Privacy Policy
Who processes your data, for what purpose, how long we keep it and what rights you can exercise.
Effective date: [DO UZUPEŁNIENIA: data wejścia polityki prywatności w życie]
This policy explains how ReptiShop processes personal data under Regulation (EU) 2016/679 (GDPR) and Polish data protection law.
1. Data controller
The controller of your personal data is ReptiShop Sp. z o.o., ul. Hodowlana 5, 05-870 Błonie, Poland, NIP 5127987433, REGON 521112922, KRS [DO UZUPEŁNIENIA: numer KRS].
Contact for data protection matters: shop@reptishop.pl, phone +48 883 032 695, postal address as above.
Data protection officer: [DO UZUPEŁNIENIA: imię i nazwisko oraz adres e-mail inspektora ochrony danych albo informacja, że administrator nie wyznaczył IOD].
2. Purposes and legal bases
We process data only for the specific purposes listed below. For each purpose we state the legal basis and the scope of data.
Order fulfilment and performance of the sales contract
- Scope: name, delivery address, e-mail, phone number, order contents, payment data, parcel number.
- Legal basis: Art. 6(1)(b) GDPR — performance of a contract to which you are a party, or steps taken before entering into it.
- Consequence of not providing data: providing the data is voluntary, but without it we cannot conclude or perform the contract.
Customer account
- Scope: e-mail address, password stored as a cryptographic hash, profile data and addresses, order history, wishlist.
- Legal basis: Art. 6(1)(b) GDPR — performance of the account service agreement.
Accounting and tax obligations
- Scope: buyer details on the sales document, VAT ID, transaction amounts.
- Legal basis: Art. 6(1)(c) GDPR in connection with the Polish Accounting Act and VAT Act.
Complaints, returns and customer service
- Scope: contact details, order number, content of the request, attached photos, correspondence.
- Legal basis: Art. 6(1)(c) GDPR — legal obligation under consumer law, and Art. 6(1)(f) GDPR — our legitimate interest in handling requests and defending against claims.
Newsletter and direct marketing
- Scope: e-mail address, first name (optional), date and content of consent, open and click statistics.
- Legal basis: Art. 6(1)(a) GDPR — your consent, collected using double opt-in, together with Polish rules implementing the ePrivacy Directive. You can withdraw consent at any time using the link in the message footer or by writing to us; withdrawal does not affect the lawfulness of processing before it.
Statistics, analytics and online marketing
- Scope: cookie identifiers, IP address, device and browser data, store events (views, add-to-cart, purchases).
- Legal basis: Art. 6(1)(a) GDPR — consent given in the cookie banner; for purely internal statistics also Art. 6(1)(f) GDPR.
- Details are set out in the Cookie policy. You can change your consent at any time in the cookie settings.
Product reviews
- Scope: first name or signature, review content, rating, link to the order.
- Legal basis: Art. 6(1)(a) GDPR — consent to publication, and Art. 6(1)(c) GDPR for verifying that the review comes from someone who bought the product.
Wholesale cooperation and the affiliate programme
- Scope: company details, VAT ID, contact person, settlement data.
- Legal basis: Art. 6(1)(b) GDPR — pre-contractual steps and performance of the contract, and Art. 6(1)(c) GDPR for settlements.
Security, fraud prevention and legal claims
- Scope: server logs, IP address, timestamps, login events, payment history.
- Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in keeping the service secure, preventing abuse and establishing, exercising or defending legal claims.
3. Retention periods
- Order and sales-document data — 5 years from the end of the calendar year in which the tax became payable.
- Customer account data — until you delete the account or request deletion; afterwards we keep only what tax and accounting obligations require.
- Complaints and returns — 6 years from the closure of the case, matching the general limitation period for claims.
- Newsletter — until consent is withdrawn; proof of granting and withdrawing consent is kept for 3 years after withdrawal.
- Cookies and analytics data — as stated in the Cookie policy, no longer than 24 months from the last activity.
- Security logs — up to 12 months, unless they constitute evidence in proceedings.
