Privacy Policy

Privacy Policy

Last updated: 2026-03-23

1. General Provisions

1.1. This Privacy Policy (the "Policy") governs the processing of personal data by UAB "OrderKrab" (the "Company") via the website orderkrab.com, the OrderKrab Web Application (admin.orderkrab.com), and all associated e-commerce connectors/plugins (collectively, the "Platform").

1.2. We are committed to the highest standards of data protection and process all personal data in strict accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Law on Legal Protection of Personal Data of the Republic of Lithuania.

1.3. This Policy applies to all Users (Merchants) who register an account, as well as the data of End-Customers processed through our Platform's fulfillment infrastructure.

2. Data Controller and Contact Information

2.1. The Data Controller for User account data is:

UAB "OrderKrab"
Registration Number: 307409974
Legal Address: Perkūnkiemio g. 19, LT-12120 Vilnius, Lithuania
Email: info@orderkrab.com

2.2. For all inquiries regarding data protection, data subjects may contact our designated privacy officer at the email address provided above.

3. Identification of Roles: Controller vs. Processor

3.1. Company as Controller: The Company is the Data Controller for the personal data of its Users (Merchants), including account credentials, billing details, and carrier API secrets.

3.2. Company as Processor: The Company acts strictly as a Data Processor regarding the personal data of End-Customers (shipment recipients) imported from e-commerce platforms. The User remains the Data Controller for their customers' data and warrants that they have a valid legal basis for transferring such data to the Company.

4. Categories of Personal Data Processed

4.1. Account Metadata: Full name, business email, phone number, company registration number, VAT code, and physical business address.

4.2. Integration & API Data: OAuth tokens, API keys, and secret credentials for e-commerce platforms (Shopify, WooCommerce, etc.) and shipping carriers.

4.3. Shipment Information: Full name of recipient, granular delivery address, contact phone number, email address, package weight, dimensions, and declared value/contents.

4.4. Financial Data: Payment method details (including card brand, last four digits, and expiry where applicable) and transaction metadata processed through Stripe, our payment service provider; we do not store full primary account numbers on our own systems. Subscription and invoice records, transaction history, tax identifiers relevant to billing, and billing logs.

4.5. Technical Logs: IP addresses, device fingerprints, browser versions, clickstream data, and session identifiers.

4.6. Debt Collection & Legal Enforcement: Where a User fails to pay subscription or other fees, we may share with debt collectors or legal representatives the data necessary to pursue the debt—including contact details, account identifiers, billing history, and related documentation—in accordance with applicable law.

5. Purposes and Legal Bases for Processing

5.1. Contract Performance (Art. 6(1)(b) GDPR): To provide the fulfillment hub services, synchronize orders, and facilitate the generation of shipping labels via User-provided carrier contracts.

5.2. Legal Compliance (Art. 6(1)(c) GDPR): To comply with Lithuanian and EU tax, accounting, and anti-money laundering (AML) regulations.

5.3. Legitimate Interest (Art. 6(1)(f) GDPR): To maintain Platform security, prevent API abuse, troubleshoot technical errors, and defend legal claims.

5.4. Consent (Art. 6(1)(a) GDPR): For the use of non-essential cookies and the distribution of marketing communications.

5.5. Debt Collection & Legal Enforcement (Art. 6(1)(b)/(f) GDPR): To enforce payment obligations and recover unpaid subscription fees, we may disclose relevant personal data to debt collection agencies or legal representatives. This processing is necessary for the performance of the contract and our legitimate interest in recovering sums owed.

5.6. Business Restructuring (Art. 6(1)(f) GDPR): In the event of a merger, acquisition, sale of assets, or other corporate restructuring, we may transfer the database (including personal data) to the successor or acquirer. Such transfers are carried out with appropriate safeguards and do not require renewed consent from each User, as the processing remains necessary for the same services under the new controller.

5.7. Billing & payments (Art. 6(1)(b) GDPR): To charge for subscription or usage-based fees, apply taxes, maintain billing records, and process payments through our payment service provider (Stripe), including fraud-related signals we receive in connection with successful or failed charges.

