AGATATEREBUS.COM STORE PRIVACY POLICY
Effective from August 25, 2026.
§ 1. GENERAL INFORMATION
1. This Privacy Policy defines the rules for processing personal data of individuals using the online store operating at agataterebus.com, as well as the rules for using cookies and similar technologies.
2. The policy fulfills the information obligation resulting from Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
3. The administrator of personal data is Agata Terebus, operating a sole proprietorship entered into the CEIDG, business address: ul. Bartosza Głowackiego 4/49, 85-614 Bydgoszcz, NIP: 5543046345, REGON: 544580743 (hereinafter: "Administrator").
4. Contact with the Administrator regarding personal data:
- email: tellme@agataterebus.com
- correspondence address: ul. Bartosza Głowackiego 4/49, 85-614 Bydgoszcz
5. The Administrator has not appointed a data protection officer. For all matters concerning the processing of personal data, please contact the Administrator directly.
6. The Administrator takes particular care to protect the interests of the data subjects and, in particular, ensures that data is processed lawfully, collected for specific, legitimate purposes, adequate and limited to what is necessary, accurate, stored no longer than necessary, and secured in a manner appropriate to the risk.
§ 2. SOURCES OF DATA ACQUISITION
1. The Administrator obtains personal data:
a) directly from the data subject – when placing an order, subscribing to the newsletter, contacting via email or phone, and reporting returns or complaints;
b) automatically – in connection with the use of the Store, especially through cookies and similar technologies;
c) from external entities – in particular from payment operators regarding transaction confirmation and from carriers regarding parcel delivery status.
2. Providing personal data is voluntary, however:
a) providing identification, address, and contact data is necessary for the conclusion and performance of the sales contract – without them, order fulfillment is not possible;
b) providing invoice data is necessary for issuing it and results from tax law regulations;
c) providing an email address is necessary to use the newsletter.
§ 3. CATEGORIES OF PROCESSED DATA
1. Identification and contact data: first name and last name, delivery address, billing address, email address, phone number.
2. Invoice data: company name, address, NIP (tax identification number) – if a request to issue an invoice is made.
3. Transaction data: information about ordered products, order value, selected payment and delivery method, order history, returns and complaints, order number, date and status of the transaction.
4. Payment data: information about the payment method and confirmation of its completion. The Administrator does not have access to full payment card numbers or authentication data – these are processed only by the payment operators indicated in § 5.
5. Correspondence data: content of emails, complaint reports, declarations of withdrawal from the contract, and return forms.
6. Technical and activity data: IP address, approximate location determined by IP address, browser type and version, operating system, cookie identifiers, date and time of visit, visited subpages, viewed products, shopping cart content, source of entry to the Store.
7. Marketing data: email address provided when subscribing to the newsletter, consent status, information about delivery, opening, and clicks in sent messages.
8. The Administrator does not process special categories of personal data within the meaning of Article 9 of the GDPR, nor data relating to criminal convictions and offenses.
§ 4. PURPOSES, LEGAL BASES, AND STORAGE PERIODS
1. Conclusion and performance of the sales contract
Scope: identification, contact, address, transactional, payment data.
Purpose: order acceptance and fulfillment, picking and shipping, payment processing, order contact, return handling.
Legal basis: Article 6(1)(b) GDPR – processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Period: for the duration of the contract, and then for the period of limitation of claims arising from the contract, i.e., 6 years from the completion of the order (Article 118 of the Civil Code).
2. Fulfillment of accounting and tax obligations
Scope: identification data, address data, invoice data, transactional data.
Purpose: issuing and storing sales documents, keeping ledgers, tax settlements.
Legal basis: Article 6(1)(c) GDPR in conjunction with the Accounting Act and the Tax Ordinance.
Period: 5 years counting from the end of the calendar year in which the tax payment deadline expired.
3. Processing withdrawals from contracts and complaints
Scope: identification data, contact data, transactional data, correspondence data, photographic documentation.
Purpose: accepting and processing the application, record keeping, return settlement.
Legal basis: Article 6(1)(c) GDPR in conjunction with the Consumer Rights Act.
Period: 6 years from the conclusion of the case.
4. Newsletter and direct marketing via email
Scope: email address, consent status, data on reaction to messages.
Purpose: sending information about new collections, promotions, and events.
Legal basis: Article 6(1)(a) GDPR – consent, in conjunction with Article 10 of the Act on Providing Services by Electronic Means and Article 172 of the Telecommunications Law.
Period: until consent is withdrawn. After withdrawal, the Administrator stores information about the fact and date of granting and withdrawing consent for the period of limitation of claims, to demonstrate the lawfulness of previous processing (Article 7(1) GDPR).
