Sharpsum Terms of Service
These terms are an agreement between SIA MANUM ("MANUM", "we", "us"), a company registered in Latvia with registration number 40203414494 and legal address Gaismas iela 22-26, Daugavpils, LV-5414, Latvia, and the business that installs Sharpsum ("you").
- Part A covers your use of Sharpsum.
- Part B, the Data Processing Terms, covers how we process personal data for you.
Part A: Using Sharpsum
1. Agreeing to these terms
- By installing or using Sharpsum, you agree to these terms. If you do not agree, do not install or use Sharpsum.
- If you accept these terms for a company, you confirm that you have the authority to bind it.
- Our Privacy Policy explains how we handle data. Part B of these terms applies to personal data we process for you.
2. Who can use Sharpsum
- Sharpsum is for businesses that sell through Shopify. You may use it only for your business, not as a consumer.
- You need an active Shopify store, and you must follow Shopify's terms.
3. What Sharpsum does
Sharpsum shows your store's profit by day and by month. Revenue is Shopify's net sales plus shipping charges. From it, Sharpsum subtracts the cost of goods, shipping cost, handling, payment fees, ad spend and the expenses you enter.
- The figures depend on their sources. They come from Shopify, from any ad platforms you connect, and from what you enter. If that data is missing or wrong, the figures will be wrong too.
- Currency conversion. Figures in another currency use Shopify's daily exchange rates, which can differ from the rates your bank or accountant uses.
- Not advice. Sharpsum is not accounting, tax, legal or financial advice. Check the figures before you use them for tax returns, financial statements or other official purposes.
4. Shopify's role
- SIA MANUM, not Shopify, is solely responsible for Sharpsum.
- Shopify is not liable for any fault in Sharpsum, or for any harm that may result from installing or using it.
- Shopify cannot provide help with installing or using Sharpsum. Please contact us instead.
- SIA MANUM, not Shopify, is solely responsible for any liability that may arise from your access to or use of Sharpsum.
5. Plans, fees and billing
- Shopify bills you for Sharpsum through Shopify's app pricing. The charges appear on your Shopify bill, and Shopify collects them. Prices are in US dollars.
- Plans: Free, up to 50 orders a month; Starter, USD 19 a month or USD 190 a year, up to 500 orders a month; Growth, USD 49 a month or USD 490 a year, up to 2,000 orders a month; Pro, USD 99 a month or USD 990 a year, up to 6,000 orders a month. For more orders we offer a plan of your own.
- Paid plans start with a 14-day free trial. You are charged only if you keep the plan after the trial.
- You can change or cancel your plan at any time in Sharpsum, without contacting us.
- Fees already charged are not refunded, except where the law requires it.
- We tell you at least 30 days before a price change applies to you.
- When you remove Sharpsum, Shopify stops charging for it.
6. Your data
- Your data stays yours. This covers the store data that Sharpsum reads from Shopify and everything you enter in Sharpsum.
- Our use. You allow us to use your data only to provide Sharpsum to you, as described in the Privacy Policy and in Part B.
- Your responsibility. You are responsible for the data you enter, and for having the right to share your store data with us.
- Export. The Profit, Expenses and Ad spend pages each let you download your data as a CSV file. On request we also send you a copy of all your data in a structured, commonly used, machine-readable format. Your order data also stays available in Shopify.
- Before you leave. If you want to keep your data, download it before you remove Sharpsum. When you remove it, we delete your data as set out in Part B, section 12.
- Switching. If you want to move to another service, tell us. We help you take your data with you and, within 30 days, make sure you can retrieve it; we then delete it.
7. Other services
- Sharpsum depends on Shopify and, if you connect ad accounts, on those ad platforms. Their own terms apply to your use of their services.
- We are not responsible for those services. If they change or stop their APIs, some Sharpsum features may change or stop.
8. Acceptable use
You must not:
- try to access the data of other stores, or any system you are not allowed to access;
- copy, sell, resell or rent Sharpsum;
- reverse-engineer Sharpsum, except where the law allows it;
- disrupt or overload Sharpsum, or test its security without our written permission;
- use Sharpsum for anything unlawful.
If you find a security problem in Sharpsum, please tell us at support@manum.lv.
9. Availability and changes
- We work to keep Sharpsum available and correct. We cannot promise that it will always be available or free of errors.
- We may need to pause Sharpsum for maintenance or for security reasons.
- We may change, add or remove features. If we remove an important feature of a paid plan, we tell you in advance.
10. Support
Write to support@manum.lv. We aim to answer within two business days.
11. Our rights in Sharpsum
- We own Sharpsum, including its software, design and content.
- While you have Sharpsum installed, and have paid for it where your plan requires payment, you may use it for your business. This right is limited and non-exclusive, and you cannot transfer it.
- If you send us ideas or feedback, we may use them without any obligation to you.
