Meykt
Home Pricing Help Center Demo
Start free trial Login
Home Pricing Help Center Demo
Start free trial Login
Language

Privacy Policy

Last updated: August 30, 2026

Contents

  1. Controller
  2. Privacy contact
  3. General principles
  4. Website visits
  5. Cookies and local storage
  6. Analytics
  7. Contact and communication
  8. Registration and account
  9. Use of the platform
  10. Shop and external integrations
  11. Meykt Agent and machine control
  12. Payment and billing
  13. AI features
  14. Image vectorization
  15. Image background removal
  16. Security and audit logs
  17. Recipients and processors
  18. International transfers
  19. Retention and deletion
  20. Data subject rights
  21. Requirement to provide data
  22. Automated decisions
  23. Changes

1. Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation is:

Company
Dumanu GmbH
Address
Beethovenstr. 120 C, 42655 Solingen, Germany
Represented by
Dominik Hassel
Email
info@meykt.com

This Privacy Policy applies to the websites meykt.com, meykt.de, their subdomains and the use of the Meykt platform to the extent that Dumanu GmbH determines the purposes and means of processing.

Where customers use Meykt to process their own customer, employee, supplier, service provider, shop, order, file or production data, Dumanu GmbH usually acts as a processor within the meaning of Art. 28 GDPR. The respective customer remains responsible for such processing. Details are governed by the data processing agreement.

2. Privacy contact

For privacy questions, data subject requests or questions about the processing of personal data, Dumanu GmbH can be reached at info@meykt.com.

No data protection officer has been appointed.

3. General principles

We process personal data only where this is necessary to provide our websites, perform contracts, secure the platform, communicate with users, comply with legal obligations or where processing is based on consent.

Processing is limited to the data required for the respective purpose. Access within Meykt is role- and permission-based. Customer data is processed in tenant-separated environments.

4. Website visits and technical delivery

When our websites are accessed, technically necessary data is processed to deliver the website, operate it reliably and protect it. This includes in particular:

  • IP address
  • date and time of access
  • requested URL
  • referrer URL
  • browser type and version
  • operating system
  • amount of data transferred
  • technical error and security events

The processing takes place to provide the website, detect and prevent attacks, analyze errors and ensure operation. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our websites and services.

We use Vercel for hosting and delivery. Data may also be processed outside the European Union. For such transfers, we rely on suitable safeguards, in particular adequacy decisions, standard contractual clauses and supplementary protective measures.

5. Cookies, local storage and similar technologies

Meykt uses technically necessary cookies and comparable storage technologies to provide login sessions, language settings, security functions, routing and required platform features.

Technically necessary storage includes in particular:

  • session and refresh cookies for login through Supabase Auth
  • locale or language cookies to store the preferred language
  • cookies and local storage for selecting stations, machines or employees in production contexts
  • local UI preferences such as navigation state, favorites or display options

The legal basis for technically necessary cookies and storage is Sec. 25(2) German TDDDG and Art. 6(1)(b) GDPR where they are required for contract performance, and Art. 6(1)(f) GDPR where they support secure and user-friendly operation.

For non-essential analytics or marketing technologies, we obtain consent in advance. The legal basis is Sec. 25(1) TDDDG and Art. 6(1)(a) GDPR. Consent can be withdrawn at any time with effect for the future.

6. Analytics

We currently do not use any web analytics or tracking services that recognize visitors or track them across websites. Only the technical access data described in Section 4 is processed.

The use of Google Analytics is planned for the future. Google Analytics will only be used once and where valid consent has been obtained. Google may process usage information, technical device and browser data and interaction data. We will use Google Analytics with privacy-friendly settings, in particular IP anonymization, consent management and Google's data processing terms.

The legal basis for Google Analytics will then be Art. 6(1)(a) GDPR and Sec. 25(1) TDDDG. Consent can be withdrawn at any time with effect for the future.

7. Contact and communication

If users contact us by email, form or support features, we process the information provided to handle the request. This may include name, email address, organization, role, message, technical information and previous communication.

The legal basis is Art. 6(1)(b) GDPR where communication is necessary for contract performance or pre-contractual steps, and Art. 6(1)(f) GDPR for general inquiries and support communication.

We use Resend to send transactional emails, invitations, system notifications, support emails and similar messages. Resend processes the necessary recipient, content, sending and delivery data. Where data is processed in the United States, we rely on suitable safeguards such as standard contractual clauses.

