Privacy policy

PRIVACY POLICY

Lovingly Made

www.lovinglymadeshop.com

Effective from: 3 June 2026


1. General Information

  1. This Privacy Policy explains how personal data is collected, used, stored, protected and shared in connection with the use of the online store Lovingly Made, available at www.lovinglymadeshop.com, hereinafter referred to as the “Store”.
  2. This Privacy Policy applies to users of the Store, Customers, persons placing Orders, persons contacting the Seller, newsletter subscribers, persons submitting complaints or returns, persons using the Customer Account, persons adding reviews or comments, and other persons whose personal data may be processed in connection with the operation of the Store.
  3. The Store processes personal data in accordance with applicable data protection laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, commonly known as the General Data Protection Regulation or GDPR, and Polish data protection regulations.
  4. Providing personal data is voluntary, but in certain cases it is necessary to use specific functions of the Store, including placing an Order, making a payment, receiving delivery, creating a Customer Account, submitting a complaint, returning a Product, contacting the Seller or subscribing to the newsletter.
  5. If the Customer does not provide the data necessary to complete an Order, the Seller may be unable to conclude or perform the sales contract.
  6. This Privacy Policy is divided into the following main parts:
    • cookies and similar technologies,
    • other purposes of personal data processing,
    • recipients of personal data,
    • rights of persons whose data is processed,
    • information about external tools and providers used by the Store.

2. Data Controller

  1. The controller of personal data processed in connection with the operation of the Store is:

Full registered business name: Anita Wójcik
Sole trader: Anita Wójcik
Store name / Trading name: Lovingly Made
Registered office address: ul. Michała Kleofasa Ogińskiego 2, 27-400 Ostrowiec Świętokrzyski, Poland
Tax Identification Number, NIP: 6612226885
VAT / Tax ID: PL6612226885
E-mail address: anita1888@o2.pl
Telephone number: +48 793 116 144

hereinafter referred to as the “Controller” or the “Seller”.

  1. The Controller may be contacted:
    • by e-mail at: anita1888@o2.pl,
    • by telephone at: +48 793 116 144,
    • in writing at: Anita Wójcik, ul. Michała Kleofasa Ogińskiego 2, 27-400 Ostrowiec Świętokrzyski, Poland.
  2. The Controller has not appointed a Data Protection Officer. In all matters concerning personal data, the Controller may be contacted directly using the contact details indicated above.

3. Categories of Personal Data Processed

  1. Depending on how the user uses the Store, the Controller may process the following categories of personal data:
    • first name and surname,
    • company name, if applicable,
    • tax identification number, if applicable,
    • billing address,
    • shipping address,
    • e-mail address,
    • telephone number,
    • Order details,
    • payment status and payment-related information,
    • invoice details,
    • complaint, return and withdrawal details,
    • correspondence content,
    • newsletter subscription data,
    • Customer Account data,
    • review or comment content,
    • IP address,
    • browser and device data,
    • cookie identifiers and similar online identifiers,
    • website activity data,
    • information about viewed products,
    • information about items added to the cart,
    • marketing and analytical data, where such data is collected through analytical, advertising, functional or marketing tools.
  2. The Controller does not intentionally collect special categories of personal data, such as health data, biometric data, political opinions, religious beliefs or other sensitive data within the meaning of GDPR.
  3. Users should not provide sensitive personal data through the Store, Order notes, contact forms, e-mail correspondence, reviews, comments or other communication channels unless it is strictly necessary for a specific matter.

4. Purposes, Categories of Data, Legal Bases and Retention Periods

The Controller processes personal data for the following purposes, on the following legal bases and for the following periods.

