Privacy policy

Privacy Policy

Effective: August 1, 2026 · Last updated: August 1, 2026

1. Introduction – Your privacy matters

At Rill & River, we don't treat privacy as a formality. We respect your data just as we respect the planet – we don't collect more than we need, we don't keep it longer than we have to, and we never sell personal data.

This Privacy Policy describes the information we collect when you use the Store, place an order, sign up for our newsletter, or simply visit us. It has been prepared in accordance with the GDPR (General Data Protection Regulation, EU 2016/679) and the Polish Personal Data Protection Act.

2. Who is the data controller?

The controller of your personal data is:

Piotr Kozłowski
operating under the name:
Rill&River

Address: ul. Poniatowskiego 49/2, 37-450 Stalowa Wola, Poland
Email (privacy matters): contact@rillandriver.com
Email (general): contact@rillandriver.com

For matters related to personal data protection, you can contact us directly at the email address provided above.

Data Protection Officer: Under applicable law, we are not required to appoint a Data Protection Officer. However, if you need to contact us regarding a particularly sensitive matter, please contact us at contact@rillandriver.com—we treat these matters as a priority.

3. What data do we collect and why?

We only collect data that is necessary for a specific purpose. Here's a detailed list:

Purpose Data Why?
Order Fulfillment Name, surname, delivery address, billing address, phone number, email address To deliver the ordered product and contact you in case of delivery issues
Payment Payment data (processed by the operator) To complete the transaction. We do not store full card details.
User Account: Email address, password (hashed), order history. To enable you to manage orders and make subsequent purchases faster.
Newsletter: Email address, optional name. To send you information about new products, inspiration, and—only with your consent—promotions.
Inquiry handling: Name, email address, message content. To answer your questions.
Store analysis and improvement: IP address, browser data, behavior in the Store (via cookies). To understand how users use the Store and to continuously improve it.
Marketing and remarketing: User ID, behavior in the Store (via pixels). To show you advertisements for products that may be of interest to you—only with your consent.
Legal obligations: Purchase data (invoices). To fulfill tax and accounting obligations.
4. Where does your data come from?

The data comes solely from you – you provide it voluntarily when:

placing an order,

creating a User Account,

signing up for the newsletter,

sending messages via the contact form,

accepting cookies.

5. Legal Basis for Processing

All data processing is based on one of the following legal bases under the GDPR:

Article 6, paragraph 1, letter b of the GDPR – performance of the contract (order fulfillment, payment processing, delivery).

Article 6, paragraph 1, letter c of the GDPR – legal obligation (invoicing, tax bookkeeping).

Article 6, paragraph 1, letter a of the GDPR – your consent (newsletter, marketing, necessary analytical and advertising cookies).

Article 6, paragraph 1, letter f of the GDPR – legitimate interests of the controller (statistical analysis, fraud protection, complaint handling).

You can withdraw your consent at any time – this does not affect the lawfulness of processing carried out before its withdrawal.

6. Who do we transfer your data to? (recipients and entrusted entities)

Your data may be transferred to the following categories of recipients who support us in running the Store:

Recipient Role Examples
Shop Platform Store Hosting and Management: Shopify Inc. (Canada/USA)
Payment Processors: Transaction Processing: Stripe, PayU, Przelewy24, Klarna
POD Provider: Production and Shipping: Printify, Printful, or other designated provider
Couriers: Parcel Delivery: InPost, DHL, DPD, FedEx
Analytics: Traffic Analysis: Google Analytics 4
Advertising Platforms: Remarketing (only with consent): Meta (Facebook/Instagram), TikTok, Google Ads
Accounting Firm: Accounting and Tax Services

Law Firm: Legal Protection

Government Authorities: Fulfillment of Legal Obligations: Tax Office, Sanitary Inspectorate (SANEPID), Office of Competition and Consumer Protection (UOKiK) (where required by law)

All entities process data based on trust agreements (in accordance with Article 28 of the GDPR) or standard contractual clauses.

7. Does data travel outside the European Economic Area (EEA)?

Yes, some of our suppliers (in particular Shopify and potentially the POD provider) store data on servers located in the United States or other countries outside the EEA.

In such cases, we ensure an adequate level of data protection through:

Standard Contractual Clauses (SCCs) approved by