Privacy policy

This Privacy and Cookies Policy describes how THE CODE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, based in Warsaw, uses information about you that constitutes personal data within the meaning of the General Data Protection Regulation (GDPR). Here you will also find information about the rights you have in relation to the processing of your personal data.

The Privacy Policy applies to all customers of the online store and visitors to our websites who may or may not be our customers.

In the event of any doubts or inconsistencies between this Policy and consents provided by an individual, regardless of the provisions of this Policy, the basis for determining and defining the scope of actions taken by the Company shall always be the voluntarily provided consents or applicable legal provisions.

In the event of any conflict between this Policy and the content of information clauses provided by the Company when collecting personal data (usually placed below forms in the Online Store or on individual pages), the information that the Customer should follow is the information provided in these information clauses.

DEFINITIONS

Whenever the following terms and definitions are used in this Policy, they shall have the following meanings:

Administrator or CompanyTHE CODE Sp. z o.o., with its registered office in Warsaw, 02-995, ul. Komfortowa 10/2, registered in the register of entrepreneurs maintained by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Division of the National Court Register under KRS number 0001164311, NIP (Tax Identification Number) 9512618328, REGON 541288210, with share capital of PLN 50,000, and email address: info@thecodestore.pl.

Cookies – means IT data, in particular small text files, stored and saved on devices through which the User accesses the websites of the Online Store.

Administrator’s Cookies – means Cookies placed by the Administrator, related to the provision of electronic services by the Administrator through the Online Store.

External Cookies – means Cookies placed by the Administrator’s partners through the Online Store website.

Personal Data – all information relating to an identified or identifiable natural person through one or more specific factors determining their physical, physiological, genetic, psychological, economic, cultural, or social identity, including device IP address, location data, online identifier, and information collected through cookies and similar technologies.

Policy – this Privacy Policy.

Device – means an electronic device through which the User accesses the Online Store.

GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC.

Online Store – an online store operated by the Administrator at: www.thecodestore.com.

Visitor – any natural person visiting the Online Store or using one or more of the services or functionalities described in the Policy. A person becomes a Customer after registering in the Online Store or subscribing to the Newsletter.

§1.

GENERAL PROVISIONS

The administrator of personal data collected through the Online Store is THE CODE Sp. z o.o., with its registered office in Warsaw, 02-995, ul. Komfortowa 10/2, registered in the register of entrepreneurs maintained by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Division of the National Court Register under KRS number 0001164311, NIP 9512618328, REGON 541288210, with share capital of PLN 50,000, and email address: info@thecodestore.pl — hereinafter referred to as the “Administrator”, who is also the provider of the Online Store services and the Seller.

Personal data in the Online Store is processed by the Administrator in accordance with applicable laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 regarding the protection of natural persons in relation to the processing of personal data and the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation) — hereinafter referred to as the “GDPR” or the “GDPR Regulation”.

The official text of the GDPR Regulation is available here:
http://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX%3A32016R0679

Use of the Online Store, including making purchases, is voluntary. Similarly, providing personal data by a person using the Online Store, Service User, or Customer is voluntary, subject to two exceptions:

(1) Entering into agreements with the Administrator – failure to provide, in cases and within the scope indicated on the Online Store website, in the Online Store Terms and Conditions, and in this Privacy Policy, the personal data necessary to conclude and perform a Sales Agreement or an Electronic Service Agreement with the Administrator will result in the inability to conclude such an agreement.

Providing personal data is therefore a contractual requirement, and if a person wishes to enter into a given agreement with the Administrator, they are required to provide the necessary data. The scope of data required to conclude an agreement is each time indicated in advance on the Online Store website and in the Online Store Terms and Conditions.

(2) Legal obligations of the Administrator – providing personal data is a legal requirement resulting from generally applicable laws that impose an obligation on the Administrator to process personal data (e.g., processing data for maintaining tax or accounting records). Failure to provide such data will prevent the Administrator from fulfilling these obligations.