Purpose of processing Categories of data Legal basis under GDPR Retention period
Handling Orders in the Store Identification and contact data, delivery data, billing data, Order details, payment status Article 6(1)(b) GDPR — performance of a contract For the period necessary to perform the contract and then for the limitation period of possible claims
Handling Customer Accounts Identification data, contact data, account login data, Order history Article 6(1)(b) GDPR — provision of the Customer Account service For the duration of the Customer Account and then for the limitation period of possible claims
Contact with the Customer and handling enquiries Identification data, contact data, correspondence content Article 6(1)(f) GDPR — legitimate interest in communication; Article 6(1)(b) GDPR if the enquiry relates to a contract For the period necessary to handle the enquiry and then for the limitation period of possible claims
Processing payments and refunds Identification data, Order data, payment status, transaction data Article 6(1)(b) GDPR — performance of a contract; Article 6(1)(f) GDPR — legitimate interest in secure payment handling For the period necessary to process payment and refund, and then for accounting, tax and claim-related periods
Delivery of Products Identification data, delivery address, e-mail address, telephone number, shipment data Article 6(1)(b) GDPR — performance of a contract For the period necessary to deliver the Product and then for the limitation period of possible claims
Complaints, returns and withdrawal from the contract Identification and contact data, Order details, complaint or return content, correspondence history Article 6(1)(b) GDPR — performance of a contract; Article 6(1)(c) GDPR — legal obligations; Article 6(1)(f) GDPR — claims For the period necessary to handle the matter and then for the limitation period of possible claims
Accounting and tax obligations Identification data, billing data, invoice details, Order details Article 6(1)(c) GDPR — compliance with legal obligations For the period required by tax and accounting regulations
KSeF — National e-Invoicing System, where applicable Data included in VAT invoices and structured invoices Article 6(1)(c) GDPR — compliance with legal obligations For the period required by applicable tax regulations and KSeF rules
Newsletter E-mail address, subscription data, opening statistics, click statistics Article 6(1)(a) GDPR — consent; Article 6(1)(f) GDPR — legitimate interest in analysing newsletter effectiveness where permitted Until consent is withdrawn or the user unsubscribes, unless another legal basis applies
Product reviews and comments Review or comment content, identification data of the person posting the review or comment Article 6(1)(a) GDPR — consent expressed by submitting or publishing the review or comment; Article 6(1)(f) GDPR — legitimate interest in presenting reviews Until the review is removed, consent is withdrawn, or further storage is no longer necessary
Analytics and Store statistics Website activity data, device data, browser data, anonymised or aggregated statistical data, cookie identifiers Article 6(1)(f) GDPR — legitimate interest in analysing and improving the Store; Article 6(1)(a) GDPR where consent is required for cookies For the period resulting from the settings of the relevant analytical tools or until consent is withdrawn
Marketing of the Controller’s own products and services Website activity data, purchase history, viewed products, marketing segment data, cookie identifiers Article 6(1)(f) GDPR — legitimate interest in marketing own products and services; Article 6(1)(a) GDPR where consent is required Until the user objects, withdraws consent or the data is no longer useful for the marketing purpose
Archiving and accountability under GDPR All data necessary to demonstrate compliance with obligations Article 6(1)(f) GDPR — legitimate interest in demonstrating compliance and defending rights For the period necessary to demonstrate compliance or until the limitation period of possible claims expires
Establishing, pursuing or defending claims Data necessary in relation to a specific claim or potential claim Article 6(1)(f) GDPR — legitimate interest in protecting rights Until the limitation period of possible claims expires

5. Personal Data and Orders

  1. Personal data is processed in order to accept, confirm, prepare, ship and complete Orders placed in the Store.
  2. Data necessary to fulfil an Order may include the Customer’s name, surname, address, e-mail address, telephone number, Order details, payment status and delivery details.
  3. The legal basis for such processing is Article 6(1)(b) GDPR, as processing is necessary for the performance of a sales contract or to take steps before concluding such a contract.
  4. Order-related data may also be processed for accounting, tax, complaint, return, archiving and claim-related purposes.

6. Accounting, Tax Obligations and KSeF

  1. The Controller processes personal data for accounting and tax purposes, including issuing and storing invoices, accounting documents and other documentation required by law.
  2. Where applicable, data contained in VAT invoices may be transferred to the Polish National e-Invoicing System, KSeF, administered by the National Revenue Administration.
  3. Access to invoices in KSeF is available to entities authorised under applicable law, in particular tax authorities and the National Revenue Administration.
  4. In connection with the use of KSeF, the Controller may grant access to KSeF to entities supporting the Controller in fulfilling accounting and tax obligations, such as an accounting office, in accordance with the rules for granting access in KSeF.
  5. Structured invoices sent to KSeF are stored in KSeF for the period required by applicable tax regulations.
  6. The legal basis for processing data for accounting, tax and KSeF purposes is Article 6(1)(c) GDPR, meaning that processing is necessary to comply with legal obligations imposed on the Controller.

