Privacy Policy of the KubekUrody.pl online store

Last updated: 16 July 2026

This Privacy Policy explains how personal data is processed and how cookies and similar technologies are used in the online store available at kubekurody.pl.

The rules governing use of the Store, Orders and Electronic Services are set out in the Terms and Conditions.

Table of contents

  1. Data controller
  2. Scope of this Policy
  3. Categories of data
  4. Sources of data
  5. Purposes and legal bases
    1. Website use
    2. Orders
    3. Customer Account
    4. Payments
    5. Delivery
    6. Accounting
    7. Complaints and returns
    8. Contact
    9. Newsletter
    10. Analytics and marketing
    11. Security
    12. Legal claims
    13. Availability notification
    14. Reviews and illegal-content notices
  6. Voluntary provision of data
  7. Recipients
  8. External tools and services
  9. Cookies and similar technologies
  10. Transfers outside the EEA
  11. Retention periods
  12. Data subject rights
  13. Profiling and automated decisions
  14. Security measures
  15. Changes to this Policy

1. Data controller

The controller of personal data processed in connection with the Store is:

Kubek Urody Dominik Hoffmann
ul. Obornicka 8A
62-002 Jelonek, Poland
Tax ID (NIP): 9720967924
Business Registry No. (REGON): 300718188
email: support@kubekurody.pl
tel.: +48 732 448 881

The entity is referred to below as the “Controller” or the “Store”. Questions about data processing and data subject rights may be sent by email or by post to the address above.

Back to the table of contents


2. Scope of this Policy

This Policy applies to processing connected with:

  • use of kubekurody.pl;
  • placing and fulfilling Orders;
  • operating Customer Accounts;
  • payments and delivery;
  • invoices and accounting records;
  • complaints, returns and withdrawal from a Contract;
  • contact with the Store;
  • Newsletter subscriptions using double opt-in;
  • one-time Product availability notifications;
  • publishing, verifying and moderating Product reviews;
  • illegal-content notices and requests for reconsideration;
  • statistics and analysis of Store use;
  • advertising measurement, remarketing and advertising personalisation;
  • optional external resources and widgets;
  • cookies and similar technologies;
  • website and information-system security;
  • establishment, exercise and defence of legal claims.

Back to the table of contents


3. Categories of personal data

Depending on how the Store is used, the Controller may process:

  • name and surname;
  • business name, tax number and invoicing data;
  • residential, registered-office, delivery or correspondence address;
  • email address and telephone number;
  • Order, Product, payment and delivery details;
  • Order history and Account data;
  • complaint, return and withdrawal data;
  • correspondence with the Store;
  • information about consent, confirmation and withdrawal of consent;
  • IP address, event date and time and online identifiers;
  • device, operating system, browser, activity and traffic-source information;
  • email address, Product or variant identifier, Store and language identifiers and an Account identifier connected with an availability notification;
  • review text and rating, submission or publication date, display name or nickname and information needed to link the review to an Order;
  • review moderation status and the reason for rejection, restriction or removal;
  • data contained in an illegal-content notice, including the reporting person's contact details, reasons, content location, statement and subsequent correspondence.

The Controller does not request special categories of data, such as health data, political opinions, religious beliefs or racial or ethnic origin. Such data should not be included in forms, reviews or messages unless necessary, lawful and agreed with the Controller in advance.

Back to the table of contents


4. Sources of personal data

Data is obtained primarily from the individual when placing an Order, creating an Account, contacting the Store, making a complaint, subscribing to the Newsletter, requesting an availability notification, submitting a review, reporting content or selecting cookie settings.

Technical data may be collected automatically through server logs, cookies, local storage, pixels, tags and similar technologies.

Where an ordering person provides another person's data, for example a delivery recipient, the ordering person is the source. They should have a lawful basis for providing that data and inform the recipient that the data has been provided to the Controller.

