Privacy Policy
1. Who is the controller
The controller of your personal data is Sugibana MB, a Lithuanian mažoji bendrija, company code 308103418, registered office Gelininkų g. 17, Laumėnai, LT-53135 Kauno r..
Before this version the controller was the founder, Edmundas Adamonis, acting personally while the company was being registered. Sugibana MB has taken over that role. The purposes, means and safeguards described in this notice did not change as a result of that transfer.
We have no United States entity and no United States establishment. We are established solely in the Republic of Lithuania.
Data-protection contact: [email protected]. We have not appointed a Data Protection Officer, because we do not meet the criteria in GDPR Article 37(1) that make one mandatory. Your requests go to the address above and are handled by the controller directly.
2. The waitlist
If you join the waitlist we collect your email address, and any name or company details you choose to give us, together with the timestamp of your signup and the version of the Terms and this Policy shown to you at that moment.
- Purpose: to invite you to create an account when we have capacity for you, and to tell you about the launch.
- Legal basis: your consent (GDPR Art. 6(1)(a)). You can withdraw it at any time, with no effect on processing carried out before withdrawal.
- Retention: twelve (12) months after we invite you or close the list, or until you ask us to delete it — whichever comes first.
- Consequence of not providing it: none, beyond not being invited. The waitlist is entirely optional and free.
A correction we owe you. Waitlist entries collected before 2026-09-08-1 were shown a version of this Policy that named two companies which do not exist. We have kept those signup records (they show who joined and when) but we are not treating the consent captured with them as valid. Before we send you any launch email we will contact you with this corrected notice and ask you to confirm. If you would rather not wait, you can have your entry deleted now at [email protected].
3. What we collect once you have an account
Account data
When you sign up via Google we receive your name, email address, Google account identifier and profile picture URL. We need this to create your workspace and identify you on sign-in. Legal basis: performance of a contract.
Workspace and business data
SKU, inventory, order, customer, supplier, warehouse and connector data you upload or that we read on your behalf from connected marketplaces. Legal basis: performance of a contract.
Some of this data may include the personal information of your customers (e.g. shipping addresses on Amazon orders). With respect to that data you are the controller and we are the processor. A data-processing agreement (DPA) governs that relationship — request a signed copy at [email protected].
Buyer personal data that reaches us through a marketplace API is additionally subject to that marketplace’s own data-protection rules, which require us to delete it on a much shorter clock than our general retention periods. Where they conflict, the shorter period wins.
Billing data
If you upgrade beyond Nano, we use Stripe to process payment. Stripe collects card and billing details directly; we receive only a token, the last four digits of the card and the billing country. Legal basis: performance of a contract. No payment data is collected while you stay on the free Nano plan.
Operational logs
We log API requests, errors, job runs and a sha-256 hash of the user-agent for security, abuse prevention and debugging. IP addresses are kept for up to ninety (90) days then discarded. Legal basis: legitimate interests (operating a secure service), balanced against your reasonable expectations.
Marketing surfaces
On public pages we record anonymised page-views (hashed user-agent, surface name, referring URL fragment) to measure adoption. We do not place tracking cookies on these surfaces. The acceptance cookie that records your Terms consent is a strictly necessary cookie and does not require a banner.
4. Where data is hosted
Production data is hosted on infrastructure located in the European Union. Some of the sub-processors listed in section 5 process data outside the EEA; where they do, transfers rely on the European Commission’s 2021 Standard Contractual Clauses together with additional safeguards (encryption at rest, access logging). You may request a copy of the relevant clauses at [email protected].
5. Who can see your data
- You and the users you invite to your workspace.
- The operator named in section 1, and any contractors bound by confidentiality, on a strict need-to-know basis (incident response, customer support you initiate).
- Sub-processors who help us run the service:
- Hostinger / VPS infrastructure provider — EU hosting.
- Google LLC — Firebase Authentication.
- Stripe, Inc. — billing & payments (paid plans only).
- Resend — transactional email.
- Amazon Web Services / Cloudflare — egress, edge caching.
- Authorities, only where compelled by law and where we have exhausted reasonable challenges. We publish a transparency note in our changelog when we have received and responded to such a request.
6. We do not sell or rent your data
We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising. We do not feed your operational data into third-party analytics platforms.
7. How long we keep data
- Waitlist entries: as described in section 2.
- Account & workspace data: for the lifetime of your account. On deletion, we delete operational copies within 90 days and purge backups within 180 days, subject to legal retention.
- Marketplace buyer data: deleted on the marketplace’s required timetable, which is shorter than the above and takes precedence.
- Billing records: kept for ten (10) years after account closure, as Lithuanian accounting and tax law requires.
- Records of which Terms version you accepted: kept for the life of the contract plus the applicable limitation period — these are our proof of what you agreed to, so they outlive the logs below.
- Audit logs: kept for two (2) years.
- Operational logs: kept for up to ninety (90) days.
8. Your rights
Wherever you live, you can ask us to do all of the following, and we will apply them to everyone rather than only to the people whose local law compels it. You have the right to:
- access the personal data we hold about you;
- have inaccurate or incomplete data corrected;
- have your data erased (subject to legal retention);
- restrict or object to certain processing;
- receive your data in a structured, commonly used, machine-readable form (data portability — available via the in-app Export feature once you have an account);
- withdraw consent at any time where processing is based on consent, such as the waitlist (this does not affect the lawfulness of prior processing);
- be free from any detriment or retaliation for exercising these rights.
To exercise any right, email [email protected]. We respond within thirty (30) days. We will verify your identity using the email address on your account or waitlist entry before disclosing or deleting anything.
If you are in the EEA, UK or Switzerland, these are your rights under GDPR Articles 15–22 and you may also lodge a complaint with your national supervisory authority. Our lead authority is the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija).
If you are in the United States, note that we are established only in Lithuania and, being well below every applicable revenue and volume threshold, we are not a “business” subject to the California Consumer Privacy Act. We are telling you this rather than implying a compliance status we do not have — but the rights listed above are offered to you regardless, as a matter of policy.
9. Children
Sugibana Flow is a business tool and is not directed at children. In Lithuania the minimum age at which a child can validly consent to information-society services is fourteen (14) (ADTAĮ Art. 6, implementing GDPR Art. 8(1)). You must be at least 14 to join the waitlist, and at least 18 — or otherwise legally capable of binding a business — to open an account. We do not knowingly collect personal data from children under 14; if you believe we have, contact us and we will delete it.
10. Security
We protect your data with TLS in transit, encryption at rest for backups and database snapshots, hashed credentials, multi-tenant isolation enforced at the row level, audit logging of administrative actions, and principle-of-least-privilege access for staff. Despite our best efforts, no system is fully secure — we will notify affected users without undue delay and within seventy-two (72) hours of confirming a personal data breach, in line with GDPR Article 33. Where an incident involves data obtained from a marketplace API, we additionally notify that marketplace within the shorter window its developer terms require.
11. Changes to this Policy
We may update this Policy from time to time. The version string at the top is bumped on every material change. We will email you and prompt you in the app before any material change takes effect, and you will be asked to re-consent before your next sign-in. The completion of Sugibana MB’s registration is a material change and will be handled that way.
12. Contact
All data-protection enquiries: [email protected].
