📄 Legal

Privacy policy

Plain language, no surprises. Applies to MailMedic, Repeatly and ThemeMedic. Last updated: August 22, 2026.

This policy explains what our Shopify apps collect when you install them, how that information is used, and how it is deleted. The apps are operated by MB „Liūto media“, a company registered in Lithuania (“we”, “us”).

For data belonging to your store and your customers, you are the data controller and we act as your processor. Details are in our data processing agreement.

MailMedic

DataWhy
Your domain names and their public DNS recordsTo check SPF, DKIM, DMARC and related email settings
Scan results, scores and historyTo show findings and detect when deliverability degrades
An email address you enter for alertsOnly to send monitoring alerts you asked for

MailMedic reads publicly available DNS records. It does not read your emails, your orders, your products or your customers — and it never changes anything in your store or DNS.

Repeatly

DataWhy
Customer email address and marketing consent statusTo send the reminder, and to skip customers who did not consent
Purchased products, quantity, order date, line amountTo learn repurchase intervals and show recovered revenue
Reminder log, unsubscribes and snooze choicesTo avoid duplicates and never contact someone who opted out
Web push subscription (browser endpoint and keys)Only when a shopper explicitly allows notifications

Repeatly never stores customer names, postal addresses, phone numbers or payment details.

ThemeMedic

DataWhy
Theme file contents and namesTo find leftover app code, broken renders and dead resources
Scan results and theme backupsTo show findings and to make every cleanup reversible
An email address you enter for alertsOnly to send monitoring alerts you asked for

ThemeMedic does not process any personal data about your shoppers.

How the information is used

We never use merchant or customer data for our own marketing, never build profiles across stores, and never use it to train machine-learning models.

Sharing and selling

We do not sell, rent or share personal information — including as those terms are defined by the CCPA. Our sub-processors are listed on the GDPR & CCPA page.

Storage and security

Data is stored on our own servers in the European Union. Databases sit on an encrypted volume (LUKS2, AES-256), all traffic is encrypted with TLS, and daily backups are encrypted before storage. The full description is in our security policy.

Retention and deletion

Your rights

Depending on where you live, you may have rights to access, correct, delete or port your personal data, and to object to or restrict processing. How to exercise them — and how California's CCPA/CPRA applies — is explained on the GDPR & CCPA page.

Cookies

Our marketing pages set no cookies and run no analytics. Inside the apps, only the session cookies required by Shopify for authentication are used.

Contact

Questions about this policy or your data: app@liutomedia.lt
MB „Liūto media“, Lithuania · company details