Back to the table of contents


5. Purposes and legal bases for processing

5.1. Website use

Technical data may be processed to display the website, maintain a session, operate the Cart, login, forms, privacy settings and caching, detect errors and ensure security.

The legal basis is, as applicable:

  • Article 6(1)(b) GDPR – performance of a service requested by the user;
  • Article 6(1)(f) GDPR – proper and secure operation of the Store;
  • Article 399(3) of the Polish Electronic Communications Law – technologies strictly necessary for transmission or for a service expressly requested by the user.

5.2. Placing and fulfilling Orders

Data is processed to receive an Order, enter into and perform the sales Contract, prepare the shipment, communicate about the Order and document performance. The legal basis is Article 6(1)(b) GDPR.

5.3. Customer Account

Data is processed to create the Account immediately after successful registration, operate it, enable login, manage Account data and provide Order history. The legal basis is Article 6(1)(b) GDPR.

Deleting an Account does not erase data that must be retained by law or is required for Orders, complaints or the establishment, exercise or defence of claims.

5.4. Payments

Data is processed to enable and settle payments under Article 6(1)(b) GDPR. Where Przelewy24 is selected, necessary data may be provided to PayPro S.A., which may act as a separate controller. The Store does not receive full card or online-banking login data.

5.5. Delivery

Recipient data is processed to deliver an Order under Article 6(1)(b) GDPR and may be provided to a courier, postal operator, delivery broker or collection-point operator.

5.6. Tax and accounting records

Order, invoice and payment data is processed to meet tax, accounting and record-keeping obligations under Article 6(1)(c) GDPR.

5.7. Complaints, returns and withdrawal

Data is processed to handle and document a case and refund payments on the basis of:

  • Article 6(1)(b) GDPR – performance of the Contract;
  • Article 6(1)(c) GDPR – compliance with legal obligations;
  • Article 6(1)(f) GDPR – documentation and protection against claims.

5.8. Contact with the Store

Data sent by email, telephone or a form is processed to respond and conduct correspondence. The legal basis is Article 6(1)(b) GDPR where the communication concerns a Contract and Article 6(1)(f) GDPR in other cases.

5.9. Newsletter and direct marketing

The email address and information about consent and its confirmation are processed to send a Newsletter concerning Products, promotions, guidance and the Controller's activities. The legal basis is Article 6(1)(a) GDPR.

Commercial communications and direct marketing by email are sent only with the consent required by Article 398 of the Polish Electronic Communications Law.

The Store uses double opt-in. After the form is submitted, the system sends a technical message containing an activation link. The Newsletter becomes active only after the link is clicked. Without confirmation, the address is not used to send the Newsletter.

Data relating to an unconfirmed request is used only to complete verification, prevent an unauthorised subscription of another person's address and document the form's operation, and is deleted when confirmation does not occur and retention is no longer necessary.

Subscription is voluntary and is not a condition of an Account or Order. Consent may be withdrawn through the unsubscribe link or by contacting sklep@kubekurody.pl.

5.10. Analytics and online marketing

After appropriate consent, technical and activity data may be used to:

  • prepare statistics and analyse Store use;
  • identify usability issues;
  • measure conversions and campaign effectiveness;
  • create audiences and conduct remarketing;
  • personalise advertising based on likely interests.

The legal basis is Article 6(1)(a) GDPR and, for storing or accessing information on the device, consent under Article 399 of the Polish Electronic Communications Law.

5.11. Security and abuse prevention

Technical data may be used to protect Accounts, forms, sessions, payments and infrastructure, and to detect bots, fraud, attacks, errors and unauthorised access. The legal basis is Article 6(1)(b) or Article 6(1)(f) GDPR, as applicable.

5.12. Establishment, exercise and defence of legal claims

Data may be processed to protect the Controller's rights, document compliance and defend against unjustified claims under Article 6(1)(f) GDPR.

5.13. Product availability notification

A user may provide an email address to receive one message when a selected Product or variant becomes available again.