7. Recipients of Personal Data

  1. Personal data may be disclosed to external entities only where necessary for the operation of the Store, fulfilment of Orders, payment processing, delivery, compliance with legal obligations or protection of the Controller’s rights.
  2. Recipients of personal data may include in particular:
    • Shopify and entities providing the Store’s e-commerce infrastructure,
    • payment operators and payment service providers, including Shopify Payments, Przelewy24 / PayPro S.A., Klarna and providers of card, BLIK or electronic wallet payments,
    • banks and financial institutions involved in payment handling,
    • courier companies, postal operators, parcel locker operators, pickup point operators and logistics providers,
    • accounting and tax service providers,
    • providers of invoicing and accounting software,
    • IT service providers, hosting providers and technical support providers,
    • providers of analytical tools,
    • providers of advertising and marketing tools,
    • providers of newsletter and e-mail marketing tools,
    • providers of customer communication tools,
    • social media platforms,
    • legal advisors, debt collection entities or public authorities, where required by law or necessary to protect rights.
  3. Personal data is not sold by the Controller.
  4. Personal data may be made available to public authorities only where required by applicable law.
  5. Some entities receiving data may act as separate data controllers, in particular payment providers, courier companies, postal operators, social media platforms and public authorities.

8. Shopify and E-commerce Platform

  1. The Store operates using the Shopify e-commerce platform.
  2. Shopify may process certain personal data of Store users and Customers as a service provider or processor for the Controller, in particular data necessary to operate the Store, process Orders, support payments, manage checkout, maintain technical infrastructure, provide security and perform related e-commerce services.
  3. Shopify may also place cookies or similar technologies necessary for the operation of the Store, cart, checkout, payment process, analytics, security and Store management.
  4. Shopify may also process certain data in accordance with its own privacy documentation and applicable laws, depending on the specific service or functionality used.
  5. Shopify-related tools may collect technical and statistical data concerning how users interact with the Store, including visited pages, viewed products, cart events, checkout events and purchase-related statistics.
  6. Customers may find more information about Shopify’s privacy practices in Shopify’s own privacy documentation.

9. Payment Providers

  1. Payments in the Store may be processed through Shopify Payments and, in the scope of payment methods made available through Przelewy24, through Przelewy24 / PayPro S.A.
  2. Available payment methods may include in particular:
    • Shop Pay,
    • BLIK,
    • Przelewy24,
    • Klarna,
    • Visa,
    • Mastercard,
    • American Express,
    • Maestro,
    • UnionPay,
    • Apple Pay,
    • Google Pay.
  3. When the Customer chooses a specific payment method, personal data necessary to process the payment may be transferred to the relevant payment provider.
  4. Payment providers may process personal data in accordance with their own terms, privacy notices and legal obligations.
  5. The Controller does not store full payment card details. Card and payment data is processed by authorised payment service providers in accordance with applicable security standards.
  6. Payment providers, anti-fraud systems or security tools may use automated mechanisms to verify transactions, prevent fraud, ensure payment security or comply with legal obligations, in accordance with their own terms and privacy notices.

10. Delivery Providers

  1. In order to deliver Products, the Controller may transfer the Customer’s personal data to courier companies, postal operators, parcel locker operators, pickup point operators or other logistics providers.
  2. The data transferred may include in particular:
    • first name and surname,
    • delivery address,
    • e-mail address,
    • telephone number,
    • shipment details.
  3. Delivery providers process the data in order to deliver the parcel, provide delivery notifications and handle delivery-related matters.

COOKIES AND SIMILAR TECHNOLOGIES

11. What Cookies Are

  1. The Store uses cookies and similar technologies.
  2. Cookies are small text files stored on the user’s computer, smartphone, tablet or other device when the user visits a website.
  3. Cookies may contain information about the user’s activity on the website, device, browser, preferences or session.
  4. Similar technologies may include pixels, tags, scripts, local storage, software development kits and other technologies that allow information to be stored or accessed on the user’s device.

