Privacy & Cookies Policy
Who We Are
Controller: Rostyslav Letunov (sole trader, indywidualna działalność gospodarcza)
Registered address: ul. Chrystiana Piotra Aignera 6A/242, 00-710 Warszawa, Poland
NIP: 1182292752 | REGON: 529948880
Privacy contact: nothing.roastery@gmail.com
Personal Data We Collect
We collect and process only the data necessary to run our business:
Contact / enquiry form – your name, email address and any information you include in the message.
Newsletter sign-up – your email address.
Checkout & customer account – name, billing and shipping address, email, phone (optional), order details and payment confirmation.
Automatic logs & analytics – IP address, browser type, device identifiers, pages visited, time spent on the site.
We do not intentionally collect special-category data (e.g. health information or children’s data).
Purposes and Lawful Bases
Responding to enquiries – Legitimate interest (running our business and assisting customers).
Processing and delivering orders – Contract (necessary to fulfil your order).
Sending marketing newsletters – Consent (you choose to opt in and can unsubscribe at any time).
Running analytics and improving the site –
Consent for non-essential cookies;
Legitimate interest for aggregated, anonymised server logs.
Preventing fraud and ensuring security – Legitimate interest.
Sharing & International Transfers
We share data only with trusted processors who act on our instructions:
Hosting & platform: Squarespace, Inc. (USA – protected by EU Standard Contractual Clauses, “SCCs”).
Payments: Stripe Payments Europe Ltd. (EU / USA – SCCs).
Email marketing: Squarespace Email Campaigns; Mailchimp (USA – SCCs).
Analytics & tracking: Squarespace Analytics, Google Analytics 4, Meta/Facebook Pixel, Hotjar.
Embedded media: Instagram feeds, Google Maps.
When providers are outside the EEA we rely on SCCs or equivalent safeguards.
Cookies & Similar Technologies
Our site uses both Squarespace’s own cookies and third-party cookies.
1. Necessary cookies (always active)
• Enable core features such as secure log-in, shopping cart and form submission.
2. Analytics cookies (require consent)
• Squarespace Analytics cookies (e.g. ss_cid, ss_cvr).
• Google Analytics (_ga etc.).
• Hotjar session cookies.
3. Marketing / advertising cookies (require consent)
• Meta/Facebook Pixel (_fbp).
• Google Analytics remarketing features.
4. Preference / functionality cookies
• Remember dismissal of pop-ups, announcement bars and similar site settings.
Cookie banner
A banner appears on your first visit. By clicking Accept you consent to Analytics and Marketing cookies. If you decline or close the banner, only Necessary cookies load. At present Squarespace does not provide an on-page settings panel after dismissal; you can, however, delete or block cookies any time via your browser settings.
Data Retention
Order and invoice records: kept for 6 years in line with Polish accounting law.
Newsletter subscriber list: retained until you unsubscribe or we receive a bounce.
Enquiry emails: deleted 12 months after our last correspondence.
Analytics data: retained up to 26 months (Google Analytics default) or sooner on request.
Your Rights
Under the GDPR you can:
Access your personal data.
Correct inaccurate or incomplete data.
Request deletion (“right to be forgotten”).
Restrict or object to processing.
Request a copy of your data in a portable format.
Withdraw consent at any time (for newsletters and optional cookies).
Send requests to nothing.roastery@gmail.com
You may also lodge a complaint with the Polish supervisory authority: President of the Personal Data Protection Office (UODO).
Security Measures
Full-site HTTPS with TLS encryption.
Data stored in Squarespace ISO-certified data centres.
Owner-only admin access secured by strong password and two-factor authentication.
Payment data handled exclusively by Stripe; we never store full card details.
No automated decision-making that produces legal or similarly significant effects.
Changes to This Policy
We may update this notice to reflect legal or operational changes. Any material updates will be posted on this page and are effective once published. Continued use of the site indicates acceptance of the revised terms.
Questions?
Write to us at nothing.roastery@gmail.com – we’re happy to help.
Last updated: 5 June 2025