POLITYKA PRYWATNOŚCI – ColorStories.pl (PL 2026)

Last update: 01/01/2026

Who is the data controller?

The controller of your personal data is:

ColorStories Agnieszka Czajkowska

ul. Antoniego Kocjana 1/8, 01-473 Warsaw, Poland

VAT ID (NIP): 5222539972, REGON: 146242483
General and privacy contact: [email protected]
Phone: +48 536 200 001

For matters concerning personal data, you can contact us at: [email protected] (subject
line: “GDPR”).

What data do we process?

Depending on how you use the website, we may process:

Identification and contact data: first name, last name, e-mail address, phone number,
delivery/billing address.
● Transaction data: order number, purchase history, payment details (without card data –
these are handled by the payment operator).
● Data necessary to handle returns and complaints: the content of the request,
correspondence, shipment information and, if applicable, product photos.
● Customer account data (if you create an account): login/e-mail address, order history.
● Newsletter data: e-mail address and shipment data (e.g., opens/clicks), if available in the
tool.
● Technical data: IP address, cookies/device identifiers, server logs, browser data and activity
on the website (analytics).
● Marketing data: information about interactions with ads and the website (e.g., for
remarketing purposes – if you consent to marketing cookies).

Providing data is voluntary, but in many cases it is necessary, e.g., to process an order, deliver it,
handle a return or a complaint.

For what purposes and on what legal basis do we process data?

We process personal data for the following purposes:

  1. Entering into and performing a contract (order, delivery, payment, order-related communication) – legal basis: Article 6(1)(b) GDPR (performance of a contract).
  2. Handling returns (withdrawal from a contract) and complaints – legal basis: Article 6(1)(b) GDPR (performance of rights arising from the contract) and Article 6(1)(c) GDPR (legal obligation – e.g., consumer/accounting regulations, where applicable).
  1. Issuing and storing accounting documents – legal basis: Article 6(1)(c) GDPR (legal obligation).
  2. Contact and handling inquiries (form/e-mail/phone) – legal basis: Article 6(1)(f) GDPR (our legitimate interest: communication and handling inquiries) or Article 6(1)(b) GDPR (pre- contractual steps).
  3. Newsletter (direct e-mail marketing) – legal basis: Article 6(1)(a) GDPR (consent). You can withdraw your consent at any time.
  4. Analytics and statistics (GA4) – to better understand how the website works and what to improve – legal basis: Article 6(1)(a) GDPR (consent to analytics cookies expressed in the cookie banner) or Article 6(1)(f) GDPR for data that are technically necessary (e.g., logs).
  5. Marketing and remarketing (e.g., Meta Pixel) – legal basis: Article 6(1)(a) GDPR (consent to marketing cookies expressed in the cookie banner).
  6. Website security and prevention of abuse (e.g., logs, security measures, firewall/Wordfence) – legal basis: Article 6(1)(f) GDPR (legitimate interest: security).
  7. Establishing, pursuing or defending claims – legal basis: Article 6(1)(f) GDPR (legitimate interest: protection of rights).

Who do we share your data with? (recipients / processors)

We do not sell your data. We share data only when necessary to provide services or required by
law, in particular with:

● Hosting providers / IT infrastructure providers (store, server, e-mail maintenance).
● Courier companies and logistics operators (delivery, shipment handling).
● Payment operators: PayU, PayNow, Przelewy24, PayPal and Blue Media (card payment processing) – to the extent necessary to handle payments.
● Newsletter and marketing automation provider: Omnisend (newsletter sending, automations, delivery statistics).
● Analytics and marketing tools providers: Google Analytics 4, Meta Pixel – depending on your cookie consents.
● Review system provider: Trusted Shops (widget/reviews handling).
● Entities supporting customer service and accounting (if used – only as necessary and under data processing agreements).
● Authorized authorities – if required by law.

Authorized authorities – if required by law.

Some of our providers may process data outside the EEA (e.g., in the USA). This may apply in
particular to: Google (GA4), Meta (Pixel) as well as Omnisend and PayPal – depending on the
configuration of the services.

