Privacy and cookie policy
PRIVACY AND COOKIE POLICY
This is a courtesy translation for reference. The Polish text governs.
Version of 2026-08-31.
§1. CONTROLLER
1. The controller is Closter Polska sp. z o.o., Jana Pawła II 22, 00-133 Warszawa, PL, NIP 5253083935, REGON 544317336, KRS 0001230607 (Sąd Rejonowy dla m.st. Warszawy w Warszawie, XII Wydział Gospodarczy Krajowego Rejestru Sądowego), share capital PLN 5000
("Closter").
2. Contact on any data protection matter: hej@closter.pl.
3. Closter has not appointed a data protection officer; none of the conditions in art. 37 GDPR
applies.
§2. WHO THIS COVERS
Three groups: people who send goods to Closter ("Sellers"), people who buy from the shop
("Buyers"), and visitors to the site.
§3. WHAT DATA, AND WHY
1. SELLERS:
a) name, address, email, telephone — to conclude and perform the contract
(art. 6(1)(b) GDPR);
b) bank account number — to pay amounts due (art. 6(1)(b));
c) the outcome of identity verification — to limit the risk of fraud, in Closter's
legitimate interest (art. 6(1)(f)). The identity document itself is not retained; only
the outcome is;
d) transaction data: description of the goods, acquisition price, the specific resale, tax —
to discharge tax obligations, including the margin-scheme register and the tax on civil
law transactions (art. 6(1)(c) GDPR with art. 120 of the VAT Act, the PCC Act, and
art. 86 § 1 of the Tax Ordinance);
e) the text of each accepted document with its cryptographic hash, date, IP address and
session identifier — to establish on what terms the contract was concluded
(art. 6(1)(f)).
2. BUYERS: order data — name, delivery address, email, and payment data processed by the
payment provider — to perform the sale (art. 6(1)(b)) and to issue and retain sales
documents (art. 6(1)(c)).
3. VISITORS: IP address, browser information and cookie data — to operate and secure the site
(art. 6(1)(f)).
4. PHOTOGRAPHS of goods are taken by Closter. They do not depict people. They are linked to a
Seller's record and to that extent are their personal data.
§4. RECIPIENTS
Closter uses the following providers, processing data on its instructions:
a) Shopify — the online shop, order handling and account sign-in;
b) Vercel — application hosting; processing takes place in the Frankfurt region (EU);
c) Supabase — database and file storage; Frankfurt region (EU);
d) Resend — transactional email; dispatched from the Ireland region (EU);
e) Google — analysis of photographs of the goods by a language model, to draft the item
description; every output is reviewed by a member of staff;
f) ConsignCloud — the inventory and settlement system. The consignor account created there
carries only Closter's own internal identifier; the Seller's name, address and email
address are never sent to it.
INPOST — A CARRIER, NOT A PROCESSOR. Where a Seller chooses to send a parcel, Closter passes
InPost S.A. the Seller's name, address and telephone number as the sender, in order to book the
consignment. InPost processes those details as a SEPARATE CONTROLLER, for its own purposes and
under its own legal duties as a carrier, and not on Closter's instructions. InPost's own privacy
policy governs what it does with them.
Data may also be disclosed to bodies entitled to it by law, including the tax authorities.
§5. TRANSFERS OUTSIDE THE EEA
1. Some providers listed in §4 are established outside the EEA. Transfers rest on a European
Commission adequacy decision or on standard contractual clauses (art. 45 and art. 46 GDPR).
2. For transactional email, dispatch takes place from an EU region, while account data, logs
and message metadata are stored in the United States.
3. Current information on the basis for a transfer is available on request to
hej@closter.pl.
§6. RETENTION
1. Data entering tax settlements, including the margin-scheme register, is retained for the
period required by tax law, running from the end of the year in which the tax fell due
(art. 86 § 1 of the Tax Ordinance). During that period a request to erase it cannot be met
(art. 17(3)(b) GDPR).
2. Data necessary to establish, exercise or defend legal claims — including the text of
accepted documents — is retained until limitation periods expire (art. 17(3)(e) GDPR).
3. Data for which neither basis applies — in particular a registration from which no
transaction followed — is erased on request without delay.
4. Identity documents are not retained. Only the verification outcome is kept.
5. The retention basis is recorded at the moment each record is written, not decided when a
request arrives. That is why a refusal to erase always cites the specific provision it rests
on.
§7. YOUR RIGHTS
1. You have the right of access, rectification, erasure, restriction, portability, and
objection to processing based on legitimate interests (art. 15–21 GDPR).
2. Requests go to hej@closter.pl and are answered within one month.
3. Erasure is refused only within the scope of §6(1)–(2), and the refusal states its legal
basis.
4. You may lodge a complaint with the President of the Personal Data Protection Office
(Prezes UODO), ul. Stawki 2, 00-193 Warsaw.
§8. NO SOLELY AUTOMATED DECISION-MAKING
1. Closter takes no decisions based solely on automated processing, including profiling, that
produce legal effects or similarly significantly affect a person (art. 22 GDPR).
2. Machine-learning tools are used during intake to draft a description, a condition grade and
a price. A draft has no effect at all until a member of staff approves it. No item is ever
listed without a human decision.
§9. COOKIES
1. The site stores cookies strictly necessary to provide the service: keeping a sign-in session
and a basket, and security. These require no consent (art. 398(3) of the Polish Electronic
Communications Law of 12 July 2024).
2. Cookies that are not strictly necessary are stored only with consent, which may be withdrawn
at any time.
3. Consent may be withdrawn and stored cookies deleted in the browser settings. Disabling
strictly necessary cookies may make it impossible to sign in or to place an order.
§10. CHANGES
Closter announces changes on the site, with the version date in the header. A change does not
limit rights acquired while an earlier version was in force.
privacy_policy@2