Privacy policy
Privacy Policy
Effective from: August 1, 2026 · Last updated: August 1, 2026
1. Introduction — Your privacy matters
At Rill &River, we do not treat privacy as a formality. We respect your data just as we respect the planet — we do not collect more than we need, we do not keep it longer than we must, and we never sell personal data.
This Privacy Policy describes what information we collect when you use the Store, place an order, subscribe to the newsletter, or simply visit us. It has been prepared in accordance with GDPR (General Data Protection Regulation, EU 2016/679) and the Polish Personal Data Protection Act.
2. Who is the data controller?
The controller of your personal data is:
Piotr Kozłowski
conducting business under the business name:
Rill&River
Address: ul. Poniatowskiego 49/2, 37-450 Stalowa Wola, Poland
E-mail (privacy matters): contact@rillandriver.com
E-mail (general): contact@rillandriver.com
In matters related to personal data protection, you can contact us directly at the e-mail address indicated above.
Data Protection Officer: Under applicable regulations, we are not required to appoint a Data Protection Officer. However, if you need to contact us regarding a particularly sensitive matter, write to contact@rillandriver.com — we treat these matters with priority.
3. What data do we collect and why?
We collect only the data that is necessary for a specific purpose. Here is a detailed breakdown:
| Purpose | Data | Why? |
|---|---|---|
| Order fulfillment | First name, last name, delivery address, billing address, phone number, e-mail | To deliver the ordered product to you and contact you in case of delivery issues |
| Payment | Payment data (processed by the payment provider) | To process the transaction. We do not store full card details |
| User Account | E-mail address, password (hashed), order history | To enable you to manage orders and make faster future purchases |
| Newsletter | E-mail address, optionally first name | To send you information about news, inspirations, and — strictly with your consent — promotions |
| Inquiry handling | First name, e-mail, message content | To answer your questions |
| Store analysis and improvement | IP address, browser data, behavior in the Store (via cookies) | To understand how users use the Store and continuously improve it |
| Marketing and remarketing | User ID, behavior in the Store (via pixels) | To show you ads for products that may interest you — strictly with consent |
| Legal obligations | Purchase data (invoices) | To fulfill tax and accounting obligations |
4. Where does your data come from?
The data comes exclusively from you — you provide it voluntarily when:
-
placing an order,
-
creating a User Account,
-
subscribing to the newsletter,
-
sending a message via the contact form,
-
accepting cookies.
5. Legal bases for processing
Every processing of data is based on one of the following GDPR legal bases:
-
Art. 6(1)(b) GDPR — performance of a contract (order fulfillment, payment processing, delivery).
-
Art. 6(1)(c) GDPR — legal obligation (issuing invoices, keeping tax records).
-
Art. 6(1)(a) GDPR — your consent (newsletter, marketing, non-essential analytical and advertising cookies).
-
Art. 6(1)(f) GDPR — legitimate interest of the controller (statistical analysis, fraud prevention, handling complaints).
You can withdraw your consent at any time — this does not affect the lawfulness of processing carried out before its withdrawal.
6. Who do we share data with? (recipients and data processors)
Your data may be transferred to the following categories of recipients who support us in running the Store:
| Recipient | Role | Examples |
|---|---|---|
| Store platform | Hosting and Store operation | Shopify Inc. (Canada/USA) |
| Payment processors | Transaction processing | Stripe, PayU, Przelewy24, Klarna |
| POD Provider | Production and shipping | Printify, Printful, or another designated provider |
| Courier companies | Delivery of shipments | InPost, DHL, DPD, FedEx |
| Analytical tools | Traffic analysis | Google Analytics 4 |
| Advertising platforms | Remarketing (solely with consent) | Meta (Facebook/Instagram), TikTok, Google Ads |
| Accounting firm | Accounting and tax services | |
| Law firm | Legal protection | |
| State authorities | Fulfillment of legal obligations | Tax Office, SANEPID, UOKiK (when required by law) |
All entities process data on the basis of data processing agreements (in accordance with Art. 28 GDPR) or standard contractual clauses.
7. Is data transferred outside the European Economic Area (EEA)?
Yes, some of our suppliers (in particular Shopify and potentially the POD provider) store data on servers located in the United States or other countries outside the EEA.