- Customer service correspondence — 3 years from the last contact.
4. Recipients of data
We share data only with entities whose involvement is necessary for the purposes above:
- Carriers and logistics operators — InPost, DPD, DHL and the courier broker handling our shipments; they receive address, phone and e-mail data solely to deliver the parcel and send status notifications, acting as separate controllers.
- Payment providers — [DO UZUPEŁNIENIA: pełna nazwa i dane operatora płatności], PayPal, PayPo, Alior Bank (instalments); they receive data needed to settle the transaction and act as separate controllers.
- Hosting and server infrastructure provider — [DO UZUPEŁNIENIA: nazwa i siedziba dostawcy hostingu] — a processor under a data processing agreement.
- E-mail and messaging provider — [DO UZUPEŁNIENIA: nazwa dostawcy poczty i systemu mailingowego] — a processor.
- Accounting office and advisers — [DO UZUPEŁNIENIA: nazwa biura rachunkowego] and legal counsel, to the extent needed for settlements and protection of claims.
- Analytics and advertising providers — Google Ireland Limited (Google Analytics 4, Google Tag Manager), Meta Platforms Ireland Limited (Meta Pixel), TikTok Technology Limited (TikTok Pixel) — only after the relevant cookie consent is given.
- Public authorities — where disclosure is required by law.
We do not sell personal data and we do not share it with third parties for their own marketing.
5. Transfers outside the European Economic Area
As a rule we process data within the EEA. A transfer outside the EEA may occur through the use of Google, Meta and TikTok tools whose infrastructure includes servers in the United States. Such transfers rely on the European Commission adequacy decision of 10 July 2023 concerning the EU-U.S. Data Privacy Framework, for providers certified under that framework, or on standard contractual clauses approved by the European Commission together with supplementary safeguards. You can obtain a copy of the safeguards applied by writing to the address in section 1. [DO UZUPEŁNIENIA: weryfikacja listy dostawców spoza EOG i aktualnych podstaw transferu na dzień uruchomienia sklepu]
6. Your rights
- Access — to learn whether and what data we process and to receive a copy (Art. 15 GDPR);
- Rectification — to correct inaccurate data and complete incomplete data (Art. 16 GDPR);
- Erasure — the right to be forgotten where data is no longer needed, consent has been withdrawn or processing is unlawful (Art. 17 GDPR);
- Restriction of processing — while the accuracy of data or an objection is being verified (Art. 18 GDPR);
- Data portability — to receive data processed on the basis of consent or a contract in a structured, machine-readable format (Art. 20 GDPR);
- Objection — to processing based on legitimate interest; for direct marketing the objection is unconditional and always effective (Art. 21 GDPR);
- Withdrawal of consent at any time, without affecting the lawfulness of earlier processing (Art. 7(3) GDPR);
- Complaint to a supervisory authority — the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl. You may also lodge a complaint with the supervisory authority of your country of residence.
We handle requests without undue delay and no later than one month from receipt. In complex cases the deadline may be extended by two further months, of which we will inform you. Some rights — data export and account deletion — can be exercised yourself in the Privacy tab of your customer panel.
7. Profiling and automated decisions
We do not make decisions based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you.
We do use limited profiling: based on browsing and purchase history we select product recommendations and advertising content. This takes place only after consent to marketing cookies and does not affect the prices shown in the store — we do not personalise prices. You can object to profiling for marketing purposes at any time.
8. Data security
We apply technical and organisational measures proportionate to the risk: TLS-encrypted transmission, passwords stored only as cryptographic hashes, role-based access control, logging of operations in the admin panel, regular backups and software updates. Only authorised staff bound by confidentiality have access to data.
9. Children's data
The store is intended for adults. We do not target children and do not knowingly collect data of persons under 16. If we find that an account was created by a minor without guardian consent, the data will be deleted.
10. Changes to this policy
We may update this policy when the scope of processing, the tools we use or the law changes. A new version is published on this page with its effective date, and registered Customers are informed of material changes by e-mail.