Privacy Policy (GDPR)

Effective from: 01.03.2026

Data Controller: ULTRASSHOP.COM Mariusz Nowak
ul. Ogrodowa 167, 33-300 Nowy Sącz, Poland
VAT ID: PL7343265753   REGON: 386985689
Email: contact@ultrasshop.com

1. Scope

This Privacy Policy explains how we process personal data when you use our website, place orders, contact us, or use our services (B2C and B2B worldwide).

↑ Back to top

2. What data we collect

  • Account data: name, email, phone, billing/shipping address.
  • Order data: products, quantities, prices, invoices, correspondence.
  • Payment data: payment status, transaction IDs (no full card data stored).
  • Technical data: IP address, device/browser data, logs.
  • Content files: designs/images you upload for production.
↑ Back to top

3. Purposes & legal bases (GDPR)

We process data based on:

  • Contract performance: fulfilling your orders.
  • Legal obligation: tax and accounting laws.
  • Legitimate interest: fraud prevention and security.
  • Consent: newsletter and marketing activities.
↑ Back to top

4. Payments

Payments are handled by external providers (Mollie, Stripe, PayPal). They act as independent controllers. We only receive payment status and transaction identifiers to confirm your order.

↑ Back to top

5. Shipping & fulfilment

We share your delivery details (name, address, phone) with our logistics partners (e.g., DPD, DHL, GLS) solely to deliver your package and provide tracking updates.

↑ Back to top

6. Marketing & analytics

We use email marketing (newsletters) only if you have given explicit consent. For website improvement, we use analytical tools (cookies) to understand how users interact with our store.

↑ Back to top

7. Sharing data

We may share data with:

  • Payment operators (processing transactions).
  • Courier companies (delivery).
  • IT & Hosting providers (store maintenance).
  • Accounting & Law firms (compliance).
↑ Back to top

8. International transfers

If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCC) approved by the European Commission.

↑ Back to top

9. Retention periods

  • Order data: 5 years from the end of the tax year (legal requirement).
  • Account data: Until you request deletion of your account.
  • Marketing: Until you withdraw your consent.
↑ Back to top

10. Your rights

  • Access, rectify, or erase your data.
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent at any time.
↑ Back to top

11. Security

We use technical and organizational measures (like SSL encryption, firewalls, and access control) to ensure a level of security appropriate to the risk of processing personal data.

↑ Back to top

12. Contact & complaints

Questions regarding your data can be sent to contact@ultrasshop.com. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) in Poland.

↑ Back to top

Questions?

Contact us: contact@ultrasshop.com