5. Online marketing, analytics, and advertising effectiveness measurement
Scope: technical and activity data, cookie identifiers, encrypted email address and phone number as described in § 7.
Purpose: measuring the effectiveness of advertising activities, displaying ads tailored to interests, analyzing traffic in the Store.
Legal basis: Article 6(1)(a) GDPR – consent expressed via the cookie banner, in conjunction with Article 173 of the Telecommunications Law.
Period: until consent is withdrawn or until the expiration of individual cookies, whichever comes first.
6. Correspondence handling
Scope: contact data, content of correspondence.
Purpose: answering questions and requests not directly related to the concluded contract.
Legal basis: Article 6(1)(f) GDPR – legitimate interest of the Administrator in maintaining communication with individuals interested in the offer.
Period: 1 year from the end of correspondence.
7. Ensuring security and preventing abuse
Scope: transactional data, technical data, IP address.
Purpose: detecting and preventing payment fraud attempts, protecting the Store against unauthorized access, ensuring system integrity.
Legal basis: Article 6(1)(f) GDPR – legitimate interest of the Administrator in protecting against abuse and ensuring transaction security.
Period: 6 years.
8. Establishing, exercising, and defending claims
Scope: all data categories necessary for a given case.
Purpose: possibility of pursuing claims and defending against claims.
Legal basis: Article 6(1)(f) GDPR – legitimate interest of the Administrator.
Period: until the expiration of claim limitation periods, no longer than 6 years.
9. Shopify platform network functions
Scope: transactional data and data on the use of the Store.
Purpose: described in § 8.
Legal basis: Article 6(1)(f) GDPR – legitimate interest in ensuring transaction security and the development and optimization of the Store.
Period: according to the retention rules applied by Shopify.
§ 5. RECIPIENTS OF PERSONAL DATA
1. Store platform provider Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.
Scope: all categories of data processed in the Store.
Role: data processor on behalf of the Administrator, based on a data processing agreement concluded within the terms of use of the platform.
Shopify provides Store hosting, order processing, Shopify Payments payment service, message sending (Shopify Messaging), forms (Shopify Forms), automations (Shopify Flow), translations (Translate & Adapt), visitor location recognition (Geolocation), and customer communication channel (Shopify Inbox).
2. Payment operators
Shopify International Limited (Shopify Payments) – for card payments, BLIK, Apple Pay, Google Pay, and Bancontact.PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg – for PayPal payments.
Scope: identification, contact, transactional, and payment data.
Role: separate data controllers for their respective payment services.
Data processing rules are defined by the privacy policies of these entities.
3. Entities providing delivery services
Furgonetka Sp. z o.o. Sp.k. with its registered office in Warsaw – handling parcel sending and return shipments. In addition to address data, the Furgonetka.pl application gains access to technical data, including IP address, approximate location, and browser and operating system information.
InPost S.A. with its registered office in Krakow – delivery of parcels to parcel lockers and by courier.
DPD Polska Sp. z o.o. with its registered office in Warsaw, DHL Parcel Polska Sp. z o.o. with its registered office in Warsaw, Ruch S.A. (Orlen Paczka) with its registered office in Warsaw – delivery of parcels.
Scope: first name and last name, delivery address, phone number, email address, parcel number.
Role: separate data controllers for the transport services provided.
4. Entities providing marketing services
Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
The scope and principles of cooperation are described in § 7.
5. Accounting services - MK Biuro Rachunkowe Monika Kruszka, ul. Białostocka 2a, 85-860 Bydgoszcz.
Scope: identification data, address data, invoice data, transactional data.
Role: data processor based on a data processing agreement.
6. Public authorities
Data may be disclosed to public authorities if they make a request based on legal provisions. Disclosure takes place only to the extent and for the purpose resulting from such a request.
7. The Administrator has concluded data processing agreements with processing entities that meet the requirements of Article 28 of the GDPR. These entities process data only on the documented instructions of the Administrator and to the extent specified by him.
§ 6. TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA
1. Some entities to whom the Administrator entrusts data belong to capital groups headquartered outside the European Economic Area, particularly in Canada and the United States. This applies in particular to Shopify and Meta.
2. The transfer of data outside the EEA takes place based on:
a) a decision of the European Commission stating an adequate level of data protection in the third country (Article 45 GDPR) – in the case of Canada and entities participating in the EU-US Data Privacy Framework;
b) standard contractual clauses approved by the European Commission (Article 46(2)(c) GDPR) along with additional safeguards.