During registration, users may also optionally and separately from accepting the Terms of Service choose to receive news, practical tips, and information about new features and offers from Meykt by email. This choice is not required for registration, a trial, a contract, or use of the platform.

The choice initially triggers only a confirmation email using a double opt-in process. Its opaque link opens a confirmation page; consent is confirmed only after the user consciously presses the button on that page. Merely opening the email or the link is not sufficient. We do not send marketing emails without this confirmation. The confirmation link is valid for seven days, and only a cryptographic hash of the token is stored in our database. The confirmation email is sent as a plain-text message without an open-tracking pixel or rewritten tracking link.

To evidence and manage the choice, we process the user identifier, normalized email address, source and time of the choice, language, consent version and the wording shown at the time, the status and timestamps of the double opt-in process, and the IP address and user agent when confirmation is requested, completed or withdrawn. The legal basis for subsequently sending marketing emails is Art. 6(1)(a) GDPR. We retain evidence of consent to meet our accountability obligations under Art. 5(2) and Art. 7(1) GDPR; the legal basis is Art. 6(1)(c) GDPR. We process security and abuse-prevention data on the basis of Art. 6(1)(f) GDPR.

A pending choice or confirmed consent can be withdrawn at any time with effect for the future in the personal profile under “Email news” or by emailing info@meykt.com. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

8. Registration, user account and organizations

When registering, logging in and using a Meykt account, we process in particular:

  • name
  • email address
  • password or authentication data
  • organization and organization role
  • language, time zone and profile information
  • login, security and session data
  • invitation and permission data
  • onboarding and usage settings

Processing takes place to create and manage the user account, authenticate users, separate tenants, assign permissions and provide the platform. The legal basis is Art. 6(1)(b) GDPR. Security and log data is also processed on the basis of Art. 6(1)(f) GDPR.

We use Supabase for authentication, database, storage and platform data. The Supabase project is currently operated in the Frankfurt am Main region. Supabase Auth may process session and authentication data. Google OAuth may optionally be used if users log in through Google.

9. Use of the Meykt platform

When using Meykt Central, we process the data that customers and users create, import, upload or provide through integrations. Depending on usage, this may include:

  • organization, location, station and machine data
  • user, team, role and permission data
  • employee data, workstations, production roles and availability
  • customer and contact data
  • delivery and billing data where stored in the system
  • shop connections and shop metadata
  • products, variants, article numbers, SKUs, prices and product descriptions
  • orders, line items, shipping and customer data from shops
  • production jobs, work steps, workflows, process states and logs
  • approvals, briefings, quote data, service provider or customer portal data
  • uploaded files, images, production files and technical attachments
  • machine commands, machine status, telemetry, local action logs and Agent status
  • support, error, audit and security logs

Where these data are processed to perform the contract with the customer, the legal basis is Art. 6(1)(b) GDPR. Where data is processed for security, error analysis or abuse prevention, the legal basis is Art. 6(1)(f) GDPR. Where statutory retention or evidence obligations apply, the legal basis is Art. 6(1)(c) GDPR.

For personal data that customers process in Meykt relating to their own end customers, employees, service providers, suppliers or shop customers, Dumanu GmbH usually acts as processor. The customer remains responsible for lawfulness, notices, legal bases, deletion periods and data subject rights.

10. Shop connections and external integrations

Meykt can be connected to external shop and platform services, for example WooCommerce, Etsy, Shopify, Amazon, eBay or future providers. Such connections are actively configured by the customer.

Meykt connects to all shop platforms directly: the access tokens or API keys required for the connection are stored by Meykt in its own database and used exclusively for the connection set up by the customer. All traffic to and from the platforms runs exclusively over encrypted connections (TLS); access to the stored credentials is restricted to the respective customer organization, and other organizations cannot technically use them. Meykt does not store the password of your shop account. Where a platform provides a separate API password for access, that password is stored encrypted.