In such cases, we apply safeguards required by law, in particular:
● Standard Contractual Clauses (SCC) approved by the European Commission, and/or
● other GDPR-compliant mechanisms (e.g., adequacy decisions – where applicable).

How long do we retain data? (retention)

We retain data only for the period necessary to achieve the purposes, including:

PurposeRetention period
Order fulfilment and customer serviceFor the duration of fulfilment + the period necessary for settlements
Accounting documentsFor the period required by tax/accounting regulations.
Complaints and returnsFor the duration of handling + the limitation period for claims.
Customer accountUntil the account is deleted (plus a technical period for backups).
Newsletter (Omnisend)Until you unsubscribe or withdraw consent.
Analytics/marketing cookiesIn line with your consents and the lifetime of cookies/identifiers (details in the Cookies Policy).
Security logsFor the period necessary to ensure security and detect abuse.

What rights do you have?

Under the GDPR, you have the right to:
● access your data,
● rectify your data,
● erase your data (“right to be forgotten”) – to the extent not limited by law,
● restrict processing,
● data portability,
● object to processing based on legitimate interest (Article 6(1)(f) GDPR),

● withdraw consent at any time (where processing is based on consent – withdrawal does not affect the lawfulness of processing before withdrawal),
● lodge a complaint with the supervisory authority: the President of the Personal Data Protection Office (UODO, Poland).

To exercise your rights, contact us at: [email protected].

Do we make automated decisions and use profiling?

We may use marketing tools (e.g., remarketing) that tailor ads to your previous activity on the website – only if you consent to marketing cookies.

We do not make decisions concerning you that produce legal effects solely based on automated processing (within the meaning of Article 22 GDPR).

Security

We apply technical and organizational measures to protect data (including SSL connection encryption, access control, website security measures and abuse monitoring).

Social media

If you follow our profiles (e.g., Facebook/Instagram) or interact with our content, your data may also be processed by the providers of these services in accordance with their rules.

We may process basic statistical and communication data to run the profile and communicate with users (legal basis: Article 6(1)(f) GDPR – legitimate interest).

Changes to this Privacy Policy

We may update this Privacy Policy when the law changes or when the Store/tools we use change. The current version is always published on the website.

COOKIES POLICY – ColorStories.pl

Ostatnia aktualizacja: 01.01.2026 r.

What are cookies?

Cookies are small text files stored on your device (computer/phone) that help to:

● display the website correctly,
● remember your settings (e.g., the cart),
● analyze website traffic,
● carry out marketing activities (e.g., remarketing) – if you consent.

Cookies can be:

● session cookies (deleted when you close the browser),
● persistent cookies (stored for a specified period or until deleted).

What cookies do we use?

We use the following categories of cookies in the Store:

A) Necessary (technical)
These are required for the website to function properly (e.g., cart, security, session, settings). They operate without consent, because without them the website may not work correctly.

B) Analytics (statistics)
These help us understand how users use the website (e.g., how many people visit and which pages they choose). Tool: Google Analytics 4 (GA4). We activate these cookies only after your consent.

C) Marketing (advertising/remarketing)
These make it possible to tailor ads and measure their effectiveness. Tool: Meta Pixel (Facebook/Instagram). We activate these cookies only after your consent.

Cookie consents – how do they work?

On your first visit, we display a cookie banner where you can:

● accept all cookies,
● reject analytics/marketing cookies,
● set preferences for selected categories.

You can change your consents at any time (e.g., by reopening cookie settings – if you see a
button such as “Cookie settings” or a similar option in the banner).

How to disable cookies in your browser

You can manage cookies yourself in your browser settings (block/delete cookies). Please note: blocking necessary cookies may cause some store functions (e.g., the cart) to stop working.

Instructions can be found in your browser help section (Chrome, Safari, Firefox, Edge).

Do cookies involve transfers outside the EEA?

Using GA4 and Meta Pixel may involve transferring data outside the EEA (e.g., to the USA), depending on configuration and providers. We apply GDPR-compliant mechanisms (e.g., SCC). Details are described in the Privacy Policy.

Changes to this Cookies Policy

We may update this policy if the tools we use or the law changes. The current version is always published on the website.