Privacy Policy of DRIPELY online store
Last updated: August 3, 2026
1. Who is the controller of your data?
The controller of personal data processed in connection with the use of the online store available at https://www.dripely.pl (the "Store") is Patrycja Kawałczewska, operating a business under the brand DRIPELY, address: ul. Piotrkowska 276A, 90-361 Łódź, Poland, NIP: 7292767308, REGON: 543580468 ("DRIPELY", "Controller" or "we").
For matters concerning privacy and personal data, you can contact us:
-
by email:
kontakt@dripely.com
All matters regarding personal data can be directed to the email address provided above.
2. Scope of the Policy
This Policy explains what personal data we collect, from what sources we obtain it, for what purposes and on what basis we use it, to whom we may transfer it, how long we store it, and what rights you have.
It applies to individuals who, in particular:
-
visit the Store or use its features;
-
place an order or create a customer account;
-
contact us;
-
make a return or submit a complaint;
-
subscribe to the newsletter;
-
post a review, if the review function is available;
-
interact with DRIPELY's social media profiles.
3. What data may we process?
The scope of data depends on how you use the Store. We may process:
-
Identification and contact data: first name and last name, email address, phone number, delivery address, billing or correspondence address.
-
Order data: ordered products, selected variants, order value, discounts, delivery method, fulfillment status, history of returns, complaints, and contact regarding the order.
-
Invoice data: buyer's name or first name and last name, address, NIP (Tax Identification Number), and other data required by law. We do not require a PESEL number for the standard issuance of an invoice for purchases in the Store.
-
Payment data: selected method, amount, currency, transaction status and ID, and limited information provided by the payment operator. Full card data is generally processed by the payment provider, not directly by DRIPELY.
-
Customer account data: account ID, login data managed by Shopify, order history, saved addresses, and preferences.
-
Communication content: messages, attachments, submissions, information provided in the contact form, and data needed to respond.
-
Newsletter data: email address, date and method of subscription, history of given or withdrawn consent, and information on newsletter usage, if privacy settings allow.
-
Review data: review content, name or pseudonym, rating, purchase information, and technical data needed to verify authenticity and prevent abuse.
-
Technical and activity data: IP address, device information, browser and operating system, cookie or pixel identifiers, pages visited, source of visit, and interactions with the Store, depending on the choices made regarding cookies.
-
Security-related data: information about login attempts, suspicious activities, errors, and events that may indicate fraud or security breaches.
-
Social media data: profile name, public information, comments, reactions, and messages transmitted during contact with the DRIPELY profile.
Please do not provide us with special categories of data, such as health information, unless it is essential for handling a specific request. If such data proves necessary, we will inform you about the appropriate basis and scope of its processing.
4. Where do we obtain data from?
We may obtain data:
-
directly from you, e.g., when placing an order, creating an account, subscribing to the newsletter, contacting us, making a return, filing a complaint, or adding a review;
-
automatically from your device and browser, via cookies, pixels, and similar technologies — according to your settings;
-
from Shopify, payment operators, courier companies, application providers, and other entities involved in supporting the Store and order fulfillment;
-
from social media platforms, when you contact us, react to our content, or use the features of these platforms;
-
from public sources, if legally permissible and necessary to protect against abuse or pursue claims.
5. Purposes and legal bases of processing
| Purpose | Example data | Legal basis |
|---|---|---|
| Basket handling, order acceptance and fulfillment, delivery, transaction confirmations | contact data, address data, order, payment, and delivery | Art. 6(1)(b) GDPR — performance of a contract or steps taken prior to entering into a contract |
| Creation and maintenance of a customer account | account data, contact details, addresses, and order history | Art. 6(1)(b) GDPR |
| Handling payments and refunds | amount, status, method, transaction ID, possibly account for refund | Art. 6(1)(b) GDPR; to an appropriate extent Art. 6(1)(c) GDPR |
| Returns, complaints, and exercise of consumer rights | order data, contact, problem description, photos, request | Art. 6(1)(b) and (c) GDPR and Art. 6(1)(f) GDPR — documenting service and protecting claims |
| Issuing and storing accounting documents and fulfilling tax obligations | transaction data, invoice data | Art. 6(1)(c) GDPR — legal obligation |
| Contact and handling inquiries | contact details and message content | Art. 6(1)(b) GDPR, when the inquiry concerns a contract, or Art. 6(1)(f) GDPR — legitimate interest consisting in communication and customer service |
| Newsletter, promotional information, and provision of a 10% code for the first order | email address and consent information | Art. 6(1)(a) GDPR — consent, together with consent required by electronic communication regulations |
| Reminder about unfinished purchases | email address and cart content | consent to marketing communication, if required; simply entering the address at checkout is not automatically marketing consent |
| Publishing and verifying reviews | content, rating, name or pseudonym, purchase information | Art. 6(1)(a) GDPR — consent to publication; Art. 6(1)(f) GDPR — authenticity verification, moderation, and protection against abuse |
| Ensuring security, detecting fraud and abuse | technical, transactional, and activity data | Art. 6(1)(f) GDPR — legitimate interest consisting in protecting the Store, customers, and payments |
| Establishing, exercising, or defending legal claims | order data, payment, communication, and documentation | Art. 6(1)(f) GDPR |
| Fulfilling obligations related to product safety, warnings, or product recalls | buyer, order, and contact data | Art. 6(1)(c) GDPR, and subsidiarily Art. 6(1)(f) GDPR — protection of customers |
| Store analytics, personalization, and online advertising, including Meta Pixel | technical data, identifiers, activity, and purchase events | Art. 6(1)(a) GDPR — consent for the appropriate category of cookies or similar technologies |
| Maintaining DRIPELY profiles on social media | profile data, comments, reactions, messages, and statistics | Art. 6(1)(f) GDPR — communication, brand building, and activity analysis; consent, when required for a specific action |
If processing is based on consent, providing it is voluntary. You can withdraw it at any time without affecting the legality of prior processing.
