between the User's e-commerce platform, the OrderKrab Web App, and Carrier APIs is encrypted via TLS 1.3 protocols.
9.3. Access Control: We enforce strict "Principle of Least Privilege" (PoLP) access for all employees and contractors.
10. Rights of Data Subjects
10.1. Users and End-Customers (via the Merchant) possess the following rights:
- Right of Access: To obtain confirmation and a copy of processed data.
- Right to Rectification: To correct inaccurate or incomplete data.
- Right to Erasure: To request deletion when data is no longer necessary.
- Right to Restriction: To "freeze" processing in specific legal scenarios.
- Right to Data Portability: To receive data in a machine-readable format (JSON/CSV).
- Right to Object: To halt processing based on legitimate interests.
11. Cookies and Tracking Technologies
11.1. The Platform uses cookies to distinguish you from other users and ensure functionality.
11.2. Categories of Cookies:
- Strictly Necessary: Required for authentication and security.
- Analytical/Performance: Provided by third parties (e.g., Google Analytics) to monitor Platform health.
- Advertising/Targeting: Set by advertising partners to measure campaign performance and to show you OrderKrab advertisements on third-party platforms. These are never loaded before you have accepted them.
- Preference: To store your UI settings (language, timezone).
11.3. Meta Pixel (Facebook and Instagram): If you accept advertising cookies, the Platform loads the Meta Pixel, a tracking technology provided by Meta Platforms Ireland Limited (4 Grand Canal Square, Dublin 2, Ireland). The Pixel records that a browser visited a page on orderkrab.com and sets the first-party cookies _fbp and, where you arrived from a Meta advertisement, _fbc. We use it to measure advertising performance and to show OrderKrab advertisements on Facebook and Instagram to people who have previously visited this website. The Pixel is loaded only after consent has been given (Art. 6(1)(a) GDPR): no request is sent to Meta, and no Meta cookie is set, before that point. Meta necessarily receives your IP address and basic browser information in order to receive any event.
11.4. Identifiers sent when you submit a form: The Pixel uses Meta's Automatic Advanced Matching. Where advertising cookies are active and you submit a form on this website, the following values are read from that form, hashed in your browser, and transmitted to Meta in hashed form only: your email address, your first and last name, and your country. The readable values are not transmitted, and the content of free-text fields, including your message, is not transmitted. Meta uses these hashes to match the submission to a Meta account. Hashed identifiers remain personal data under the GDPR: this processing rests on the same consent as the rest of this section, and withdrawing that consent stops it.
11.5. Joint controllership and international transfers: For the collection of the Pixel data and identifiers described above and their transmission to Meta, the Company and Meta Platforms Ireland Limited act as joint controllers within the meaning of Art. 26 GDPR, on the terms of Meta's Controller Addendum. Meta's subsequent processing of that data is carried out by Meta alone and is governed by Meta's own privacy policy. You may exercise your data subject rights against either party. Meta may transfer this data to Meta Platforms, Inc. in the United States on the basis of the EU-U.S. Data Privacy Framework and, where applicable, Standard Contractual Clauses. Advertising audiences built from website activity are retained for no longer than 180 days from your last visit.
11.6. You may accept or refuse each category of non-essential cookies when you first visit the Platform, and may change or withdraw that choice at any time using the cookie preferences control available on every page. Withdrawal is as straightforward as giving consent and takes effect immediately; it does not affect the lawfulness of processing carried out beforehand. Essential cookies cannot be disabled, as the Platform will not function without them.
12. Modifications to This Policy
12.1. We reserve the right to modify this Policy at any time. Significant changes will be notified via the Platform dashboard or via email. Continued use of the Platform after changes constitutes acceptance of the updated terms.
13. Supervisory Authority
13.1. If you believe your rights have been violated, you have the right to lodge a complaint with the State Data Protection Inspectorate of the Republic of Lithuania (vdai.lrv.lt).