The Administrator takes particular care to protect the interests of individuals whose personal data is processed and ensures that the collected data is:

  1. processed lawfully;
  2. collected for specified, legitimate purposes and not further processed in a manner inconsistent with those purposes;
  3. accurate and adequate in relation to the purposes for which it is processed;
  4. stored in a form that allows identification of the persons concerned for no longer than necessary to achieve the purpose of processing; and
  5. processed in a manner ensuring appropriate security of personal data, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage through appropriate technical and organizational measures.

Taking into account the nature, scope, context, and purposes of processing, as well as the risk of violating the rights or freedoms of natural persons with varying likelihood and severity, the Administrator implements appropriate technical and organizational measures to ensure that processing is carried out in accordance with this Regulation and to demonstrate compliance.

These measures are reviewed and updated where necessary. The Administrator applies technical measures preventing unauthorized persons from obtaining or modifying personal data transmitted electronically.

All words, expressions, and acronyms appearing in this Privacy Policy and beginning with a capital letter (e.g., Seller, Online Store) should be understood in accordance with their definitions contained in the Online Store Terms and Conditions available on the Online Store website.

§2.

BASIS FOR PROCESSING PERSONAL DATA

The Administrator is entitled to process personal data where — and to the extent that — at least one of the following conditions applies:

  1. The data subject has given consent to the processing of their personal data for one or more specific purposes;
  2. Processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract;
  3. Processing is necessary for compliance with a legal obligation to which the Administrator is subject; or
  4. Processing is necessary for the purposes of the legitimate interests pursued by the Administrator or by a third party, except where such interests are overridden by the interests, rights, or freedoms of the data subject requiring protection of personal data, especially where the data subject is a child.

The processing of personal data by the Administrator requires, in each case, the existence of at least one of the legal bases indicated in section 2.1 of this Privacy Policy.

The specific legal bases for processing personal data of Service Users and Customers of the Online Store by the Administrator are indicated in the following section of this Privacy Policy — in relation to each specific purpose of personal data processing carried out by the Administrator.


§3.

PURPOSE, LEGAL BASIS AND PERIOD OF PERSONAL DATA PROCESSING IN THE ONLINE STORE

In each case, the purpose, legal basis, retention period, and recipients of personal data processed by the Administrator result from the actions undertaken by a given Service User or Customer in the Online Store or by the Administrator.

For example, if a Customer decides to make a purchase in the Online Store and chooses personal collection of the purchased Product instead of courier delivery, their personal data will be processed for the purpose of performing the concluded Sales Agreement, but will no longer be shared with the carrier responsible for deliveries on behalf of the Administrator.

The Administrator may process personal data within the Online Store for the following purposes, based on the following legal grounds and retention periods:

