QuoteHarbor
Privacy Policy
Version: 1.0
Effective from: 3 August 2026
Applies to: The QuoteHarbor application for Shopify, its buyer portal, Rep Console, Partner Console, public application pages and the quoteharbor website
Data controller / processor: MB ML Consulting (Lithuania)
Privacy contact: support@mlconsulting.lt
Companion documents: Data Processing Agreement (DPA) · Subprocessor list · Terms of Service · Security & Privacy Overview
1. Introduction
1.1 Who we are
QuoteHarbor is a business-to-business commerce application for Shopify stores. It gives wholesale merchants a governed workflow for account registration and approval, quote negotiation, procurement approval chains, and ordering by sales representatives on behalf of the accounts they manage.
QuoteHarbor is owned and operated by MB ML Consulting, a small partnership (mažoji bendrija) registered in the Republic of Lithuania, company code 306991112.
In this policy, "we", "us" and "our" mean MB ML Consulting. "QuoteHarbor" means the application and the services described above. "Shopify" means Shopify Inc. and its affiliates, which operate the commerce platform QuoteHarbor is built on.
1.2 What this policy covers
This policy explains what personal data QuoteHarbor collects, why, on what legal basis, who it is shared with, how long it is kept, and what rights you have. It covers all of the following surfaces:
- the embedded merchant application inside the Shopify admin;
- the buyer portal, delivered either as a Shopify customer-account extension or as a themed page on the merchant's storefront;
- the public wholesale application form, whether hosted on the merchant's storefront or at apply.quoteharbor.app;
- the Rep Console at reps.quoteharbor.app;
- the Partner Console at partners.quoteharbor.app;
- quote and approval emails we send on a merchant's behalf, and replies sent back to our inbound email address;
- the quoteharbor.app marketing website, help centre and support channels.
1.3 What this policy does not cover
This policy does not cover:
- The merchant's own storefront and Shopify store. How a merchant collects and uses data about its customers is governed by that merchant's own privacy policy. Shopify's own processing is governed by Shopify's privacy policy.
- Third-party websites linked from QuoteHarbor or from a merchant's emails.
- A merchant's internal use of data it exports from QuoteHarbor.
1.4 The short version
Do we sell personal data?
Answer: No. We have never sold or shared personal data for cross-context behavioural advertising, and we do not intend to.
Do we run advertising trackers on buyer-facing pages?
Answer: No. The buyer portal and the public application form use strictly necessary cookies only, and carry no third-party analytics or advertising code.
Where is data stored?
Answer: In the European Union by default. See section 8.
Who is responsible for buyer data?
Answer: The merchant is. We process it on their documented instructions. See section 2.
Who is responsible for merchant, rep and partner account data?
Answer: We are, for the account and security aspects. See section 2.
How do I get a copy of my data, or have it deleted?
Answer: Section 11 (Europe and the UK), section 12 (United States) and section 13 (merchant self-service tools).
Who do I complain to?
Answer: Us first, at support@mlconsulting.lt. Then the Lithuanian State Data Protection Inspectorate, or your own supervisory authority. See section 11.5.
2. Our role: when we are a controller and when we are a processor
QuoteHarbor sits between three parties: the merchant who installs it, the buyers who use it to purchase from that merchant, and the representatives and agencies who work on the merchant's behalf. Data protection law treats our responsibilities differently depending on whose data it is and who decides what happens to it. This section is the single most important part of this policy, and everything that follows depends on it.
2.1 Where we act as a data controller
We are the controller — meaning we decide the purposes and means of processing, and we answer to you directly — for:
- Merchant account data: the identity, contact details and role of the Shopify staff members who install, configure and operate QuoteHarbor, and the records of what they did in the application.
- Rep and Partner Console account data: the login identity, authentication events, session and device records, and security logs of sales representatives and agency users. We decide how these accounts are authenticated and secured, because we are accountable for the security of our own service.
- Billing and subscription records: plan, usage against plan limits, subscription status. Card payments are handled entirely by Shopify Billing; we never see card details.
- Support correspondence: emails, tickets and any information you give us when you ask for help.
- Website and marketing data: visitors to quoteharbor.app, help-centre readers, people who sign up for the design-partner programme or a newsletter.
- Product analytics on merchant, rep and partner surfaces, used to understand how the application is used and to improve it. See section 14.
- Security, abuse-prevention and service-integrity data across every surface, including rate-limit records, bot-protection signals and records of authentication events.
One record, two roles — authentication events
Sign-in, sign-out and act-on-behalf events are written into the same per-store audit log as everything else, because a single tamper-evident chain is what makes the log trustworthy. That means the same entries serve two purposes at once: we are the controller when they are used to secure our service, and the merchant is the controller when they are used as their accountability record. Whichever of us you ask, we will make sure your request reaches the other. You do not have to work out which role applies before you write to us.
2.2 Where we act as a data processor
We are a processor — meaning we act only on the merchant's documented instructions, and the merchant is the controller who answers to you — for essentially all of the commercial content that flows through the application:
Company, company location and company contact records mirrored from the merchant's Shopify store
Whose instructions we act on: The merchant. Shopify remains the system of record; we hold a read-through copy for performance and resilience.
Wholesale account applications submitted through the public form, including uploaded documents such as resale certificates and business licences
Whose instructions we act on: The merchant, who designs the form, decides what is asked, and decides whether to approve, reject, merge or request more information.
Quotes, quote versions, negotiation messages, attachments and inbound email replies
Whose instructions we act on: The merchant.
