OFFLY STORE PRIVACY AND COOKIE POLICY offly.store | orders | Stripe | Supabase | delivery | Custom | newsletter
Version 1.0 | effective 27 August 2026
Controller: Szymon Bocianowski, Aleja Jerzego Waszyngtona 57, 04-074 Warsaw, Poland support@offly.store | +48 511 318 352
§ 1. Data controller
The controller of personal data processed in connection with offly.store is Szymon Bocianowski at the address above (“Offly” or the “Controller”). Offly is currently operated by an individual who intends to register a business after exceeding the threshold under the Polish Entrepreneurs’ Law. After registration, the same individual will remain the controller and the identification details will be updated. Privacy enquiries and requests may be sent to support@offly.store. No data protection officer has been appointed because Offly has not identified a legal obligation to do so at this stage.
§ 2. Scope
This Policy covers the website and shop, ordering, payment, delivery, Custom products, complaints, contact, newsletters, website security, cookies and similar technologies. The Offly mobile app has a separate App Privacy Policy covering accounts, system functions, NFC, app data and Supabase. Both policies may apply where the same information is processed by the Shop and the App. Third-party services, including Stripe, carriers and infrastructure providers, may also apply their own privacy notices when acting as separate controllers.
§ 3. Data we collect
Order data: name, delivery and—where required—billing address, email, telephone number, selected product and variant, quantity, price, order status, delivery method and fulfilment details.
Payment data: transaction identifier, amount, currency, payment status and limited technical data from the payment provider. Offly normally does not receive the full card number or CVV.
Custom data: text, graphics, photographs, files, instructions or other specifications submitted for personalisation, including personal data of the customer or third parties if included by the customer.
Contact and complaint data: correspondence, order number, product photos or recordings, problem details and other information needed to handle the matter.
Newsletter data: email address, optional name, date and source of consent, withdrawal records and basic sending data.
Technical data: IP address, timestamps, browser and device details, security logs, session identifiers, cookies and similar technologies. Tax and accounting data are processed when required for sales documents and statutory duties.
§ 4. Purposes and legal bases
Orders, delivery and contract-related contact are processed to perform or take steps toward a contract under Article 6(1)(b) GDPR. Custom materials are processed on the same basis. Tax, accounting and statutory records are processed under Article 6(1)(c). Complaints, after-sales support and claims are processed under Article 6(1)(b), (c) or (f), depending on the stage. Shop and transaction security, fraud prevention and evidence are based on Offly’s legitimate interests under Article 6(1)(f). Newsletters and electronic marketing use consent under Article 6(1)(a) GDPR and Article 398 of the Polish Electronic Communications Law. Non-essential analytical or marketing cookies are used only with consent under Article 399 of that Law and, for personal data, Article 6(1)(a) GDPR.
Offly’s legitimate interests include securing the Shop and transactions, preventing abuse, retaining evidence and establishing, pursuing or defending claims. Offly assesses whether those interests are overridden by the rights of the data subject.
§ 5. Stripe payments
The Shop may use Stripe. In Europe, the relevant Stripe entities, including Stripe Payments Europe, Limited, participate depending on the service and processing role. Stripe may process data on Offly’s instructions for transaction handling and may act as a separate or joint controller for certain regulatory, security, fraud-prevention or payment-service purposes. Data sent to Stripe may include identification and contact data, address, IP address, transaction data and payment-instrument information required to make the payment. Stripe may use automated fraud and risk controls. Offly does not itself make decisions producing legal effects for the customer solely by automated means on that basis unless it expressly informs customers of such a process in the future.
§ 6. Supabase backend
Offly uses Supabase for backend infrastructure. Depending on the actual configuration, Supabase may store order and customer data, transaction statuses, technical information, consent records, form data and other Shop data. Supabase acts as processor for data stored in the Offly project and offers a data processing agreement and project-region selection. If processing involves a transfer outside the EEA, safeguards required by the GDPR are used, such as an adequacy decision, the EU–US Data Privacy Framework where available, or Standard Contractual Clauses.
