THIS PRIVACY POLICY DESCRIBES THE RULES FOR PROCESSING INFORMATION ABOUT YOU, INCLUDING PERSONAL DATA AND COOKIES.
1. GENERAL INFORMATION
* This policy applies to the website operating at the URL: oldcraftrides.com
* The operator of the website and the Data Controller is: Bartosz Styszyński, Jerzykowo, ul. Nad Zalewem 49, 62-007, Poland
* Operator’s contact email address: contact@oldcraftrides.com
* The operator is the Controller of your personal data in relation to data voluntarily provided on the Website.
* The Website uses personal data for the following purposes:
* Conducting online chat conversations
* Displaying user announcements
* Handling inquiries via form
* Preparing, packaging, and shipping goods
* Execution of ordered services
* Presentation of offers or information
* The Website collects information about users and their behavior in the following way:
* Through data voluntarily entered in forms, which are then entered into the Operator’s systems.
* By storing cookies on end-user devices.
2. SELECTED METHODS OF DATA PROTECTION USED BY THE OPERATOR
• Login and personal data entry points are protected at the transmission layer (SSL certificate).
• User passwords are stored in hashed form. The hashing function is one-way – it cannot be reversed, which is a modern standard for storing user passwords.
• Two-factor authentication is used in the service, providing an additional layer of login protection.
• The operator periodically changes administrative passwords.
• To protect data, the operator regularly performs security backups.
• A key element of data protection is the regular updating of all software used by the Operator to process personal data, especially programming components.
3. HOSTING
• The Website is hosted (technically maintained) on servers of the operator: cyberFolks.pl
• The hosting company, to ensure technical reliability, maintains server-level logs, which may include:
– resources identified by URL (addresses of requested resources – pages, files),
– time of request,
– time of response,
– client station name – identification by HTTP protocol,
– information about errors that occurred during the HTTP transaction,
– URL of the previously visited page (referer link) – if the visit occurred through a link,
– information about the user’s browser,
– information about the IP address,
– diagnostic information related to the self-ordering process via the site,
– information related to email correspondence to and from the Operator.
4. YOUR RIGHTS AND ADDITIONAL INFORMATION ON DATA USAGE
• In some situations, the Administrator has the right to transfer your personal data to other recipients if necessary to perform the contract with you or to fulfill legal obligations. This applies to the following recipient groups:
– hosting company on the basis of data processing agreement,
– online chat solution providers,
– companies providing marketing services for the Administrator.
• Your personal data will be processed by the Administrator no longer than necessary to perform the related actions defined by separate regulations (e.g., accounting regulations). For marketing data, processing will not exceed 3 years.
• You have the right to request from the Administrator:
– access to personal data about you,
– rectification,
– deletion,
– restriction of processing,
– data portability.
• You have the right to object to the processing referred to in section 3.2 for the purposes of legitimate interests pursued by the Administrator, including profiling, but this right does not apply if there are legitimate grounds for the processing that override your interests, rights, and freedoms, particularly to establish, assert or defend legal claims.
• You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.
• Providing personal data is voluntary but necessary for using the Website.
• Automated decision-making, including profiling, may apply to you to provide services under the contract and for direct marketing by the Administrator.
• Personal data is not transferred to third countries within the meaning of data protection regulations. This means that data is not sent outside the European Union.
5. INFORMATION IN FORMS
• The website collects information voluntarily provided by the user, including personal data, if provided.
• The website may save information about connection parameters (timestamp, IP address).
• In some cases, the website may save information facilitating the linking of form data with the user’s email address filling out the form. In such cases, the user’s email address appears in the URL of the page containing the form.
• Data provided in the form is processed for the purpose resulting from the function of the specific form, e.g., to handle a service request or commercial contact, service registration, etc. Each form clearly explains its purpose.
6. ADMINISTRATOR LOGS
• Information about user behavior on the website may be logged. These data are used to administer the site.
7. IMPORTANT MARKETING TECHNIQUES
• The operator uses statistical analysis of website traffic through Google Analytics (Google Inc., USA). The operator does not provide personal data to the service provider, only anonymized information. The service uses cookies stored on the user’s device.
• The operator uses remarketing techniques to tailor advertising messages to user behavior on the website. This may give the impression that personal data is being tracked, but in practice, no personal data is transferred from the Operator to advertisers. The technical basis is enabled cookie support.
• The operator uses Facebook Pixel. This technology allows Facebook (Facebook Inc., USA) to know that a registered person uses the Website. Facebook uses data for which it is a separate controller. The Operator does not transfer any additional personal data to Facebook. The service uses cookies on the user’s device.
• The operator uses tools that track user behavior by creating heat maps and recording sessions. These data are anonymized before being sent to the service provider and do not include personal data like passwords.
• The operator uses automation tools that may, for example, send an email after visiting a specific subpage, provided the user has consented to receive marketing emails from the Operator.
8. COOKIE INFORMATION
• The website uses cookies.
• Cookies are IT data, especially text files stored on the User’s end device, intended for use with the Website’s pages. Cookies usually contain the name of the originating website, storage time on the end device, and a unique number.
• The entity placing cookies and accessing them is the Website operator.
• Cookies are used for the following purposes:
– maintaining the User’s session (after logging in), so the User does not have to re-enter their login and password on each subpage;
– achieving the purposes described above in ‘Important Marketing Techniques’.
• The Website uses two basic types of cookies: ‘session’ cookies and ‘persistent’ cookies. Session cookies are temporary and are stored on the User’s device until logout, leaving the site, or closing the browser. Persistent cookies remain until the time specified in the cookie parameters or until manually deleted by the User.
• Web browsing software (web browser) usually allows cookies to be stored by default. Users can change these settings. Browsers allow deletion or automatic blocking of cookies. Detailed information can be found in the browser’s help or documentation.
• Limiting the use of cookies may affect some functionalities of the Website.
• Cookies stored on the User’s device may also be used by partners of the Website operator, especially Google (Google Inc., USA), Facebook (Facebook Inc., USA), and Twitter (Twitter Inc., USA).
9. COOKIE MANAGEMENT – HOW TO GIVE AND WITHDRAW CONSENT?
• If the user does not want to receive cookies, they can change their browser settings. Note: disabling cookies essential for authentication, security, and user preference maintenance may hinder or, in extreme cases, prevent the use of websites.
• To manage cookie settings, select your browser from the list below and follow the instructions:
– Edge
– Internet Explorer
– Chrome
– Safari
– Firefox
– Opera
Mobile devices:
– Android
– Safari (iOS)
– Windows Phone.