Privacy policy

Last updated: 22-07-2026

TYTAX operates this store and website and provides the related information, content, features, tools, products and services (collectively, the “Services”). The store is powered by the Shopify platform.

This Privacy Policy describes how we collect, use, store and disclose personal data when you visit or use the Services, make a purchase or other transaction, or contact us.

Main sections

1. Personal data we collect or process

“Personal data” means information that identifies a person or can be linked to them. Personal data does not include information that has been anonymised in such a way that a person cannot be identified from it or reasonably linked to it.

Depending on how you use the Services, we may collect or process the following categories of data:

  • Contact details, including your first and last name, billing address, delivery address, telephone number and email address.
  • Payment and billing data, including the selected payment method, amount and currency, payment status and confirmation, transaction identifiers, refund information, and limited information about the payment instrument made available by Shopify or another payment provider, such as the card brand and its masked number or last digits. Full payment card numbers and security codes are processed by Shopify Payments or another applicable payment provider and are not made available to us.
  • Customer account data, including your email address, profile information, saved addresses, and account-related settings and preferences. Account authentication is handled by Shopify and may use a one-time code or another method provided by Shopify. We do not receive passwords used for Shopify services.
  • Transaction data, including information about products viewed, added to a cart, purchased, returned, exchanged or cancelled, and your order and transaction history.
  • Communications with us, including information contained in messages submitted through the contact form or other customer support channels that we make available.
  • Technical and device data, automatically processed when you use the Services by Shopify and technology service providers. Depending on the service used, this may include your IP address, browser type and settings, operating system, device category, screen resolution, network connection information, and pseudonymous identifiers stored in cookies or similar technologies. We may receive selected technical information, aggregated or pseudonymous reports, and security indicators related to orders.
  • Service usage data, including information about how and when you use the Services, how you navigate the website, the source of traffic, and interactions with product pages, the cart and the checkout process.
  • Analytics, advertising and security data, including information collected through cookies, pixels, tags, local storage, server-side event processing, analytics and advertising tools, conversion measurement technologies, consent management tools, and anti-bot or traffic quality assessment systems.

2. Sources of personal data

We may obtain personal data:

  • directly from you, for example when you place an order, create an account, contact us or use other features of the Services;
  • automatically through the Services, your device, cookies and similar technologies;
  • from Shopify and service providers that provide us with services related to payments, hosting, security, analytics, advertising, customer support, order fulfilment or delivery;
  • from partners and third parties, where necessary to fulfil an order, process a payment, prevent fraud, conduct analytics or advertising in accordance with your choices, or comply with legal obligations.

3. Analytics, advertising, cookies and anti-bot protection

We use cookies, pixels, tags, local storage, server-side event processing, network and device information, and similar technologies to operate and secure the store, remember preferences, analyse use of the Services, measure advertising effectiveness, and detect bots, fraud, spam, abuse and invalid traffic.

3.1. Strictly necessary functions

Technologies required for the store to operate, for the purchasing process, authentication, security, fraud prevention, load balancing, recording consent choices or providing other requested functions may operate without consent to the extent permitted by law. The legal bases for processing are described in section 4.

3.2. Analytics and advertising

Where consent is required, analytics, advertising, remarketing and conversion measurement technologies that are not strictly necessary are activated only after consent has been obtained. Consent may be refused or withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before it was withdrawn.

3.3. Information processed

Depending on your choices and how you use the Services, the information may include your IP address, device and browser data, pseudonymous identifiers, consent choices, activity on pages and product pages, traffic source and campaign data, cart and checkout events, transaction identifiers, fraud and security signals, and information used to distinguish users from automated or invalid traffic.

3.4. Providers and recipients

In connection with the purposes described above, we use in particular:

  • Shopify;
  • Cloudflare;
  • Google services, such as Google Analytics, Google Ads, Google Tag Manager and Google Cloud;
  • Meta technologies, such as Meta Pixel and Conversions API;
  • Stape server-side tagging services;
  • SCF360 LLC as a technical provider supporting analytics, measurement and anti-bot protection.

The scope of processing and the provider’s legal role depend on the specific service. A provider may act as a processor on our behalf, a joint controller or an independent controller for specified purposes.

3.5. Protective analytics and automated signals

Security and anti-bot systems may automatically analyse technical and behavioural signals to detect automated traffic, fraud, spam, abuse or invalid traffic. They may display a verification challenge, temporarily restrict a suspicious request or flag certain activity for further review.