The Controller may process:

  • the email address;
  • the Product or variant identifier;
  • technical Store and language identifiers;
  • the Account identifier where the request was made by a logged-in Customer.

Data is used to register and maintain the request, identify availability, send the message, handle cancellation and document performance. The legal basis is Article 6(1)(b) GDPR.

Requesting a notification does not subscribe the user to the Newsletter and is not consent to other marketing. The system does not send a separate email confirming registration.

When delivery of the availability message is initiated, the active request for the Product or variant is deleted. It may be cancelled earlier by emailing sklep@kubekurody.pl and providing the email address used and the Product name, variant or Product page link.

An active request is retained until delivery, earlier cancellation, permanent withdrawal of the Product, discontinuation of the service or another cessation of the purpose. Limited information may be retained longer only where required for legal claims or legal obligations.

5.14. Reviews and illegal-content notices

A Customer who purchased a Product may submit a review. The Controller may process the review, rating, publication details and information needed to link it to the relevant Order.

Data is processed to:

  • receive, verify and publish the review;
  • confirm that it was submitted by a purchaser;
  • moderate content that breaches the law or the Terms and Conditions;
  • prevent spam, false reviews and other abuse;
  • handle removal and reconsideration requests;
  • establish, exercise and defend legal claims.

The legal basis is:

  • Article 6(1)(b) GDPR – the requested Electronic Service of receiving and publishing a review;
  • Article 6(1)(f) GDPR – review reliability, moderation, abuse prevention and legal claims.

The review text, rating, publication date and the name or nickname selected for publication may be publicly available. The email address, Order number and verification data are not published.

Any person may report content considered illegal. The Controller may process contact details, the reasons for the notice, content location, the reporting person's statement and correspondence concerning the decision and reconsideration.

The legal basis is Article 6(1)(c) GDPR to the extent necessary to comply with the Digital Services Act and Article 6(1)(f) GDPR for documentation, protection of the parties' rights and legal claims.

The reporting person's data is not published. It may be disclosed to the content author, an authority or another entitled recipient only where required by law or necessary for fair handling of the matter, taking account of the rights of the persons concerned.

Back to the table of contents


6. Voluntary provision of data

Providing data is voluntary, although particular data is necessary for a selected action, including a Contract, delivery, invoice, complaint, Account, Newsletter, availability notification or publication of a review.

Consent is voluntary for:

  • the Newsletter and direct marketing;
  • analytics;
  • advertising personalisation;
  • website personalisation;
  • other optional technologies listed in the SEIGI Cookie panel.

Refusing or withdrawing optional consent does not prevent use of core Store functions or Orders. Some optional fonts or widgets may not be displayed.

Back to the table of contents


7. Recipients of personal data

Data may be provided where necessary to:

  • hosting, server, backup and email providers;
  • IT, maintenance and software-development providers;
  • software, Store-module and Newsletter-system providers;
  • PayPro S.A., banks and other payment operators;
  • couriers, postal operators, delivery brokers and collection points;
  • accountants, tax advisers and legal advisers;
  • the SEIGI Cookie provider;
  • Google Ireland Limited and relevant Google group entities;
  • Meta Platforms Ireland Limited and relevant Meta group entities;
  • Microsoft Ireland Operations Limited and relevant Microsoft group entities;
  • public authorities and other recipients authorised by law.

Recipients may act as processors, separate controllers or, in a defined scope, joint controllers. PrestaShop software installed on the Store's server is not itself a recipient, although a hosting, module or external-service provider may be one.

For a published review, its text, rating, date and selected display name or nickname are available to internet users. Email addresses, Order numbers and verification data are not published.

Back to the table of contents


8. External tools and services

8.1. SEIGI Cookie

SEIGI Cookie displays the consent panel, records the user's choice and conditionally activates optional technologies. The choice may be stored in the necessary seigi_cookie, which may contain accepted categories, configuration version, date and a technical identifier.