12. Confidentiality
We keep your data confidential and protect it as described in Part B and in the Privacy Policy.
13. No warranties
As far as the law allows, Sharpsum is provided "as is" and "as available". We do not promise that it will meet your needs or that its figures will be free of errors.
14. Limitation of liability
- As far as the law allows, we are not liable for indirect or consequential loss, or for loss of profit, revenue, data or goodwill.
- As far as the law allows, our total liability for all claims together is limited to the fees you paid for Sharpsum in the 12 months before the claim.
- These limits do not apply where the law does not allow them, for example for harm caused on purpose or by gross negligence.
15. Suspension and ending
- You can stop using Sharpsum at any time by removing it from your store.
- We may suspend or end your access if you break these terms, if charges are not paid, or if we must do so to protect Sharpsum, other users or Shopify. Where we can, we warn you first.
- We may stop offering Sharpsum. If we do, we tell you at least 60 days in advance.
- When you remove Sharpsum, we delete your store's data as set out in Part B, section 12.
16. Changes to these terms
- We may update these terms. We publish the new version and change the effective date.
- For important changes, we tell you in Sharpsum at least 30 days before they apply.
- If you keep using Sharpsum after that date, the new terms apply. If you do not agree, remove Sharpsum.
17. Law and disputes
- These terms are governed by the law of the Republic of Latvia.
- Disputes go to the courts of the Republic of Latvia.
- Before you go to court, please contact us. We will try to solve the problem with you.
18. General
- These terms, including Part B, and the Privacy Policy are the whole agreement between you and us about Sharpsum.
- If part of these terms is invalid, the rest stays in force. If we do not enforce a right, we do not give it up.
- You may not transfer this agreement without our written consent.
- We send notices in Sharpsum. Send notices to us at support@manum.lv or to our legal address.
- These terms are written in English. If we translate them, the English version applies.
Part B: Data Processing Terms
These Data Processing Terms are part of the Terms of Service and apply automatically when you install Sharpsum. They contain the terms that Article 28 of the GDPR requires between a controller and a processor. If you need a signed copy, write to support@manum.lv.
1. Definitions
- GDPR: Regulation (EU) 2016/679, the General Data Protection Regulation.
- Personal data, processing, controller, processor: as defined in the GDPR.
- Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data (GDPR Article 4(12)).
- Store personal data: the personal data that Sharpsum processes for you, described in section 3.
- Sub-processor: a service provider we use to process store personal data.
- Data protection laws: the GDPR and any other privacy law that applies to the processing.
2. Roles
- You are the controller of store personal data; if you act for another controller, you confirm that you have its authority. We are your processor.
- For data about you as our user (support messages, technical logs, subscription status), we are the controller. The Privacy Policy covers that data.
- You are responsible for having a legal basis for the processing you ask us to do, and for informing your customers, for example in your store's privacy policy.
3. Details of the processing
| Subject matter | Providing Sharpsum: profit calculations and reports for your store |
|---|---|
| Duration | While Sharpsum is installed, until we delete the data as set out in section 12 |
| Nature | Reading data from Shopify (Admin API and ShopifyQL) and, if you connect them, from ad platforms; storing it; calculating; showing results to you; deleting it |
| Purpose | Showing your store's profit by day and by month |
| Types of personal data | Order data that can relate to a customer: order IDs, dates, line items, quantities, prices, discounts, taxes, refunds, cancellations, shipping charges, shipping country and region, and payment transactions (payment method, amount, fee). Any personal data you put in expense names or settings. For connected ad accounts: access tokens. |
| Data we do not store | Customer names, email addresses, phone numbers and street addresses |
| Special categories | None expected (GDPR Article 9) |
| Data subjects | Your customers; people you mention in data you enter; your staff who connect ad accounts |
4. Your instructions
- We process store personal data only on your documented instructions: these terms, your settings and your use of Sharpsum, including the use of the sub-processors in Annex 2 and any transfers this involves.
- If the law requires us to process the data in another way, we tell you before we do, unless the law forbids it.
- We tell you immediately if we believe an instruction breaks data protection laws.
5. Confidentiality
- Only the owner of SIA MANUM has access to store personal data.
- Anyone who gets access in future must first commit to confidentiality in writing.
- Every person with access processes the data only on your instructions.
6. Security
- We protect store personal data with the technical and organisational measures in Annex 1.
- We review these measures at least once a year. We may change them, but never in a way that lowers the protection of your data.
7. Sub-processors
- You give us general authorisation to use sub-processors. The current list is in Annex 2.
- We tell you in Sharpsum at least 30 days before we add or replace a sub-processor.
- You may object on reasonable data protection grounds within 14 days of our notice. We will then try to find a solution with you. If we cannot, you may stop using Sharpsum by removing it, and we refund any fees you prepaid for the time after it is removed.
- Each sub-processor is bound by a written contract with data protection duties no weaker than these terms. We remain fully liable to you for each sub-processor's work.