Procurement approval policies, approval requests, and each approver's decision, comment, timestamp, IP address and user agent
Whose instructions we act on: The merchant, and — where the buying organisation configures its own policy — the buyer's Location Admin acting within the merchant's account.
Sales-rep account books, account assignments and act-on-behalf (impersonation) session records
Whose instructions we act on: The merchant.
Inventory holds, draft-order and order lineage, and the tamper-evident audit log content
Whose instructions we act on: The merchant.
2.3 Shopify's role
QuoteHarbor is built on Shopify's native B2B data model. Companies, company locations, company contacts, catalogues, draft orders and orders live in Shopify and are the merchant's records held on Shopify's platform. Shopify's handling of that data is governed by the agreement between Shopify and the merchant, and by Shopify's own privacy policy — not by this one.
We access Shopify data using an access token the merchant grants at install, limited to the permission scopes the application actually needs. We never write to a merchant's Shopify store except to perform the actions the merchant or their authorised users ask for.
2.4 What this means for you in practice
A merchant or merchant staff member
For account, login and security data, contact: Us — support@mlconsulting.lt
For quotes, applications, approvals and orders, contact: Us, as controller of your own staff records; but data about your buyers is yours and you are its controller.
A buyer, buyer contact or procurement approver
For account, login and security data, contact: The merchant you buy from. We will assist them.
For quotes, applications, approvals and orders, contact: The merchant you buy from. We will assist them.
A sales representative
For account, login and security data, contact: Us — support@mlconsulting.lt
For quotes, applications, approvals and orders, contact: The merchant whose accounts you work.
An agency or partner user
For account, login and security data, contact: Us — support@mlconsulting.lt
For quotes, applications, approvals and orders, contact: The merchant client whose store you are working in.
A wholesale applicant who has not yet been approved
For account, login and security data, contact: The merchant you applied to. We will assist them.
For quotes, applications, approvals and orders, contact: The merchant you applied to.
If you contact the wrong party, we will not leave you stranded
If you send us a request that belongs to a merchant, we will not simply refuse it. We will acknowledge you, tell you which merchant holds the data, and forward your request to them without undue delay so that their statutory response clock starts running. If you do not know which merchant holds your data, tell us what you know and we will try to identify it.
3. The personal data we process
The tables below list every category of personal data QuoteHarbor processes, by the type of person it relates to. "Optional" means the data is only present if a merchant configures the application to collect it, or if you choose to provide it.
3.1 Merchant users (Shopify staff)
Identity and contact
Detail: Name, email address, Shopify staff user ID, the store domain and store ID, preferred locale and time zone.
Role and permissions
Detail: Your QuoteHarbor role, the Shopify permissions your session carries, and the results of permission checks — including checks that were denied.
Usage
Detail: Pages viewed, features used, onboarding steps completed, saved views and filters, and product-analytics events such as "quote sent" or "plan limit reached". Analytics events carry no direct identifiers (see section 14.2).
Technical
Detail: IP address, user agent, device and browser type, request identifiers, performance measurements, and error diagnostics.
Billing
Detail: Plan, trial dates, subscription status, usage against metered limits. No card data — Shopify Billing handles payment end to end.
Support
Detail: Anything you send us in a support request, and our replies.
3.2 Sales representatives
Identity and status
Detail: Name, email address, the merchant who invited you, whether you are internal staff or an external contractor, your linked Shopify staff identifier if you have one, and the date you were last active.
Commercial terms
Detail: Your commission rate, where the merchant records one in QuoteHarbor.
Authentication
Detail: Magic-link tokens (stored only as hashes), Google sign-in identifier if you use it, session records, and device-binding fingerprints. QuoteHarbor uses no passwords.
Security
Detail: Sign-in and sign-out events, IP address and user agent at sign-in, changes of device or network that trigger re-verification, and failed authentication attempts.
Work record
Detail: Your account book, quotes you built, prices you offered, discounts you applied, act-on-behalf sessions you opened, and the reason text you entered — all recorded in the merchant's audit log and visible to that merchant.
Performance reporting
Detail: The merchant can run a report on each representative showing quotes sent, win rate, value won, average discount and average margin. The merchant is the controller of that reporting; if you have questions about how it is used, they are properly for your employer or the merchant you contract with.
Offline data
Detail: If you use the Rep Console offline, a copy of your account book and any draft quotes is stored in your own browser and synchronised when you reconnect.
Representatives should know this
The Rep Console is a workplace tool. Your quote activity, your discounts, your margins and every act-on-behalf session you open are recorded in an audit log that the merchant can read and export, and the merchant can run a performance report on you covering win rate, value won, average discount and average margin. That is a deliberate design decision, made so that acting on a customer's behalf is never anonymous. It is not covert monitoring — but it is monitoring, and you should be told plainly rather than discover it.
3.3 Agency and partner users
The same categories as section 3.2, plus: the portfolio of client stores you have been granted access to; the scope and expiry date of each merchant's delegation to you; configuration templates you save and apply; and referral or partner-code attribution. Every action you take inside a client store is recorded in that store's audit log, attributed to you by name.
3.4 Wholesale account applicants
When you apply for a wholesale account through a merchant's QuoteHarbor application form, the merchant decides which fields to ask for. The field library available to them includes:
Business identity
Detail: Company name, trading name, business address, country and region, website, and business type.
Your contact details
Detail: Name, business email address, phone number, and job title.
Documents you upload
Detail: Resale certificates, business licences and similar. PDF, PNG, JPG, WEBP or DOCX only; maximum 10 MB per file and 5 files per application; every file is scanned for malware before anyone can open it.