12. Why the Store Uses Cookies

  1. Cookies and similar technologies may be used in particular to:
    • ensure the proper operation of the Store,
    • enable cart functionality,
    • enable checkout,
    • remember cart contents,
    • maintain session functionality,
    • remember user preferences,
    • ensure Store security,
    • prevent fraud and abuse,
    • analyse Store traffic,
    • improve Store functionality,
    • measure the effectiveness of marketing campaigns,
    • display personalised advertisements,
    • embed newsletter forms,
    • measure the effectiveness of newsletter sign-up forms,
    • display or support additional Store functions, such as product reviews, recently viewed products, chat functions or social media links.
  2. Some cookies are necessary for the Store to function and cannot be disabled through the Store’s cookie consent tool.
  3. Non-essential cookies, including analytical, advertising and certain functional cookies, are used only where permitted by law and, where required, only after the user has given consent.

13. Types of Cookies Used by the Store

  1. The Store may use the following categories of cookies:

13.1. Necessary cookies

  1. Necessary cookies are required for the proper functioning of the Store.
  2. They may be used to:
    • operate the Store,
    • manage the cart,
    • enable checkout,
    • ensure payment security,
    • remember cookie consent choices,
    • maintain user session,
    • protect the Store against abuse,
    • enable technical administration of the Store.
  3. Necessary cookies do not require the user’s consent where they are strictly necessary to provide the service requested by the user.
  4. The legal basis for using necessary cookies and processing related data is the legitimate interest of the Controller in ensuring the proper functioning and security of the Store, Article 6(1)(f) GDPR, and, where the processing is necessary to perform a contract, Article 6(1)(b) GDPR.

13.2. Analytical cookies

  1. Analytical cookies help the Controller understand how users use the Store.
  2. They may collect information such as:
    • number of visits,
    • visited pages,
    • time spent on pages,
    • source of the visit,
    • browser type,
    • device type,
    • approximate location,
    • clicked links,
    • cart and checkout events,
    • purchase-related statistics.
  3. The Controller uses analytical data to create statistics, improve the Store, optimise the purchasing process and improve communication and marketing activities.
  4. The legal basis for processing data through analytical cookies is the user’s consent, Article 6(1)(a) GDPR, where such consent is required.

13.3. Advertising cookies

  1. Advertising cookies are used to conduct marketing activities, including displaying advertisements on other websites and social media platforms, measuring the effectiveness of advertising campaigns and adjusting advertising content to users’ interests.
  2. Advertising cookies may allow advertising providers to create user profiles based on information such as:
    • visited pages,
    • viewed products,
    • cart activity,
    • purchase history,
    • device data,
    • browser data,
    • frequency of visits,
    • marketing identifiers.
  3. The legal basis for processing data through advertising cookies is the user’s consent, Article 6(1)(a) GDPR, where such consent is required.

13.4. Functional cookies

  1. Functional cookies allow the Store to provide additional features and remember user preferences.
  2. They may be used to:
    • remember language or display preferences,
    • show recently viewed products,
    • support product reviews,
    • support newsletter subscription forms,
    • support chat or customer service tools,
    • enable social media functions.
  3. The legal basis for processing data through functional cookies is the user’s consent, Article 6(1)(a) GDPR, where such consent is required, or the legitimate interest of the Controller, Article 6(1)(f) GDPR, where the cookie is necessary for a function requested by the user.

14. Cookie Consent and Managing Cookies

  1. During the first visit to the Store, the user may be asked to consent to the use of non-essential cookies.
  2. The user may accept all cookies, reject non-essential cookies or manage cookie preferences, depending on the options available in the cookie consent tool used by the Store.
  3. The user may change cookie settings at any time, where such functionality is available in the Store.
  4. The user may also manage cookies through browser settings.
  5. Disabling certain cookies may affect the functionality of the Store, including cart, checkout, login, preferences, analytics or marketing features.
  6. Session cookies expire after the browsing session ends, in particular after closing the browser.
  7. Persistent cookies remain on the user’s device for a defined period or until the user deletes them manually.
  8. Third-party cookies are subject to the privacy policies and cookie policies of the relevant third-party providers.

