Privacy Policy
Last updated: 29 July 2026
Thank you for being part of the Bymello community. UAB "Bymello" (legal entity code 308015345, Krokuvos g. 53-3, Vilnius, LT-09306, Lithuania — "we", "us", "our") takes the protection of your personal data seriously. If you have any questions, please contact us at hello@bymello.eu.
This policy applies to customers and visitors of bymello.eu in Lithuania, Latvia, and Estonia. It explains how Bymello acts as a data controller and how you can exercise your GDPR rights in your country of residence.
GDPR (General Data Protection Regulation)
Under Regulation (EU) 2016/679, you have the right to access, rectify, erase, and restrict the processing of your personal data, as well as the right to object to processing and to data portability. We process your data based on: your consent, the necessity to perform a contract, compliance with legal obligations, and our legitimate interests. You may withdraw your consent at any time by emailing hello@bymello.eu — this does not affect the lawfulness of processing carried out before the withdrawal.
Data Controller: UAB "Bymello", Krokuvos g. 53-3, Vilnius, LT-09306, Lithuania
Purposes and Legal Bases:
- Purchases and account management (performance of a contract; legal obligation for invoicing/accounting)
- Customer support (legitimate interest; performance of a contract)
- Marketing communications (consent — withdrawable at any time)
- Analytics and site security (legitimate interest); non-essential cookies only with consent
- Fraud prevention, legal claims, and legal compliance (legal obligation; legitimate interest)
What Information Do We Collect?
Information you provide directly: name, address, contact details, account login information, payment information.
We collect your name, email, postal address, and phone number when you register, place an order, or contact us.
Payment data: processed through Shopify Payments — we do not store full card numbers. Please also review Shopify's own privacy policy.
Automatically collected information: IP address, browser/device characteristics, language, country, and on-site behaviour — for site security and internal analytics. Non-essential cookies (marketing/analytics) are collected only with your consent via the cookie banner (see our Cookie Policy).
Information from other sources: limited data from public databases, partners, and social media.
How Do We Use Your Information?
- To create and manage your account
- To send marketing communications (only with your consent; you can unsubscribe anytime)
- To send administrative notifications (orders, policy changes)
- To fulfil and manage your orders, payments, and returns
- To show personalised advertising (only with consent — see Meta section below)
- To request feedback
- To protect the Site (fraud prevention)
- To enforce our Terms of Use
- To respond to legal requests
- To analyse Site usage and improve our services
Service Providers (Processors): to run our store, we use vetted partners: Shopify (store platform/hosting), Shopify Payments (payment processing), email service providers, Google Analytics (analytics — only with consent), and Omniva (shipping/logistics). These partners process data on our instructions and under data processing agreements.
Will Your Information Be Shared With Anyone?
We share data only on the following legal bases: your consent, legitimate interest, performance of a contract, legal obligation, or protection of vital interests (fraud investigation, policy violations).
Advertising and Meta (Facebook/Instagram): we may use Meta tools, including the Meta Pixel, to show you relevant ads and measure their effectiveness — only with your prior consent via the cookie settings. You can withdraw consent at any time through the Site's cookie settings. For more on how Meta processes data, see their Data Policy.
International transfers: some of our providers (e.g. Shopify, Meta) may process data outside the EEA (e.g. in the US). In such cases, we ensure appropriate safeguards under GDPR Chapter V, including Standard Contractual Clauses (SCCs).
Do We Use Cookies?
Yes — for details on which cookies we use and how to manage them, see our Cookie Policy.
How Long Do We Keep Your Information?
We retain data only as long as necessary for the purposes described in this policy, or as required by law:
- Order and invoicing data: up to 10 years, in line with Lithuanian accounting and tax law requirements.
- Customer support records: up to 3 years after resolution.
- Marketing data: until you withdraw consent.
- Account data: for the lifetime of your account.
When data is no longer needed, we delete it or irreversibly anonymise it.
How Do We Keep Your Information Safe?
We apply technical and organisational security measures: encryption in transit, access controls, least-privilege staff access, and vendor due diligence. However, we cannot guarantee that the internet is 100% secure — transmitting data to our Site is at your own risk.
Do We Collect Information From Minors?
No. Our services are intended for individuals aged 18 and over. By using the Site, you confirm that you are at least 18, or that you are the parent/guardian of a minor and consent to their use of the Site. If we learn we have collected data from someone under 18, we will delete the account and the data.
What Are Your Privacy Rights?
You have the right to: request access to your data and a copy of it; request rectification or erasure; restrict processing; object to processing; and receive your data in a portable format. To exercise these rights, email hello@bymello.eu. We will respond within one month (extendable by up to two additional months for complex requests, per GDPR).
If you believe we are processing your data unlawfully, you have the right to lodge a complaint with your national supervisory authority:
- Lithuania — State Data Protection Inspectorate (VDAI) — vdai.lrv.lt
- Latvia — Data State Inspectorate (DVI) — dvi.gov.lv
- Estonia — Data Protection Inspectorate (AKI) — aki.ee
We'd appreciate the chance to resolve any concern directly first — please contact us at hello@bymello.eu.
Do-Not-Track
There is currently no uniform standard for Do-Not-Track signals, so we do not respond to them. If such a standard is adopted, we will update this policy accordingly.
Updates to This Policy
We may update this policy from time to time. The current version is always published on this page with the update date.
Contact Us
For questions about this policy, contact:
UAB "Bymello"
Krokuvos g. 53-3, Vilnius, LT-09306, Lithuania
hello@bymello.eu
You can review, update, or delete your data by logging into your account on bymello.eu, or by contacting us directly — we will respond within 30 days.