Document
Privacy Policy
Current version. Any change is published on this page.
1. Data controller
The controller of your personal data is BUSZ sp. z o.o., with its registered office at Wiązowa 1A / 1, 62-002 Suchy Las, Poland (KRS 0001098137, NIP 9721351496, REGON 528264635), the operator of the storemate.io website.
For any matter concerning personal data, write to contact@storemate.io.
2. Scope of this policy
This policy covers two areas: (a) data collected through the storemate.io website — through the contact form and in connection with your use of the site (technical data, cookies), and (b) data processed within the Storemate service, including data fetched on behalf of our customers from connected sales platforms (Section 3).
3. Data processed within the Storemate service
Our role. Within the Storemate service we process data that our customers enter into the system or that the system fetches on their behalf from connected sales platforms and tools (including Temu, Allegro, Shopify etc.). The controller of this data is the customer; we act as a processor, solely on the customer's documented instructions, under a data processing agreement annexed to the terms of service.
Categories of data. Buyer data necessary to handle orders: name, delivery address, e-mail address, phone number, order, shipment and billing data, and order-related as well as business-related correspondence and context.
Purposes and limits. We use this data solely to provide the service: managing and synchronising orders, handling shipments, issuing sales documents, preparing analytics and handling messages (including with the AI Assistant — after prior data minimisation and pseudonymisation). We do not use this data for our own marketing, we do not sell it, we do not profile buyers, and we do not use it to train AI models.
Retention. We process this data for as long as we provide the service to the customer. After the customer's agreement ends, the data is permanently deleted from production systems within 90 days, unless further storage is required by law.
Security. We apply encryption in transit (TLS) and at rest, least-privilege access control, and a no-personal-data-in-logs rule. We maintain a data breach response procedure: in the event of a confirmed breach we notify the affected customers (controllers) without undue delay, support them in notifying the supervisory authority within 72 hours, and notify platform partners where required by the obligations binding on us.
Recipients. We use subprocessors (including hosting, database, AI processing, invoicing and payment vendors) listed in the public, regularly updated register at storemate.io/subprocessors.
Rights of data subjects. Buyers should address requests concerning their data to the merchant they bought from (the data controller). If such a request reaches us, we will promptly pass it on to the relevant controller and support its fulfilment.
4. What data we collect through the website
Contact form: the email address or phone number you provide, optionally your company name and first name, and the content of your message.
Technical data: basic information about your visit (such as IP address, device type and browser) and data collected through cookies and similar technologies, including analytics tools where these are used.
5. Purposes of processing (website)
Answering your enquiry and contacting you about our offer.
Keeping the website running and secure and, with your consent, analysing traffic in order to improve the site.
6. Legal basis
Handling an enquiry from the contact form: our legitimate interest in communicating with people interested in our offer (Article 6(1)(f) GDPR).
Analytics and marketing that require consent: your consent (Article 6(1)(a) GDPR), which you may withdraw at any time.
Providing the Storemate service to our customers: performance of a contract (Article 6(1)(b) GDPR); with respect to buyer data we act as a processor under Article 28 GDPR.
7. Recipients of data
Data may be entrusted to trusted providers acting on our behalf under data processing agreements — in particular providers of hosting and infrastructure, the provider of the contact form service, providers of analytics tools (where used) and the service subprocessors listed in the register at storemate.io/subprocessors. We share data with them only to the extent necessary to deliver those services. Data may also be disclosed to public authorities where required by law.
We do not sell your data.
8. Transfers outside the European Economic Area
Some of our providers may process data outside the European Economic Area (including in the US). In that case we make sure the transfer relies on mechanisms compliant with the GDPR — an adequacy decision of the European Commission (including the Data Privacy Framework) or standard contractual clauses, supported by a transfer impact assessment (TIA) and supplementary safeguards such as encryption, pseudonymisation and keeping personal data out of system logs.
9. Retention period
We keep data from the contact form for as long as it takes to handle your enquiry and carry on the correspondence, and afterwards for the period needed to establish, pursue or defend claims and for the period required by law. Data processed on the basis of consent is kept until that consent is withdrawn. Retention of data processed within the service is described in Section 3.
10. Your rights
You have the right to access your data, to rectify it, to erase it, to restrict processing, to object, to data portability and, where we process on the basis of consent, to withdraw that consent at any time.
To exercise these rights, write to us at contact@storemate.io. We respond within one month at the latest.
11. Complaint to the supervisory authority
If you believe we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office in Poland (ul. Stawki 2, 00-193 Warsaw).
12. Cookies
We use cookies necessary for the website to work correctly and, with your consent, analytics and statistical cookies. You manage cookie consent in your browser settings or in the consent banner available on the site.
13. Changes to this policy
We may update this policy, in particular when the law, our providers or the scope of the service changes. The current version is always available on this page.
Polska wersja: polityka prywatności
← Back to the home page