15. Social Media Links and Plugins

  1. The Store may include links or plugins leading to the Seller’s profiles on social media platforms, including Facebook, Instagram, TikTok or other platforms.
  2. If the user visits the Seller’s profile on a social media platform or interacts with social media content, the operator of that platform may receive information that the user came from the Store.
  3. Social media platforms may process users’ personal data as separate controllers in accordance with their own privacy policies.
  4. The Controller may process data related to social media interactions in order to communicate with users, respond to messages and comments, promote the Store and analyse the effectiveness of social media activities.
  5. The legal basis for such processing is Article 6(1)(f) GDPR, meaning the legitimate interest of the Controller in communicating with users and promoting its activity, or Article 6(1)(a) GDPR, where consent is required.

16. Embedded Videos and External Content

  1. The Store may display embedded videos or other external content, including content from YouTube or other platforms.
  2. If the user plays an embedded video or interacts with external content, the provider of that content may receive information from the user’s browser, including information about the visit to the Store.
  3. If the user is logged into the relevant external platform, the provider may be able to associate the user’s activity in the Store with the user’s profile on that platform.
  4. The user may prevent or limit such processing by:
    • not playing embedded videos,
    • refusing consent to non-essential cookies,
    • logging out of the relevant external platform,
    • changing cookie or privacy settings in the browser or external platform.
  5. External content providers process personal data in accordance with their own privacy policies.

17. Profiling and Marketing Based on Cookies

  1. The use of analytical and advertising cookies may involve profiling.
  2. Profiling means that the Controller or providers of marketing tools may use collected information to create a user profile and make predictions about the user’s interests or purchasing preferences.
  3. Such information may include:
    • e-mail address, where available and legally permitted,
    • purchase history,
    • viewed products,
    • cart activity,
    • device type,
    • browser type,
    • website activity,
    • frequency of visits,
    • marketing identifiers.
  4. Profiling may be used to decide what content, offers or advertisements should be displayed to the user in the Store or on other websites and platforms.
  5. The user may object to profiling based on the Controller’s legitimate interest or withdraw consent where profiling is based on consent.
  6. The Controller does not make decisions based solely on automated processing, including profiling, which would produce legal effects concerning the user or similarly significantly affect the user within the meaning of GDPR.

OTHER PURPOSES OF PERSONAL DATA PROCESSING

18. Newsletter and E-mail Marketing

  1. The Store may allow users to subscribe to a newsletter.
  2. The newsletter is sent only to persons who have voluntarily subscribed to it or otherwise consented to receive marketing communication, where such consent is required.
  3. The newsletter may contain information about:
    • new products,
    • promotions,
    • discount codes,
    • special offers,
    • Store updates,
    • educational content,
    • content related to the Seller’s products and activity.
  4. The Controller may analyse newsletter statistics, including:
    • whether a message was opened,
    • whether a link was clicked,
    • which content generated interest,
    • subscription source,
    • effectiveness of sign-up forms.
  5. Such analysis may be used to improve newsletter content and send more relevant messages to subscribers.
  6. Newsletter tools may allow the Controller to combine newsletter statistics with Store activity data, where permitted by law and applicable consents.
  7. The subscriber may unsubscribe from the newsletter at any time:
    • by clicking the unsubscribe link included in each newsletter message,
    • by contacting the Controller at: anita1888@o2.pl.
  8. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
  9. If a subscriber does not open newsletter messages for a period longer than 1 year, the Controller may stop sending newsletters to that subscriber and may remove the subscriber from the newsletter list after prior notice.
  10. Further rules concerning the newsletter may be described in the Store’s Terms and Conditions.