3. The data subject can obtain a copy of the applied safeguards from the Administrator by sending a request to tellme@agataterebus.com.
§ 7. META MARKETING TOOLS (FACEBOOK AND INSTAGRAM)
1. The Administrator uses advertising tools provided by Meta Platforms Ireland Limited, including Meta Pixel, Advanced Matching, and the Conversions API.
2. Scope of operation of individual tools:
a) Meta Pixel – a piece of code that records user activity in the Store, in particular visited subpages, viewed products, additions to cart, and placed orders;
b) Advanced Matching – transferring a hashed (encrypted) email address and phone number to Meta to link user activity with their account on Meta services;
c) Conversions API – transferring some of this information directly from the Store's server, bypassing the user's browser.
3. Purpose: measuring the effectiveness of advertising campaigns, optimizing their display, and presenting ads tailored to user interests.
4. The legal basis for processing is the user's consent expressed through the cookie banner (Article 6(1)(a) GDPR). Until consent is given, these tools are not activated. Consent can be withdrawn at any time in the manner described in § 9.
5. With regard to data collected through Meta tools, the Administrator and Meta Platforms Ireland Limited are joint controllers of data within the meaning of Article 26 of the GDPR. The principles of this cooperation, including the division of responsibilities for exercising the rights of data subjects, are defined by an agreement available at: https://www.facebook.com/legal/controller_addendum
According to this agreement, Meta is responsible for exercising the rights of data subjects with regard to data processed by Meta after receiving it.
6. Regardless of the rights against the Administrator, the user can restrict the use of data about their activity directly in the account settings on Meta services, in the "Activity Off-Facebook" section.7. The rules for data processing by Meta are defined in the privacy policy of this entity, available on Meta services.
§ 8. SHOPIFY PLATFORM NETWORK FUNCTIONS
1. The Administrator uses Shopify Network Intelligence functions.
2. As part of this function, Shopify uses data regarding transactions and the use of the Store, including data from other stores operating on the Shopify platform, to improve services, detect and prevent fraud, and personalize store functions and advertising tools.
3. Other merchants using the Shopify platform do not gain access to the Administrator's customer data.
4. The legal basis for processing is Article 6(1)(f) GDPR – legitimate interest in ensuring transaction security and the development and optimization of the Store. The Administrator has conducted a balancing test and concluded that this processing does not unjustifiably infringe the rights and freedoms of data subjects, due to the limited scope of data and the lack of its sharing with other merchants.
5. The data subject has the right to object to this processing on the principles set out in § 10.
6. Detailed information about data processing by Shopify is available at https://privacy.shopify.com/pl
§ 9. COOKIES AND SIMILAR TECHNOLOGIES
1. The Store uses cookies, which are small text files stored on the user's end device, and similar technologies.
2. Categories of cookies used:
a) Essential – condition the proper functioning of the Store, including maintaining cart content, sessions, and the order process. They are used based on Article 6(1)(f) GDPR and Article 173(3) of the Telecommunications Law and do not require user consent, as they are necessary to provide the service requested by the user.
b) Personalization – enable remembering user preferences and tailoring presented content.
c) Analytical – enable analysis of how the Store is used to improve it.
d) Marketing – enable presenting ads tailored to user interests and measuring their effectiveness. They include files used by Meta tools described in § 7.
3. Personalization, analytical, and marketing cookies are used only after the user's prior consent has been given via the cookie banner. Until consent is given, the corresponding scripts are not activated.
4. Consent may be withdrawn or amended at any time for individual categories. To do so, please use the "Cookie Settings" link available in the footer of the Store or delete saved cookies in your browser settings – upon your next visit, the banner will be displayed again.
5. The user can also manage cookies from their web browser settings, including blocking their storage. Blocking essential cookies will prevent the use of the shopping cart and placing an order.
6. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
§ 10. RIGHTS OF DATA SUBJECTS
1. Right of access to data (Art. 15 GDPR) – the right to obtain confirmation as to whether data is being processed, to obtain information about the purposes, categories of data, recipients, and storage periods, and to receive a copy of the data.
2. Right to rectification of data (Art. 16 GDPR) – the right to request immediate rectification of inaccurate data and completion of incomplete data.
3. Right to erasure of data (Art. 17 GDPR) – the right to request erasure of data, particularly when they are no longer necessary for the purposes for which they were collected, when consent has been withdrawn, or when an effective objection has been raised. This right does not apply to the extent that processing is necessary for compliance with a legal obligation, particularly accounting and tax obligations, or for the establishment, exercise, or defence of legal claims.