In such cases, we ensure an appropriate level of data protection through:
-
Standard Contractual Clauses (SCC) approved by the European Commission,
-
EU-US Data Privacy Framework certification (in the case of entities that have joined it),
-
additional technical and organizational safeguards.
8. How long do we store data?
We store data only as long as necessary:
| Data category | Retention period |
|---|---|
| Order-related data | 5 years from the end of the year in which the purchase was made (tax obligation) |
| User Account | Until account deletion or consent withdrawal |
| Newsletter | Until unsubscribing or consent withdrawal |
| Correspondence (e-mail) | 2 years from the resolution of the matter |
| Analytical/advertising cookies | In accordance with the period specified in browser settings (max. 13 months from the last interaction) |
| Data for complaint handling purposes | 1 year from the end of complaint handling proceedings |
After the specified periods expire, data is irreversibly deleted or anonymized.
9. Your rights — you have choice and control
The GDPR grants you a number of rights. Here they are, in plain language:
-
Right of access — you can ask what data we store about you and what it is used for.
-
Right to rectification — if your data is incorrect or outdated, we will correct it.
-
Right to erasure ("right to be forgotten") — you can request the deletion of data if there are no grounds for its further processing. This does not apply to data that we must retain due to legal obligations.
-
Right to restriction of processing — you can ask to suspend data processing in specific situations (e.g., when you contest its accuracy).
-
Right to data portability — you can receive your data in a structured format (e.g., CSV) and transfer it to another controller.
-
Right to object — you can object at any time to data processing for marketing purposes or based on a legitimate interest.
-
Right to withdraw consent — you can withdraw consent for the newsletter, marketing cookies, or analytical cookies at any time. Withdrawing consent is as easy as granting it.
How to exercise your rights? Write to us at contact@rillandriver.com We respond within 30 days. In complex cases, we may extend this deadline by another 60 days, but we will always inform you.
Right to lodge a complaint: If you believe that we have violated your rights, you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) (ul. Stawki 2, 00-193 Warsaw, Poland).
10. Cookies and tracking technologies
10.1. What are cookies?
Cookies are small text files saved in your browser that help the Store function properly and allow us to understand how you use it.
10.2. What cookies do we use?
| Category | Examples | Requires consent? |
|---|---|---|
| Necessary | Cart session, login, security | No — necessary for the operation of the Store |
| Functional | Remembering preferences (language, currency) | No — but you can disable them in your browser |
| Analytical | Google Analytics 4, Shopify statistics | Yes — consent may be implicit, but we ask for explicit consent |
| Advertising / Marketing | Meta Pixel, TikTok Pixel, Google Ads Remarketing | Yes — explicit consent is required |
10.3. Consent Mode and consent management
We use Google Consent Mode v2 and Shopify's built-in consent management system. Upon entering the Store, you will see a cookie banner where you can:
-
accept all categories,
-
accept necessary only,
-
customize your choice individually.
You can change your preferences at any time by clicking the link "Privacy / Cookie Settings" in the Store footer.
10.4. How to disable cookies?
You can block cookies in your browser settings. However, remember that disabling necessary cookies may make it impossible to place an order.
11. Data security
We apply technical and organizational measures to ensure data protection:
-
SSL/TLS encryption across the entire site (HTTPS certificate),
-
encrypted passwords (hashed in the Shopify database),
-
two-step verification for access to the administration panel,
-
regular system updates,
-
data access restricted exclusively to authorized persons.
12. Profiling and automated decision-making
We do not make decisions about you in a fully automated manner, including decisions based on profiling, that would produce legal effects concerning you or similarly significantly affect you.
However, we use analytical and advertising tools (e.g., Meta Pixel) which, based on your behavior in the Store, may display personalized ads to you. This activity is based on consent and you can disable it at any time.
13. Privacy contact
Please address all matters related to personal data protection to:
E-mail: contact@rillandriver.com
Subject: [GDPR] — [description of the matter, e.g., "Request for access to data"]
We respond to all messages within 30 days.
14. Policy changes
We may update this Policy as the Store develops or regulations change. We will inform you of significant changes by e-mail or via a prominent notice in the Store. The current version is always available on this page.
| Tables | |||
|---|---|---|---|
| Version | Date | Change | |
| 1.0 | 01.08.2026 | First release — basic version of the Terms/Policy for the PL and EU market |
