Security & Data Protection

Encryption in transit

Metly uses HTTPS/TLS for communication between browser, frontend, backend, and external integration sources like Shopify.

Access limitation

Data is logically separated per merchant via user ID, and the application only returns data for the authenticated merchant.

Retention

Metly automatically removes orders, order lines, and linked customer details 36 months after a customer's latest order as part of the daily backend job. See the Privacy Policy for details.

Security incident response

If a security incident is discovered or suspected — for example unauthorized access to personal data, a data breach, or a vulnerability that could expose customer data — we contain the incident immediately, assess scope and impact, and remediate the cause. Affected merchants are notified without undue delay, and we report to the relevant data protection authorities where required by law (including within 72 hours where GDPR applies). Incidents are documented and reviewed so we can prevent recurrence. Contact us about suspected incidents at security@metly.dk.

Automated recommendations

Metly provides decision support and does not make automated decisions with legal or similarly significant effects on customer rights.