Your data
Privacy policy
A transparent outline of the information needed for accounts, orders and customer contact.

Version: 1.0 · Updated: September 7, 2026
Controller and contact
The controller of personal data of visitors and customers of No Empty Pots at noemptypots.com is:
Karolina Kuczewska — No Empty Pots
Hallera 12/2
55-010 Wrocław
For privacy enquiries and to exercise your rights, contact: contact@noemptypots.com
Data, purposes and legal bases
Accounts and orders: email address, name, phone number, delivery and billing addresses, optional business and tax details, login details and purchase, payment, delivery, return and complaint history. We use this information to provide accounts, fulfil orders and take steps at your request before a contract — Article 6(1)(b) GDPR.
Legal obligations: we process transaction and accounting records to meet tax, accounting and consumer-law obligations — Article 6(1)(c) GDPR in conjunction with applicable tax, accounting and consumer legislation.
Correspondence and claims: we use contact details, correspondence and case records to answer enquiries and establish, exercise or defend legal claims. The basis is Article 6(1)(f) GDPR — our legitimate interests in handling enquiries and protecting our rights; contractual matters also rely on point (b), and legal obligations on point (c).
We record the time, language and versions of documents accepted at checkout and newsletter consent information to document transactions and consent. The bases are GDPR accountability obligations — Article 6(1)(c) — and our legitimate interests in demonstrating contract terms and protecting claims — point (f).
Security, IP address and device
When you use the site, we record a basic technical log: IP address, request time, shortened page or service address without parameters, response status and browser information. This helps diagnose failures and prevent abuse — Article 6(1)(f) GDPR, our legitimate interest in operating a secure shop. It does not require consent to optional analytics.
When you create an account or initiate payment, we record your IP address, browser information, approximate country of connection and an event record linked to the account or order. We use this to detect abuse and protect the shop — Article 6(1)(f) GDPR, our legitimate interest in security.
Automated decisions
Our analytics and security signals, including device recognition, are not used to make decisions based solely on automated processing that produce legal or similarly significant effects on you within Article 22 GDPR. Security signals may flag an event for additional review by an authorised person. The payment provider applies its own payment authorisation and fraud prevention rules.
Optional device recognition
Only after separate consent do we run the locally bundled FingerprintJS library to analyse selected browser and device characteristics. Our server converts the result into an HMAC device key. We do not store the raw result or components, or send data to Fingerprint Pro. A key suggests a probably returning device; it does not establish identity and is not used for advertising.
Linking a device to visits also requires analytics consent. Device recognition consent alone does not create a visitor identifier used to analyse browsing history. It does create a pseudonymous device key for subsequent recognition for the purposes described here. Without enhanced analytics consent, we do not link that key to the shop browsing history. At registration and checkout, the key may help detect multiple accounts using a device in a separate security register, without automatically refusing purchases. Optional recognition relies on Article 6(1)(a) GDPR and Article 399 of the Polish Electronic Communications Law.
Device mappings are deleted after 180 days without recognition. Device keys in events follow event retention, at most 180 days, and 90 days in the security register. Withdrawing consent in Privacy settings removes mappings and optional device data associated with the previous consent.
Who receives data
Authorised people have access to data. We use processors acting on our behalf, particularly hosting, storage, website security and email providers, to the extent needed for those services. Our analytics runs on the shop infrastructure.
Our payment provider, Stripe, receives information needed for payments and fraud prevention; our carrier, InPost, receives contact and delivery details needed to deliver your order. We do not store full payment card details.
Using the pickup-point map shares your IP address and browser information with the map provider. If you activate nearby-point search and consent to location access, your browser may share your location with the InPost widget to show nearby points. This optional use relies on consent under Article 6(1)(a) GDPR; you can revoke browser permission in its settings. Our backend does not receive or store your current device location from this feature. We store the selected pickup point, including its coordinates, with the order under the order fulfilment and retention rules. You can select a point manually without sharing your location.
Accounting and legal service providers and authorised public bodies may also receive data. Providers process data on our behalf or as independent controllers for their own obligations.
Transfers outside the EEA
Using international IT providers may involve transfers outside the European Economic Area, particularly to the United States.
Such transfers require a basis under Chapter V GDPR: a European Commission adequacy decision, including the EU–US Data Privacy Framework only for a certified recipient covered by it, or standard contractual clauses with the required safeguards. Contact us for details and a copy of the safeguards for a specific transfer.
How long data is kept
Account data is kept while the account exists. Order, return and correspondence records are kept while the matter is handled and then as necessary for legal obligations and claims until the applicable limitation periods expire. Closing an account does not delete records we are legally required to retain.
Tax records are generally retained for five years from the end of the calendar year in which the tax payment was due. The period may be extended where the law requires it, for example due to suspension or interruption of the limitation period.
Newsletter mailing data is kept until consent is withdrawn or the newsletter ends. After unsubscribing, a limited consent and withdrawal record is retained as necessary to demonstrate compliance and defend claims until the applicable limitation period expires, without further marketing mailings.
Account and order security events, including IP and device information, are kept for 90 days and then automatically deleted. Requests to erase data are assessed independently of this maximum period. Evidence necessary for a specific dispute may be retained until it ends and the relevant legal periods expire.
Retention of consented events in our analytics: 180 days
Website technical logs in Render are retained for: 7 days (technical logs in Render)
Your rights
Under the conditions set out in the GDPR, you can request access and a copy of your data, rectification, erasure or restriction. Portability applies to data you provided that is processed automatically on the basis of consent or a contract.
You may object to processing based on legitimate interests on grounds relating to your particular situation. You can object to direct marketing at any time. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
Contact the address above to exercise your rights. If we have reasonable doubts, we may request information necessary to verify your identity. We normally respond within one month; where the GDPR permits, this may be extended by two months, with notice and reasons.
You may complain to the President of the Polish Personal Data Protection Office (uodo.gov.pl) or a competent EU supervisory authority, particularly where you habitually reside, work or consider an infringement occurred.
Is providing data required?
Providing data is voluntary, but fields marked as required are necessary to handle the order, account or enquiry. Without them we cannot provide that service; billing data may be required by law. An account is not required to purchase. Consent to newsletters, enhanced analytics or device recognition is not a condition of creating an account or placing an order.
We primarily receive data from you and your browser when you use the shop. We also receive payment and delivery status information from the payment provider and carrier.