8.2. Google tag and basic Consent Mode

Google tag or Google Tag Manager may technically manage tags. The Store uses basic Consent Mode: optional Google, Meta and Microsoft tags are blocked until consent for the relevant category.

8.3. Google Analytics 4

After consent to “Analytics”, the Store may activate Google Analytics 4 provided by Google Ireland Limited. It prepares statistics about visits, traffic sources, pages, devices and events. Online identifiers, device data, traffic source, approximate location and activity may be processed. The Controller does not intentionally transmit names, emails, phone numbers or full addresses.

Under the Controller's settings, event data is retained for 2 months and user data for 14 months. These settings may not apply to standard aggregated reports.

8.4. Microsoft Clarity

After consent to “Analytics”, the Store may activate Microsoft Clarity. It provides click and scroll maps and session reconstructions. A reconstruction is not a camera recording but a representation of interactions with the website.

Available form-masking functions are used. Standard playback data is generally retained for 30 days, while heatmap data and sessions labelled, saved or otherwise retained by the service may be kept for up to 9 months under Microsoft's current rules.

8.5. Google Ads

After consent to “Advertising personalisation”, Google Ads may measure conversions and campaign effectiveness, create audiences and conduct remarketing. Events may include Product views, adding a Product to the Cart, starting checkout and completing a purchase.

8.6. Meta Pixel

After consent to “Advertising personalisation”, Meta Pixel may measure advertising effectiveness, record conversions, optimise campaigns and create audiences. For collection and transmission of events, the Controller and Meta Platforms Ireland Limited may be joint controllers; Meta may then process received data as a separate controller.

8.7. Microsoft Advertising and UET

After consent to “Advertising personalisation”, Microsoft Advertising, including UET, may record website actions, measure conversions, create remarketing lists and optimise campaigns.

8.8. Google Fonts

After consent to “Website personalisation”, the browser may download Google Fonts from Google servers, transmitting technical data such as the IP address, device information and connection time. Without consent, substitute fonts are used and the ability to place an Order is unaffected.

8.9. Google Merchant Store Quality Widget

The home page may display an optional Google Merchant store-quality widget showing a Store rating, review count or service-quality information. It is activated only after consent to both “Website personalisation” and “Analytics”. Refusal does not affect core Store functions.

8.10. LiteSpeed Cache and lsc_private

LiteSpeed Cache improves website speed and stability. It may create the necessary lsc_private cookie for private caching and delivery of the correct page version. It is not used for analytics, advertising or profiling. Its current duration is shown in the SEIGI Cookie panel and depends on server configuration.

Back to the table of contents


9. Cookies and similar technologies

9.1. What cookies are

Cookies are small files stored on a user's device. The Store may also use local storage, pixels, scripts, online identifiers and tracking tags.

9.2. Technology categories

  • Necessary – session, Cart, login, Order, consent settings, caching and core security.
  • Analytics – statistics and website-use analysis, including GA4, Clarity and the analytical part of the widget.
  • Advertising personalisation – conversions, remarketing and audiences, including Google Ads, Meta Pixel and Microsoft UET.
  • Website personalisation – optional external resources, including Google Fonts and the functional part of the widget.
  • Security – protection of Accounts, forms, sessions, payments and infrastructure.

9.3. Consent management

On the first visit, SEIGI Cookie allows the user to accept, reject or individually choose optional categories. Inaction is not consent. Consent may be changed or withdrawn at any time in the panel, as easily as it was given, without affecting the lawfulness of earlier processing.

Cookies may also be blocked or deleted in browser settings. Blocking necessary technologies may disrupt the Cart, login, payments or other core functions.

9.4. Examples of necessary cookies

Name Purpose Category
seigi_cookie Records the category choice, date and consent version. Necessary
lsc_private Private caching and delivery of the correct page version. Necessary

The current list of providers, purposes and durations is available in the SEIGI Cookie panel.

