Privacy Policy
We care about your privacy. Below we explain what data we process, for what purposes and on what legal basis. We also inform you of the rights you have as a consumer. The rules for using our store are described in our Terms of Service.
1. Who is the controller of your data?
The controller of your personal data is:
FIRMA JUBILERSKA FROART S.C. ERWIN FRONT, ANDRZEJ FRONT
ul. Gołębia 10, 31-007 Kraków, Poland
Tax ID (NIP) 6790044235 · REGON 350206437
Email: froart@froart.com
Phone: +48 603 351 676
We have not appointed a Data Protection Officer. If you have questions about personal data, please contact us at froart@froart.com.
2. What data do we collect?
Depending on how you use our store, we process different data:
- Data provided when placing an order — first name, last name, delivery address, email, phone number, delivery and payment method details, and tax ID (NIP) if you request an invoice.
- Payment-related data — transaction number, payment identifier, payment status, data provided by payment operators. We do not process full payment card details.
- Customer account data — login, email, order history, saved delivery addresses, account settings.
- Contact form data — name, email, message content, data arising from further correspondence.
- Newsletter data — email address, consent confirmation, marketing preferences.
- Complaint data — information about product defects and the customer's request.
- Technical data — IP address, date and time of connection, device, browser and operating system information, cookie identifiers.
- Analytics and marketing data — pages visited, time on site, clicks, device data, campaign effectiveness. We process this only after consent via the cookie banner; tools (e.g. Google Analytics, Meta Pixel) are installed via Admin → Customer events, not directly in the theme.
- Server log data — IP address, server date and time, URL, error information.
We obtain data directly from you (e.g. when placing an order, creating an account, subscribing to the newsletter, or contacting us). We obtain technical and analytics data automatically when you use the site (cookies, pixels, server logs).
Providing data is voluntary but necessary to place an order, create an account, or receive the newsletter. If you do not provide this data, we will not be able to fulfil your order or provide the selected services.
3. For what purposes and on what legal basis do we process data?
| Processing purpose | Data scope | Legal basis | Retention period |
|---|---|---|---|
| Access to the store | IP address | Art. 6(1)(f) GDPR | 3 years from last visit |
| Account creation and login | IP address, email, first and last name | Art. 6(1)(b) GDPR | Until account deletion or 3 years from last login |
| Purchase of goods | Email, first and last name, phone number, delivery address | Art. 6(1)(b) GDPR | For the period necessary to perform the contract and handle the order; data related to pursuing claims may be retained until civil limitation periods expire (up to 6 years from purchase — Polish Civil Code Art. 118), separately from accounting obligations |
| Email contact | Email, first and last name, data voluntarily provided in the message | Art. 6(1)(f) GDPR | 24 months from end of correspondence, unless law requires longer retention |
| Phone contact | Phone number, first and last name, data voluntarily provided during the call | Art. 6(1)(f) GDPR | 12 months from end of call |
| Accounting documents | First and last name, address, bank account number, business data | Art. 6(1)(c) GDPR | 5 years from end of tax year (Polish Tax Ordinance) |
| Store traffic analysis | IP address, cookies | Art. 6(1)(a) GDPR | Until data is no longer useful or consent is withdrawn |
| Newsletter | Email address | Art. 6(1)(a) GDPR (consent) | Until newsletter unsubscribe or 3 years from last activity |
| Social media profiles | First name, last name, profile identifier, voluntary data | Art. 6(1)(f) GDPR | Until comment/profile deletion or objection is raised |
| Complaint handling | First name, last name, email, phone | Art. 6(1)(f) GDPR | Until limitation periods for claims arising from lack of conformity expire, and for the period necessary to pursue or defend claims |
| Security and error diagnostics | IP address, server date and time, URL, error information | Art. 6(1)(f) GDPR | Maximum 30 days |
We do not make any automated decisions about you and do not apply profiling within the meaning of Art. 22 GDPR.
3.1. Data archiving
We process data for the periods indicated in the table above. After those periods, data may be stored additionally for:
- securing claims,
- documenting service performance,
- meeting tax and accounting obligations.
Correspondence may be archived for up to 5 years, unless law requires a longer period.
3.2. Marketing profiling
We do not make automated decisions that produce legal effects concerning you. However, we may carry out marketing profiling (e.g. ad targeting) if you consent via the cookie banner. Profiling is based on analysis of your activity on the site.