Consent records
Detail: Your ticked acceptance of the merchant's terms and privacy notice, with a timestamp.
Verification and anti-abuse
Detail: Your IP address, a bot-protection result from Cloudflare Turnstile, an email-confirmation round trip if you applied without JavaScript, the age and mail-server validity of your email domain, and duplicate-detection matches against existing accounts.
Attribution
Detail: Referral and campaign parameters, if the merchant has configured them.
Review record
Detail: Which reviewer looked at your application, when, the decision, and any reason text or requests for more information.
A duplicate-detection match never results in an automatic rejection. It is shown to a human reviewer as a warning, and a person makes the decision. See section 6.
If you start an application and abandon it, we email you a signed link so you can come back and finish it. That link is valid for 7 days. An application started without JavaScript is not visible to any reviewer until you confirm it by email, and is deleted after 7 days if you never do.
3.5 Buyer users: company contacts, orderers and approvers
Identity and role
Detail: Name, business email address, phone number, locale, the company and location you belong to, and your role on that location — all sourced from the merchant's Shopify store.
Commercial activity
Detail: Quotes you requested, viewed, countered, accepted or declined; the prices, quantities and products involved; purchase-order numbers; messages you wrote in a quote thread and files you attached; and your order history.
Approval decisions
Detail: Every approval or rejection you make, with the comment you wrote, the exact quote version you were shown (recorded as a content hash), the date and time, and the IP address and user agent you acted from. This is recorded deliberately: an approval that cannot be attributed is worthless to the organisation relying on it.
Delegation
Detail: Out-of-office delegations you set, and who you delegated to.
Internal notes about you
Detail: Merchant staff and sales representatives can record notes on a quote, on a quote line and on your account that are marked internal and are not shown to you in the portal. These are still personal data about you and are disclosed if you make an access request.
Email correspondence
Detail: If you reply by email to a quote, the message body, headers, attachments and authentication results (SPF, DKIM, DMARC) are stored on the quote timeline.
Notification preferences
Detail: Which emails you have chosen to receive, and in what form.
Technical
Detail: IP address, user agent, session records and error diagnostics.
3.6 Email correspondents
QuoteHarbor accepts inbound email replies at a per-quote, per-recipient address so that buyers who prefer email still land in the system. Every inbound message is checked twice: the signed token in the address must be valid and the sender must still be authorised on that quote, and the sending domain must pass SPF, DKIM and DMARC alignment.
3.7 Website visitors
On quoteharbor.app and the help centre we process your IP address, user agent, referring page, pages viewed and, if you fill in a form, whatever you tell us. On the public application form and the buyer portal we process only what is strictly necessary to deliver the page, protect it from abuse and keep your session working.
3.8 Data we deliberately do not process
- Payment card numbers, bank details or any payment credential. Shopify handles all payment, and we never receive card data.
- Special categories of personal data under Article 9 GDPR — health, biometrics, race or ethnicity, political opinions, religion, trade-union membership, sex life or sexual orientation. QuoteHarbor has no field for them and no use for them. Please do not put them into a free-text field.
- Data about children. QuoteHarbor is a business tool and is not directed at anyone under 18. See section 17.
- Third-party advertising or behavioural-tracking identifiers on buyer-facing surfaces. There are none.
- Data purchased from data brokers. We enrich an application only with checks we perform ourselves — whether the email domain resolves and how old it is — and, where a merchant enables it, a validity check of a tax identifier against an official public registry.
- Personal data in URLs or query strings. As a matter of engineering policy, personal data never appears in a web address, where it would leak into browser history, referrer headers and server logs.
4. Where the data comes from
- From you directly — when you fill in an application, build or answer a quote, make an approval decision, write a message, upload a document, or contact support.
- From the merchant — when they invite you as a representative or a partner, assign you to an account book, or import company records.
- From Shopify — company, location, contact, catalogue, product, inventory, draft-order and order records, synchronised through Shopify's API and webhooks. Shopify is the source of truth for all of it.
- Automatically from your device — IP address, user agent, approximate location derived from IP for security purposes only, and performance and error diagnostics.
- From our own systems — audit records, permission-check outcomes, notification delivery results, rate-limit counters and reconciliation findings.
5. Why we process personal data, and our legal basis
The table below applies to processing where we are the controller (section 2.1). Where we act as a processor, the merchant determines the purpose and the legal basis; we simply follow their instructions.
Providing the application to a merchant, and providing accounts to their reps and partners
Data involved: Identity, contact, role, authentication, session and usage data
Legal basis (GDPR Article 6): Performance of a contract (Art. 6(1)(b)) with the merchant; legitimate interests (Art. 6(1)(f)) in providing accounts to reps and partners who are not themselves our contracting party
Authenticating users and keeping accounts secure
Data involved: Magic-link hashes, session and device records, IP address, user agent, sign-in events
Legal basis (GDPR Article 6): Legitimate interests (Art. 6(1)(f)) in the security of our service and our users’ data; legal obligation (Art. 6(1)(c)) under Art. 32 GDPR
Preventing abuse of public forms and inbound email
Data involved: IP address, bot-protection results, rate-limit counters, email-authentication results
Legal basis (GDPR Article 6): Legitimate interests (Art. 6(1)(f)) in protecting merchants and ourselves from spam, fraud and enumeration attacks
Maintaining the audit log and demonstrating who did what
Data involved: Actor identity, action, subject, outcome, IP address, user agent, timestamp, and a before-and-after copy of the record that changed — which may itself contain personal data
Legal basis (GDPR Article 6): Legitimate interests (Art. 6(1)(f)) in accountability, dispute resolution and fraud prevention; legal obligation (Art. 6(1)(c)) where the record supports accounting or tax duties
Sending transactional and service email
Data involved: Name, email address, message content, delivery and bounce results
Legal basis (GDPR Article 6): Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for service notices to non-contracting users
Billing, plan enforcement and financial records
Data involved: Plan, subscription status, usage counters, merchant identity
Legal basis (GDPR Article 6): Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for accounting retention
Support
Data involved: Whatever you tell us, plus enough account context to help
Legal basis (GDPR Article 6): Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Product analytics on merchant, rep and partner surfaces, and feature flags
Data involved: Pseudonymous usage events with no direct identifiers; store, plan, actor type and surface
Legal basis (GDPR Article 6): Legitimate interests (Art. 6(1)(f)) in understanding and improving the product. A documented legitimate-interests assessment supports this; ask us for it.
