PRIVACY POLICY AND COOKIES

§ 1. GENERAL PROVISIONS

This privacy policy of the Online Store operating at the address www.bb-akcesoria.pl (hereinafter referred to as the “Online Store” or the “Store”) is provided for information purposes only, which means that it does not constitute a source of obligations for Service Recipients or Customers of the Online Store.

The controller of personal data collected via the Online Store is Beata Piątkowska, conducting business activity under the name Beata Piątkowska BB-Akcesoria, Tarnowiec 353, 38-204 Tarnowiec, Poland, Tax Identification Number (NIP) 6851261212, National Business Registry Number (REGON) 523013319, entered in the Central Register and Information on Economic Activity (CEIDG), e-mail address: bb.obslugaklienta@gmail.com, contact telephone number: 724 252 776 (charged according to the operator’s standard tariff) – hereinafter referred to as the “Controller”.

Personal data within the Online Store is processed by the Controller in accordance with the applicable law, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the “GDPR”). The official text of the GDPR is available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679.

Use of the Online Store, including making purchases, subscribing to the Newsletter and using the online chat, is voluntary. However, the provision of personal data is necessary for the conclusion and performance of a contract of sale or the provision of an Electronic Service – failure to provide the required data prevents the conclusion of such a contract – and also for the fulfilment of legal obligations incumbent upon the Controller, in particular in the field of accounting and taxation.

The Controller exercises particular diligence in protecting the interests of data subjects and, in particular, ensures that the data collected by it is: processed lawfully; collected for specified, lawful purposes; substantively correct and adequate in relation to the purposes for which it is processed; stored for no longer than is necessary; and processed in a manner ensuring appropriate security of personal data.

The Online Store operates on the Shopify platform, and the Store’s domain is maintained by OVH.pl. The Controller applies security measures including an SSL certificate, strong access passwords and two-factor authentication (2FA) when logging in to the Store’s management panel.

All capitalised terms used in this privacy policy (e.g. Store, Customer, Newsletter) should be understood in accordance with their definitions contained in the Terms and Conditions of the Online Store, available at www.bb-akcesoria.pl/pages/regulaminy.

§ 2. LEGAL BASES FOR THE PROCESSING OF DATA

The Controller is entitled to process personal data in cases where at least one of the following conditions is met:

  • the data subject has given consent to the processing of their personal data for one or more specific purposes (Article 6(1)(a) GDPR);
  • processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR);
  • processing is necessary for compliance with a legal obligation to which the Controller is subject (Article 6(1)(c) GDPR);
  • processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party (Article 6(1)(f) GDPR).

§ 3. PURPOSE, LEGAL BASIS, PERIOD AND SCOPE OF DATA PROCESSING

The Controller processes the personal data of Customers and Service Recipients for the following purposes:

Conclusion and performance of a contract of sale, including order handling, packaging and shipment of Products.

Legal basis: Article 6(1)(b) GDPR (performance of a contract). Data is stored for the period necessary for the performance, termination or expiry of the contract concluded, and subsequently for the period of limitation of claims. Scope: first name and surname, e-mail address, telephone number, delivery address, and, where necessary, residential/business address, and, in the case of Customers who are not consumers – additionally the company name and NIP.

Handling of online payments via the Przelewy24 system and Shopify Payments.

Legal basis: Article 6(1)(b) GDPR. Data is stored for the period necessary for the processing and settlement of payments, in accordance with the requirements of the payment operator. Scope: first name and surname, e-mail address, transaction data; payment card data is processed directly by the payment operator.

Maintenance of accounting records and fulfilment of tax obligations.

Legal basis: Article 6(1)(c) GDPR in conjunction with Article 74(2) of the Accounting Act. Data is stored for the period required by tax and accounting regulations. Scope: first name and surname, address, transaction data, and, where an invoice is issued – additionally the company name and NIP.

Provision of the Newsletter service and sending information about the Store’s products, promotions and offers.

Legal basis: Article 6(1)(a) GDPR (consent of the data subject), in conjunction with the provisions of the Law on Electronic Communications concerning the sending of commercial information and direct marketing by means of electronic communication. Data is processed until consent is withdrawn or the Newsletter subscription is cancelled. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. Scope: e-mail address and first name – if voluntarily provided.

Direct marketing and remarketing, including through the use of Google Analytics, Meta Pixel and marketing automation tools.

Legal basis: Article 6(1)(f) GDPR (legitimate interest of the Controller) as regards direct marketing, and Article 6(1)(a) GDPR (consent) as regards analytical and marketing cookies – the rules for giving consent to cookies are described in § 8. Data is stored until an effective objection is raised or consent is withdrawn, but no longer than the period of limitation of claims. Scope: e-mail address, cookie identifiers, data on behaviour on the Store’s website.

Handling of the online chat and the contact form.

