Skip to content
Free shipping over PLN 399 · Plants shipped safely

Your data

Privacy policy

A transparent outline of the information needed for accounts, orders and customer contact.

A No Empty Pots plant representing data privacy

Version: 1.0 · Updated: September 7, 2026

Controller and contact

The controller of personal data of visitors and customers of No Empty Pots at noemptypots.com is:

Karolina Kuczewska — No Empty Pots
Hallera 12/2 55-010 Wrocław

For privacy enquiries and to exercise your rights, contact: contact@noemptypots.com

Data, purposes and legal bases

Accounts and orders: email address, name, phone number, delivery and billing addresses, optional business and tax details, login details and purchase, payment, delivery, return and complaint history. We use this information to provide accounts, fulfil orders and take steps at your request before a contract — Article 6(1)(b) GDPR.

Legal obligations: we process transaction and accounting records to meet tax, accounting and consumer-law obligations — Article 6(1)(c) GDPR in conjunction with applicable tax, accounting and consumer legislation.

Correspondence and claims: we use contact details, correspondence and case records to answer enquiries and establish, exercise or defend legal claims. The basis is Article 6(1)(f) GDPR — our legitimate interests in handling enquiries and protecting our rights; contractual matters also rely on point (b), and legal obligations on point (c).

We record the time, language and versions of documents accepted at checkout and newsletter consent information to document transactions and consent. The bases are GDPR accountability obligations — Article 6(1)(c) — and our legitimate interests in demonstrating contract terms and protecting claims — point (f).

Security, IP address and device

When you use the site, we record a basic technical log: IP address, request time, shortened page or service address without parameters, response status and browser information. This helps diagnose failures and prevent abuse — Article 6(1)(f) GDPR, our legitimate interest in operating a secure shop. It does not require consent to optional analytics.

When you create an account or initiate payment, we record your IP address, browser information, approximate country of connection and an event record linked to the account or order. We use this to detect abuse and protect the shop — Article 6(1)(f) GDPR, our legitimate interest in security.

Automated decisions

Our analytics and security signals, including device recognition, are not used to make decisions based solely on automated processing that produce legal or similarly significant effects on you within Article 22 GDPR. Security signals may flag an event for additional review by an authorised person. The payment provider applies its own payment authorisation and fraud prevention rules.

Newsletter

If you subscribe, we use your email address and chosen language to send news, care tips, restock announcements and No Empty Pots offers. The basis is voluntary consent — Article 6(1)(a) GDPR and Article 398 of the Polish Electronic Communications Law.

You may withdraw consent at any time using the unsubscribe link in an email or by contacting us. Withdrawal does not affect earlier lawful processing. We also use subscription status to check welcome-bonus eligibility under the offer terms. Account and order service messages do not require a newsletter subscription.

Optional device recognition

Only after separate consent do we run the locally bundled FingerprintJS library to analyse selected browser and device characteristics. Our server converts the result into an HMAC device key. We do not store the raw result or components, or send data to Fingerprint Pro. A key suggests a probably returning device; it does not establish identity and is not used for advertising.

Linking a device to visits also requires analytics consent. Device recognition consent alone does not create a visitor identifier used to analyse browsing history. It does create a pseudonymous device key for subsequent recognition for the purposes described here. Without enhanced analytics consent, we do not link that key to the shop browsing history. At registration and checkout, the key may help detect multiple accounts using a device in a separate security register, without automatically refusing purchases. Optional recognition relies on Article 6(1)(a) GDPR and Article 399 of the Polish Electronic Communications Law.

Device mappings are deleted after 180 days without recognition. Device keys in events follow event retention, at most 180 days, and 90 days in the security register. Withdrawing consent in Privacy settings removes mappings and optional device data associated with the previous consent.

Cookies and our analytics

Analytics and device recognition are independent choices. We store a versioned preference receipt in browser localStorage, valid for 180 days. Once expired, the choice no longer permits optional collection and the record is removed the next time the site starts. localStorage does not delete data automatically while you are away. The browser sends its token to the server to verify validity and consent categories. This record remembers and enforces privacy choices, including withdrawal; it is not used to recognise visitors in basic statistics. Enhanced analytics uses separate random identifiers. Basic statistics measure and improve shop operation through aggregate counters based on server operations and limited events sent by the browser. The counter layer receives only the event, day, shop channel, product or public page, language, currency and count or value. It receives no visitor or session identifier, account data, IP address or device characteristics. Connection and security data are processed separately under “Security, IP address and device”.

Search statistics come from server and browser search operations without a persistent visitor identifier. We keep aggregate counts for phrases restricted to the catalog vocabulary, rejecting unknown words, addresses, numbers and identifiers. These counts do not cover all traffic. Enhanced aggregates without identifiers are produced hourly and remain after raw events are deleted.

The “Privacy settings” link in the footer lets you enable or disable enhanced analytics. It is off by default. Browsing the site or closing the banner does not grant consent. We store your choice for 180 days and its receipt, version, language and dates for 730 days to demonstrate consent — Article 6(1)(c) in conjunction with Article 7(1) GDPR.

The shop uses cookies and browser storage for the session, cart and language choice. Sessions last up to 30 days, language preferences up to one year, and local storage remains until overwritten or deleted. Storage access necessary for a requested service does not require consent under Article 399(3) of the Polish Electronic Communications Law. Personal data is processed to fulfil the contract or protect the service — Article 6(1)(b) or (f) GDPR.

