Legal
Privacy policy
Last updated 7 September 2026.
This policy covers the korbora.com website and the Shopify apps Korbora publishes. It is written for the merchants who install those apps. A bracketed line is a fact that has not been filled in yet; it stays visible until it is.
Overview
Korbora is the app-publishing name of Digitasodas MB, a company registered in Lithuania. Korbora builds Shopify apps that do one narrow job inside your store. This policy says what data those apps read, what they keep and for how long, who else processes it, and what you can ask for.
The website
korbora.com is a static site. It sets no cookies. Traffic is measured with Cloudflare Web Analytics, which does not use cookies or client-side state and does not follow visitors across sites. Fonts are served from korbora.com itself; your browser makes no request to a third-party service from this site.
Writing to info@korbora.com sends an email. That email, and the reply, is kept at Google Workspace indefinitely, unless you ask for it to be deleted.
Information the apps collect
When you install a Korbora app, Shopify shares the data covered by the app’s access scopes and nothing else. Each app’s page on korbora.com lists its scopes in plain language.
Korbora Quantity Rules & MOQ reads and writes product and variant metafields (the quantity rules you set), installs and reads the checkout validation that enforces them, reads your store’s primary language once at install, and registers an app proxy the storefront embed fetches rules through. It keeps your store’s domain and access token, your plan, and the rule configuration and messages you set. The rules themselves are metafields on your own products, inside your Shopify store.
Korbora Bury Sold Out reads products, inventory and locations, and writes the sort order of the collections you tell it to manage. It keeps your store’s domain and access token, which collections are managed and their positions, the inventory levels it has seen, and an audit log of every move it made.
Technical data. Request metadata — time, IP address, user agent — for the app’s own endpoints and webhooks, kept in server logs.
What no Korbora app collects. No Korbora app reads your orders, and none stores your customers’ names, emails or addresses. Korbora Quantity Rules & MOQ evaluates customer tags inside Shopify — in your theme and in the checkout validation, which has no network access — so tags are never sent to or stored on Korbora servers.
How the information is used
- To authenticate with Shopify and read and write what the scopes allow.
- To do what the app is for: enforce quantity rules, or reorder collections and keep an audit log so you can undo.
- To show you the app’s own screens: rules, audit log, plan, health.
- To provide support when you write in.
- To meet Shopify’s platform requirements and the law.
Korbora does not use your data for advertising, does not sell it, and does not build profiles from it.
Legal basis
Processing is necessary to perform the contract with you — providing the app you installed — and, for support, logs and security, it rests on the legitimate interest of running the service reliably.
Retention
App data is kept while the app is installed.
After uninstall, Korbora Quantity Rules & MOQ clears its own records within 48 hours and leaves the metafield definitions and rule values on your products, because they are your data. Korbora Bury Sold Out clears its own records within 48 hours as well; while it is installed, audit-log detail is kept for 90 days.
Server logs are kept for up to 30 days.
Sharing
Korbora does not sell personal data. Limited data is processed by these providers under their own agreements:
- Shopify — the platform the apps run on
- Hetzner, in the EU — hosts the app servers and their PostgreSQL databases
- Cloudflare — serves korbora.com and provides its analytics
No third-party error-tracking service is used; errors go to server logs. Data is disclosed beyond this only where the law requires it.
International transfers
The app servers and databases run in the EU, at Hetzner. Shopify and Cloudflare process data globally under their own data processing agreements; no other provider is involved.
Security
Each app asks for the fewest scopes that do its job, and lists them. Access tokens are stored server-side and never sent to the browser. Webhook requests are verified with Shopify’s HMAC signature before they are processed.
Your rights
You can ask what data Korbora holds about your store, ask for it to be corrected or deleted, object to its processing, or ask for a copy, by writing to info@korbora.com. Requests are answered within two to three business days. If you are in the EU or EEA you can also complain to your supervisory authority; for Lithuania that is the State Data Protection Inspectorate (VDAI).
Shopify compliance
Every Korbora app responds to Shopify’s mandatory privacy webhooks: customers/data_request, customers/redact and shop/redact. Because no Korbora app stores customer personal data, the customer requests find nothing to return or delete; a shop redact removes the store’s records.
Korbora does not yet offer a separate data processing agreement. If your store requires one, write to info@korbora.com.
Company details
- Company: Digitasodas MB
- Company code: 305676811
- Country of registration: Lithuania
- Registered address: K. Čerbulėno g. 17-2, LT-47266 Kaunas, Lithuania
- Contact: info@korbora.com
Changes
When this policy changes, the date at the top changes with it. A change that affects what is collected or kept is announced by email to the store’s contact address.
Contact
Questions about this policy or about your data: info@korbora.com.