Marketing about QuoteHarbor to merchants and prospects
Data involved: Name, business email address, engagement with our emails
Legal basis (GDPR Article 6): Consent (Art. 6(1)(a)) where required, otherwise legitimate interests (Art. 6(1)(f)) in business-to-business marketing to existing customers. Every message carries a one-click unsubscribe.
Complying with law, responding to lawful requests, and defending legal claims
Data involved: Whatever the specific matter requires
Legal basis (GDPR Article 6): Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) in establishing, exercising or defending legal claims
Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and concluded that the processing is proportionate and would be reasonably expected. You can object to any of it — see section 11.
Where we rely on consent, you can withdraw it at any time, and withdrawal does not affect the lawfulness of anything done beforehand.
6. Automated decision-making and profiling
We do not make decisions producing legal effects, or similarly significant effects, about you by purely automated means. Two features come close enough to deserve an explicit explanation.
6.1 Duplicate and abuse screening on wholesale applications
When an application is submitted, the system checks it against existing accounts by normalised email domain, tax identifier, and fuzzy company name plus postcode, and runs bot-protection and rate-limit checks. These checks flag; they never decide. A flagged application is shown to a human reviewer with the reason for the flag, and a person approves, rejects, merges or asks for more information. An application rejected for being a suspected duplicate has been rejected by a human being.
The one exception is volumetric abuse control: if a submission exceeds the published rate limits, or fails bot protection outright, it may be refused before a human sees it. If you believe your legitimate application was blocked this way, email support@mlconsulting.lt or apply again through the merchant's alternative route, and we will make sure a person sees it.
6.2 Procurement approval policies configured by a merchant or a buying organisation
A merchant, or a buyer's Location Admin, can configure an approval policy that routes an order for internal sign-off, and can set what happens when an approver misses their deadline: escalate, hold, automatically approve, or automatically reject. Where a policy is set to automatically approve or automatically reject on timeout, an outcome can be reached without a person acting at that step.
That configuration belongs to the organisation, not to us — the merchant or the buying organisation is the controller of that decision. If a policy affects you and you want human intervention, want to express your point of view, or want to contest the outcome, contact the merchant or your own organisation's administrator. We will support them in giving effect to your request, and every step of every approval chain — including automatic ones — is fully recorded and can be produced for you.
We do not use personal data to build profiles for advertising, credit scoring, or predicting personal characteristics or behaviour.
7. Who we share personal data with
7.1 Categories of recipient
- The merchant whose store the data belongs to, and the staff, representatives and agencies that merchant has authorised — subject to the permission model, so that a representative sees only their own account book and a buyer sees only their own company.
- Shopify, as the platform of record, for the commerce data QuoteHarbor reads and writes on the merchant's instruction.
- Subprocessors who provide hosting, storage, email delivery, error monitoring, analytics and bot protection under written contract. Annex A lists them.
- Systems a merchant connects to QuoteHarbor's outbound webhooks. A merchant can nominate an HTTPS endpoint of their choosing — typically an ERP, a data warehouse or an integration platform — and we will send event payloads to it, which can include quote, approval and contact details. The merchant chooses that destination and is the controller of the transfer; we do not vet it and we have no relationship with it. Ask the merchant which systems they have connected.
- Google, if a representative or partner chooses to sign in with a Google account rather than a magic link. Google acts as an independent identity provider under its own privacy policy; we receive only the account identifier and email address needed to authenticate you.
- Professional advisers — lawyers, accountants, auditors and insurers — under confidentiality obligations, where necessary.
- Authorities, courts and law enforcement, where we are legally required to disclose. We assess every request, refuse those that are overbroad or improperly made, and notify the affected merchant unless we are legally prohibited from doing so.
- A successor, if the business or the relevant part of it is sold, merged or reorganised. We would tell affected merchants in advance and this policy would continue to apply until any successor gave notice of its own.
7.2 We do not sell or share personal data for advertising
We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined in United States state privacy laws. We do not run advertising networks, install advertising pixels, or provide personal data to advertising partners. Buyer-facing surfaces carry no third-party analytics at all.
8. Where data is stored, and international transfers
8.1 European hosting by default
QuoteHarbor is hosted in the European Union. The application and its background workers run in EU regions (Frankfurt and Amsterdam), the primary database is an EU-region managed PostgreSQL instance, and uploaded documents are stored in object storage under an EU jurisdiction setting. Backups are held in the same jurisdiction as the data they protect.
Merchant and buyer data does not leave the European Economic Area except where a specific service requires it, namely: Shopify's own platform APIs, our transactional email provider, and error-monitoring and telemetry services. Those exceptions are listed in Annex A with the safeguard that applies to each.