19. Product Reviews and Comments

  1. The Store may allow Customers or users to add reviews, comments or ratings concerning Products.
  2. If a user adds a review or comment, the Controller may process:
    • the content of the review or comment,
    • name or nickname,
    • e-mail address,
    • Order information, where review verification is used,
    • technical information related to the publication of the review.
  3. The legal basis for processing may be Article 6(1)(a) GDPR, meaning consent expressed by submitting or publishing the review or comment, and Article 6(1)(f) GDPR, meaning the legitimate interest of the Controller in presenting opinions about Products and protecting the Store against abuse.
  4. Reviews and comments may be moderated in accordance with the Store’s Terms and Conditions.

20. Customer Service, Complaints and Returns

  1. The Controller processes personal data in order to handle correspondence, enquiries, complaints, returns, withdrawal statements and after-sales service.
  2. Data processed for these purposes may include:
    • first name and surname,
    • e-mail address,
    • telephone number,
    • postal address,
    • Order number,
    • Order history,
    • complaint or return description,
    • photos or other materials sent by the Customer,
    • correspondence history.
  3. The legal basis for processing is Article 6(1)(b) GDPR, Article 6(1)(c) GDPR and Article 6(1)(f) GDPR, depending on the specific matter.

21. Archiving and Accountability

  1. The Controller may process personal data for archiving purposes and to demonstrate compliance with GDPR and other legal obligations.
  2. This may include storing documentation relating to:
    • Orders,
    • payments,
    • complaints,
    • returns,
    • newsletter consents,
    • cookie consents,
    • correspondence,
    • accounting and tax obligations.
  3. The legal basis for processing is Article 6(1)(f) GDPR, meaning the legitimate interest of the Controller in securing documentation, demonstrating compliance and defending against claims.

22. Transfers of Personal Data Outside the European Economic Area

  1. In connection with the use of Shopify, payment providers, analytical tools, marketing tools, newsletter tools, communication tools or other technical service providers, personal data may be transferred outside the European Economic Area, including to the United States.
  2. If personal data is transferred outside the European Economic Area, such transfer takes place in accordance with applicable data protection laws and with the use of appropriate safeguards required by GDPR, where applicable.
  3. Such safeguards may include in particular:
    • an adequacy decision of the European Commission,
    • participation of the relevant provider in the EU-U.S. Data Privacy Framework,
    • standard contractual clauses approved by the European Commission,
    • additional security measures,
    • other mechanisms permitted by GDPR.
  4. The user may contact the Controller to obtain more information about the safeguards used for transfers of personal data outside the European Economic Area.

23. Rights of Data Subjects

  1. A person whose personal data is processed has the following rights under GDPR:
    • the right of access to personal data,
    • the right to obtain a copy of personal data,
    • the right to rectification of inaccurate personal data,
    • the right to erasure of personal data,
    • the right to restriction of processing,
    • the right to data portability,
    • the right to object to processing,
    • the right to withdraw consent at any time, where processing is based on consent,
    • the right to lodge a complaint with a supervisory authority.
  2. The exercise of certain rights may depend on the legal basis and circumstances of the processing.
  3. The right to erasure may be limited where further processing is necessary to comply with legal obligations, establish, pursue or defend claims, or fulfil other legally justified purposes.
  4. The right to object applies in particular where personal data is processed on the basis of the Controller’s legitimate interest.
  5. If processing is based on consent, the user may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
  6. To exercise the above rights, the data subject may contact the Controller at: anita1888@o2.pl.
  7. The Controller may ask the person making the request to provide additional information necessary to verify their identity, if this is required to protect personal data against unauthorised disclosure.
  8. The Controller responds to requests within the time limits provided by GDPR.

24. Right to Lodge a Complaint with a Supervisory Authority

  1. A person whose personal data is processed has the right to lodge a complaint with the competent supervisory authority if they believe that the processing of their personal data violates GDPR.
  2. In Poland, the competent supervisory authority is:

President of the Personal Data Protection Office
Personal Data Protection Office
ul. Stawki 2
00-193 Warsaw
Poland
Website: uodo.gov.pl


25. Automated Decision-Making

  1. Personal data may be processed by technical systems used by the Store, Shopify, payment providers, analytical tools, advertising tools, newsletter tools or security tools.
  2. The Controller does not make decisions towards Customers based solely on automated processing, including profiling, which would produce legal effects concerning them or similarly significantly affect them within the meaning of GDPR.
  3. Payment providers, anti-fraud systems or security tools may use automated mechanisms to verify transactions, prevent fraud, ensure payment security or comply with legal obligations, in accordance with their own terms and privacy notices.