We do not use these systems to make, solely by automated means, final decisions concerning the conclusion or performance of a contract, a complaint or a return that produce legal effects or similarly significantly affect a person.

3.6. Transfers outside the EEA

Some providers may process personal data outside the European Economic Area. The use of regional data collection points or infrastructure located in the EEA does not always mean that subsequent storage or processing takes place exclusively within the EEA. Further information is provided in section 12.

3.7. Retention period

We retain information relating to analytics, advertising, consent, security and anti-bot protection no longer than necessary for the purposes for which it was collected.

In particular, we determine retention periods on the basis of:

  • the period for which data is needed to conduct analytics, measure advertising effectiveness or ensure the security of the Services;
  • configured retention periods and the lifetimes of identifiers, cookies and similar technologies;
  • the time needed to detect, analyse and handle fraud, abuse, a security incident or invalid traffic;
  • the period needed to document your choices and consents;
  • retention obligations arising from law;
  • periods needed to establish, exercise or defend legal claims.

After the applicable period has expired, data is deleted or anonymised unless further retention is required by law or is necessary to establish, exercise or defend legal claims. Providers acting as independent controllers may apply their own retention periods.

3.8. Your choices

Using the “Cookie Preferences” mechanism available in the footer, you can review or change your choices regarding cookies and similar technologies that are not strictly necessary.

You may also exercise the rights described in section 10.

We use personal data only where there is an appropriate legal basis.

  • Entering into and performing a contract — Article 6(1)(b) GDPR. We process data to accept and fulfil orders, process payments, arrange delivery, operate customer accounts, communicate about orders, handle returns, exchanges and complaints, and take other steps at your request before entering into a contract or in order to perform it.
  • Compliance with legal obligations — Article 6(1)(c) GDPR. We process data to comply with tax, accounting, consumer protection and other legal obligations, and to respond to authorised public bodies.
  • Consent — Article 6(1)(a) GDPR. We rely on consent for processing related to optional analytics and advertising technologies and email and SMS marketing communications where consent is required. Consent may be withdrawn at any time.
  • Legitimate interests — Article 6(1)(f) GDPR. We may process data to ensure network and information security, prevent fraud and abuse, manage customer relationships, improve the Services, produce basic operational statistics, and establish, exercise or defend legal claims. Before relying on this basis, we take into account the rights, freedoms and reasonable expectations of the persons concerned.
  • Direct marketing. We conduct marketing communications in accordance with the laws governing electronic communications. Where the law permits marketing of our own similar products to an existing customer without separate consent, we provide an easy and free opportunity to object when the data is collected and in every message.

4.1. Is providing data mandatory?

Providing data marked as required when placing an order is a condition of entering into and performing the contract. Without this data, we may be unable to accept payment, fulfil the order, deliver the product or handle a return or complaint.

Providing data needed to comply with legal obligations may be required by applicable law. Providing other data, creating an account, consenting to marketing, and consenting to optional analytics and advertising technologies are voluntary. Refusing or withdrawing consent does not prevent you from making a basic purchase, but it may limit the availability of optional features or personalised content.

5. How we disclose personal data

We do not sell personal data.

We may disclose data only to the extent necessary to fulfil the purposes described:

  • to Shopify and providers of infrastructure, hosting, cloud services, security, IT management and technical support;
  • to payment providers and fraud prevention service providers;
  • to carriers, logistics operators and other entities involved in fulfilling an order or return;
  • to providers of customer support, email, SMS and contact form services;
  • to analytics, advertising and conversion measurement providers, in accordance with your choices and to the extent permitted by law;
  • to accountants, legal advisers, tax advisers and other professional advisers;
  • to public authorities, courts or other authorised entities where disclosure is required by law or necessary to protect rights and security;
  • to a purchaser of the business or part of it if a relevant transaction takes place and the disclosure is lawful.

We use Shopify enhanced features that use data and information from your interactions with our store, other merchants and Shopify. Shopify may therefore process data to provide Enhanced Services, including protection, personalisation, measurement and advertising features. For these purposes, Shopify may act as an independent controller. You may withdraw consent or exercise your rights using the tools available in the Services and the Shopify Privacy Portal.