Purpose of processing personal data Legal basis for processing Retention period
Performance of a Sales Agreement or an agreement for the provision of Electronic Services, or taking actions at the request of the data subject before entering into such agreements Article 6(1)(b) of the GDPR (performance of a contract) — processing is necessary for the performance of a contract to which the data subject is a party or for taking steps at the request of the data subject before entering into a contract Data is stored for the period necessary to perform, terminate, or otherwise expire the concluded Sales Agreement or Electronic Service Agreement
Direct marketing Article 6(1)(f) of the GDPR (legitimate interest of the Administrator) — processing is necessary for purposes arising from the legitimate interests pursued by the Administrator, including protecting the interests and good reputation of the Administrator and the Online Store, as well as pursuing the sale of Products Data is stored for the duration of the legitimate interest pursued by the Administrator, but no longer than the limitation period for claims that the Administrator may bring against the data subject in connection with its business activity. Limitation periods are determined by law, in particular by the Civil Code (the basic limitation period for business-related claims is three years, and for sales agreements two years). The Administrator may not process data for direct marketing purposes if the data subject has effectively objected to such processing
Marketing Article 6(1)(a) of the GDPR (consent) — the data subject has given consent to the processing of their personal data for marketing purposes by the Administrator Data is stored until the data subject withdraws consent to further processing of their data for this purpose
Marketing by third parties Article 6(1)(a) of the GDPR (consent) — the data subject has given consent to the processing of their personal data for marketing purposes by the Administrator’s Partners Data is stored until the data subject withdraws consent to further processing of their data for this purpose
Providing an opinion about the concluded Sales Agreement by the Customer Article 6(1)(a) of the GDPR — the data subject has given consent to the processing of their personal data for the purpose of submitting an opinion Data is stored until the data subject withdraws consent to further processing of their data for this purpose
Maintaining accounting records Article 6(1)(c) of the GDPR in connection with Article 74(2) of the Accounting Act of 30 January 2018 (Journal of Laws of 2018, item 395) — processing is necessary for compliance with a legal obligation imposed on the Administrator Data is stored for the period required by law requiring the Administrator to retain accounting records (5 years, calculated from the beginning of the year following the financial year to which the data relates)
Establishing, pursuing, or defending claims that may be made by the Administrator or against the Administrator Article 6(1)(f) of the GDPR (legitimate interest of the Administrator) — processing is necessary for purposes arising from the legitimate interests pursued by the Administrator, consisting of establishing, pursuing, or defending claims Data is stored for the duration of the legitimate interest pursued by the Administrator, but no longer than the limitation period for claims that may be made against the Administrator (the basic limitation period for claims against the Administrator is six years)
Use of the Online Store website and ensuring its proper operation Article 6(1)(f) of the GDPR (legitimate interest of the Administrator) — processing is necessary for purposes arising from the legitimate interests pursued by the Administrator, consisting of operating and maintaining the Online Store website Data is stored for the duration of the legitimate interest pursued by the Administrator, but no longer than the limitation period for claims that the Administrator may bring against the data subject in connection with its business activity. The limitation periods are determined by law, in particular the Civil Code (the basic limitation period for business-related claims is three years, and for sales agreements two years)
Maintaining statistics and analysing traffic in the Online Store Article 6(1)(f) of the GDPR (legitimate interest of the Administrator) — processing is necessary for purposes arising from the legitimate interests pursued by the Administrator, consisting of maintaining statistics and analysing traffic in the Online Store in order to improve its operation and increase Product sales Data is stored for the duration of the legitimate interest pursued by the Administrator, but no longer than the limitation period for claims that the Administrator may bring against the data subject in connection with its business activity. The limitation periods are determined by law, in particular the Civil Code (the basic limitation period for business-related claims is three years, and for sales agreements two years)

 

§4.

RECIPIENTS OF DATA IN THE ONLINE STORE

For the proper functioning of the Online Store, including the performance of concluded Sales Agreements, the Administrator needs to use services provided by external entities (such as, for example, software providers, courier companies, or payment service providers). The Administrator uses only such processors that provide sufficient guarantees for the implementation of appropriate technical and organisational measures, ensuring that the processing complies with the requirements of the GDPR and protects the rights of data subjects.

The transfer of data by the Administrator does not take place in every case and does not apply to all recipients or categories of recipients indicated in the Privacy Policy. The Administrator transfers data only when it is necessary to achieve a specific purpose of personal data processing and only to the extent necessary to fulfil that purpose. For example, if a Customer chooses personal collection, their data will not be transferred to a carrier cooperating with the Administrator.

Personal data of Service Users and Customers of the Online Store may be transferred to the following recipients or categories of recipients:

Carriers / shipping companies / courier brokers – in the case of a Customer who chooses delivery of a Product via postal or courier shipment in the Online Store, the Administrator provides the collected personal data of the Customer to the selected carrier, shipping company, or intermediary responsible for delivering shipments on behalf of the Administrator, only to the extent necessary to complete the delivery of the Product to the Customer.

Electronic payment service providers or payment card operators – in the case of a Customer who chooses electronic payment or payment by card in the Online Store, the Administrator provides the collected personal data of the Customer to the selected payment service provider handling such payments in the Online Store on behalf of the Administrator, only to the extent necessary to process the payment made by the Customer.