26. Data Security

  1. The Controller applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration or disclosure.
  2. The Store uses technical solutions provided by Shopify and other service providers to ensure the security of the Store, checkout, payment process and Order handling.
  3. Access to personal data is limited to persons and entities that need such access for the purposes described in this Privacy Policy.
  4. The Controller uses reasonable organisational measures to ensure that persons processing personal data are authorised and obliged to maintain confidentiality.
  5. Despite the use of security measures, no method of data transmission over the Internet or electronic storage is completely secure. The Controller makes reasonable efforts to protect personal data in accordance with applicable law.

27. Links to External Websites

  1. The Store may contain links to external websites, payment providers, delivery providers, social media platforms or other third-party services.
  2. The Controller is not responsible for the privacy practices of external websites or third-party services.
  3. Users should read the privacy policies of external websites and services before using them.

APPENDIX NO. 1

LIST OF ANALYTICAL, ADVERTISING, FUNCTIONAL AND COOKIE-BASED TOOLS

This Appendix describes the main categories of external tools that may be used in the Store and may involve cookies, similar technologies or the processing of personal data.


1. Shopify Cookies and Shopify Analytics

  1. The Store operates on the Shopify platform.
  2. Shopify may use cookies and similar technologies necessary for:
    • operating the Store,
    • managing the cart,
    • enabling checkout,
    • processing Orders,
    • ensuring Store security,
    • remembering user preferences,
    • providing Store statistics,
    • analysing Store performance,
    • supporting marketing and sales functions.
  3. Shopify may collect information such as:
    • pages visited by the user,
    • products viewed by the user,
    • cart activity,
    • checkout activity,
    • purchase-related statistics,
    • browser and device data,
    • IP address,
    • approximate location,
    • technical identifiers.
  4. The Controller may receive aggregated or statistical information from Shopify concerning Store performance, sales, conversion rates and customer activity.

2. Google Analytics

  1. The Store may use Google Analytics to analyse how users interact with the Store.
  2. Google Analytics may collect information such as:
    • number of visits,
    • visited pages,
    • date and time of visits,
    • first and last visit,
    • duration of visits,
    • source of the visit,
    • browser type,
    • device type,
    • clicked links,
    • approximate location,
    • anonymised or shortened IP address,
    • events related to Store activity.
  3. The Controller uses Google Analytics reports to understand Store traffic and improve the Store, Products, communication and marketing activities.
  4. Google may assign its own identifier to users and may collect data from cookies placed on different websites where Google tools are used.
  5. The Controller receives reports and statistics concerning the Store, not direct access to full data stored by Google on the user’s device.
  6. Google Analytics is used only where permitted by law and, where required, after the user has given consent to analytical cookies.
  7. The user may prevent Google Analytics from collecting information by refusing analytical cookies or using browser tools provided by Google.

3. Google Ads and Other Google Advertising Tools

  1. The Store may use Google Ads and other Google advertising tools to:
    • display advertisements,
    • measure the effectiveness of advertising campaigns,
    • conduct remarketing,
    • reach users who have visited the Store,
    • analyse advertising conversions.
  2. Google advertising tools may collect information such as:
    • visited pages,
    • products viewed,
    • advertisements clicked,
    • conversions,
    • browser and device data,
    • cookie identifiers,
    • marketing identifiers.
  3. The Controller may use Google advertising tools to create advertising campaigns addressed to groups of users with selected characteristics, for example users who visited the Store or viewed specific Products.
  4. The Controller does not receive direct access to personal data stored by Google in cookies on the user’s device, but may receive aggregated or statistical campaign data.
  5. Google advertising cookies are used only where permitted by law and, where required, after the user has given consent to advertising cookies.
  6. Users may manage Google advertising settings through Google’s privacy and advertising settings.