Depending on the connected platform, the following data in particular may be processed:

  • shop name and shop URL
  • connection status and technical configuration
  • external product and order IDs
  • product, variant and order data
  • customer data from shop orders
  • payment, shipping and fulfillment information where provided by the shop
  • raw API response data for mapping, traceability and error analysis

Etsy in detail: For Etsy, every business connects only its own shop, by signing in to Etsy and granting Meykt the corresponding authorization. Access is read-only — Meykt writes nothing back to Etsy: no listings, no prices, no inventory, no order or shipping statuses. The only data read is:

  • orders of the connected shop, including the details submitted by the buyer (for example name and delivery address) and personalization texts, such as a requested engraving text
  • listings of the connected shop
  • shop master data such as shop name and shop identifier
  • the email address of the connected Etsy account, so that the connection can be assigned to the correct account

This corresponds to the four Etsy read permissions “transactions_r”, “listings_r”, “shops_r” and “email_r”. Meykt does not request any further or write permissions.

Purpose: The data read from a connected shop is used solely to carry out the respective business's own production — for example to turn an order into a production job with the matching engraving text and to steer its processing. It is not used for Meykt's own purposes, for advertising or for market and competitive analysis. Data from different shops and from different customer organizations is never merged, never compared with one another and never analysed across organizations.

Meykt does not pass this data on to third parties on its own initiative. It is handed to another business only when the customer initiates it: if the customer engages a production partner through the fulfillment feature, the order items they release for that purpose are transferred, together with the associated details, to that partner's organization. The customer decides per order what is handed over; without such a release, each organization sees only its own data.

Customer control: A business can disconnect a shop connection at any time in the Meykt dashboard. Access ends immediately and no further data is retrieved from the shop. For Etsy and WooCommerce the stored access tokens or credentials are deleted in the process. For Shopify the Meykt app stays installed in the shop until the business uninstalls it there; the authorization can be revoked at any time in the Shopify admin. In addition, the authorization can be revoked at any time directly at the platform itself. Order and listing data already imported remains in the business's account until the business deletes it or the periods set out in Section 17 apply.

Questions about a shop connection, about the data processed through it or about its deletion are answered at info@meykt.com. This address is monitored by us and is expressly open to sellers on the connected platforms as well.

Through the public customer API, customers can connect their own systems. They may register their own destination address to which Meykt sends status notifications about their orders. These notifications contain order and line item data and are sent to the server designated by the customer. The recipient and destination are determined solely by the customer; Meykt sends only on their instruction. Failed deliveries are logged for traceability.

The legal basis is Art. 6(1)(b) GDPR where the integration is used for contract performance. Where technical logs are processed for security and troubleshooting, the legal basis is Art. 6(1)(f) GDPR.

The customer is responsible for connecting only those shop and third-party accounts for which they are authorized and for informing their own customers about processing by connected systems.

11. Meykt Agent and local machine control

The Meykt Agent is a local desktop application installed in the customer's production environment. The Agent can communicate with Meykt Central and, depending on configuration, perform local actions such as:

  • receiving or executing machine commands
  • communicating with local software or machine interfaces
  • opening, providing, printing or transferring files to machines
  • reporting status and result data to Meykt Central
  • confirming or logging production steps

Personal and technical data may be processed, for example user identifiers, station data, machine assignments, production job data, file paths, file names, status messages, error logs and execution results.

Processing takes place to provide the local production features configured by the customer. The legal basis is Art. 6(1)(b) GDPR. Security and error data is additionally processed on the basis of Art. 6(1)(f) GDPR.

The customer decides which local machines, programs, files and automations are connected. The customer remains responsible for ensuring that the use of the Meykt Agent in their production environment is lawful, safe and covered under labor law and data protection law.

12. Payment processing and billing

Once paid plans are activated, we process payments, subscriptions and invoices through Paddle. Paddle is not merely a payment service provider but the seller of record (Merchant of Record): the subscription contract is concluded with Paddle, Paddle issues the invoice and remits sales tax and VAT. Depending on the payment method, Paddle processes in particular the following payment and billing data:

  • name, company and billing data
  • email address
  • payment method and payment status
  • invoice and tax data
  • technical payment and fraud prevention data

Processing takes place for contract performance and billing on the basis of Art. 6(1)(b) GDPR and to comply with legal obligations on the basis of Art. 6(1)(c) GDPR. Because of its role as seller, Paddle is an independent controller for payment, invoice and tax data and not our processor; this applies in particular to fraud prevention, compliance, payment network obligations and statutory retention obligations. On our side we only store a subscription's payment account identifier, the chosen plan, its status and the billing period — no card or bank account details.