Providers of customer review and feedback survey systems – in the case of a Customer who has agreed to provide an opinion about a concluded Sales Agreement, the Administrator provides the collected personal data of the Customer to the selected provider of a review survey system for Sales Agreements concluded in the Online Store, acting on behalf of the Administrator, only to the extent necessary for the Customer to submit a review using the review system.

Providers of services supplying the Administrator with technical, IT, and organisational solutions that enable the Administrator to conduct business activities, including operating the Online Store and providing Electronic Services through it (in particular, providers of software used to operate the Online Store, email and hosting providers, and providers of business management and technical support software) – the Administrator provides the collected personal data of the Customer to the selected provider acting on behalf of the Administrator only when and to the extent necessary to achieve a specific purpose of data processing in accordance with this Privacy Policy.

Providers of accounting, legal, and advisory services providing the Administrator with accounting, legal, or consulting support (in particular accounting offices, law firms, or debt collection companies) – the Administrator provides the collected personal data of the Customer to the selected provider acting on behalf of the Administrator only when and to the extent necessary to achieve a specific purpose of data processing in accordance with this Privacy Policy.

Facebook Ireland Ltd. – the Administrator uses social media plugins from Facebook on the Online Store website (e.g. the Like button, Share button, or login using Facebook account details) and therefore collects and shares personal data of Customers using the Online Store website with Facebook Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) to the extent and in accordance with the privacy rules available here: https://www.facebook.com/about/privacy/

This data includes information about activities performed on the Online Store website, including information about the device used, visited websites, purchases, displayed advertisements, and the way the services are used – regardless of whether the Service User has a Facebook account or is logged in to Facebook.

§5.

PROFILING IN THE ONLINE STORE

The GDPR imposes an obligation on the Administrator to provide information about automated decision-making, including profiling referred to in Article 22(1) and (4) of the GDPR, and – at least in such cases – to provide meaningful information about the rules governing such decision-making, as well as the significance and the expected consequences of such processing for the data subject. Taking this into account, the Administrator provides information regarding possible profiling in this section of the Privacy Policy.

The Administrator may use profiling in the Online Store for direct marketing purposes; however, decisions made by the Administrator based on such profiling do not concern the conclusion or refusal to conclude a Sales Agreement, nor do they affect the ability to use Electronic Services available in the Online Store. The effects of using profiling in the Online Store may include, for example, granting a discount to a particular person, sending them a discount code, reminding them about unfinished purchases, sending suggestions for Products that may correspond to their interests or preferences, or offering better terms compared to the standard offer available in the Online Store. Despite the use of profiling, the individual always independently decides whether they wish to use the discount or improved terms received in this way and make a purchase in the Online Store.

Profiling in the Online Store involves the automatic analysis or prediction of a person's behaviour on the Online Store website, for example by adding a specific Product to the shopping cart, browsing a specific Product page in the Online Store, or analysing the history of previous purchases made in the Online Store. A prerequisite for such profiling is that the Administrator has access to the person's personal data in order to subsequently send them, for example, a discount code.

The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning that person or similarly significantly affects them.

§6.

RIGHTS OF THE DATA SUBJECT

Right of access, rectification, restriction, erasure, or data portability – the data subject has the right to request from the Administrator access to their personal data, rectification, erasure (“right to be forgotten”), or restriction of processing, and has the right to object to processing, as well as the right to data portability. Detailed conditions for exercising the above rights are set out in Articles 15–21 of the GDPR.

Right to withdraw consent at any time – where the Administrator processes personal data based on the consent provided by the data subject (pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR), the data subject has the right to withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.

Right to lodge a complaint with a supervisory authority – the data subject whose personal data is processed by the Administrator has the right to lodge a complaint with a supervisory authority in the manner and procedure specified by the provisions of the GDPR and Polish law, in particular the Act on the Protection of Personal Data. The supervisory authority in Poland is the President of the Personal Data Protection Office.

Right to object – the data subject has the right, at any time, to object – on grounds relating to their particular situation – to the processing of their personal data based on Article 6(1)(e) (public interest or tasks carried out in the public interest) or Article 6(1)(f) (legitimate interests pursued by the Administrator), including profiling based on these provisions. In such a case, the Administrator may no longer process the personal data unless they demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or grounds for establishing, exercising, or defending legal claims.

