Privacy Policy
Privacy Policy – Truck-Shop.pl
(updated version compliant with GDPR, PSD2, and current cookie and third-party service requirements)
1. Personal Data Controller
The controller of personal data is:
Truck-Shop Sp. z o.o.
ul. Nowowiejskiego 28
83-000 Pruszcz Gdański
Poland
VAT ID (NIP): PL 604-014-73-10
e-mail: info@truck-shop.pl
phone: +48 58 728 21 55
mobile: +48 605 542 060
Website: www.truck-shop.pl
The Controller processes personal data in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”),
- the Polish Act on Providing Services by Electronic Means,
- the Telecommunications Law,
- the Consumer Rights Act,
- and other applicable Polish and European Union laws.
2. Scope and Purpose of Data Processing
Personal data is processed for the following purposes:
- processing and fulfilling orders,
- concluding sales agreements,
- maintaining customer accounts,
- payment processing,
- delivery fulfillment,
- customer communication,
- handling complaints and returns,
- marketing activities,
- newsletter distribution,
- ensuring website security,
- statistical and analytical purposes,
- fraud prevention and abuse detection.
Legal bases for processing:
- Article 6(1)(b) GDPR – performance of a contract,
- Article 6(1)(c) GDPR – compliance with legal obligations,
- Article 6(1)(a) GDPR – user consent,
- Article 6(1)(f) GDPR – legitimate interest of the Controller.
3. Automatically Collected Data
When using the website, the following data may be collected automatically:
- IP address,
- device type,
- browser type,
- operating system,
- date and time of visit,
- information about user activity on the website,
- data stored in cookies.
This data is used solely for:
- technical purposes,
- security,
- statistical analysis,
- marketing,
- website optimization.
4. Customer Account
Creating a customer account is voluntary.
The following data may be processed within the account:
- first and last name,
- delivery address,
- e-mail address,
- phone number,
- order history,
- invoicing details.
The customer may at any time:
- edit their data,
- delete the account,
- request data deletion in accordance with GDPR.
5. Order Fulfillment and Deliveries
For the purpose of order fulfillment, personal data may be shared with delivery service providers, including:
- DPD Polska,
- InPost.
Only data necessary for delivery processing is transferred.
6. Payments
For payment processing purposes, data may be shared with payment service providers, including:
- Autopay,
- Stripe,
- Google Pay.
Available payment methods:
- traditional bank transfer,
- online instant payments,
- BLIK,
- payment cards,
- Google Pay,
- cash on delivery.
The Controller does not store full payment card details.
All transactions are protected using SSL/TLS encryption and comply with PSD2 requirements and Strong Customer Authentication (SCA).
7. Newsletter and Marketing
With the user’s consent, the Controller may send:
- newsletters,
- commercial information,
- promotional offers,
- discount codes,
- information about new products.
The user may at any time:
- withdraw consent,
- unsubscribe from newsletters,
- request deletion of marketing-related data.
8. Cookies and Tracking Technologies
The website uses:
- technical cookies,
- functional cookies,
- analytical cookies,
- marketing cookies.
During the first visit, the user may manage cookie preferences through the cookie consent banner.
The user may:
- accept all cookies,
- reject optional cookies,
- change cookie settings in the browser.
Disabling certain cookies may limit website functionality.
9. Analytical and Marketing Tools
The website may use the following services:
The Controller uses services such as:
- Google Analytics,
- YouTube,
- Google Ads.
Google may process data outside the European Economic Area in accordance with EU Standard Contractual Clauses.
Meta (Facebook / Instagram)
The Controller may use:
- Meta Platforms,
- Facebook Ads,
- Meta Pixel.
Data may be used for:
- remarketing,
- advertising analytics,
- personalized advertising.
10. Social Media
Truck-Shop.pl may operate social media profiles on:
- Facebook,
- Instagram,
- YouTube.
The use of these platforms is subject to the terms and privacy policies of their operators.
11. Data Retention Period
Data is stored:
- for the duration of the contract,
- for the period required by tax and accounting regulations,
- until the expiration of legal claims,
- until consent is withdrawn by the user.
12. User Rights
The user has the right to:
- access personal data,
- rectify data,
- erase data,
- restrict processing,
- transfer data,
- object to processing,
- withdraw consent,
- lodge a complaint with the supervisory authority.
Supervisory authority:
Polish Personal Data Protection Office (UODO)
13. Data Security
The Controller applies technical and organizational measures ensuring data protection, including:
- SSL/TLS encryption,
- server security measures,
- restricted access to data,
- regular system updates,
- personal data access control.
14. Transfer of Data Outside the EEA
Certain data may be transferred outside the European Economic Area due to the use of services provided by Google, Meta, or other technology providers.
Data transfers are carried out in compliance with GDPR mechanisms, including:
- Standard Contractual Clauses approved by the European Commission,
- adequacy decisions issued by the European Commission.
15. Changes to the Privacy Policy
The Controller reserves the right to update this Privacy Policy, particularly in the event of:
- changes in legal regulations,
- technological changes,
- modifications to website functionality,
- implementation of new services.
The current version of the Privacy Policy is always available on the Truck-Shop.pl website.
16. Contact
For matters related to personal data protection, please contact:
Truck-Shop Sp. z o.o.
ul. Nowowiejskiego 28
83-000 Pruszcz Gdański
Poland
e-mail: info@truck-shop.pl
phone: +48 58 728 21 55
mobile: +48 605 542 060