4. Right to restriction of processing (Art. 18 GDPR) – the right to request restriction of processing, particularly for the period of verification of data accuracy or the consideration of an objection raised.
5. Right to data portability (Art. 20 GDPR) – in relation to data processed based on consent or a contract, in an automated manner, the right to receive data in a structured, commonly used and machine-readable format and to request their transmission to another controller.
6. Right to object (Art. 21 GDPR) – the right to object to processing based on the legitimate interests of the Administrator, for reasons relating to the data subject's particular situation. In the case of processing for direct marketing purposes, the objection is unconditional – upon its submission, the Administrator ceases processing data for this purpose.
7. Right to withdraw consent (Art. 7(3) GDPR) – in relation to processing based on consent, particularly for newsletters and cookies. Withdrawing consent is as easy as giving it and does not affect the lawfulness of processing carried out before withdrawal.
8. To exercise the above rights, please contact the Administrator at tellme@agataterebus.com.
9. The Administrator will respond without undue delay, no later than one month after receiving the request. In the case of complex or numerous requests, this period may be extended by another two months, of which the Administrator will inform the requesting person within one month, stating the reasons for the delay.
10. The Administrator may request additional information to confirm the identity of the person making the request if there are reasonable doubts as to their identity (Art. 12(6) GDPR).
11. The exercise of rights is free of charge. In the case of requests that are manifestly unfounded or excessive, the Administrator may charge a reasonable fee or refuse to take action (Art. 12(5) GDPR).
§ 11. COMPLAINT TO THE SUPERVISORY AUTHORITY
1. The data subject has the right to lodge a complaint with the supervisory authority (Art. 77 GDPR):
President of the Personal Data Protection Office
ul. Stawki 2
00-193 Warszawa
uodo.gov.pl
2. A complaint may be filed irrespective of the use of other legal remedies.
3. The Administrator encourages prior direct contact – most matters can be clarified without the involvement of the supervisory authority.
§ 12. AUTOMATED DECISION-MAKING AND PROFILING
1. The Shopify platform performs automated analysis of orders for abuse risk, assigning them a risk indicator based on transactional and technical data.
2. This analysis is purely supplementary. The decision to fulfil or refuse to fulfil an order is always made by the Administrator.
3. In the context of online marketing, data may be subject to profiling involving the matching of displayed advertising content to the user's interests. This profiling is carried out based on consent and does not produce legal effects concerning the user or similarly significantly affect them.
4. The Administrator does not make decisions concerning data subjects based solely on automated processing which would produce legal effects concerning them or similarly significantly affect them, within the meaning of Art. 22(1) GDPR.
§ 13. DATA SECURITY
1. The Administrator applies technical and organizational measures corresponding to the risk associated with data processing, in particular:
a) encryption of data transmission with the SSL/TLS protocol,
b) two-factor authentication for administrative panel access,
c) restriction of data access solely to persons for whom it is essential,
d) regular verification of permissions of applications having access to customer data,
e) use only of providers ensuring an appropriate level of data protection.
2. In the event of a personal data breach, the Administrator reports it to the supervisory authority without undue delay, no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights or freedoms of natural persons (Art. 33 GDPR). If the breach is likely to result in a high risk to the rights or freedoms, the Administrator also notifies the data subjects (Art. 34 GDPR).
3. No security measures completely eliminate the risk associated with transmitting data over the Internet. The Administrator advises against sending particularly sensitive information via unsecured communication channels.
§ 14. CHILDREN'S DATA
1. The Store is not intended for persons under 16 years of age. The Administrator does not knowingly collect personal data of such persons.
2. In accordance with Art. 8 GDPR in conjunction with Art. 5 of the Personal Data Protection Act, in the case of information society services offered directly to a child, the processing of a child's personal data is lawful if the child is at least 16 years old.
3. A parent or legal guardian who finds that a child has provided their personal data to the Administrator may request their deletion by sending an email to tellme@agataterebus.com. The data will be deleted immediately.
§ 15. LINKS TO EXTERNAL SERVICES
1. The Store may contain links to services operated by external entities, particularly to the Administrator's social media profiles.
2. The Administrator is not responsible for the data processing rules applicable in these services. It is recommended to review their privacy policies.
3. The inclusion of a link does not imply acceptance of the content published on the external service.
§ 16. CHANGES TO THE PRIVACY POLICY
1. The Administrator may update this Privacy Policy, particularly in the event of changes in legal regulations, implementation of new tools, or changes in the manner of data processing.
2. The updated version is published on this page along with the effective date.
3. The Administrator will additionally inform about significant changes – by email in the case of newsletter users or by a notice posted in the Store.