13. AI features

Meykt provides AI features, currently in particular an AI assistant for workflow support and AI-assisted translation features. Further AI features, for example to support evaluations, texts, mappings, data preparation or error analysis, may be added. AI features are used only where they are activated for the respective function or contractually agreed.

Depending on the feature, prompts, files, order data, product data, process data, technical logs or other content selected by the user may be transmitted to an AI provider. As AI provider we currently use the Gemini API provided by Google; this also applies to the public Meykt Community parameter assistant. Data may also be processed outside the European Union, in particular in the United States; the information in Section 16 applies. If further providers are integrated in the future, they will be listed in this Privacy Policy or in a subprocessor list.

The legal basis is Art. 6(1)(b) GDPR where the AI feature is part of the booked service, or Art. 6(1)(a) GDPR where separate consent is required. Art. 6(1)(f) GDPR may apply to security, quality and abuse protection measures.

Meykt uses AI services only with suitable contractual privacy arrangements. Customer data is not used by Meykt for its own model training purposes. Where an AI provider offers options to use customer data for model training or product improvement, such options will be disabled for business customer data where contractually and technically possible.

Logging of account-based AI assistants: For quality assurance, abuse prevention and error analysis, Meykt logs the texts entered into the signed-in AI assistants and the corresponding responses. These logs may be viewed by staff of Dumanu GmbH authorized for this purpose. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the quality, security and abuse prevention of the service). The logs are deleted or anonymized once they are no longer required for these purposes.

Public Community parameter assistant: This assistant can be used without an account. It processes the question entered, the language, the public parameter cards selected for the answer and a randomly generated pseudonymous visitor identifier used to limit abuse and cost. Meykt does not permanently store questions and answers from this public assistant in its own database; only aggregated technical usage values such as request count, token volume, runtime and error status are recorded. Inputs are transmitted to Google to generate the answer. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is providing anonymously accessible, source-grounded parameter help and protecting it against abuse. To protect against automated bulk requests, Vercel BotID evaluates technical browser and device signals when a question is submitted; the content of the question is not analysed for this purpose. Users should not enter personal or confidential content.

Proposals for the public parameter library: Customers can propose one of their own parameter sets for inclusion in the public library. What is transmitted and stored by the Meykt team is the parameter set itself (procedure, material, thickness, machine, tool, settings, notes) together with a display name chosen by the submitter. On acceptance the display name is shown publicly and permanently next to the entry; anyone who does not want a personal reference should choose a company or made-up name. Organisation details, stock levels, prices, customer or order data are not transmitted. The legal basis is Art. 6(1)(a) GDPR (consent, given by deliberately submitting the proposal). Consent can be withdrawn at any time; a proposal that has not yet been decided can be withdrawn in the application, and an entry that has already been published will be anonymised or removed on request. To be able to report back on the decision we also store which account submitted the proposal; that link is never published.

Business profile of the AI assistant (memory): Upon request, the AI assistant can remember individual entries about the customer organization's business that have been confirmed by the customer (for example manufacturing processes used, sales channels or software in use) in order to tailor answers to the organization. This feature is only activated after an authorized representative of the customer organization has given prior express consent; the legal basis is Art. 6(1)(a) GDPR. Only entries that a user has expressly confirmed in the conversation or created in the settings are stored. All stored entries can be viewed, edited and deleted individually or in full by the organization in the settings at any time. The consent can be revoked at any time with effect for the future; from the moment of revocation the entries are no longer used. When the feature is active, the stored entries are transmitted to the AI service provider named in this section together with the chat input. Users should not store personal data of third parties (such as names or order data of end customers) in the business profile.

Assistant access to operational data: So that the AI assistant can answer questions about a specific job, it may read operational data of the customer organisation — in particular orders including status, line items, quantities, prices and production state, the compiler values created by the customer themselves (such as engraving texts or dimensions), and the processing state of the associated files. Personal data of the customer's own end customers is excluded: the orderer's name, e-mail address, telephone number and addresses, as well as the unmodified raw data from the connected shop, are not made technically accessible to the assistant and cannot be produced by it even on request. This restriction is enforced in the system and cannot be lifted by a setting. The function is only enabled once an authorised representative of the customer organisation has expressly consented to the access once; without that consent the assistant is blocked for the entire organisation. The legal basis is Art. 6(1)(a) GDPR. In addition, every person using it confirms before first use that they have read the notice about the scope of access. Consent may be withdrawn at any time with effect for the future; from withdrawal onwards the assistant can no longer be used. The operational data retrieved is transmitted to the AI service provider named in this section in order to answer the question.