4. Data recipients
We share your data only with entities necessary to process orders, operate the store, and provide our services:
- Shopify — store hosting, order and customer account processing (processor).
- Courier companies — to deliver orders (they receive only data necessary for delivery).
- PayPro S.A. (Przelewy24) — ul. Pastelowa 8, 60-198 Poznań, KRS 0000347935, NIP 7792369887, REGON 301345068. Processes data necessary to execute the payment (independent controller for the payment service). We do not store full payment card details.
- Accounting office — for bookkeeping and settlements.
- IT service providers — store maintenance and technical support (to the extent necessary to operate the Store).
- Google and Meta — only after consent via the cookie banner, for analytics and marketing installed via Admin → Customer events (they may process data outside the EEA).
- Law firms — when necessary to pursue or defend against claims.
Data may also be disclosed to authorised public authorities under applicable law (e.g. police, courts, tax authorities).
Every entity to which we entrust data ensures an appropriate level of security and confidentiality. Data is not shared with unauthorised persons or entities.
5. Is data transferred outside the European Union?
Yes. When using Google and Meta tools activated after consent, your data may be transferred to third countries, including the United States. This is done on the basis of Standard Contractual Clauses (SCC) approved by the European Commission or other mechanisms provided under the GDPR.
6. Your rights
In connection with data processing, you have the following rights:
- Right of access — you have the right to know what data we process about you.
- Right to rectification — you may request correction of inaccurate or completion of incomplete data.
- Right to erasure — you may request deletion of data, unless we have a legal obligation to retain it.
- Right to restriction — you may request that we temporarily stop processing your data.
- Right to data portability — you may receive your data in a structured format and transfer it to another controller.
- Right to object — you may object to processing based on legitimate interest.
- Right to withdraw consent — if we process data based on your consent (e.g. newsletter), you may withdraw it at any time.
- Right to lodge a complaint — you may file a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
6.1. How to exercise your rights
You may send a request regarding personal data to: froart@froart.com. We will respond without undue delay and no later than one month. In justified cases the period may be extended by a further two months — we will inform you of the reason for the delay.
When can we refuse deletion? When law requires further retention (e.g. accounting documents).
When can you request restriction of processing? When you contest the accuracy of data or object to processing — for the duration of the request review.
If you live outside Poland, you may lodge a complaint with the supervisory authority in your country.
7. Cookies and tracking technologies
Our site uses cookies — small files stored in your browser. They help the site function properly and allow us to analyse traffic.
7.1. Types of cookies we use
- Essential — enable proper site operation, including login, cart, session maintenance, and basic security. They do not require your consent.
- Analytics (Google Analytics) — these tools may analyse your activity on the site (e.g. pages visited, clicks, visit duration). Processed only with your consent.
- Marketing — enable ads tailored to your interests and measure their effectiveness (e.g. Meta Pixel). Processed only with your consent.
You can manage your preferences via the cookie banner on our site (“Accept all”, “Accept necessary”, or “Manage preferences”) or in your browser settings.
7.2. Types of cookies by operation
- Session cookies — active until you close the browser.
- Persistent cookies — remain on your device until deleted.
- First-party cookies — used for cart, login, session, settings, and site performance.
- Third-party cookies — from partners including Google (Analytics, Ads) and Meta (Pixel).
We do not use dark patterns or mechanisms that make it difficult to refuse consent.
7.3. Managing cookies
You have the right to change settings in the cookie banner (“Accept all”, “Accept necessary”, or “Manage preferences”), block cookies in your browser, and delete stored cookies. Disabling cookies may limit store functionality.
8. How we protect your data
We protect your personal data using appropriate technical and organisational measures against unauthorised access, loss, alteration, or destruction. In particular we apply:
- SSL encryption — all data transmitted between your device and our site is encrypted.
- Server security — data is stored on protected servers with access control and network security.
- Access control — only authorised persons trained in data protection have access to data.
- Regular system updates — we keep software and security measures up to date.
- Security monitoring — we continuously analyse potential threats and respond to them.
9. Changes to this privacy policy
We may update this Privacy Policy, in particular when laws, technology, or store operations change. We will inform you of material changes in advance.
Using the store after changes take effect means acceptance of the updated Privacy Policy.
Matters not covered by this Privacy Policy are governed by Polish law and the GDPR.
The current version of the Privacy Policy is always available at froart.pl.
Questions about your data? Contact us: froart@froart.com.