Privacy policy

PRIVACY POLICY

Last updated: April 2026

This Privacy Policy describes how MnCwood ("we", "us", "our") collects, 
uses and protects your personal data when you visit mncwood.com (the "Site") 
or purchase our products. We comply with the EU General Data Protection 
Regulation (GDPR / RODO) and applicable Polish law.

-----------------------------------------------------------
1. DATA CONTROLLER
-----------------------------------------------------------

The controller of your personal data is:

MnCwood
[Vorname Nachname], sole proprietor (JDG)
ul. Łęczycka 8, 85-737 Bydgoszcz, Poland
NIP: 5543018515 · REGON: 526883788

Contact for privacy matters:
Email: contact@mncwood.com
Phone: +48 883 201 656

-----------------------------------------------------------
2. WHAT PERSONAL DATA WE COLLECT
-----------------------------------------------------------

Data you provide directly:
- Identification data: name, surname
- Contact data: email, phone, delivery address, billing address
- Order data: items ordered, engraving text, order history
- Payment data: handled by our payment providers — we do NOT store 
  full card numbers on our servers
- Communication: content of emails and messages you send us

Data collected automatically:
- Technical data: IP address, browser type, device, operating system
- Usage data: pages visited, time on site, referring URL, clicks
- Cookies and similar technologies (see Section 7)

-----------------------------------------------------------
3. WHY WE PROCESS YOUR DATA (LEGAL BASIS)
-----------------------------------------------------------

We process your data on the following GDPR legal bases:

a) Contract performance — Art. 6(1)(b) GDPR
   Processing orders, delivery, returns, customer service.

b) Legal obligation — Art. 6(1)(c) GDPR
   Issuing invoices, tax and accounting records (retained for 5 years 
   under Polish tax law).

c) Legitimate interest — Art. 6(1)(f) GDPR
   Website analytics, fraud prevention, improving our services, 
   answering enquiries.

d) Consent — Art. 6(1)(a) GDPR
   Newsletter subscription, marketing cookies, personalised ads. 
   You can withdraw consent at any time.

-----------------------------------------------------------
4. WHO WE SHARE YOUR DATA WITH
-----------------------------------------------------------

We share data only with trusted processors, strictly for the purposes 
listed above:

- Shopify Inc. (Canada/Ireland) — e-commerce platform and hosting
- Payment providers — Shop Pay, PayPal, Klarna, Stripe and others 
  depending on your chosen method
- Shipping carriers — DHL, FedEx, InPost, DPD and equivalents
- Email service providers — transactional and newsletter emails
- Google LLC — Google Analytics, Google Ads (only with your consent)
- Meta Platforms Ireland — Facebook/Instagram Pixel (only with your consent)
- Accountant / tax advisor — for invoicing and bookkeeping

All processors are bound by data processing agreements (DPA) as required 
by Art. 28 GDPR.

-----------------------------------------------------------
5. INTERNATIONAL DATA TRANSFERS
-----------------------------------------------------------

Some of our processors (Shopify, Google, Meta) may process data outside 
the European Economic Area. Such transfers are secured by:

- EU Standard Contractual Clauses (SCCs), or
- Adequacy decisions of the European Commission (e.g. EU-US Data 
  Privacy Framework for certified US providers).

-----------------------------------------------------------
6. HOW LONG WE KEEP YOUR DATA
-----------------------------------------------------------

- Order data: 5 years from the end of the tax year (Polish tax law)
- Account data: for as long as your account is active; deleted on request
- Newsletter subscribers: until you unsubscribe
- Contact form enquiries: up to 2 years after the last message
- Analytics data: up to 14 months (Google Analytics default)

-----------------------------------------------------------
7. COOKIES
-----------------------------------------------------------

We use the following categories of cookies:

- Strictly necessary — cart, checkout, security (no consent needed)
- Analytics — Google Analytics 4 (consent required)
- Marketing — Google Ads, Meta Pixel, Pinterest Tag (consent required)
- Preferences — language, currency (consent required)

You can manage your cookie preferences at any time via the cookie 
banner on our Site or via your browser settings.

-----------------------------------------------------------
8. YOUR RIGHTS UNDER GDPR
-----------------------------------------------------------

You have the right to:

- Access your personal data (Art. 15 GDPR)
- Rectify inaccurate data (Art. 16 GDPR)
- Erasure / "right to be forgotten" (Art. 17 GDPR)
- Restrict processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on legitimate interest (Art. 21 GDPR)
- Withdraw consent at any time — without affecting lawfulness of 
  processing before withdrawal (Art. 7 GDPR)
- Not be subject to automated decision-making (Art. 22 GDPR) — 
  we do not use such decision-making

To exercise any of these rights, email us at contact@mncwood.com. 
We respond within 30 days.

-----------------------------------------------------------
9. RIGHT TO LODGE A COMPLAINT
-----------------------------------------------------------

If you believe we process your data unlawfully, you have the right 
to lodge a complaint with the Polish data protection authority:

Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
https://uodo.gov.pl

Customers in other EU countries may also lodge a complaint with 
their local supervisory authority.

-----------------------------------------------------------
10. SECURITY
-----------------------------------------------------------

We apply technical and organisational measures to protect your data:
SSL/TLS encryption, secure hosting on Shopify infrastructure, 
restricted access on a need-to-know basis, regular security reviews.

-----------------------------------------------------------
11. CHILDREN
-----------------------------------------------------------

Our Site is not directed at children under 16. We do not knowingly 
collect personal data from children. If you believe a child has 
provided us with personal data, please contact us and we will 
delete it.

-----------------------------------------------------------
12. CHANGES TO THIS POLICY
-----------------------------------------------------------

We may update this Privacy Policy from time to time. The latest 
version is always available at mncwood.com/policies/privacy-policy 
with the "Last updated" date.

-----------------------------------------------------------
CONTACT
-----------------------------------------------------------

Questions about this policy or your personal data?
Email: contact@mncwood.com
Post: MnCwood, ul. Łęczycka 8, 85-737 Bydgoszcz, Poland