8. Transfers outside the EEA
- We keep every store's data in Cloudflare's European Union jurisdiction.
- We transfer store personal data outside the European Economic Area only with a safeguard under Chapter V of the GDPR, such as an adequacy decision or the EU Standard Contractual Clauses. Cloudflare's data processing terms include the EU Standard Contractual Clauses.
9. Help with your customers' requests
- Shopify's privacy webhooks pass privacy requests about your store to us. We complete each one within 30 days, as section 13 of the Privacy Policy describes.
- If one of your customers contacts us directly, we forward the request to you without undue delay and do not answer it ourselves unless you ask us to.
- On request, we give you a copy of store personal data in a structured, commonly used and machine-readable format, and we let you correct it.
10. Other help
Taking into account the nature of the processing and the information we have, we help you with the security of processing (GDPR Article 32), with notifying personal data breaches to authorities and to the people concerned (Articles 33 and 34), and with data protection impact assessments and prior consultations (Articles 35 and 36).
11. Personal data breaches
- We notify you without undue delay, and no later than 48 hours after we become aware of a personal data breach that affects store personal data.
- We tell you, as far as we know: what happened; the categories and approximate number of people and records concerned; the likely consequences; what we have done and propose to do; and who you can contact for more information. If we do not have all the information at once, we send it in stages, without further undue delay.
- We send the notice in Sharpsum and to the email address of your Shopify store.
- We take reasonable steps to contain the breach and limit the harm, and we report breaches of merchant data to Shopify, as Shopify's terms require.
- As the controller, you decide whether to notify a supervisory authority or your customers. We will help you. Our notice is not an admission of fault.
12. Deleting data
- When you remove Sharpsum, Shopify tells us at once and we delete all of your store's data. Shopify's deletion request, which arrives 48 hours later, finds nothing left.
- Cloudflare keeps a 30-day recovery history of each Durable Object, so deleted data leaves it within 30 days.
- If you want to keep your data, download it before you remove Sharpsum (Part A, section 6).
- We keep data for longer only where EU or Member State law requires it, and then we tell you. On request, we confirm the deletion in writing.
13. Information and audits
- On request, we give you the information you need to show that we meet these terms, including these terms, Annex 1 and answers to reasonable security questionnaires.
- If that is not enough, you or an independent auditor bound by confidentiality may audit us, with at least 30 days' written notice, once a year, or more often if a personal data breach or a supervisory authority requires it. Each party bears its own costs.
- We tell you immediately if we believe an audit instruction breaks data protection laws.
14. Records
We keep a record of the processing we carry out for you, as GDPR Article 30(2) requires.
15. Liability and order of precedence
- Liability under Part B follows Part A, section 14, as far as data protection laws allow.
- If Part B conflicts with Part A, Part B applies to the processing of personal data.
Annex 1: Technical and organisational measures
- Hosting and separation. Sharpsum runs on Cloudflare Workers. Each store's data is stored in its own Durable Object, apart from other stores, in Cloudflare's European Union jurisdiction.
- Encryption. At rest, Cloudflare encrypts all Durable Object data, including its recovery history, with AES-256. In transit, all traffic uses TLS. Ad account access tokens are stored encrypted with a key kept apart from the data.
- Data minimisation. We do not store customer names, email addresses, phone numbers or street addresses; of a shipping destination we keep only the country and region.
- Access control. Only the owner of SIA MANUM has access to the production systems. All accounts with access use two-factor authentication and unique passwords kept in a password manager, or passkeys. Our admin tools sit behind Cloudflare Access.
- Logging. Every look we take at a store's data is logged for that store. Cloudflare's audit logs record sign-ins and changes in our Cloudflare account.
- Test and production. Development uses separate Cloudflare services and Shopify development stores with test data only. Production data is never copied to test.
- Data loss prevention. Access tokens have the narrowest rights the app needs. Production data is not exported in bulk except to the merchant it belongs to, and is not kept on personal devices.
- Webhooks. We check that every webhook comes from Shopify (HMAC signature) and reject any that does not. We act on Shopify's privacy webhooks within 30 days.
- Incident response. We follow a written security incident response policy with severity levels, roles, escalation paths, evidence collection and time limits.
Annex 2: Sub-processors
| Sub-processor | Purpose | Data | When |
|---|---|---|---|
| Cloudflare | Hosting (Cloudflare Workers and Durable Objects) | All Sharpsum data | Always |
| Shopify | Platform and billing | Store data; subscription and charges | Always |
| Google (Google Workspace) | Support messages | When you write to us | |
| Meta, Google Ads, TikTok, Microsoft Advertising, Pinterest, Snapchat | Reading ad spend | Access token; daily spend totals | Only for the accounts you connect |
Contact
SIA MANUM, registration number 40203414494
Gaismas iela 22-26, Daugavpils, LV-5414, Latvia
support@manum.lv