Privacy Policy of the Magna Maa Online Store
Effective date: [27.06.2026r]
1. Controller of personal data
- The controller of personal data processed in connection with the online store available at https://magnamaa.com/ (the “Store”) is MAGNA spółka z ograniczoną odpowiedzialnością with its registered office in Poznań, Poland, at ul. Grudziądzka 3, 60-446 Poznań, entered in the National Court Register under KRS number 0001218930, NIP 7812103917, REGON 543787287 (the “Controller”).
- You can contact the Controller by e-mail: hello@magnamaa.com, by post at the address above and by telephone: [insert telephone number].
- The Controller has not appointed a Data Protection Officer. In all matters concerning personal data, please contact the Controller using the contact details above. If a Data Protection Officer is appointed, this section should be updated.
2. Scope of this Privacy Policy
- This Privacy Policy explains how the Controller processes personal data of Store users, Customers, newsletter subscribers, persons contacting the Store and persons whose data is processed in connection with Orders, payments, delivery, complaints and returns.
- The Store operates on the WooCommerce platform integrated with WordPress and uses external service providers necessary to run the Store, process payments, deliver Orders and maintain the website.
3. What personal data we process
Depending on how you use the Store, we may process the following categories of personal data:
- identification data: name, surname, company name, tax identification number where provided;
- contact data: e-mail address, telephone number, billing address, delivery address;
- Order data: ordered Products, size, configuration, custom order details, price, payment status, delivery method, complaint or return information;
- payment data: payment status, transaction identifier, payment method and information provided by PayU or Stripe; we do not store full payment card numbers;
- account data: login, password hash, account settings and order history if you create an account;
- communication data: content of messages, complaint correspondence, return forms and customer service history;
- technical data: IP address, browser data, device data, cookies and similar identifiers, logs and website activity data;
- marketing data: newsletter consent, marketing preferences and interaction with marketing messages if such services are used.
4. Purposes and legal bases of processing
| Purpose | Legal basis under GDPR | Examples of data |
|---|---|---|
| Creating and managing a Customer account | Performance of a contract or taking steps prior to entering into a contract – Article 6(1)(b) GDPR | Name, e-mail address, account credentials, order history |
| Processing Orders and performing the Sales Agreement | Article 6(1)(b) GDPR | Name, address, e-mail, phone, ordered Products, custom order details |
| Handling payments | Article 6(1)(b) GDPR and legitimate interest – Article 6(1)(f) GDPR | Transaction status, transaction ID, payment method, billing data |
| Delivery of Products | Article 6(1)(b) GDPR | Name, address, phone, e-mail, delivery details |
| Issuing invoices and keeping accounting records | Legal obligation – Article 6(1)(c) GDPR | Billing data, tax number, transaction data |
| Handling complaints, returns and withdrawal statements | Article 6(1)(b), Article 6(1)(c) and Article 6(1)(f) GDPR | Order data, correspondence, bank account if needed for refund |
| Customer service and responding to inquiries | Legitimate interest – Article 6(1)(f) GDPR, or Article 6(1)(b) GDPR where the inquiry relates to a contract | Contact details and message content |
| Sending newsletter or marketing communication | Consent – Article 6(1)(a) GDPR; legitimate interest may apply to direct marketing in permitted cases | E-mail address, consent record, marketing preferences |
| Website analytics, statistics and improvement of the Store | Consent – Article 6(1)(a) GDPR where required for optional cookies; legitimate interest – Article 6(1)(f) GDPR for basic non-invasive statistics | Cookie identifiers, IP address, device and activity data |
| Advertising, remarketing and measuring ad effectiveness | Consent – Article 6(1)(a) GDPR where required | Cookie identifiers, event data, website activity |
| Security, fraud prevention and protection of claims | Legitimate interest – Article 6(1)(f) GDPR | IP address, logs, transaction data, correspondence |
5. Requirement to provide data
- Providing data required to place an Order is necessary to conclude and perform the Sales Agreement. Without such data, we cannot process the Order.
- Providing data for a newsletter, marketing communication or optional cookies is voluntary. You may withdraw consent at any time.
- Providing data required by tax or accounting laws may be mandatory where such laws apply.
6. Recipients of personal data
Your personal data may be disclosed to the following categories of recipients, only to the extent necessary:
- hosting, IT maintenance and website administration providers;
- WooCommerce/WordPress plugin and technical service providers used to operate the Store;
- payment providers, including PayU and Stripe;
- courier, postal and logistics operators;
- accounting, tax, legal and advisory service providers;
- banks and financial institutions involved in payment or refund processing;
- newsletter and e-mail communication service providers, if used;
- analytics and advertising providers, if such tools are enabled and consent has been obtained where required;
- public authorities, courts or other authorised entities where disclosure is required by law.
7. Payment providers
- The Store uses PayU and Stripe to process online payments. When you choose a payment method, your payment-related data is processed by the relevant provider according to its own rules and legal obligations.
- The Controller receives from payment providers information necessary to confirm and settle the payment, such as payment status, transaction identifier and selected payment method.
- PayU and Stripe may act as independent controllers or processors depending on the specific payment service and processing context.
- The Controller does not store full card numbers or complete card security codes.
