Privacy Policy
This explains what data we collect, why, on what legal basis, and how long we keep it.
1. Data controller
The controller of your personal data is:
Name: «…»
Address: «…», «…»
Correspondence address: «…»
For any data-protection matter the fastest route is the contact form: https://repoloot.com/contact. You may also write to the correspondence address above.
We have not appointed a data protection officer, as we are not required to.
2. What data we process
Guest purchase: e-mail address, order data (reference, item, amount, status), the sender name and transaction ID you declare, and timestamps of the consents you gave.
Account: e-mail address, display name, hashed password (held by our authentication provider), granted access rights, favourites and notifications.
Contact form: name (optional), e-mail address, message, order reference (optional), basic technical data (browser) and an irreversible hash of your IP address used only for abuse limiting. The IP address itself is not stored.
Payment proofs: if a signed-in user voluntarily attaches a confirmation file, we store it in a private bucket readable only by that user and by an administrator.
3. Purposes and legal bases
Fulfilling your order and granting access — Art. 6(1)(b) GDPR (performance of a contract).
Handling contact-form enquiries — Art. 6(1)(b) or (f) GDPR (our legitimate interest in answering enquiries).
Accounting and tax obligations — Art. 6(1)(c) GDPR (legal obligation).
Site security, abuse prevention and establishing or defending legal claims — Art. 6(1)(f) GDPR (legitimate interest).
Providing data is voluntary but necessary to conclude the contract — without an e-mail address we cannot deliver access.
4. Recipients
Supabase (database, authentication, file storage) — processor.
Resend (transactional e-mail delivery) — processor.
The hosting provider running the site — processor.
Revolut — the transfer happens inside your own Revolut app; Revolut is an independent controller of the transaction data. We never receive your card or banking credentials.
Data may be transferred outside the EEA (including to the USA) on the basis of the European Commission's standard contractual clauses.
5. Retention
Order and accounting data — for the period required by tax and accounting law (as a rule, 5 years from the end of the tax year).
Account data — until you ask us to delete the account; afterwards only what is needed for accounting and defence against claims.
Contact-form messages — up to 24 months after the matter is closed. IP hashes — up to 12 months.
6. Your rights
You have the right to: access your data, rectify it, erase it, restrict processing, data portability, and to object to processing based on legitimate interest.
To exercise these rights, write through the contact form: https://repoloot.com/contact. We reply without undue delay and within one month at the latest.
You also have the right to lodge a complaint with the Polish supervisory authority (Prezes UODO, ul. Stawki 2, 00-193 Warsaw) or with the authority in your country of residence.
7. Profiling and security
We do not make automated decisions producing legal effects concerning you, and we do not profile you for marketing purposes.
Traffic is encrypted (HTTPS), access to private repository data is enforced by row-level security in the database, and guest order links are stored only as an irreversible hash.
8. Cookies
Our use of cookies and browser storage is described separately: https://repoloot.com/cookies
A question about this document?
Use the contact form — it is our primary support channel.
Contact form