8.2 Safeguards for transfers outside the EEA and the UK
Where personal data is transferred outside the EEA or the UK, we rely on one or more of:
- an adequacy decision of the European Commission, or UK adequacy regulations, covering the destination country or a certified recipient — including the EU–US Data Privacy Framework where the recipient is certified under it;
- the European Commission's standard contractual clauses (2021 modules), together with the UK International Data Transfer Addendum where UK data is involved;
- a documented transfer impact assessment and, where needed, supplementary technical measures such as encryption in transit and at rest and minimisation of the data sent.
We maintain standard contractual clauses as a fallback even with recipients certified under the EU–US Data Privacy Framework, because that framework is currently under appeal before the Court of Justice of the European Union and we do not want a single legal instrument to be a single point of failure. You can ask us for a copy of the safeguards that apply to a particular transfer, and we will provide it or explain what we can share.
8.3 A note on Shopify
Shopify is the merchant's own platform provider, not our subprocessor. Data flowing between a merchant's Shopify store and QuoteHarbor moves under the merchant's agreement with Shopify. Shopify processes data in a number of countries; consult Shopify's privacy policy and data processing addendum for the detail.
9. How we protect personal data
Security is not a paragraph of reassurance in this product; it is a set of specific, testable controls. The following are implemented and verified as a condition of release.
9.1 Technical measures
Encryption
What it means: All data is encrypted in transit using TLS and at rest by the storage platform. Shopify access tokens and the body of a wholesale application are additionally encrypted at the field level with AES-256-GCM, using keys held in a secret manager and rotated on a schedule. Identifiers we have to be able to search on — an applicant's email address and company name, a buyer contact's name and email — cannot be field-encrypted and rely on storage-level encryption instead. Backups are encrypted.
Tenant isolation
What it means: Every record carries the identifier of the store it belongs to, and a guard in our data-access layer rejects any query that omits it. An automated test suite attempts cross-store and cross-account-book access against every endpoint on every build.
Access control
What it means: Every permission decision in the application routes through a single authorisation function; there are no ad-hoc role checks anywhere in the code. Denied attempts return an error and are written to the audit log.
Authentication
What it means: Merchant sessions are verified against Shopify on every request. Representatives and partners sign in by single-use magic link valid for 15 minutes, or Google SSO; sessions are device-bound and revocable, and sensitive actions force re-authentication. There are no passwords to steal. Approval links emailed to procurement approvers are single-use, expire after 7 days, and are bound to that approver, that request and a hash of exactly what they were shown.
Audit logging
What it means: Every state change, permission decision, platform write, notification and sign-in is recorded in an append-only log, together with a before-and-after copy of the record that changed. Each entry is hash-chained to the one before it, so any tampering is detectable, and the chain is verified nightly.
Personal data in logs
What it means: Operational logs use a field allowlist. Logging an email address, an application payload or an access token is blocked by an automated check before code can be merged.
File uploads
What it means: Type-allowlisted, size-capped, scanned for malware before they can be opened, stored on a separate origin, and served only through signed links that expire after 5 minutes. Uploads are never rendered as web pages.
Webhooks and inbound email
What it means: Platform webhooks are verified by constant-time signature check before the payload is parsed. Inbound email must pass both a signed-token check and sender-domain authentication, or it is quarantined.
Public identifiers
What it means: Anything reachable from a public link uses a non-sequential identifier, so records cannot be enumerated by counting.
Dependency and code security
What it means: Dependencies are scanned on every change; no known high or critical vulnerability ships to production. A documented security review covering the full threat model is completed before general availability, and repeated on a documented schedule thereafter.
9.2 Organisational measures
- Production, staging and development environments are separate. Staging and development use synthetic data; real merchant data is never copied into them.
- Everyone with access to personal data is bound by confidentiality obligations.
- We maintain a documented incident-response process, a merchant-notification template and a public status page.
- Backups use point-in-time recovery with a 6-hour window, and restore drills are performed and timed before release and quarterly thereafter. An untested backup is not a backup.
9.3 Personal data breaches
If a personal data breach occurs, we will:
1. contain it and assess the risk to affected individuals without delay;
2. where we are the processor, notify the affected merchant without undue delay after becoming aware, with the information they need to meet their own 72-hour notification duty, and support their investigation;
3. where we are the controller, notify the Lithuanian State Data Protection Inspectorate within 72 hours of becoming aware where the breach is likely to result in a risk to individuals, and notify affected individuals directly where the risk is high;
4. record every breach, including those we assess as not notifiable, and the reasoning for that assessment.
No security programme is perfect, and we will not pretend otherwise. What we commit to is that you will hear about it from us, promptly and in plain language.
10. How long we keep personal data
10.1 Retention schedule
Wholesale application content, including uploaded documents
Retention: 24 months after the decision, unless the merchant configures a shorter period. Approved applications leave behind the company record in Shopify, which the merchant controls.
Quotes, versions, messages, approvals and order lineage
Retention: For as long as the merchant's subscription is active, then per section 10.2. These are the merchant's commercial records.
Audit log
Retention: Set by the merchant's plan: 12 months (Starter), 24 months (Growth), 7 years (Scale); configurable upward.
Merchant, rep and partner account records
Retention: For the life of the account, then 90 days, then deletion.
Operational and security logs
Retention: 90 days.
Unconfirmed applications submitted without JavaScript
Retention: 7 days.
Abandoned-application resume links
Retention: 7 days.
Magic-link and approval tokens
Retention: 15 minutes and 7 days respectively; stored only as hashes and invalidated on first use.
