Last updated: 27 July 2026
Melodyly ("we", "us") is operated from Lithuania and is the controller of the personal data described here. Contact: hello@melodyly.com. The short version: we collect what's needed to make and deliver your song, we don't sell your data, and analytics only runs if you say yes.
Account details — your name, email and a hashed password.
Your song brief — the recipient's first name, your relationship, the occasion, the
stories you write, an optional photo and gift note. This is personal by design — it's what
the musician writes from.
Order and payment records — what you ordered and its status. Payments are handled by
Stripe (merchant of record); your card details go directly to Stripe and never touch
our servers. We keep only Stripe's reference IDs.
Emails we send you — order updates and, if you use it, gift delivery to your
recipient's email address.
Technical basics — standard server logs (IP, time, page) kept briefly for security
and debugging.
To perform our contract with you (make and deliver your song, process payment, send order emails); with your consent (analytics cookies, the recipient's email you choose to provide); and for our legitimate interests (keeping the service secure and preventing abuse).
The musician assigned to your order sees your brief — that's how the song gets written. Stripe processes payments. Our hosting provider stores the site and database in the EU. Our email provider relays the emails above. Each acts under contract and only to provide their service. We do not sell or rent personal data. If the law requires disclosure, we comply.
Song files, cover photos and gift pages are kept for 2 months after delivery (or after the preview, for orders never unlocked) and are then deleted automatically — the exact date is shown on your order and gift pages, and we encourage you to download your song before then. Your account, order history and the song's lyrics remain while your account exists. Delete your account (or ask us to) and we remove personal data not needed for legal record-keeping. Server logs rotate on a short schedule.
Under the GDPR you can ask for access, correction, deletion, restriction, portability, or object to processing — email hello@melodyly.com and we'll respond within a month. You can also complain to your local data-protection authority (in Lithuania: the State Data Protection Inspectorate, vdai.lrv.lt).
We keep cookies to a minimum:
| Cookie | Purpose | Lifetime |
|---|---|---|
PHPSESSID |
Essential — keeps you logged in while you use the site. | Session |
mg_cookie_consent |
Essential — remembers your cookie choice so we stop asking. | 1 year |
_ga, _ga_* |
Google Analytics — only set if you clicked Accept on our cookie bar. Helps us understand which pages work. | Up to 2 years |
Essential cookies need no consent and can't be switched off. Analytics runs only after you accept, and declining changes nothing about how the site works. Change your mind any time via Cookie preferences in the footer.
Melodyly is for adults. We don't knowingly collect data from children under 16 — song recipients are described to us by the adult placing the order.
If this policy changes materially we'll say so on the site; the date above always shows the current version.