PRIVACY POLICY
1. GENERAL INFORMATION
This Privacy Policy sets out the principles for processing and protecting personal data provided by Users in connection with their use of the maracatu.pl online store.
The controller of personal data contained in the service is SMARTLINE GROUP SP. Z O.O. with its registered office in Warsaw, at ul. Konduktorska 18, lok. 7, 00-775 Warsaw, NIP: 5214078410, REGON: 529198047, entered in the National Court Register under KRS number: 0001117189.
The Controller can be contacted:
- by email: biuro@maracatu.pl
- in writing to the address: ul. Konduktorska 18, lok. 7, 00-775 Warsaw
The Controller takes special care to protect the interests of the data subjects and ensures, in particular, that the data it collects is:
- processed in accordance with the law,
- collected for specified, legitimate purposes and not subject to further processing incompatible with these purposes,
- substantively correct and adequate in relation to the purposes for which they are processed,
- stored in a form allowing identification of the persons to whom they relate, no longer than necessary to achieve the purpose of processing.
2. PURPOSE AND SCOPE OF DATA COLLECTION
The personal data of Users are processed by the Controller for the purpose of:
- Execution of orders and sales contracts for products offered in the maracatu.pl store
- Providing information about products, services, and offers
- Handling complaints and contract withdrawals
- Issuing sales documents (invoices, receipts)
- Maintaining sales statistics and online store visit statistics
- Managing the user account in the online store
- Contacting the User, including for purposes related to permitted marketing activities
- Monitoring User activity to improve store functionality
The Controller processes the following personal data of Users:
- First and last name
- Email address
- Contact phone number
- Delivery address (street, house/apartment number, postal code, city, country)
- Residence/business/headquarters address (if different from the delivery address)
- Tax identification number (NIP) - in case of issuing a VAT invoice
- Data on viewed products and content
- Purchase history
- Information about the device and web browser
Providing personal data is voluntary but necessary for the provision of services by the Controller through the maracatu.pl store. Failure to provide the required personal data will prevent the provision of services by the Controller.
3. LEGAL BASIS FOR PERSONAL DATA PROCESSING
The processing of personal data by the Controller is based on:
- Art. 6(1)(b) GDPR - processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject prior to entering into a contract
- Art. 6(1)(c) GDPR - processing is necessary for compliance with a legal obligation to which the controller is subject (e.g., tax obligations, archiving)
- Art. 6(1)(f) GDPR - processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party
- Art. 6(1)(a) GDPR - the data subject has given consent to the processing of their personal data for one or more specific purposes (e.g., newsletter, direct marketing)
4. PERIOD OF PERSONAL DATA PROCESSING
The Controller stores personal data for the period necessary to achieve the individual purposes of processing, i.e.:
- In the case of contract performance - for the duration of the contract and the limitation period for claims related to the contract
- In the case of fulfilling legal obligations - for the period required by law
- In the case of processing data based on the legitimate interest of the Controller - until the existence of this interest or submission of an effective objection
- In the case of processing data based on consent - until its withdrawal
5. SHARING PERSONAL DATA
The Controller may share Users' personal data with the following entities:
- Transport/courier service providers carrying out order deliveries
- Payment service providers, including Przelewy24 (PayPro SA)
- Providers of IT, hosting, and analytical tools
- Providers of accounting and legal services
- Providers of marketing services
- Entities authorized to receive them under the provisions of law (e.g., state authorities)
6. COOKIES AND OTHER TRACKING TECHNOLOGIES
The maracatu.pl online store uses cookies and other tracking technologies to adapt the content of websites to user preferences and optimize the use of websites.
6.1 Types of cookies used:
- Necessary cookies - cookies that are essential for the proper functioning of the online store. This type of cookies allows navigation around the site and use of its features. The legal basis for these cookies is Art. 6(1)(f) GDPR.
- Analytical/performance cookies - cookies that collect information about how Users use the website, e.g., which subpages are most frequently visited and whether error messages appear on certain pages. The legal basis for these cookies is Art. 6(1)(a) GDPR.
- Functional cookies - cookies that allow "remembering" the settings selected by the User and personalizing the interface, e.g., in terms of the selected language or region from which the User comes. The legal basis for these cookies is Art. 6(1)(a) GDPR.
- Advertising cookies - cookies that enable delivering advertising content to Users that is more suited to their interests. The legal basis for these cookies is Art. 6(1)(a) GDPR.
6.2 Cookie management tools
The maracatu.pl store uses a cookie consent management system provided by Cookie Script (https://cookie-script.com/). This system allows Users to express consent to the use of certain types of cookies and withdraw such consent at any time.
The User can change their cookie preferences at any time by clicking on the "Cookie settings" button available in the footer of the website.
Additionally, most internet browsers allow you to control cookies through browser settings. Detailed information on deleting, blocking, or limiting cookies can be found in the settings of the internet browser used by the User.
6.3 Analytical and marketing tools
To analyze traffic on the site and conduct marketing activities, the Controller uses the following tools:
- Google Analytics - an analytical tool provided by Google LLC that helps measure traffic on the website and analyze User behavior.
- Google Ads - an advertising platform provided by Google LLC that allows displaying ads in the Google search engine and the Google advertising network.
- Facebook Pixel - an analytical tool provided by Meta Platforms, Inc. that helps measure the effectiveness of ads on the Facebook platform and target ads to the appropriate audience.
- TikTok Pixel - an analytical tool provided by TikTok Inc. that helps measure the effectiveness of ads on the TikTok platform and target ads to the appropriate audience.
The above tools may use cookies and other tracking technologies. Data collected by these tools may be transferred to the providers of these tools.
7. USER RIGHTS
The User has the following rights related to the processing of their personal data:
- Right of access to personal data
- Right to rectification of personal data
- Right to erasure of personal data ("right to be forgotten")
- Right to restriction of processing of personal data
- Right to data portability
- Right to object to the processing of personal data
- Right to withdraw consent to the processing of personal data (if processing is based on consent)
- Right to lodge a complaint with a supervisory authority - the President of the Office for Personal Data Protection
To exercise the above rights, please contact the Controller via email at: biuro@maracatu.pl or in writing to the address of the Controller's headquarters.
8. TRANSFER OF DATA OUTSIDE THE EEA
The Controller, as part of using analytical and marketing tools, may transfer Users' personal data to recipients located in countries outside the European Economic Area (EEA), in particular to the United States. The Controller ensures that in such a case, the transfer of data will take place on the basis of appropriate legal safeguards, which are the standard contractual clauses for the protection of personal data, approved by the European Commission.
9. SECURITY OF PERSONAL DATA
The Controller applies technical and organizational measures to ensure the protection of processed personal data appropriate to the risks and categories of data protected, and in particular protects data against disclosure to unauthorized persons, taking by an unauthorized person, processing in violation of applicable regulations, and change, loss, damage, or destruction.
The maracatu.pl store uses a secure data transmission protocol (SSL), which additionally secures communication with the site.
10. CHANGES TO THE PRIVACY POLICY
The Controller reserves the right to change this Privacy Policy. Changes to the Privacy Policy will be published on the maracatu.pl online store website. The amended Privacy Policy comes into effect upon its publication on the online store website.
Date of last update: 01.03.2025