4. Meta Pixel, Facebook and Instagram Advertising Tools

  1. The Store may use Meta Pixel or other tools provided by Meta Platforms in order to manage advertising on Facebook and Instagram.
  2. If the user consents to advertising cookies, Meta tools may collect information that the user has visited the Store or specific pages of the Store.
  3. Such information may be associated with the user’s Facebook or Instagram profile if the user has such a profile and is logged in or identifiable by Meta.
  4. If the user does not have a Facebook or Instagram account, Meta may assign information to a technical identifier.
  5. The Controller may use Meta tools to:
    • conduct remarketing,
    • display advertisements to users who visited the Store,
    • create advertising audiences,
    • measure advertising effectiveness,
    • analyse conversions.
  6. The Controller receives statistical information about the effectiveness of advertising campaigns, for example how many users viewed or clicked an advertisement, without direct access to full individual profiles maintained by Meta.
  7. Meta Pixel and similar advertising tools are used only where permitted by law and, where required, after the user has given consent to advertising cookies.
  8. Users who have Facebook or Instagram accounts may manage privacy and advertising settings directly within those platforms.

5. TikTok Tools

  1. The Store may use TikTok tools, including TikTok Pixel or links to TikTok profiles, for marketing, advertising or analytical purposes.
  2. TikTok tools may collect information about:
    • visits to the Store,
    • viewed pages,
    • interactions with Products,
    • advertising events,
    • device and browser data,
    • technical identifiers.
  3. TikTok may process data as a separate controller in accordance with its own privacy policy.
  4. TikTok tools are used only where permitted by law and, where required, after the user has given consent to advertising or analytical cookies.

6. E-mail Marketing and Newsletter Tools

  1. The Store may use an external e-mail marketing or newsletter tool to manage subscriptions and send newsletters.
  2. Such a tool may process:
    • e-mail address,
    • subscription date,
    • consent status,
    • newsletter opening statistics,
    • click statistics,
    • unsubscribe information,
    • technical information about delivery.
  3. E-mail marketing tools may also use cookies or similar technologies to:
    • display newsletter subscription forms,
    • measure the effectiveness of forms,
    • analyse newsletter campaigns,
    • personalise newsletter content.
  4. The Controller uses such data to manage the newsletter, improve message content and analyse the effectiveness of communication.
  5. The subscriber may unsubscribe at any time by clicking the unsubscribe link or contacting the Controller.

7. Functional Tools

  1. The Store may use functional tools that support additional Store features, including:
    • product reviews,
    • star ratings,
    • recently viewed products,
    • product recommendations,
    • customer service chat,
    • contact forms,
    • product sharing functions,
    • cookie consent management.
  2. Such tools may process technical data, activity data or information entered by the user, depending on the function used.
  3. Functional tools are used where necessary to provide a function requested by the user or, where required, after the user has given consent.

8. YouTube and Embedded Video Tools

  1. The Store may embed videos from YouTube or other video platforms.
  2. If the user plays an embedded video, the video provider may receive information from the user’s browser, including information that the user visited the Store.
  3. If the user is logged into the video platform, the provider may be able to associate the video playback with the user’s profile.
  4. Embedded video tools may use cookies or similar technologies only where permitted by law and, where required, after the user has given consent.

9. Social Media Links

  1. The Store may include links to social media profiles of the Seller.
  2. When the user clicks a social media link, the relevant platform may receive information that the user came from the Store.
  3. Social media platforms process personal data in accordance with their own privacy policies.

10. Changes to the List of Tools

  1. The list of analytical, advertising, functional and cookie-based tools may change as the Store develops.
  2. The Controller may update this Appendix in the event of:
    • adding a new analytical tool,
    • adding a new advertising tool,
    • changing the newsletter system,
    • changing the e-commerce platform functions,
    • changing cookie consent tools,
    • changing legal requirements.
  3. The current version of this Privacy Policy and Appendix is available on the Store’s website.

28. Changes to this Privacy Policy

  1. The Controller may amend this Privacy Policy, in particular in the event of:
    • changes in applicable law,
    • changes in Store functionality,
    • changes in payment, delivery, analytical or marketing tools,
    • changes in data processing methods,
    • changes in the Controller’s contact details.
  2. The current version of the Privacy Policy is always available on the Store’s website.
  3. This Privacy Policy is effective from: 3 June 2026.