Legal basis: Article 6(1)(b) or (f) GDPR, depending on whether the enquiry concerns a concluded or planned contract. Data is stored for the period necessary to provide a response and clarify the matter, no longer than 12 months from the last contact, unless a longer retention period is justified by the need to establish, pursue or defend claims. Scope: first name and surname, contact details, the content of the correspondence, and – if the enquiry concerns an order – order and transaction data.

Establishment, pursuit or defence of claims, including debt collection.

Legal basis: Article 6(1)(f) GDPR (legitimate interest of the Controller). Data is stored for the period necessary to establish, pursue or defend claims, no longer than until the expiry of the relevant limitation period under applicable law. Scope: first name and surname, contact details, address, transaction data.

Publication by the Customer of an opinion on a concluded contract of sale.

Legal basis: Article 6(1)(a) GDPR (consent). Data is stored until consent is withdrawn. Scope: first name, any photograph of the product provided, and the content of the review.

§ 4. RECIPIENTS OF DATA

For the proper functioning of the Online Store and the performance of concluded contracts of sale, it is necessary for the Controller to make use of the services of external entities. The Controller discloses data only where necessary for the performance of a given processing purpose, and only to the extent necessary for that purpose. Personal data may be transferred to the following recipients or categories of recipients:

  • the provider of the Shopify e-commerce platform (Shopify Inc., Canada / Shopify International Ltd., Ireland) – as the entity supplying the infrastructure of the Online Store;
  • the hosting company maintaining the Store’s domain – OVH.pl;
  • carriers, forwarders and courier brokers – InPost, Orlen Paczka, DPD – in the case of a Customer using courier or postal delivery, to the extent necessary to carry out the delivery;
  • electronic payment operators – Przelewy24, Shopify Payments – to the extent necessary to process payments made by the Customer;
  • banks handling the Controller’s settlements – to the extent necessary for financial settlements;
  • the provider of the Shopify Inbox online chat tool – with respect to the content and contact details provided during the conversation;
  • providers of analytical and marketing tools – Google (Google Analytics), Meta (Meta Pixel) – with respect to data collected by means of cookies, following the consent referred to in § 8;
  • the law firm providing legal advisory services to the Controller, including in respect of the pursuit of claims and debt collection;
  • the accounting office providing accounting services to the Controller;
  • public authorities, in cases where the obligation to disclose data results from generally applicable law.

The payment card operator is PayPro SA Agent Rozliczeniowy, ul. Pastelowa 8, 60-198 Poznań, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court Poznań – Nowe Miasto i Wilda in Poznań, VIII Commercial Division of the National Court Register, under KRS number 0000347935, NIP 7792369887, REGON 301345068.

With respect to payments processed via Shopify Payments, data may be transferred to Shopify International Limited, The Sidings, 4th Floor, Grand Canal Quay, Dublin D02 E7K8, Ireland, and to payment processors cooperating with Shopify, to the extent necessary to process, settle and ensure the security of payments.

§ 5. TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA

In connection with the Controller’s use of the services of Shopify, Google Analytics and Meta Pixel, personal data may be transferred to countries outside the European Economic Area (EEA), in particular to the United States and Canada.

The transfer of data to the United States takes place primarily on the basis of the European Commission’s implementing decision of 10 July 2023 finding an adequate level of protection of personal data under the EU-U.S. Data Privacy Framework (“DPF”), to which providers such as Google and Meta have adhered. To the extent that a given service provider or data recipient is not covered by DPF certification, the Controller bases the transfer of data on standard contractual clauses approved by the European Commission (SCCs), applied within data processing agreements.

Detailed information on the data transfer mechanisms applied by individual providers is available in their respective privacy policies: Shopify – https://www.shopify.com/legal/privacy; Google – https://policies.google.com/privacy; Meta – https://www.facebook.com/privacy/policy/.

§ 6. PROFILING

The Controller may use profiling within the Online Store for the purposes of direct marketing, including in order to grant a discount, send a discount code, remind about incomplete purchases, or present a Product proposal tailored to the interests of a given person. Decisions made on the basis of profiling do not concern the conclusion or refusal to conclude a contract of sale, nor the possibility of using Electronic Services – the decision to make use of a presented offer rests exclusively with the data subject.

Profiling consists of the automatic analysis of a person’s behaviour on the Online Store’s website, e.g. by adding a Product to the cart, browsing a specific Product page, or analysing the history of purchases made, and is carried out, among others, by means of Google Analytics and Meta Pixel.

The data subject has the right to object at any time to profiling for direct marketing purposes.