Right to object to direct marketing – where personal data is processed for the purposes of direct marketing, the data subject has the right to object at any time to the processing of their personal data for such marketing purposes, including profiling, to the extent that the processing is related to such direct marketing.

To exercise the rights referred to in this section of the Privacy Policy, the data subject may contact the Administrator by sending an appropriate written message or email to the Administrator’s contact address indicated at the beginning of the Privacy Policy, or by using the contact form available on the Online Store website.

§7.

COOKIES IN THE ONLINE STORE, USAGE DATA AND ANALYTICS

Cookies are small text files containing information that are sent by the server and stored on the side of the person visiting the Online Store website (e.g. on the hard drive of a computer, laptop, or on a smartphone memory card – depending on which device the visitor uses to access our Online Store). Detailed information regarding cookies, as well as their history, can be found, among others, here: http://en.wikipedia.org/wiki/HTTP_cookie.

The Administrator may process data contained in cookies when visitors use the Online Store website for the following purposes:

  • identifying Service Users as logged in to the Online Store and showing that they are logged in;
  • remembering Products added to the shopping cart in order to place an Order;
  • remembering data entered in Order Forms, surveys, or login details to the Online Store;
  • adapting the content of the Online Store website to the individual preferences of the Service User (e.g. regarding colours, font size, page layout) and optimising the use of the Online Store website;
  • conducting anonymous statistics showing how the Online Store website is used;
  • remarketing, i.e. analysing the behaviour of visitors to the Online Store through anonymous analysis of their activities (e.g. repeated visits to specific pages, keywords, etc.) in order to create their profile and provide them with advertisements tailored to their expected interests, including when they visit other websites within the advertising network of Google Ireland Ltd. and Facebook Ireland Ltd.

As a standard, most web browsers available on the market accept the storage of cookies by default. Everyone has the ability to determine the conditions for using cookies through their own browser settings. This means that cookies can be partially restricted (e.g. temporarily) or completely disabled. However, disabling cookies may affect some functionalities of the Online Store (for example, it may become impossible to complete the Order process through the Order Form due to Products not being remembered in the shopping cart during subsequent steps of placing an Order).

Browser settings regarding cookies are important from the perspective of consent to the use of cookies by our Online Store – according to applicable regulations, such consent may also be expressed through browser settings. If such consent is not provided, the browser settings regarding cookies should be appropriately changed.

Detailed information on changing cookie settings and deleting cookies independently in the most popular web browsers is available in the browser’s help section and on the following pages (click on the relevant link):

Chrome browser

Firefox browser

Internet Explorer browser

Opera browser

Safari browser

Microsoft Edge browser

Cookies used in the Online Store are not harmful either to visitors or to the computers/end devices they use. Therefore, we recommend that cookie support is not disabled in browsers.

The Online Store operated by the Administrator uses two types of cookies:

Session cookies (temporary cookies) – stored on Visitors’ devices until the browser session ends. After the session is closed, the information is permanently deleted from the Visitor’s device.

Persistent cookies – are not deleted when the browser is closed and may be used by the Administrator in the future.

Depending primarily on the purposes and legal basis for processing personal data collected through cookies, such data may be stored for the period indicated in Section §3 of the Privacy Policy.

Personal data collected through cookies relating to a visitor who is not a Customer will be stored until an objection is submitted. The Administrator may delete personal data if it has not been used for marketing purposes for 3 years, unless legal regulations require the Administrator to process such data for a longer period.

Some personal data may be stored for a longer period in the event that the Visitor has any claims against the Administrator, or for the purpose of pursuing claims by the Administrator or defending against claims (including claims by third parties), for the period of limitation specified by law, in particular by the Civil Code. In each case, the longer retention period shall apply.