Backups
Retention: 6 hours (point-in-time recovery window), after which deleted data is gone from backups too.
Billing and accounting records
Retention: As required by Lithuanian accounting and tax law — generally 10 years.
Support correspondence
Retention: 24 months after the matter is closed.
10.2 What happens when a merchant uninstalls QuoteHarbor
On uninstall we immediately mark the store inactive, revoke all sessions across every surface, and stop all background processing. We then follow Shopify's mandatory data-protection process:
- Shopify sends us a shop redaction request 48 hours after uninstall. We erase the store's personal data within 48 hours of receiving that request.
- Uninstalling QuoteHarbor does not delete anything in the merchant's Shopify store. Companies, contacts, draft orders and orders remain the merchant's records on Shopify.
- Deleted data disappears from backups as those backups age out of the 6-hour recovery window.
We recommend that merchants export their data before uninstalling — every merchant can export everything QuoteHarbor holds, as JSON and CSV, from the application settings at any time, without asking us.
10.3 Erasure and the audit trail
There is a genuine tension between the right to erasure and a tamper-evident audit log, and we would rather explain our position than gloss over it.
When we act on an erasure request, we tombstone the personal data: personal identifiers in the affected records are erased or replaced, the actor's name in audit entries becomes "[erased]", and personal data inside the before-and-after snapshots those entries carry is erased with it. What remains is the non-personal commercial record — that a quote of a given value was approved on a given date by a person holding a given role — and the cryptographic hash chain that makes the log tamper-evident. Breaking the chain would destroy the integrity of every other record in it, including records belonging to people who have not asked for anything.
Our position is that the commercial record is retained under Article 17(3) GDPR for compliance with legal obligations, principally accounting and tax, and for the establishment, exercise or defence of legal claims, while the personal identifiers are erased. Merchants may also have their own retention duties that constrain what can be deleted.
11. Your rights in the EEA, the UK and Switzerland
11.1 The rights you have
Under the GDPR and the UK GDPR you have the right to:
Access
What it means: Get confirmation of whether we process your data, a copy of it, and information about how it is used.
Rectification
What it means: Have inaccurate data corrected and incomplete data completed.
Erasure
What it means: Have your data deleted where one of the grounds in Article 17 applies. See section 10.3 for how this interacts with the audit log.
Restriction
What it means: Have processing limited while a dispute about accuracy or legitimate interests is resolved.
Portability
What it means: Receive data you gave us in a structured, commonly used, machine-readable format, and have it sent to another provider where technically feasible.
Objection
What it means: Object to processing based on legitimate interests, including profiling. We will stop unless we can show compelling legitimate grounds that override your interests, or we need the data for legal claims. An objection to direct marketing is always absolute — we stop, immediately, no assessment.
Withdraw consent
What it means: Withdraw consent at any time where consent is the basis. This does not affect what was lawful beforehand.
Human intervention
What it means: Where an automated decision produces legal or similarly significant effects, obtain human intervention, express your view and contest the decision. See section 6.
Complain
What it means: Lodge a complaint with a supervisory authority. See section 11.5.
11.2 How to exercise them
Email support@mlconsulting.lt with the subject line "Privacy request". Tell us what you want, and enough information for us to find your data — typically the email address you use with QuoteHarbor and, if you are a buyer, the merchant you buy from.
We respond within one month. If your request is complex or you have made several, we may extend by up to two further months and will tell you why within the first month. There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse — and we will explain our reasoning if we do.
We may need to verify your identity before acting, particularly for access and erasure requests. We will ask for the minimum needed, and we will not use anything you send for verification for any other purpose.
11.3 If your data sits with a merchant
Where we are the processor (section 2.2), the merchant is the controller and the request is properly theirs to answer. Send it to them directly if you know who they are. If you send it to us, we will acknowledge you, identify the merchant, forward your request without undue delay, and assist them in responding — including by producing exports and performing deletions on their instruction. We will not answer on their behalf, because that decision is not ours to make.
11.4 Buyers and Shopify
Because QuoteHarbor is built on Shopify's native data model, some of your data lives in the merchant's Shopify store rather than in QuoteHarbor. A request made to the merchant covers both: Shopify's own data-request and redaction process reaches us automatically, and we act on it within the timeframes Shopify requires — 30 days for a data request or customer redaction. See section 13.
11.5 Complaints
Please raise any concern with us first at support@mlconsulting.lt. We would rather fix a problem than have you take it elsewhere, and we take complaints seriously.
You always have the right to go to a supervisory authority instead of, or as well as, contacting us. Our lead supervisory authority is:
Authority: Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of the Republic of Lithuania)
Address: L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
Email: ada@ada.lt
Telephone: +370 5 271 2804
Website: https://vdai.lrv.lt
You may also complain to the supervisory authority in the EU member state where you live or work, or where the alleged infringement happened. In the United Kingdom, the Information Commissioner's Office (ico.org.uk). In Switzerland, the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
12. Your rights in the United States
12.1 Which laws apply
If you are a resident of a US state with a comprehensive consumer privacy law — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island — this section describes the rights those laws give you. Where we act as a service provider or processor for a merchant, direct your request to that merchant and we will support them; where we are the business or controller, direct it to us.
12.2 California notice at collection
We collect, and from the effective date of this policy will have collected, the following categories of personal information as defined by the California Consumer Privacy Act, as amended. Once QuoteHarbor has been generally available for twelve months, this section will describe the preceding twelve-month period.
