Privacy policy

Last updated: 18 August 2026

This Privacy Policy sets out the rules governing the processing of personal data in accordance with Regulation (EU) 2016/679 (GDPR).

Data controller

SKLEP OGRODNICZY ABC K. CHMIELEWSKI Z. WIŚNIEWSKI SPÓŁKA JAWNA

Nowomiejska 3A
16-300 Augustow
Poland

KRS: 0000067257
NIP: PL8460000543

hereinafter referred to as the “Controller”.

The Controller can be contacted by email at personaldata@bymatthew.cc.

The Controller is the controller of personal data within the meaning of the GDPR.

For matters concerning this Privacy Policy or the processing of personal data, you may contact us using the email address provided above.

Legal basis for processing personal data

The Controller processes personal data:

  • to properly provide services where this is necessary for the performance of a contract (Article 6(1)(b) GDPR);

  • to conduct marketing activities with the user’s prior consent (Article 6(1)(a) GDPR);

  • to comply with legal obligations to which the Controller is subject, such as tax and accounting obligations (Article 6(1)(c) GDPR);

  • to pursue the Controller’s legitimate interests (Article 6(1)(f) GDPR).

In particular:

  • direct marketing;

  • security and fraud prevention;

  • development of the business and services;

  • defence against claims.

Personal data processing period

The Controller retains personal data for the period necessary to fulfil the purposes specified in this Privacy Policy, but no longer than permitted by applicable law.

After this period, the data may be retained only to the extent necessary to comply with legal obligations or to establish, pursue, and defend claims.

Categories of data collected

The Controller collects, stores, and processes the following data:

  • identification data: first and last name, address, location at the time of purchase, telephone number, email address, and IP address;

  • device and software data;

  • information about the use of the website;

  • other data provided voluntarily when contacting customer service.

The Controller may process data obtained from the user together with data from publicly available sources only to the extent necessary to pursue the Controller’s legitimate interests.

Recipients of personal data

The Controller does not disclose users’ personal data except to:

  • public authorities or other entities where required by law;

  • payment providers and banks;

  • providers of IT, logistics, customer service, order fulfilment, and marketing services;

  • other entities where necessary for the performance of a contract.

Personal data may be transferred to entities providing services to the Controller, in particular:

  • Shopify and other providers of e-commerce, marketing, analytics, and communication services used to operate the Store.

These entities process data solely on the basis of appropriate agreements and in accordance with applicable law.

Transfers of data outside the European Economic Area

Personal data may be transferred outside the European Economic Area in connection with the use of third-party service providers.

In such cases, the data is protected in accordance with the GDPR, particularly through the use of Standard Contractual Clauses approved by the European Commission or other mechanisms ensuring an adequate level of data protection.

Profiling

The Controller may use profiling for marketing purposes, including tailoring content, advertisements, and offers to the user’s preferences.

Profiling is carried out using the tools and service providers used to operate the Store.

Profiling does not produce legal effects concerning the user or similarly significantly affect them within the meaning of the GDPR.

Rights of data subjects

The user has the right to:

  • access their data;

  • rectify their data;

  • erase their data;

  • restrict the processing of their data;

  • data portability;

  • object to processing;

  • withdraw consent at any time.

The user also has the right to lodge a complaint with the President of the Polish Personal Data Protection Office.

Changes to the Privacy Policy

The Controller reserves the right to amend this Privacy Policy at any time, particularly in the event of legal, technological, or organizational changes.

The user should regularly review the current version of the Privacy Policy while using the Store.