6. Newsletter and marketing communication
Newsletter subscription is voluntary. After subscribing, we may send information about products, new releases, promotions, offer availability, and the discount code promised upon subscription. If we use an email address confirmation procedure, the subscription is activated after clicking the confirmation link.
You can unsubscribe from the newsletter at any time via the link found in each message or by contacting us at kontakt@dripely.com. Unsubscribing from the newsletter does not affect messages necessary for order fulfillment, such as purchase, payment, shipping, return, or complaint confirmations.
We do not send abandoned cart messages merely because an email address was entered during the order placement process. Such a reminder may only be sent when we have a proper legal basis and the required consent for marketing communication.
7. Cookies, analytics, and advertising
The Store uses essential cookies for page operation, cart, account, payments, security, and remembering privacy settings. Functional, analytical, and marketing cookies are used according to the user's choice made in the cookie banner.
Detailed information about cookie categories, purposes, providers, and how to change consent can be found in the Cookie Policy.
8. To whom may we transfer data?
We transfer data only to the extent necessary to achieve a given purpose. Recipients or processors may include:
-
Shopify: provider of the store platform, hosting, customer accounts, order management tools, payments, security, analytics, and other e-commerce functions.
-
Payment operators and financial institutions: for payment authorization, fraud prevention, settlement, and refunds.
-
Courier companies, postal operators, and logistics partners: for delivery, tracking, and possible return of shipments.
-
Accounting, invoicing, and document archiving providers: to the extent necessary for accounting and fulfilling legal obligations.
-
IT, security, email, customer service, form, newsletter, and Shopify application providers: acting on our behalf or, if dictated by the nature of the service, as separate controllers.
-
Analytics, advertising, and social media providers: particularly Meta Platforms Ireland Limited — upon obtaining the required consent regarding marketing technologies.
-
Legal, tax, accounting advisors, insurers, and auditors: if necessary for business operations or the protection of claims.
-
Public authorities, courts, and authorized institutions: when the obligation to transfer data arises from law or a valid request.
Not every recipient receives all categories of data. The scope is limited to the information needed to perform their task.
Shopify and Shopify Network Intelligence
The Store is hosted by Shopify. Shopify processes data when you visit the Store, use its features, or make a purchase. In some cases, it acts on our instructions as a processor, and in relation to some of its own services — as a separate controller.
The Store may have advanced features based on Shopify Network Intelligence enabled. If activated, Shopify may use information about interactions with the Store, Shopify, and other merchants to protect, improve, and provide its extended services. In the EEA, the use of data for ad personalization or other purposes requiring consent is done in accordance with the user's choice.
More information:
-
Shopify Privacy Portal, where you can manage certain rights and choices regarding processing by Shopify.
Meta Pixel and social profiles
After obtaining consent for marketing cookies, we use Meta Pixel to measure the effectiveness of DRIPELY ads on Facebook and Instagram, attribute events such as product views, adding to cart, or purchases, and create advertising audience groups.
Meta may combine the information received with data it holds within Facebook and Instagram services and use it in accordance with its own policies. To the extent that DRIPELY and Meta jointly determine the purposes and means of data collection and transfer through Meta tools, they may act as joint controllers in accordance with Meta's terms. Meta is responsible for further processing of data in its services.
You can withdraw consent via "Cookie Preferences" in the Store footer. You can also manage ad settings directly in your Facebook or Instagram account.
When you visit DRIPELY's profile, comment, react, or send a message, the social media platform administrator processes data in accordance with its policy. In relation to aggregated DRIPELY profile statistics, DRIPELY and Meta may act as joint controllers to the extent resulting from the platform's regulations and terms.