Back to the table of contents


10. Transfers outside the European Economic Area

In connection with Google, Meta and Microsoft services, data may be transferred outside the EEA, including to the United States. A transfer may rely on:

  • a European Commission adequacy decision, including the EU–US Data Privacy Framework where the recipient holds a valid certification covering the relevant processing;
  • European Commission Standard Contractual Clauses;
  • Binding Corporate Rules;
  • another mechanism under Chapter V GDPR.

Additional technical and organisational safeguards are applied where required.

Back to the table of contents


11. Retention periods

Data is retained no longer than necessary for the relevant purpose:

  • Order data – during performance and then for statutory and limitation periods;
  • tax and accounting records – generally for 5 years calculated under the applicable rules;
  • Account data – until deletion or discontinuation, subject to legal obligations and claims;
  • complaints and returns – during the case and then for the relevant limitation periods;
  • correspondence – until completion and for a period justified by possible claims;
  • active Newsletter data – until consent is withdrawn, unsubscribe or discontinuation;
  • unconfirmed double-opt-in data – until confirmation or deletion after verification is no longer necessary;
  • evidence of consent and withdrawal – until the relevant liability or limitation period expires;
  • availability notifications – until delivery, cancellation, permanent Product withdrawal or discontinuation;
  • reviews – while published and then for moderation documentation and legal claims;
  • illegal-content notices and reconsideration – until completion and then to demonstrate compliance and protect against claims;
  • GA4 and Clarity data – according to the periods described for the relevant tool;
  • security logs – for the period necessary to ensure security and investigate events.

After the relevant period, data is erased, anonymised or permanently restricted unless further retention is required by law.

Back to the table of contents


12. Data subject rights

Subject to the conditions in the GDPR, an individual may have the right to:

  • access data and receive a copy;
  • rectify and complete data;
  • erase data;
  • restrict processing;
  • data portability;
  • object to processing;
  • object to direct marketing;
  • withdraw consent;
  • lodge a complaint with the President of the Polish Personal Data Protection Office;
  • rights concerning decisions based solely on automated processing.

The right to erasure is not absolute. Data may continue to be retained to comply with a legal obligation, establish, exercise or defend claims or in other cases under Article 17(3) GDPR.

An objection to processing under Article 6(1)(f) GDPR may be made for reasons relating to a person's particular situation. Following an objection to direct marketing, data is no longer processed for that purpose.

Requests may be sent to support@kubekurody.pl or by post. The Controller may request information needed to verify identity. A response is provided without undue delay, normally within one month; the period may be extended by two months where permitted by GDPR.

Back to the table of contents


13. Profiling and automated decisions

After consent to advertising personalisation, data about visited pages and Products, the Cart, purchases, traffic source, advertising interactions and the device may be used for marketing profiling. This may result in more relevant advertisements in Google, Meta or Microsoft services.

Profiling does not automatically enter into or refuse a Contract and does not restrict the ability to purchase. The Controller does not make decisions concerning Customers based solely on automated processing that produce legal or similarly significant effects.

Back to the table of contents


14. Security measures

The Controller applies measures appropriate to the data and risk, including:

  • SSL/TLS transmission encryption;
  • server and system safeguards;
  • access restrictions and control;
  • individual permissions;
  • backups;
  • software and module updates;
  • monitoring of errors and security events;
  • data-processing agreements where required.

Access is provided only to persons and entities that need it. No transmission or storage method removes every risk, and safeguards are adjusted to current risk and available technology.

Back to the table of contents


15. Changes to this Privacy Policy

This Policy may be updated due to:

  • changes in law, business operations or processing;
  • new or discontinued functionality;
  • changes in providers, tools, cookies or consent settings;
  • clarifications or correction of errors.

The current version is published with its update date. Where a change concerns a material new form of processing, the Controller provides appropriate information before processing begins where required. Where new processing requires consent, new consent is obtained; publication of an amended Policy does not replace consent.

In the event of a discrepancy between the Polish and English versions, the Polish version is authoritative, subject to mandatory data-subject rights.

Back to the table of contents

Loading...
Back to top