Privacy policy

Privacy Policy

Effective from: August 1, 2026 · Last updated: August 1, 2026

1. Introduction — Your privacy matters

At Rill &River, we do not treat privacy as a formality. We respect your data just as we respect the planet — we do not collect more than we need, we do not keep it longer than we must, and we never sell personal data.

This Privacy Policy describes what information we collect when you use the Store, place an order, subscribe to the newsletter, or simply visit us. It has been prepared in accordance with GDPR (General Data Protection Regulation, EU 2016/679) and the Polish Personal Data Protection Act.

2. Who is the data controller?

The controller of your personal data is:

Piotr Kozłowski
conducting business under the business name:
Rill&River

Address: ul. Poniatowskiego 49/2, 37-450 Stalowa Wola, Poland
E-mail (privacy matters): contact@rillandriver.com
E-mail (general): contact@rillandriver.com

In matters related to personal data protection, you can contact us directly at the e-mail address indicated above.

Data Protection Officer: Under applicable regulations, we are not required to appoint a Data Protection Officer. However, if you need to contact us regarding a particularly sensitive matter, write to contact@rillandriver.com — we treat these matters with priority.

3. What data do we collect and why?

We collect only the data that is necessary for a specific purpose. Here is a detailed breakdown:

Purpose Data Why?
Order fulfillment First name, last name, delivery address, billing address, phone number, e-mail To deliver the ordered product to you and contact you in case of delivery issues
Payment Payment data (processed by the payment provider) To process the transaction. We do not store full card details
User Account E-mail address, password (hashed), order history To enable you to manage orders and make faster future purchases
Newsletter E-mail address, optionally first name To send you information about news, inspirations, and — strictly with your consent — promotions
Inquiry handling First name, e-mail, message content To answer your questions
Store analysis and improvement IP address, browser data, behavior in the Store (via cookies) To understand how users use the Store and continuously improve it
Marketing and remarketing User ID, behavior in the Store (via pixels) To show you ads for products that may interest you — strictly with consent
Legal obligations Purchase data (invoices) To fulfill tax and accounting obligations

4. Where does your data come from?

The data comes exclusively from you — you provide it voluntarily when:

  • placing an order,

  • creating a User Account,

  • subscribing to the newsletter,

  • sending a message via the contact form,

  • accepting cookies.

Every processing of data is based on one of the following GDPR legal bases:

  • Art. 6(1)(b) GDPR — performance of a contract (order fulfillment, payment processing, delivery).

  • Art. 6(1)(c) GDPR — legal obligation (issuing invoices, keeping tax records).

  • Art. 6(1)(a) GDPR — your consent (newsletter, marketing, non-essential analytical and advertising cookies).

  • Art. 6(1)(f) GDPR — legitimate interest of the controller (statistical analysis, fraud prevention, handling complaints).

You can withdraw your consent at any time — this does not affect the lawfulness of processing carried out before its withdrawal.

6. Who do we share data with? (recipients and data processors)

Your data may be transferred to the following categories of recipients who support us in running the Store:

Recipient Role Examples
Store platform Hosting and Store operation Shopify Inc. (Canada/USA)
Payment processors Transaction processing Stripe, PayU, Przelewy24, Klarna
POD Provider Production and shipping Printify, Printful, or another designated provider
Courier companies Delivery of shipments InPost, DHL, DPD, FedEx
Analytical tools Traffic analysis Google Analytics 4
Advertising platforms Remarketing (solely with consent) Meta (Facebook/Instagram), TikTok, Google Ads
Accounting firm Accounting and tax services
Law firm Legal protection
State authorities Fulfillment of legal obligations Tax Office, SANEPID, UOKiK (when required by law)

All entities process data on the basis of data processing agreements (in accordance with Art. 28 GDPR) or standard contractual clauses.

7. Is data transferred outside the European Economic Area (EEA)?

Yes, some of our suppliers (in particular Shopify and potentially the POD provider) store data on servers located in the United States or other countries outside the EEA.