More information can be found in the Meta Privacy Policy.
9. Transferring data outside the European Economic Area
Some providers, particularly Shopify, Meta, or their subcontractors, operate globally. Therefore, data may be processed outside the European Economic Area.
If personal data is transferred to a country for which the European Commission has not issued an adequacy decision, the transfer takes place using appropriate safeguards required by the GDPR, in particular standard contractual clauses, and — where necessary — additional protective measures. Information about the mechanisms used by a specific provider can be found in its privacy policy.
10. How long do we store data?
We store data no longer than necessary for a given purpose, taking into account legal obligations and limitation periods.
| Category or purpose | Storage period or criterion |
| Orders and contract performance | for the duration of order fulfillment, and then until the expiration of complaint-related terms and claim limitation periods |
| Accounting and tax documents | for the period required by tax and accounting regulations, generally 5 years from the end of the calendar year in which the tax payment deadline expired |
| Customer account | until account deletion or service termination; transaction data is stored longer when required by law or for claims protection |
| Customer service inquiries | until the matter is resolved, and then for a maximum of 2 years, unless the message concerns a contract, complaint, dispute, or claim requiring longer storage |
| Complaints and returns | for the duration of their handling, and then until the expiration of the relevant limitation periods and periods required to demonstrate proper fulfillment of obligations |
| Newsletter | until consent is withdrawn or the newsletter is terminated; we may retain limited information about the withdrawal to demonstrate compliance and prevent resending |
| Reviews | until consent is withdrawn, the review is deleted, or its publication is terminated; verification data may be stored until the expiration of the period necessary to demonstrate authenticity and protect claims |
| Analytical and marketing data | according to user choice, the operating time of the given technology, and the periods indicated in the Cookies Policy or provider's documents |
| Security and abuse data | for the period necessary to investigate an incident, ensure security, and protect claims |
After the appropriate period, we delete, anonymize, or restrict the use of data if further storage is required by law.
11. What rights do you have?
Under the terms of the GDPR, you have the right to:
-
access your data and receive a copy of it;
-
rectify inaccurate data and complete incomplete data;
-
erase data if there are no grounds for further storage;
-
restrict processing in cases provided for by law;
-
data portability when processing is based on consent or a contract and is carried out by automated means;
-
object to processing based on our legitimate interest, for reasons related to your particular situation;
-
object to direct marketing: such an objection does not require justification, and upon its submission, we will cease processing data for this purpose;
-
withdraw consent at any time;
-
not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you;
-
lodge a complaint with the President of the Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, https://uodo.gov.pl.
To exercise your rights, please write to kontakt@dripely.com. We may ask for information necessary to confirm your identity, but we will not request excessive data. We will respond without undue delay, generally within one month, unless the GDPR allows for an extension of this period due to the complex nature or number of requests.
Rights are not absolute. In specific cases, regulations allow or mandate further data retention, e.g., tax documents or data needed for defense of claims.
12. Profiling and automated decisions
If you consent to analytical or marketing cookies, information about your activity may be used to create audience groups, measure advertisements, and tailor promotional content. This may constitute profiling, but we do not make decisions based on this that produce legal effects concerning you or similarly significantly affect you.
We do not make the possibility of purchase or the basic terms of sale conditional on consent to advertising profiling. Consent can be withdrawn via the cookie preferences panel.
13. Is providing data mandatory?
Providing data marked as required when placing an order is voluntary, but necessary for concluding and performing the contract, accepting payment, and delivering the shipment. Without this data, we will not fulfill the order.
Providing data for an invoice is required if you request its issuance. Data provided when contacting, reviewing, and subscribing to the newsletter are voluntary, but without the appropriate data, we will not be able to respond, publish a review, or send the newsletter.
14. Data Security
We apply appropriate technical and organizational measures adapted to the nature of the data and the risk, in particular encrypted HTTPS connection, access control, administrative account security, system updates, and cooperation with providers committed to data protection.
No method of data transmission or storage guarantees complete security. If you suspect a security breach of your account or data, please contact us at kontakt@dripely.com.
15. Third-party links and services
The Store may contain links to external websites, social profiles, or payment services. After navigating to such a service, its operator may process data as a separate administrator in accordance with its own privacy policy. DRIPELY is not responsible for the privacy policies of sites it does not control.
16. Policy Changes
We may update the Policy due to changes in law, Store functions, service providers used, or data processing methods. The current version is published in the Store along with the date of the last update. If the change is significant and regulations require it, we will inform about it in an appropriate manner.
17. Contact
Questions, requests, and complaints regarding privacy can be directed to:
-
email:
kontakt@dripely.com; -
phone: +48 573 396 570;
-
mail: DRIPELY, ul. Piotrkowska 276A, 90-361, Łódź, Poland.