§ 7. Recipients
Data may be disclosed, only as necessary, to postal, courier and logistics providers; Stripe and other payment providers; Supabase; hosting, domain, email, security, form and communications providers; newsletter providers if used; accountants and legal or tax advisers; and public authorities where disclosure is required by law. Offly does not sell customer personal data as a commodity or marketing database.
§ 8. Custom personalisation materials
Custom materials are used to fulfil the specific order and perform related production work. Customers should not submit special-category data, identity documents or other sensitive information unless strictly necessary. If a project includes a third party’s data, image or work, the customer must be entitled to submit and use it. Offly processes it only as needed for personalisation. Custom materials are not used in a public portfolio, advertising or AI model training without a separate legal basis or consent where required.
§ 9. Newsletter and marketing
Newsletter sign-up is voluntary and is not required to place an order. After consent, Offly may send information about products, advice, launches and special offers within the scope shown when consent was obtained. Consent may be withdrawn at any time through an unsubscribe link or by contacting support@offly.store. Withdrawal does not affect processing carried out before withdrawal. Offly may retain a minimal suppression and evidence record to demonstrate the consent history and prevent further messages without a legal basis.
§ 10. Cookies and similar technologies
The Shop may use cookies, local storage and similar technologies. Strictly necessary technologies may operate without consent where required to transmit or provide a service requested by the user, including session, security and payment functions. Analytical, advertising and other non-essential technologies are activated only after consent where legally required. Users must be able to reject non-essential cookies and later change their choice without losing basic Shop access. Retention depends on the technology and configuration and may be shown in the consent panel. Browser settings may also delete or restrict cookies, which can require the user to choose preferences again.
§ 11. Retention
Contract and order data are retained while the contract is performed and until relevant claims and archiving periods expire. Tax and accounting documents are retained for the statutory period. Complaints and correspondence are kept until the matter ends and then for the period needed for claims. Custom materials are kept for fulfilment and possible complaints or claims, and longer only where another legal basis or customer request applies. Newsletter data are kept until consent is withdrawn, with a minimal evidence/suppression record afterwards. Security logs are retained for a period justified by Shop protection and incident detection. Cookies remain for the period stated in the cookie panel or until deleted. Limited copies may remain temporarily in access-controlled, rotating backups.
§ 12. Transfers outside the EEA
Some technology providers or subcontractors may process data outside the EEA. Offly requires safeguards appropriate to the transfer, including European Commission adequacy decisions, the EU–US Data Privacy Framework or Standard Contractual Clauses with supplementary measures where needed. A selected Supabase data region does not by itself guarantee that no subcontractor has access from outside the EEA; Stripe also uses global infrastructure and transfer safeguards.
§ 13. Your rights
Subject to the statutory conditions, you may request access and a copy, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier processing and lodge a complaint with the President of the Polish Personal Data Protection Office or another competent supervisory authority. Send requests to support@offly.store. Offly may request information reasonably needed to verify identity and protect the data.
§ 14. Whether data are required
Fields marked as required during ordering are necessary to enter into or perform the contract; without them fulfilment or delivery may be impossible. Invoice data are required only by law or at the customer’s request. Newsletter data are voluntary. A customer may choose a standard product instead of Custom, but after choosing Custom the specification needed to personalise it is required to fulfil that order.
§ 15. Security
Offly applies technical and organisational measures appropriate to risk, including access controls, secure connections, least-privilege access and provider security features. No IT system is absolutely secure. If a personal-data breach occurs, Offly will take the steps required by the GDPR, including notification to the authority or affected person where statutory conditions are met.
§ 16. Changes
This Policy may be updated following changes to law, technology providers, payments, cookies, Supabase configuration or Shop data. The current version and effective date are published at offly.store. Where a change requires fresh consent, Offly will obtain it before the relevant processing starts. This Policy is effective from 27 August 2026.
CHECKOUT NOTICE
Your data in the Offly store: the controller is Szymon Bocianowski, Aleja Jerzego Waszyngtona 57, 04-074 Warsaw. We use order data for fulfilment, payment and delivery. Stripe may process payments and Shop data may be stored in Supabase. We send newsletters only with voluntary consent. This full Policy explains recipients, retention, transfers outside the EEA and your rights. Contact: support@offly.store.