Privacy Policy
Data Controller: [Legal name — to be completed], a Sole Proprietorship registered in Poland (NIP [to be completed]).
Contact for privacy requests: [email — to be completed]
We follow the principle of data minimisation under the GDPR (RODO). We do not operate our own database of personal data or payment details; all such data is held by the specialised processors described below.
1. Data Controller and Processors
The Service Provider named above is the Data Controller. We use these sub-processors:
- Authentication — Amazon Web Services (AWS Cognito), EU region (Frankfurt, eu-central-1 / EEA). Stores your account profile, password hashes, and session tokens.
- Federated sign-in — Google and/or Facebook (whichever social sign-in options are enabled). If you choose social sign-in, that provider authenticates you and shares your email and account identifier with us; that provider’s own privacy policy governs its processing.
- Payments and order records — Stripe Payments Europe, Ltd. Processes and stores your email, billing details, and card data, and holds each Order’s parameters — the target location (a town/area, resolved to approximate coordinates, not a specific street address), date range, and weather conditions — as string metadata on the Stripe payment record. This metadata is standard readable text (not encrypted) and may be updated by us to record order status or an issued reward code.
We do not sell your personal data or share it with advertising networks.
2. Location Data
- Home-page weather (transient). To show current local weather, the Platform may request your device location. This reading is used only to fetch weather for that moment and is not stored on our systems.
- Order location (stored). The location you choose for an Order is a town or area (city/area level, not a precise home or street address), stored as Stripe metadata for as long as the transaction record is retained (§4). This is necessary to perform and verify the Service.
3. What We Collect and Why (Legal Bases)
- Account data (email, hashed password, tokens) — to provide the account (contract; Art. 6(1)(b) GDPR).
- Order data (chosen location, dates, weather parameters, price) — to perform the Service (contract) and to meet tax/accounting duties (legal obligation; Art. 6(1)(c)).
- Payment data — held by Stripe to take payment (contract).
4. Retention
Account credentials are kept until you delete your account. Transaction and Order records held by Stripe are retained for the period required by Polish tax and anti-money-laundering law, after which they are removed under the processor’s schedule.
5. Your GDPR (RODO) Rights
You may request access to your data, rectification, portability, restriction, objection, and erasure of your account credentials from the authentication pool. Exception: transaction and Order records legally bound to Stripe’s financial logs cannot be erased before the statutory tax-retention period expires. To exercise any right, contact [email — to be completed]. You may also lodge a complaint with the Polish supervisory authority (UODO, uodo.gov.pl).
6. Cookies and Local Storage
The Platform uses essential browser storage (for example sessionStorage / localStorage) to keep you signed in. It does not use analytics cookies. Advertising cookies are set only if you consent to reward ads (see §7).
7. Advertising
Some order rewards can be unlocked by watching short video ads served by Google Ad Manager. Reward ads are optional — you only see one if you choose to watch to earn a discount. When an ad is shown, Google may set cookies and process device/advertising data under its own policies. For visitors in the EEA/UK we request consent through a Google-certified consent management platform (CMP) before any ad or ad cookie loads; the ad code is not loaded until you consent.