Independently of the above, in connection with the processing of payments, payment operators (Przelewy24, Shopify Payments) may apply their own automated transaction risk verification mechanisms (e.g. to counteract payment fraud). These mechanisms operate on the basis of the terms and conditions and privacy policies of those operators, and the Controller has no influence over their detailed operation. Where such action would produce significant legal effects for the person concerned (e.g. refusal to process a payment), that person has the right to obtain human intervention, to express their own point of view, and to contest such a decision – for this purpose, they should contact the Controller using the details indicated in § 1.

§ 7. RIGHTS OF THE DATA SUBJECT

The data subject has the right to:

  • access their personal data;
  • rectification of data;
  • erasure of data (“the right to be forgotten”);
  • restriction of the processing of data;
  • data portability;
  • object to processing based on Article 6(1)(f) GDPR, including profiling;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;
  • lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).

In order to exercise the above rights, the Controller may be contacted in writing, electronically at bb.obslugaklienta@gmail.com, or via the contact form available on the Online Store’s website. The Controller shall respond without undue delay, and no later than within one month of receipt of the request.

§ 8. COOKIES, OPERATIONAL DATA AND ANALYTICAL/MARKETING TOOLS

Cookies are small pieces of text information saved by a server on the device of a person visiting the Online Store’s website. The Store uses the following categories of cookies:

  • Essential cookies – required for the proper functioning of the Store (e.g. maintaining a session, cart contents, transaction security); these do not require consent and cannot be disabled without loss of the Store’s basic functionality.
  • Analytical cookies – used to collect visit statistics by means of Google Analytics; these require the user’s consent, given by means of the cookie consent banner.
  • Marketing / remarketing cookies – used to display advertisements tailored to the user’s interests and to measure the effectiveness of campaigns (Meta Pixel, marketing automation tools); these require the user’s consent, given by means of the cookie consent banner.

Consent to analytical and marketing cookies is given by means of the consent banner displayed on first visiting the Store. The user may change their preferences at any time in the cookie settings available on the Store’s website or in their web browser settings. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

Google Analytics (Google Ireland Limited / Google LLC) – a tool used to analyse traffic within the Online Store. It is possible to opt out of the sharing of website activity data at: https://tools.google.com/dlpage/gaoptout?hl=en. Further information: https://policies.google.com/privacy.

Meta Pixel (Meta Platforms Ireland Limited) – a tool used to measure advertising effectiveness and to display personalised advertisements. Advertising preferences can be managed in Facebook account settings: https://www.facebook.com/ads/preferences/. Further information: https://www.facebook.com/business/help/742478679120153.

Meta Conversions API (CAPI) – alongside Meta Pixel, the Controller applies an advanced (maximum) level of integration of the Conversions API. As part of this integration, in addition to standard browsing events, additional matching data may be transmitted to Meta Platforms Ireland Limited in encrypted form (using the SHA-256 hash function), such as: e-mail address, telephone number, first name and surname, residential/delivery address, and browser or order identifiers. This data is transmitted on a server-to-server basis and is used for the precise measurement of conversions, optimisation of advertising campaigns, and the creation of audience groups. The transmission of extended personal data via Meta CAPI takes place only after the User’s prior, voluntary consent to cookies and marketing tools has been obtained, given by means of the consent banner on the Store’s website. The User may withdraw consent at any time, which will result in the cessation of the transmission of their data to Meta’s system.

Marketing automation tools are used by the Controller to conduct e-mail campaigns and to segment recipients on the basis of purchasing behaviour, solely to the extent to which the user has given consent.

Disabling essential cookies in browser settings may prevent the use of certain functionalities of the Store, in particular the placing of an order.

§ 9. DATA SECURITY

The Controller applies appropriate technical and organisational measures to ensure the security of the personal data processed, including encryption of the connection by means of an SSL certificate, the use of strong access passwords, and two-factor authentication (2FA) when logging in to the Store’s management panel, and uses only the services of processors that provide a guarantee of an appropriate level of data security.

§ 10. FINAL PROVISIONS

The Online Store may contain links to other websites. The Controller recommends reviewing the privacy policy applicable on those websites – this privacy policy applies solely to the Controller’s Online Store.

The Controller reserves the right to introduce changes to this privacy policy for a valid reason, being, in particular: a change in the scope or manner of operation of the Online Store, including the introduction of new functionalities or tools processing personal data; a change in applicable law affecting the content of this policy; a change in the scope of cooperation with entities processing data on the Controller’s behalf (including hosting, payment, analytical or marketing service providers); or the issuance of an administrative decision or court ruling giving rise to an obligation to amend the policy. The Controller will inform of any planned changes by publishing the new content of the privacy policy on the Online Store’s website, indicating the date of its last update. A change to the policy does not affect the lawfulness of the processing of personal data carried out before its introduction, and, to the extent that processing is based on consent, any extension of the purposes of processing requires obtaining new, separate consent from the data subject.

This privacy policy forms an integral part of the Terms and Conditions of the Online Store.

Last updated: 28 August 2026.