The customer is responsible for not entering particularly sensitive or legally protected content into AI features unless this has been expressly agreed and secured.

13a. Image vectorization

Via the “Vectorization” tool, users can convert raster images (for example logos) into vector graphics. For this purpose, the image file selected by the user is transmitted to and processed by an external service provider that specializes in image vectorization and is established in the United States.

The data processed includes in particular the uploaded image file, the resulting vector output and technical processing data (for example format, size and time of processing).

The transfer takes place only if the user actively triggers the feature and expressly consents to the transfer beforehand. The legal basis is consent under Art. 6(1)(a) GDPR. The associated transfer to the United States is based on Art. 49(1)(a) GDPR (explicit consent to the data transfer). Consent can be withdrawn at any time with effect for the future by no longer using the feature.

Note on third-country transfer: For the service provider used, there is no adequacy decision, no data processing agreement and no standard contractual clauses. There is therefore a risk that U.S. authorities may access transmitted data and that the user may not have the same level of legal remedies as provided within the EU.

Storage at the service provider: The service provider stores the uploaded file and the result temporarily under its own terms, currently for up to approximately two weeks; for account-linked records, storage may last longer. We cannot guarantee earlier deletion.

Use for training purposes: The service provider reserves the right to use transmitted images to develop, train and improve its own techniques and models. No objection to this is provided for at the service provider. Users should therefore not vectorize images containing personal data of third parties or confidential content, and should only upload images for which they hold the necessary rights.

The service provider acquires no rights in the resulting vector graphic; the results belong to the user within the scope of their rights in the source image. The feature is optional; users may instead use already vectorized files without using the external service.

13b. Image background removal

Via the “Background removal” tool, users can automatically remove the background of images (for example product photos). Processing takes place exclusively on our own hardware within our infrastructure in the European Union. The image file is not transmitted to an external third-party provider, does not leave the EU and is not used for training purposes of third parties.

The data processed includes the uploaded image file, the resulting cut-out image and technical processing data (for example the method used, size and time of processing).

Processing takes place only if the user actively triggers the feature. The legal basis is Art. 6(1)(b) GDPR (provision of the feature requested by the user) and Art. 6(1)(f) GDPR (legitimate interest in operating the feature). Separate consent as for image vectorization is not required, because no transfer to third parties and no third-country transfer takes place.

Retention: The uploaded image file and the generated result are stored temporarily in our infrastructure to provide the feature (including automatic retries after technical errors) and are automatically deleted after no more than 14 days. Where the feature is embedded in other areas of the platform (for example to edit product images), the retention and deletion rules stated there additionally apply.

14. Security, abuse prevention and audit logs

To secure the platform, we process technical logs, authentication events, role changes, system events, API access, error data, security-relevant configurations and audit logs.

Processing serves to detect abuse, investigate security incidents, trace administrative changes and maintain service stability. The legal basis is Art. 6(1)(f) GDPR. Where legal obligations apply, the legal basis is Art. 6(1)(c) GDPR.

15. Recipients and processors

We disclose personal data only where this is required for the purposes described above, where a legal obligation exists, where the user has consented or where another legal basis applies.

Service providers used by us include in particular:

ProviderPurposeTypical data
SupabaseDatabase, authentication, storage, realtimeAccount, platform, file, auth and usage data
VercelHosting, deployment, delivery and detection of automated access (Vercel BotID) on the public Community parameter assistantWebsite access and technical logs; when using the public parameter assistant, also technical browser and device signals used for bot detection
InngestBackground jobs, workflow events, retry and automation processingEvent data, workflow data, technical execution data
ResendTransactional emails, invitations, system emails, double opt-in and consented marketing emailsRecipients, email content, sending and delivery data
UpstashRate limiting for the public customer API and public Community parameter assistant (protection against overload and cost abuse)Hashed API key identifier or pseudonymous visitor/network identifier, counter value and time window – no plain-text IP addresses, order, file or question content
PaddleSale, payment processing, subscriptions, invoices and VAT/sales tax (once paid plans are activated)Billing, payment, tax and fraud prevention data
GoogleGoogle OAuth, AI features (Gemini API); Google Analytics only if used in the future with consentLogin or AI feature data depending on use
External vectorization service (USA)Converting uploaded images into vector graphics (“Image vectorization” feature)Uploaded image file, resulting vector output, technical processing data

The specific list of subprocessors may change when services are replaced, added or extended. Material changes will be communicated in an appropriate manner where contractually or legally required.

