Privacy Policy
CRYSTALLOVE STORE PRIVACY POLICY
1. GENERAL INFORMATION
This Privacy Policy sets out the rules for the processing and protection of personal data of Users using the online store available at www.crystallove.pl. The document is for informational purposes and has been prepared in accordance with the Regulation of the European Parliament and of the Council (EU) 2016/679 ("GDPR") and the provisions on privacy in electronic communications (ePrivacy).
2. DATA ADMINISTRATOR
The administrator of your personal data is: GET GLOWING Magdalena Babska ul. R. Felińskiego 1/U1, 81-578 Gdynia NIP: 5862115749, REGON: 222115659. Contact: sklep@crystallove.pl. The Administrator has not appointed a Data Protection Officer.
3. HOW WE OBTAIN DATA
We obtain personal data: directly from you:
- when placing an order
- when creating an account
- via the contact form
- when subscribing to the newsletter
automatically:
- via cookies
- via analytical and marketing tools
- via tracking technologies (e.g., advertising pixels)
- via server logs (recorded by the IT systems maintaining the store)
4. SCOPE AND PURPOSES OF DATA PROCESSING
4.1 Order fulfillment and customer account
- Scope: first name, last name, address, e-mail, phone
- Purpose: fulfillment of the sales contract, account management, and participation in the CRYSTALLOVE Club Loyalty Program (point accrual and redemption).
- Basis: Art. 6(1)(b) GDPR
4.2 Legal obligations
- Scope: transactional data
- Purpose: tax and accounting settlements
- Basis: Art. 6(1)(c) GDPR
4.3 Customer service and contact
- Scope: data provided in correspondence
- Purpose: responding to inquiries, handling complaints
- Basis: Art. 6(1)(f) GDPR
- Legitimate interest: ensuring high-quality service and protection against claims
4.4 Marketing and newsletter
- Scope: e-mail address
- Purpose: sending commercial information, including the latest offers and reminders about uncompleted purchases (abandoned cart).
- Basis: Art. 6(1)(a) GDPR, in conjunction with the provisions of the Act on the Provision of Services by Electronic Means and the Telecommunications Law (requirement of consent to use communication channels). Newsletter subscription may take place in a double opt-in model (confirmation of subscription via e-mail). You can withdraw your consent at any time via the link in the message or by contacting us.
4.5 Personalization and analytics
- Scope: data on website activity
- Purpose: adapting content and offers, analyzing behavior
- Basis: Art. 6(1)(f) GDPR
- Legitimate interest: store development and sales optimization
4.6 AI Assistant (Chatbot)
- Scope: data provided voluntarily during a conversation with the AI Assistant on the website.
- Purpose: providing automatic, immediate answers to user inquiries.
- Basis: Art. 6(1)(f) GDPR.
- Legitimate interest: automating customer service and improving the quality of services provided. We warn against providing sensitive data in the chat.
5. SOCIAL MEDIA AND JOINT CONTROL
We maintain brand profiles on social media (e.g., Facebook, Instagram, TikTok). If you visit our profiles, interact with them (e.g., leave a comment, like, send a message), we process your data to build brand image and communicate with you (our legitimate interest – Art. 6(1)(f) GDPR). In terms of statistics and advertising tools provided by these platforms, we act as so-called Joint Controllers of data together with the operators of these services (e.g., Meta Platforms Ireland Ltd.).
6. PROFILING
We use profiling for marketing purposes, which involves analyzing your activity (e.g., viewed products, purchase history, clicks). Profiling:
- does not produce legal effects
- does not affect product prices
- is used solely to adapt content and advertisements. You have the right to object to profiling.
7. RECIPIENTS OF DATA
Data may be transferred to:
- e-commerce platform operator (Shopify Inc.)
- courier and logistics companies
- marketing and analytical service providers
- accounting office
- IT entities
- TrustMate SA, based in Wrocław, a provider of a system for collecting and verifying post-transaction opinions (to send an invitation to leave a review).
The above entities process data based on data processing agreements (Art. 28 GDPR). In the case of electronic payments, your data is also transferred to independent data controllers - payment operators (e.g., PayU, Przelewy24, Stripe or systems embedded in Shopify), for proper and secure transaction authorization. Your invoice data may also be transferred to the National e-Invoice System (KSeF), in accordance with applicable tax law.
8. TRANSFER OF DATA OUTSIDE THE EEA
Due to the use of the Shopify platform and marketing tools, data may be transferred outside the European Economic Area (e.g., USA, Canada). This transfer primarily takes place on the basis of European Commission implementing decisions stating an adequate level of protection (e.g., the Data Privacy Framework program for certified entities from the USA and based on the decision concerning Canada). In the absence of such a decision for a specific entity, data transfer is based on standard contractual clauses approved by the European Commission.
9. DATA RETENTION PERIOD
We store data:
- for the duration of the contract and order fulfillment
- for the period required by law (e.g., 5 years – accounting)
- until consent is withdrawn (marketing)
- until a successful objection is raised
10. YOUR RIGHTS
You have the right to:
- access data
- rectify data
- erase data
- restrict processing
- object to processing
- data portability
- withdraw consent. You also have the right to lodge a complaint with the President of the Personal Data Protection Office.
11. COOKIES AND TRACKING TECHNOLOGIES
The website uses cookies and similar technologies to ensure the proper functioning of the store, traffic analysis, and marketing activities.
11.1 What are cookies
Cookies are small text files saved on your end device (computer, smartphone) that allow your device to be recognized and the page to be displayed correctly.
11.2 Types of cookies used
a) Necessary (technical) They ensure the proper functioning of the store (e.g., shopping cart, login). They do not require user consent.
b) Analytical They allow analysis of how the website is used and improvement of its operation. c) Marketing They enable the display of personalized advertisements and remarketing.
11.3 Tools used
Within the store, we use the following tools:
- Google Analytics – traffic and statistics analysis
- Meta Ads (Facebook Pixel) – advertising and remarketing
- Shopify – store operation and functionalities.
These tools may use their own cookies.
11.4 Cookie retention period
Cookies may be stored:
- sessionally (until the browser is closed)
- permanently (for several months or years – depending on the function)
11.5 Managing cookies
During your first visit to the website, a cookie banner is displayed allowing you to:
- express consent
- reject optional cookies
- manage preferences. You can also change your cookie settings in your browser at any time.
11.6 Consequences of disabling cookies
Disabling cookies may affect:
- shopping cart operation
- login capability
- correct display of the page
11.7 Server logs
Using the website involves sending requests to the server where the store is located. Each such request is saved in the server logs. Logs include, among other things, IP address, server date and time, information about the web browser and operating system. This data is not associated with specific individuals using the website and serves solely as auxiliary material for administrative purposes and to ensure security.
12. VOLUNTARINESS OF PROVIDING DATA
Providing data is voluntary, however:
- lack of data prevents order fulfillment
- lack of marketing consent prevents receiving offers
13. DATA SECURITY
We apply appropriate technical and organizational measures, including:
- SSL encryption
- IT system security
- restricted access to data
14. POLICY CHANGES
We reserve the right to update the Privacy Policy. The current version will be published on the store's website.
15. CONTACT
For matters related to data protection, you can contact us: e-mail: sklep@crystallove.pl tel.: +48 575 136 119
We care about your privacy with the same attention with which we create our products. Version valid from: 2026-05-20