6. Billing, Pricing & Payment Processing

6.1. Plans and charges: If you use paid features or subscription plans, we process personal data needed to set up and administer billing—such as your selected plan or tier, billing cycle, applicable taxes, currency, invoice details, payment status, and (where relevant) usage or volume metrics tied to pricing. Pricing, upgrades, downgrades, and renewals are governed by your agreement with us (including our Terms of Service) and by the information presented at checkout or in your account.

6.2. Stripe as payment processor: We use Stripe (Stripe, Inc. and its affiliates) to collect payments, manage payment methods, and process refunds and chargebacks. When you pay us, Stripe receives the payment information you provide (for example, card details or other payment method data) and processes it on our behalf in accordance with applicable law and industry security standards (including PCI DSS). We do not receive or store your full card number on OrderKrab infrastructure; we may receive limited identifiers from Stripe (such as payment method type, last four digits, expiry, and Stripe customer or payment IDs) to operate subscriptions and support you.

6.3. Stripe's own processing: Stripe also processes personal data under its own policies and for its own purposes (for example, fraud prevention and compliance). How Stripe uses data is described in Stripe's privacy materials, including stripe.com/privacy.

6.4. International transfers: Payment data may be processed by Stripe in countries outside the European Economic Area. Stripe provides appropriate safeguards as described in its documentation and agreements.

7. Carrier Integrations & Data Transfers

7.1. User-Owned Contracts: The Platform functions as a technical interface. When a User initiates a shipment, the Company transmits the necessary data to the Carrier associated with the User's own contract.

7.2. Third-Party Controllers: Upon successful transmission of data to a Carrier's API, that Carrier becomes an independent Data Controller. The Company is not responsible for the data processing practices of third-party Carriers.

7.3. International Transfers: Data may be transferred outside the EEA only when:

  • (a) The User selects a Carrier located outside the EEA;
  • (b) The shipment destination is outside the EEA;
  • (c) Transfers are protected by Standard Contractual Clauses (SCCs) or Adequacy Decisions.

7.4. Identity Verification: Before processing certain data subject requests (including requests for access, rectification, erasure, or data portability), we may require the requester to verify their identity. This measure protects against fraudulent or malicious requests and ensures that personal data is disclosed only to the data subject or their duly authorised representative.

8. Data Retention Policy

8.1. Active Accounts: Data is retained for the duration of the service agreement.

8.2. Statutory Retention: Financial and tax-related documents are retained for 10 years in accordance with Lithuanian Law on Archives.

8.3. System Logs: Technical logs are retained for a period of up to 12 months unless required for ongoing security investigations.

8.4. Carrier Secrets: API keys are purged from our active databases within 30 days of account termination or integration removal.

9. Data Security and Encryption

9.1. Encryption at Rest: All sensitive API credentials and carrier secrets are stored using AES-256 encryption.

9.2. Encryption in Transit: All data moving between the User's e-commerce platform, the OrderKrab Web App, and Carrier APIs is encrypted via TLS 1.3 protocols.

9.3. Access Control: We enforce strict "Principle of Least Privilege" (PoLP) access for all employees and contractors.

10. Rights of Data Subjects

10.1. Users and End-Customers (via the Merchant) possess the following rights:

  • Right of Access: To obtain confirmation and a copy of processed data.
  • Right to Rectification: To correct inaccurate or incomplete data.
  • Right to Erasure: To request deletion when data is no longer necessary.
  • Right to Restriction: To "freeze" processing in specific legal scenarios.
  • Right to Data Portability: To receive data in a machine-readable format (JSON/CSV).
  • Right to Object: To halt processing based on legitimate interests.

11. Cookies and Tracking Technologies

11.1. The Platform uses cookies to distinguish you from other users and ensure functionality.

11.2. Categories of Cookies:

  • Strictly Necessary: Required for authentication and security.
  • Analytical/Performance: Provided by third parties (e.g., Google Analytics) to monitor Platform health.
  • Preference: To store your UI settings (language, timezone).

11.3. Users may manage cookie preferences via their browser settings; however, disabling essential cookies will result in Platform failure.

12. Modifications to This Policy

12.1. We reserve the right to modify this Policy at any time. Significant changes will be notified via the Platform dashboard or via email. Continued use of the Platform after changes constitutes acceptance of the updated terms.

13. Supervisory Authority

13.1. If you believe your rights have been violated, you have the right to lodge a complaint with the State Data Protection Inspectorate of the Republic of Lithuania (vdai.lrv.lt).