Identifiers
Examples in QuoteHarbor: Name, business email, phone, account and store identifiers, IP address
Purpose: Providing the service, authentication, security, support, billing
Customer records (Cal. Civ. Code §1798.80)
Examples in QuoteHarbor: Business address, telephone number, employment and role information
Purpose: Providing the service, account provisioning
Commercial information
Examples in QuoteHarbor: Quotes requested and received, products, quantities, prices, purchase orders, order history
Purpose: Providing the service
Internet or network activity
Examples in QuoteHarbor: Pages viewed, features used, session and device records, error diagnostics
Purpose: Providing the service, security, product improvement
Geolocation data
Examples in QuoteHarbor: Approximate location inferred from IP address only
Purpose: Security and abuse prevention
Professional or employment information
Examples in QuoteHarbor: Employer, job title, role in the buying organisation, approval authority
Purpose: Providing the service
Inferences
Examples in QuoteHarbor: None. We do not build profiles reflecting preferences, characteristics or behaviour.
Purpose: —
Sensitive personal information
Examples in QuoteHarbor: Business tax and registration identifiers where a merchant asks for them, and account credentials in the form of single-use link hashes
Purpose: Providing the service only. We do not use sensitive personal information to infer characteristics, and we do not use or disclose it for any purpose requiring an opt-out under §1798.121.
We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have never done so — including with respect to anyone under 16.
Sources of collection, categories of recipient, and retention are described in sections 4, 7 and 10 respectively, and apply equally here.
12.3 Your rights and how to use them
- Know and access — what we collect, why, from where, who we disclose to, and a copy of the specific pieces of personal information.
- Delete — subject to the exceptions in the applicable statute, including our need to keep records for legal, security, accounting and dispute-resolution purposes (see section 10.3).
- Correct — inaccurate personal information.
- Opt out of sale, sharing, and targeted advertising — there is nothing to opt out of, because we do none of these. We honour Global Privacy Control signals regardless.
- Limit the use of sensitive personal information — we already limit it to providing the service.
- Opt out of profiling in furtherance of decisions producing legal or similarly significant effects — we do not do this; see section 6.
- Non-discrimination — we will never deny you service, charge you differently or give you a lesser experience for exercising a privacy right.
- Appeal — if we decline your request, you may appeal by replying to our decision. We will respond within the period your state's law allows, generally 45 or 60 days, and if we deny the appeal we will tell you how to complain to your state Attorney General.
To exercise any of these, email support@mlconsulting.lt with the subject "Privacy request". We will verify your identity in proportion to the sensitivity of what you have asked for. An authorised agent may act for you with written permission, and we may still ask you to confirm the agent's authority directly.
12.4 A note on business-to-business data
Most US state privacy laws exclude data about people acting in a business capacity. California does not — since 1 January 2023 the CCPA applies in full to business-to-business contact data. Because nearly everyone who uses QuoteHarbor is acting for their employer, this distinction matters, and we apply California rights to California residents in a business capacity without argument about whether we have to.
13. Merchant tools: export, deletion and platform requests
QuoteHarbor implements the three data-protection processes Shopify requires of every application on its platform, and adds self-service tools on top of them.
Customer data request
What we do: When a store owner asks, through Shopify, for the data an app holds about one of their customers, we compile everything QuoteHarbor holds about that person — applications, quotes, messages, approvals, order lineage and audit entries — and provide it to the merchant within 30 days.
Customer redaction
What we do: When a store owner asks, through Shopify, for a customer's data to be deleted, we redact it within 30 days, following the tombstoning approach in section 10.3, unless we are legally required to retain it.
Shop redaction
What we do: Shopify sends this 48 hours after a merchant uninstalls. We erase the store's personal data within 48 hours of receiving it. See section 10.2.
Self-service export
What we do: Any merchant can export everything QuoteHarbor holds — as JSON and CSV — from the application settings, at any time, without contacting us. Portability is a legal right; it is also an anti-lock-in commitment we are happy to make.
Audit log export
What we do: The full audit log is exportable on demand and automatically at uninstall.
14. Cookies, local storage and analytics
14.1 Buyer-facing surfaces: strictly necessary only
The public wholesale application form and the buyer portal use only cookies and local storage that are strictly necessary: your session, a cross-site request forgery token, your resume link if you saved a partial application, and the Cloudflare Turnstile bot-protection challenge. There is no third-party analytics, no advertising pixel, no session recording and no fingerprinting on these surfaces. We do not ask for consent to these, because none is legally required for strictly necessary storage — and because there is nothing else to consent to.
14.2 Merchant, rep and partner surfaces
On the embedded merchant application, the Rep Console and the Partner Console we additionally use product analytics and feature flags, provided by PostHog on its EU cloud. These record how the application is used — which features are opened, which onboarding steps are completed, where errors occur — and they carry no direct identifiers. Events are tagged with the store, the plan, the type of actor and the surface, and any record identifier is hashed before it is sent.
We rely on legitimate interests for this, supported by a documented assessment which we will share on request. If you would rather not be included, tell us at support@mlconsulting.lt and we will exclude you.
14.3 The marketing website
quoteharbor.app uses strictly necessary cookies plus, where you consent, analytics cookies. A cookie banner presents the choice and remembers it, and you can change your mind at any time from the link in the site footer.
14.4 Email tracking
Transactional emails we send on a merchant's behalf — quotes, approval requests, notifications — record delivery, bounce and complaint events, because a quote that silently fails to arrive is a business problem. We do not use open-tracking pixels and we do not record whether you opened an email.
We do, however, record when a quote is opened in the portal, and that is shown to the merchant and to the sales representative who sent it. Knowing that a quote has been read is a core feature of the product, not a hidden one — so we say it plainly: if you view a quote, the merchant will know.