In such cases, we ensure an appropriate level of data protection through:

  • Standard Contractual Clauses (SCC) approved by the European Commission,

  • EU-US Data Privacy Framework certification (in the case of entities that have joined it),

  • additional technical and organizational safeguards.

8. How long do we store data?

We store data only as long as necessary:

Data category Retention period
Order-related data 5 years from the end of the year in which the purchase was made (tax obligation)
User Account Until account deletion or consent withdrawal
Newsletter Until unsubscribing or consent withdrawal
Correspondence (e-mail) 2 years from the resolution of the matter
Analytical/advertising cookies In accordance with the period specified in browser settings (max. 13 months from the last interaction)
Data for complaint handling purposes 1 year from the end of complaint handling proceedings

After the specified periods expire, data is irreversibly deleted or anonymized.

9. Your rights — you have choice and control

The GDPR grants you a number of rights. Here they are, in plain language:

  • Right of access — you can ask what data we store about you and what it is used for.

  • Right to rectification — if your data is incorrect or outdated, we will correct it.

  • Right to erasure ("right to be forgotten") — you can request the deletion of data if there are no grounds for its further processing. This does not apply to data that we must retain due to legal obligations.

  • Right to restriction of processing — you can ask to suspend data processing in specific situations (e.g., when you contest its accuracy).

  • Right to data portability — you can receive your data in a structured format (e.g., CSV) and transfer it to another controller.

  • Right to object — you can object at any time to data processing for marketing purposes or based on a legitimate interest.

  • Right to withdraw consent — you can withdraw consent for the newsletter, marketing cookies, or analytical cookies at any time. Withdrawing consent is as easy as granting it.

How to exercise your rights? Write to us at contact@rillandriver.com We respond within 30 days. In complex cases, we may extend this deadline by another 60 days, but we will always inform you.

Right to lodge a complaint: If you believe that we have violated your rights, you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) (ul. Stawki 2, 00-193 Warsaw, Poland).

10. Cookies and tracking technologies

10.1. What are cookies?

Cookies are small text files saved in your browser that help the Store function properly and allow us to understand how you use it.

10.2. What cookies do we use?

Category Examples Requires consent?
Necessary Cart session, login, security No — necessary for the operation of the Store
Functional Remembering preferences (language, currency) No — but you can disable them in your browser
Analytical Google Analytics 4, Shopify statistics Yes — consent may be implicit, but we ask for explicit consent
Advertising / Marketing Meta Pixel, TikTok Pixel, Google Ads Remarketing Yes — explicit consent is required

10.3. Consent Mode and consent management

We use Google Consent Mode v2 and Shopify's built-in consent management system. Upon entering the Store, you will see a cookie banner where you can:

  • accept all categories,

  • accept necessary only,

  • customize your choice individually.

You can change your preferences at any time by clicking the link "Privacy / Cookie Settings" in the Store footer.

10.4. How to disable cookies?

You can block cookies in your browser settings. However, remember that disabling necessary cookies may make it impossible to place an order.

11. Data security

We apply technical and organizational measures to ensure data protection:

  • SSL/TLS encryption across the entire site (HTTPS certificate),

  • encrypted passwords (hashed in the Shopify database),

  • two-step verification for access to the administration panel,

  • regular system updates,

  • data access restricted exclusively to authorized persons.

12. Profiling and automated decision-making

We do not make decisions about you in a fully automated manner, including decisions based on profiling, that would produce legal effects concerning you or similarly significantly affect you.

However, we use analytical and advertising tools (e.g., Meta Pixel) which, based on your behavior in the Store, may display personalized ads to you. This activity is based on consent and you can disable it at any time.

13. Privacy contact

Please address all matters related to personal data protection to:

E-mail: contact@rillandriver.com
Subject: [GDPR] — [description of the matter, e.g., "Request for access to data"]

We respond to all messages within 30 days.

14. Policy changes

We may update this Policy as the Store develops or regulations change. We will inform you of significant changes by e-mail or via a prominent notice in the Store. The current version is always available on this page.

Tables
Version Date Change
1.0 01.08.2026 First release — basic version of the Terms/Policy for the PL and EU market