Some cookies are created by third parties whose services we use, for example:

GOOGLE ANALYTICS AND GOOGLE SIGNALS

Google Analytics cookies are files used by Google to analyse how Users use the Service and to create statistics and reports regarding the operation of the Service. Google does not use the collected data to identify Users or combine this information in a way that enables identification. Detailed information regarding the scope and principles of data collection in connection with this service can be found here:
https://www.google.com/intl/en/policies/privacy/partners/

Another Google Analytics service used by the Administrator is Google Signals. Google Signals collects data from different devices from Users who are logged into their Google account on multiple devices and have ad personalisation enabled in their account, such as Gmail, YouTube, Google Play, and other Google platforms. This function enables the creation of personalised audience categories for Users by displaying relevant campaigns, using different devices, and analysing behaviour through specific reports that do not collect personally identifiable information. Detailed information regarding the scope and principles of data collection in connection with this service can be found here:
https://support.google.com/analytics/answer/7532985

GOOGLE ADS

Google Ads is a tool that enables the Administrator to measure the effectiveness of advertising campaigns, allowing analysis of data such as keywords or the number of unique Users. The Google Ads platform also allows the Administrator’s advertisements to be displayed to people who have previously visited the Service. Information about Google’s processing of data within this service is available here:
https://policies.google.com/technologies/ads

FACEBOOK ADS.

Facebook Ads are marketing and analytics tools available within the Facebook platform. Information collected through Facebook Ads is anonymous, meaning that it does not allow the Administrator to identify Users. However, please note that Facebook may combine the collected information with other information about Users visiting the Service, collected through their use of Facebook, and use it for its own purposes, including marketing purposes. Such activities by Facebook are no longer dependent on the Administrator. Detailed information regarding Facebook’s data processing can be found here:
https://www.facebook.com/help/443357099140264

FACEBOOK PIXEL

The Administrator may use the Facebook Pixel service in the Online Store provided by Facebook Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). This service helps the Administrator measure the effectiveness of advertisements, understand what actions visitors take on the Online Store website, and display personalised advertisements to those individuals. Detailed information about how Facebook Pixel works can be found here:
https://www.facebook.com/business/help/742478679120153

Management of Facebook Pixel activity is possible through advertising settings in the User’s Facebook account:
https://www.facebook.com/ads/preferences/


MICROSOFT CLARITY

Microsoft Clarity is an analytics tool that allows us to analyse activity on our website in order to improve it and adapt it to Users’ needs. Thanks to the information obtained, we can, for example, adjust our offer. Microsoft Clarity works by recording User behaviour on our website, allowing us to recreate this behaviour and observe which areas of our website are visited most frequently.

The data collected through this tool is anonymous (such as location, screen resolution, and online activity); however, the provider may combine it with data it has collected about you through the use of its browser and/or its services.

More information about this tool can be found here:
https://learn.microsoft.com/en-us/clarity/faq

Privacy information is available here:
https://privacy.microsoft.com/en-us/privacystatement

SALESMANAGO

SalesManago is a tool used to collect information about User behaviour. The SalesManago tool, provided by Benhauer sp. z o.o., analyses User activity in the Store, for example by checking what types of content are viewed and what purchases are made. Based on this information, it enables us to:

  • automatically personalise content displayed in advertisements;
  • customise the displayed offer;
  • analyse the effectiveness of advertising campaigns.

Detailed information regarding data processing by SalesManago is available here:
https://pomoc.salesmanago.pl/monitorowanie-kontaktow-zasada-dzialania-i-zakres-zbieranych-informacji/

§8.

FINAL PROVISIONS

The Online Store may contain links to other websites. The Administrator encourages Users to review the privacy policies established by those websites after accessing them. This Privacy Policy applies only to the Administrator’s Online Store.

We reserve the right to amend this Privacy Policy in the event of changes to applicable laws, guidelines issued by authorities responsible for supervising personal data protection processes, changes in the technology used to process personal data (if such changes affect the content of this document), as well as changes to the methods, purposes, or legal bases for processing personal data by us.

The current version of the Privacy and Cookies Policy was adopted and has been effective since 10 June 2025.