14.5 Do Not Track and Global Privacy Control
We honour Global Privacy Control signals. We do not respond to Do Not Track browser headers, which have no agreed meaning — but since we do not track you across sites in the first place, the practical outcome is the same.
15. Communications you receive
- Transactional and service email — quote notifications, approval requests, expiry reminders, magic links, security notices and billing warnings. These are part of the service and cannot be switched off entirely, though every user can choose per-event delivery or a daily digest, and every preference change takes effect within a minute.
- Marketing email from us — product updates and occasional news, sent only to merchants and people who asked for it. Every message carries a working one-click unsubscribe, and unsubscribing has no effect on the service you receive.
- Email a merchant sends you through QuoteHarbor — branded with the merchant's logo and reply-to address. The merchant is the controller of that message; we deliver it on their behalf.
Emails are sent from a dedicated sending domain with SPF, DKIM and DMARC alignment, and are never sent from an IP address shared with bulk marketing traffic.
16. Accessibility of this policy
This policy is published as a web page that meets WCAG 2.2 AA, the same standard the application itself is held to, and is available in accessible formats on request. If any part of it is unclear, email support@mlconsulting.lt and we will explain it — in writing, in plain language, without charge.
17. Children
QuoteHarbor is a business tool sold to businesses and used by people acting in a professional capacity. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, email support@mlconsulting.lt and we will delete it.
18. Changes to this policy
We will update this policy as the product and the law change. When we do:
- the version number and effective date at the top of the document change;
- a summary of what changed is published alongside it, so you do not have to diff two documents to find out;
- for changes that materially affect how we use personal data, we give merchants at least 30 days' notice by email and in the application before the change takes effect;
We will not make a material change retroactive, and we will not quietly broaden the purposes for which we use data you have already given us.
19. How to contact us
Company: MB ML Consulting
Company code: 306991112
Privacy contact: support@mlconsulting.lt
Product: QuoteHarbor — quoteharbor.app
Data protection officer: We are not required to appoint a data protection officer and have not appointed one. Privacy questions are handled by the CEO Mantvydas Levickis, reachable at the address above.
EU representative: Not required — we are established in the European Union.
We aim to acknowledge every privacy enquiry within two business days and to resolve it within the statutory period. If we are going to be late, we will tell you before the deadline rather than after it.
Annex A — Subprocessors
The list below is current as at the effective date of this policy.
Fly.io, Inc.
Service: Application and background-worker hosting
Personal data processed: All application data in transit and in memory
Location and transfer safeguard: EU regions (Frankfurt, Amsterdam). US-incorporated provider: standard contractual clauses.
Neon, Inc.
Service: Managed PostgreSQL database
Personal data processed: All application database content
Location and transfer safeguard: EU region. Standard contractual clauses.
Cloudflare, Inc.
Service: R2 object storage for uploaded documents; Turnstile bot protection
Personal data processed: Uploaded application documents and quote attachments; bot-challenge signals including IP address
Location and transfer safeguard: R2 configured to EU jurisdiction. Standard contractual clauses and EU–US Data Privacy Framework where applicable.
Upstash, Inc.
Service: Queue, cache and rate limiting
Personal data processed: Transient job payloads that may contain identifiers; rate-limit counters
Location and transfer safeguard: EU region. Standard contractual clauses.
Functional Software, Inc. (Sentry)
Service: Error monitoring
Personal data processed: Technical diagnostics, IP address, user agent, and any identifiers incidentally present in a stack trace
Location and transfer safeguard: Standard contractual clauses.
Shopify Inc. and Shopify International Limited are not listed as our subprocessors. Shopify is the merchant's own platform provider under a direct agreement with the merchant, and QuoteHarbor accesses that platform on the merchant's instruction.
Annex B — Definitions
Controller
Meaning: The party that decides why and how personal data is processed, and is accountable for it.
Processor
Meaning: A party that processes personal data on a controller's documented instructions.
Subprocessor
Meaning: A processor engaged by us to help deliver the service.
Merchant
Meaning: A business that has installed QuoteHarbor on its Shopify store.
Buyer
Meaning: A business that purchases from a merchant, and the individuals who act for it — company contacts, orderers and approvers.
Representative (rep)
Meaning: A salesperson, employed or contracted, who works a book of accounts for a merchant through the Rep Console. Representatives are deliberately not required to hold Shopify staff accounts.
Agency / partner
Meaning: A third party granted time-boxed, revocable access by a merchant to configure QuoteHarbor on their behalf.
Act on behalf / impersonation session
Meaning: A recorded, time-limited session in which a representative performs actions for a buyer account. Every such session is logged, and every buyer-facing artefact it produces states who placed it and for whom.
Quote
Meaning: A versioned, expiring offer of specific products at specific prices to a specific company location, which becomes a Shopify draft order when accepted.
Approval chain
Meaning: An ordered set of steps by which a buying organisation internally authorises a purchase.
Audit log
Meaning: The append-only, hash-chained record of every state change, permission decision, platform write and authentication event in a merchant's account.
Tombstoning
Meaning: Erasing personal identifiers from a record while preserving the non-personal transaction and the integrity of the hash chain. See section 10.3.
Compliance webhook
Meaning: One of the three data-protection notifications Shopify requires every app to handle: customer data request, customer redaction, shop redaction.
Protected customer data
Meaning: Shopify's term for customer information accessed through its APIs, subject to additional platform requirements on minimisation, encryption, retention and access control.
© 2026. All rights reserved.