6. Our relationship with Shopify

The Services are hosted by Shopify. When providing the platform’s core services, Shopify processes customer data in accordance with its terms of service and data processing addendum. For certain Shopify consumer services, such as Shop or Shop Pay, and certain Enhanced Services, Shopify may act as an independent controller.

Information submitted through the Services is transferred to Shopify and may be processed by Shopify entities and their subprocessors in different countries in order to provide, secure and improve the Services.

When Shopify Network Intelligence is enabled, Shopify may use data from your interactions with our store, other merchants and Shopify to provide Enhanced Services. In the EEA, the United Kingdom and Switzerland, the use of data for purposes that are not strictly necessary is subject to the applicable consent choices and the ability to withdraw consent.

Further information is available in the Shopify Consumer Privacy Policy and the Shopify Privacy Portal.

The Services may contain links to websites or platforms operated by third parties. When you visit such a website, its own privacy and security rules and terms apply. We encourage you to review them before providing any data.

The inclusion of a link does not mean that we control how an external website processes data or that we are responsible for its actions.

8. Children’s data

The Services are not directed at children. We do not knowingly collect children’s personal data in breach of applicable law. A parent or guardian who believes that a child has provided us with personal data may contact us using the contact form to request its deletion.

9. Security and retention of information

We use appropriate technical and organisational measures intended to protect data against unauthorised access, loss, alteration, disclosure or destruction. However, no system or method of transmission can guarantee absolute security.

Particularly sensitive or confidential information should not be sent through unsecured channels. The retention period for data depends on the purpose of processing, legal obligations, the need to handle claims, and the settings and retention periods applied by the relevant providers. Detailed criteria concerning analytics, advertising, consent and security are described in section 3.7.

10. Your rights and choices

To the extent provided by the GDPR, you may have:

  • the right of access to your data and to receive a copy of it;
  • the right to rectification of inaccurate data or completion of incomplete data;
  • the right to erasure where the conditions provided by law are met;
  • the right to restriction of processing in specified cases;
  • the right to data portability where processing is based on consent or a contract and is carried out by automated means;
  • the right to object to processing based on legitimate interests on grounds relating to your particular situation;
  • the right to object to direct marketing at any time, including profiling related to such marketing;
  • the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
  • the right to lodge a complaint with the competent supervisory authority.

Preferences relating to optional analytics and advertising technologies can be changed using the “Cookie Preferences” mechanism.

10.1. Communication preferences

We may send promotional messages by email and SMS in accordance with the consent you have given or another legal basis permitted by law. You can unsubscribe from email messages using the unsubscribe link, and from SMS messages using the mechanism or instructions indicated in the message.

After opting out of promotional communications, we may still send non-promotional messages concerning your account, order, payment, delivery, return, complaint or the security of the Services.

10.2. Exercising your rights

You can exercise your rights by contacting us using the contact form. Before responding to a request, we may verify your identity to the extent necessary to protect data from disclosure to an unauthorised person. We will respond within the period required by law.

Further information about rights relating to data processed by Shopify is available in the Shopify Privacy Portal.

11. Complaints

If you have concerns about how we process data, please first contact us using the contact form.

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. In Poland, where the data controllers conduct their business, the supervisory authority is the President of the Personal Data Protection Office. A list of supervisory authorities in the countries of the European Economic Area is available on the website of the European Data Protection Board.

12. International data transfers

Some providers may process personal data in countries outside the European Economic Area or outside your country of residence.

Depending on the provider, destination country, type of service and circumstances of the transfer, data is transferred on the basis of an adequacy decision, including, where applicable, the EU–U.S. Data Privacy Framework, or using appropriate safeguards such as the standard contractual clauses approved by the European Commission, the applicable UK addendum for international data transfers, binding corporate rules or other mechanisms provided by law.

Where necessary, supplementary safeguards are also applied. Information about the safeguards applicable to a specific transfer may be obtained by contacting us using the contact form.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, the Services, providers or legal requirements. We will publish the revised Privacy Policy on this page and update the date of the last revision. We will provide additional notice where required by law.

14. Contact details and data controllers

The data controllers are Alina Szultka and Stanisław Szultka, partners in the civil partnership operating under the business name:

TYTAX FACTORY ALINA I STANISŁAW SZULTKA S.C.
ul. Wojska Polskiego 31
89-632 Brusy
Poland

For questions about this Privacy Policy, how we process data, or to exercise your rights, you can contact us using the contact form available in the “Contact” section of our website.