Privacy Policy
Privacy Policy
Latest update: 20/08/2026
This policy explains what we do with your personal data when you visit our store, buy from us, or contact us. We have tried to write it in plain language rather than legal boilerplate.
1. Who is responsible for your data
The controller of your personal data is:
- Retrobroker SP. Z O.O.
- Address: Sielska 45A, 10-801 Olsztyn, warmińsko-mazurskie, Poland
- VAT Identification Number (VAT ID): PL7393990456
- Email: [email protected]
We have not appointed a Data Protection Officer, because we are not required to. Data protection questions go to the address above and reach a person who can act on them.
2. What we collect
2.1 Data you give us
- Account data: your name, email address and password (stored only as a cryptographic hash — we never see it).
- Order data: delivery and billing address, the items you bought, order value and currency, and your order history.
- Contact data: the content of emails and messages you send us, including complaints, withdrawal notices and guarantee claims.
- Membership data, if you join the 1-UP Club: your subscription status, billing interval and renewal dates, and the records behind your guarantees, holds and savings.
2.2 Data we collect automatically
- Technical data: IP address, browser type and version, operating system, device type, language and region.
- Usage data: pages viewed, items viewed, time on page, referring pages, and errors encountered.
2.3 Data from others
- Payment data from Stripe: the result of a payment, the card brand and its last four digits, and a token referring to the stored card. Full card numbers never reach our systems.
- Marketplace order data: if you buy from us through an external marketplace such as OLX, Cdiscount or Rakuten, that marketplace passes us the order and delivery details we need to fulfil it.
- Carrier data: delivery status and tracking events from the carrier handling your parcel.
We do not buy personal data from data brokers, and we do not build advertising profiles.
3. Why we use it, and on what legal basis
| What we do | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Take and fulfil your order, deliver it, handle returns and guarantee claims | To give you what you paid for | Performance of a contract (b) |
| Create and run your account | To let you see orders, guarantees and membership | Performance of a contract (b) |
| Run the 1-UP Club membership and its billing | To provide the subscription you bought | Performance of a contract (b) |
| Issue invoices and keep accounting records | Tax and accounting law obliges us | Legal obligation (c) |
| Answer your emails and complaints | To resolve your issue and evidence what was agreed | Contract (b) and legitimate interests (f) |
| Keep the site secure, prevent fraud and abuse of returns | To protect the shop and honest customers | Legitimate interests (f) |
| Measure how the site is used and fix errors | To keep the site working and improve it | Consent (a) for non-essential analytics cookies; otherwise legitimate interests (f) |
| Send marketing email | To tell you about items you might want | Consent (a) — and you can withdraw it at any time |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded that the processing is what you would reasonably expect and does not override your interests. Ask us and we will explain the assessment for any specific case.
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.
4. Who we share it with
We share personal data only where there is a reason to, and only as much as that reason needs:
- Stripe — payment processing. Stripe acts as an independent controller for card data under its own terms.
- Delivery carriers and shipping brokers (including GlobKurier and the carriers it books) — the name, address and contact details needed to deliver your parcel.
- Marketplaces (OLX, Cdiscount, Rakuten) — where your order came through one of them.
- Hosting, infrastructure and email providers — who process data on our instructions to keep the shop running.
- Analytics and error monitoring (Google Analytics, Sentry) — usage and error data, so we can see what is broken and what is used.
- Our accountants and, where necessary, legal advisers.
- Public authorities — where the law requires it, and only to the extent it requires.
Providers acting on our instructions are bound by data processing agreements that stop them using your data for their own purposes.
We never sell your personal data.
5. Sending data outside the European Economic Area
Some of our providers process data outside the EEA, including in the United States. Where that happens, the transfer is protected by an adequacy decision of the European Commission, or by the European Commission's Standard Contractual Clauses together with any additional safeguards the situation requires. You can ask us for details of the safeguards applying to a specific transfer.
6. How long we keep it
- Order and invoice records: for as long as tax and accounting law requires — in Poland, 5 years from the end of the calendar year in which the tax became due.
- Account data: while your account is open, and then up to 12 months after you close it, so an account reopened by mistake is not lost.
- Guarantee and membership records: for the life of the guarantee or membership, plus the limitation period for any claim arising from it.
- Correspondence: normally 3 years, and longer where it relates to an unresolved dispute.
- Analytics data: up to 14 months.
- Marketing consent records: until you withdraw consent, plus proof of what you consented to and when.
When a retention period ends we delete the data or anonymise it irreversibly so that it can no longer be linked to you.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectify data that is inaccurate or incomplete.
- Erase your data — see our separate Data Deletion Policy for how, and for the limits.
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
- Object to processing based on legitimate interests. Where you object to direct marketing, we stop — always, and without argument.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller where technically feasible.
- Withdraw consent at any time, where we rely on consent. This does not affect processing already carried out.
To exercise any of these, email [email protected]. We respond within one month, and may extend by two further months for genuinely complex requests — in which case we will tell you inside the first month. We may ask you to confirm your identity, but only enough to be sure we are not disclosing your data to someone else. Exercising these rights is free, unless a request is manifestly unfounded or excessive.
Right to complain. If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to a supervisory authority. In Poland this is:
Prezes Urzędu Ochrony Danych Osobowych (UODO) ul. Stawki 2 00-193 Warszawa, Poland
If you live in another EU country, you may complain to your own national authority instead.
8. Cookies and similar technologies
We use cookies and comparable storage to keep your basket and session working, remember your language, region and currency, keep the site secure, and — where you consent — measure how the site is used.
Cookies that are strictly necessary for the shop to function do not require consent. Analytics and any non-essential cookies are set only if you agree, and you can change or withdraw that choice at any time through our cookie settings or your browser. Blocking essential cookies will break checkout.
9. Security
We protect your data with encryption in transit (HTTPS), access controls limiting who on our side can see what, hashed passwords, and card handling delegated entirely to Stripe so that card numbers never reach us.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the supervisory authority as the GDPR requires.
10. Children
Our store is not aimed at children, and you must be 18 to buy from us. We do not knowingly collect data from children under 16. If you believe a child has given us personal data, email [email protected] and we will delete it.
11. Other websites
Our pages sometimes link to other websites — a manufacturer, a carrier's tracking page, a marketplace. We do not control them and are not responsible for their privacy practices. Read their policies before giving them your data.
12. Changes to this policy
We may update this policy. The date of the latest revision is at the top of this page. Where a change materially affects your rights, we will tell you rather than quietly editing the text.
13. Contact
Any question about this policy, or about your data, goes to [email protected]. We do not operate a phone line, so email reaches us fastest.