Basic statistics come from server operations and limited browser events. We store daily totals for page types and product views, transitions between page types, products visible for at least 2 seconds, gallery opens, filter and sort use, searches, and checkout stages and error categories. Form field values are not stored. Counters also cover cart activity and sales, with product, language and currency information. This layer does not store visit histories, visitor, session or customer identifiers, IP addresses or device characteristics and uses no analytics cookies. Security logs are separate.

With consent, we use our own enhanced analytics: a random visitor identifier (analytics_vid cookie, up to 180 days) and session identifier (analytics_sid, 30 minutes of inactivity). We record public page views, cart and purchase events, broad traffic sources, approved campaign codes and browser, operating system and viewport categories. We do not store IP addresses, contact details, customer identifiers or search text. A separate technical key links confirmed purchases without storing order numbers in analytics events. The basis is consent — Article 6(1)(a) GDPR and Article 399 of the Polish Electronic Communications Law.

Withdrawing consent stops enhanced analytics and removes its cookies and events linked to the withdrawn consent. If the connection fails, withdrawal is retried on the next visit. After events are deleted, aggregate statistics remain without visitor identifiers, session identifiers or device keys. Events are deleted after 180 days by a daily cleanup task. You can also contact us to withdraw consent; withdrawal does not affect the lawfulness of earlier processing.

Cookies and browser storage — overview
TechnologyPurpose and conditionValidity
Shop sessionAccount and cart functionalityUp to 30 days
Language preferenceRemember the selected languageUp to one year
Privacy preferences (localStorage)Remember and enforce choicesValid for 180 days; expired record removed on the next visit
analytics_vidVisitor — with analytics consentUp to 180 days
analytics_sidSession — with analytics consent30 minutes of inactivity
FingerprintJS / device keyRecognition with separate consent; server-side keyMapping up to 180 days after last recognition

Who receives data

Authorised people have access to data. We use processors acting on our behalf, particularly hosting, storage, website security and email providers, to the extent needed for those services. Our analytics runs on the shop infrastructure.

Our payment provider, Stripe, receives information needed for payments and fraud prevention; our carrier, InPost, receives contact and delivery details needed to deliver your order. We do not store full payment card details.

Using the pickup-point map shares your IP address and browser information with the map provider. If you activate nearby-point search and consent to location access, your browser may share your location with the InPost widget to show nearby points. This optional use relies on consent under Article 6(1)(a) GDPR; you can revoke browser permission in its settings. Our backend does not receive or store your current device location from this feature. We store the selected pickup point, including its coordinates, with the order under the order fulfilment and retention rules. You can select a point manually without sharing your location.

Accounting and legal service providers and authorised public bodies may also receive data. Providers process data on our behalf or as independent controllers for their own obligations.

Transfers outside the EEA

Using international IT providers may involve transfers outside the European Economic Area, particularly to the United States.

Such transfers require a basis under Chapter V GDPR: a European Commission adequacy decision, including the EU–US Data Privacy Framework only for a certified recipient covered by it, or standard contractual clauses with the required safeguards. Contact us for details and a copy of the safeguards for a specific transfer.

How long data is kept

Account data is kept while the account exists. Order, return and correspondence records are kept while the matter is handled and then as necessary for legal obligations and claims until the applicable limitation periods expire. Closing an account does not delete records we are legally required to retain.

Tax records are generally retained for five years from the end of the calendar year in which the tax payment was due. The period may be extended where the law requires it, for example due to suspension or interruption of the limitation period.

Newsletter mailing data is kept until consent is withdrawn or the newsletter ends. After unsubscribing, a limited consent and withdrawal record is retained as necessary to demonstrate compliance and defend claims until the applicable limitation period expires, without further marketing mailings.

Account and order security events, including IP and device information, are kept for 90 days and then automatically deleted. Requests to erase data are assessed independently of this maximum period. Evidence necessary for a specific dispute may be retained until it ends and the relevant legal periods expire.

Retention of consented events in our analytics: 180 days

Website technical logs in Render are retained for: 7 days (technical logs in Render)

Your rights

Under the conditions set out in the GDPR, you can request access and a copy of your data, rectification, erasure or restriction. Portability applies to data you provided that is processed automatically on the basis of consent or a contract.

You may object to processing based on legitimate interests on grounds relating to your particular situation. You can object to direct marketing at any time. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Contact the address above to exercise your rights. If we have reasonable doubts, we may request information necessary to verify your identity. We normally respond within one month; where the GDPR permits, this may be extended by two months, with notice and reasons.

You may complain to the President of the Polish Personal Data Protection Office (uodo.gov.pl) or a competent EU supervisory authority, particularly where you habitually reside, work or consider an infringement occurred.

Is providing data required?

Providing data is voluntary, but fields marked as required are necessary to handle the order, account or enquiry. Without them we cannot provide that service; billing data may be required by law. An account is not required to purchase. Consent to newsletters, enhanced analytics or device recognition is not a condition of creating an account or placing an order.

We primarily receive data from you and your browser when you use the shop. We also receive payment and delivery status information from the payment provider and carrier.

No Empty Pots club

10%

An automatic welcome bonus from PLN 149 for new customers subscribed to the newsletter.

Create an account and get 10% off your first order.

Join the newsletter using your account email. On your first order over PLN 149, the discount is applied automatically — no code needed.

Create an account