16. International transfers

Some service providers we use are established or have processing capacities outside the European Union or the European Economic Area, in particular in the United States. Personal data may therefore be transferred to third countries.

Where data is transferred to third countries, we rely on suitable safeguards, in particular:

  • adequacy decisions by the European Commission, such as the EU-U.S. Data Privacy Framework where the respective provider is certified
  • standard contractual clauses of the European Commission
  • supplementary technical and organizational measures
  • contractual data processing agreements

In individual cases we use services for which none of the above safeguards (adequacy decision, standard contractual clauses or data processing agreement) is in place. This concerns in particular the image vectorization feature. The transfer to the United States is then based exclusively on the user’s explicit consent under Art. 49(1)(a) GDPR, after the user has been informed of the associated risks.

17. Retention and deletion

We store personal data only for as long as necessary for the respective purposes or as long as statutory retention obligations apply.

In general, the following retention periods apply:

  • User account and contract data is stored for the duration of the contract.
  • During the running contract, the platform clears up certain content automatically. This concerns in particular photos and files from finished production orders and station runs; they are permanently deleted after a period that depends on the booked plan of 180, 365 or 730 days (retained indefinitely on the highest plan). Running or paused orders are not affected. Further automatic deletions concern cancelled and never-submitted requests (90 days), images in the image tools (14 days), automatically fetched import source files (30 days) and notifications (90 days). The periods applicable to each customer can be viewed in the application under "Settings → Usage & credits".
  • After contract termination, platform and customer data is generally retained for 30 days to allow restoration, migration or mitigation of accidental termination effects. Afterwards, it is deleted or anonymized unless statutory retention obligations prevent this.
  • Invoices, payment and tax-relevant documents are stored according to statutory retention obligations, generally for six to ten years.
  • Double opt-in tokens are stored only as hashes and become invalid after seven days. Unconfirmed requests are retained only for as long as necessary for processing, troubleshooting and preventing abuse, and are then deleted or anonymized. Evidence of confirmed or withdrawn consent is retained for as long as necessary to meet our accountability obligations and defend against potential legal claims; it is then deleted or anonymized.
  • Security, system and audit logs are stored only for as long as required for security, traceability and error analysis. Unless longer storage is necessary, they are generally deleted or anonymized after no more than 90 days.
  • Backups are overwritten or deleted according to the applicable backup cycle. Targeted individual deletion from existing backups may be technically limited; in that case deletion takes place no later than at the end of the backup cycle.

18. Data subject rights

Data subjects have the following rights subject to the statutory requirements:

  • access to personal data processed, Art. 15 GDPR
  • rectification of inaccurate data, Art. 16 GDPR
  • erasure, Art. 17 GDPR
  • restriction of processing, Art. 18 GDPR
  • data portability, Art. 20 GDPR
  • objection to processing based on legitimate interests, Art. 21 GDPR
  • withdrawal of consent with effect for the future, Art. 7(3) GDPR
  • complaint with a data protection supervisory authority, Art. 77 GDPR

The supervisory authority responsible for Dumanu GmbH is:

Authority
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Address
Kavalleriestraße 2-4, 40213 Düsseldorf, Germany
Web
www.ldi.nrw.de

19. Requirement to provide data

Providing certain data is necessary to access the website, create a user account, perform contracts, process payments or use Meykt features. Without these data, we cannot provide the respective services or can provide them only with restrictions.

20. Automated decisions

No automated decision-making within the meaning of Art. 22 GDPR currently takes place. The AI features in use also do not make decisions that produce legal effects or similarly significantly affect users. If features are used in the future that could have such effects, we will identify this separately and comply with legal requirements.

21. Changes to this Privacy Policy

We may amend this Privacy Policy if our services, providers used, legal requirements or technical processes change. The version published at the time applies.

For privacy questions, contact us at info@meykt.com.

Meykt

The universal middleware between your shops and production.

Meykt

Back to homepage Start free trial

Help

Help Center Feature Board Roadmap API & Developers

Legal

Imprint Privacy Policy Terms of Service Refunds
© 2026 Meykt. All rights reserved.
Made in Germany

The term 'Etsy' is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.