8. International data transfers
- The Controller may use service providers that process data outside the European Economic Area, especially global technology, analytics, advertising or payment providers.
- Where personal data is transferred outside the European Economic Area, the Controller uses safeguards required by GDPR, such as adequacy decisions, standard contractual clauses or other lawful transfer mechanisms.
- If Stripe, analytics providers, advertising providers or other international vendors are used, data may be processed in countries outside the EEA in accordance with their data protection terms and transfer mechanisms.
9. Data retention periods
| Data category | Retention period |
|---|---|
| Order and contract data | For the duration necessary to perform the agreement and then until expiry of limitation periods for potential claims. |
| Accounting and invoice data | For the period required by tax and accounting regulations. |
| Complaint and return data | For the duration of handling the case and then until expiry of limitation periods for claims. |
| Account data | For as long as the account exists, and afterwards to the extent necessary for legal obligations or claims. |
| Newsletter data | Until consent is withdrawn or an objection is made, and afterwards for the period needed to demonstrate lawful consent or defend claims. |
| Cookie and analytics data | Depending on the cookie type and tool settings, no longer than necessary for the purpose for which they were collected. |
| Server logs and security data | For the period necessary for security, maintenance and claim protection, unless longer retention is required by law. |
10. Your rights
Under GDPR, you have the right to:
- access your personal data;
- obtain a copy of your data;
- rectify inaccurate data;
- erase data where permitted by law;
- restrict processing;
- object to processing based on legitimate interests, including direct marketing;
- data portability where processing is based on consent or contract and carried out by automated means;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with a supervisory authority, in particular the President of the Personal Data Protection Office in Poland.
To exercise your rights, contact us at hello@magnamaa.com.
11. Automated decision-making
- The Controller does not make decisions based solely on automated processing, including profiling, that would produce legal effects concerning you or similarly significantly affect you.
- Payment providers may use automated fraud prevention or risk assessment mechanisms under their own rules and legal obligations.
12. Cookies and similar technologies
- The Store uses cookies and similar technologies. Cookies are small text files stored on your device when you use the website.
- Cookies may be used to ensure the proper operation of the Store, including cart, checkout, login, security, payment and language/currency functions.
- Optional cookies may be used for analytics, personalisation, advertising and remarketing only where legally permitted and, where required, after obtaining your consent.
- You can manage cookie preferences through the cookie banner available on the Store: [insert cookie consent tool name].
- You can also manage cookies in your browser settings. Blocking necessary cookies may prevent the Store from functioning properly.
12.1 Categories of cookies
| Category | Purpose | Legal basis |
|---|---|---|
| Necessary cookies | Store operation, cart, checkout, security, session management, payment process | Necessary to provide the service; legitimate interest |
| Functional cookies | Remembering preferences such as language, currency or display settings | Consent where required or legitimate interest where permitted |
| Analytics cookies | Statistics, traffic measurement, improving the Store | Consent where required |
| Marketing cookies | Advertising, remarketing, measuring campaign effectiveness | Consent |
13. Analytics and marketing tools
Remove or edit this section depending on actual implementation. Do not leave tools listed here if they are not actually installed.
- The Store may use Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, Pinterest Tag, Google Ads conversion tracking, Microsoft Clarity, Hotjar or similar tools, if they are enabled on the website.
- These tools may collect information about your use of the Store, including pages visited, events, device data, approximate location, browser data and cookie identifiers.
- Where required, these tools are used only after obtaining your consent through the cookie banner.
- If none of the above tools are used, this section should be replaced with a statement that the Store does not use optional analytics or marketing tracking tools.
14. Newsletter
- If you subscribe to the newsletter, we process your e-mail address and consent data to send marketing communication about Magna Maa products, offers and news.
- The newsletter provider is: [insert newsletter provider, e.g. Mailchimp / Klaviyo / Brevo / FluentCRM / WooCommerce plugin / none].
- You may unsubscribe at any time using the unsubscribe link in the newsletter or by contacting us.
- If the Store does not provide a newsletter, remove this section or state that the Store does not currently offer a newsletter.
15. Contact forms and e-mail communication
- When you contact us by e-mail or through a contact form, we process the data you provide in order to respond to your message and handle the matter.
- Correspondence may be retained for the time necessary to handle the matter and protect against possible claims.
16. Customer account
- If you create a Customer account, we process data necessary to maintain the account, provide account features and display order history.
- You may request deletion of your account, subject to retention of data required by law or necessary to establish, exercise or defend claims.
17. Security
- The Controller applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration or disclosure.
- The Store uses encrypted communication where technically available, including HTTPS.
- No method of data transmission or storage is completely risk-free; however, the Controller takes reasonable measures appropriate to the nature and scope of processing.
18. Changes to the Privacy Policy
- The Controller may update this Privacy Policy, especially if the law changes, the Store changes its functions or new service providers or tools are introduced.
- The current version of the Privacy Policy is always available in the Store.
19. Quick contact
If you have questions about privacy or personal data, contact us:
- MAGNA sp. z o.o.
- ul. Grudziądzka 3, 60-446 Poznań, Poland
- E-mail: hello@magnamaa.com
- Telephone: [insert telephone number]
