Skip to content
Free shipping across Europe — €60 to the USMade to order — 2-3 week lead timeNew drop SS25Crafted with intentionFree shipping across Europe — €60 to the USMade to order — 2-3 week lead timeNew drop SS25Crafted with intentionFree shipping across Europe — €60 to the USMade to order — 2-3 week lead timeNew drop SS25Crafted with intentionFree shipping across Europe — €60 to the USMade to order — 2-3 week lead timeNew drop SS25Crafted with intention

Legal

Privacy policy

Last updated: 2026-05-27

This policy explains what personal data we collect when you visit whywepray.shop, why we collect it, and what rights you have under the EU General Data Protection Regulation (GDPR).

Who we are

Data controller: [BUSINESS NAME], [BUSINESS ADDRESS], NIP [NIP], REGON [REGON]. Contact: orders@whywepray.shop.

What we collect and why

Order data

When you place an order, we collect your email, full name, shipping and billing address, phone number (optional), and order contents. Legal basis: performance of a contract (GDPR art. 6(1)(b)). Retention: 6 years from the end of the calendar year in which the order was placed, as required by Polish tax law (Ordynacja Podatkowa).

Account data (if you sign up)

Your email and a hashed password (argon2id). Legal basis: contract performance. Retention: until you delete your account.

Payment data

Card details are handled exclusively by Stripe; we never see or store them. We receive a payment confirmation and a tokenized reference (the Stripe payment intent ID). Legal basis: contract performance. Retention: with the order record.

Technical data

IP address, browser type, and request paths in server logs. Used for security, abuse prevention, and rate limiting. Legal basis: legitimate interest (GDPR art. 6(1)(f)). Retention: 30 days.

Who we share data with

  • Stripe Payments Europe Ltd. — payment processing. Data: name, email, billing address, transaction amount. Stripe acts as an independent controller for fraud-prevention purposes.
  • Resend (Resend Inc.) — transactional email delivery. Data: email address, message content. Acts as a processor.
  • Shipping carrier — name, address, phone (if provided). Disclosed only at fulfillment.
  • Hosting provider (OVH SAS, EU) — server infrastructure. Acts as a processor.

We do not sell personal data and we do not transfer it outside the EU/EEA.

Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you (art. 15)
  • Rectify inaccurate data (art. 16)
  • Erase your data, subject to legal retention obligations (art. 17)
  • Restrict processing (art. 18)
  • Data portability — receive your data in a machine-readable format (art. 20)
  • Object to processing based on legitimate interest (art. 21), in particular profiling
  • Lodge a complaint with the Polish supervisory authority, Prezes Urzędu Ochrony Danych Osobowych (uodo.gov.pl)

To exercise any of these rights, email orders@whywepray.shop. We respond within 30 days.

Cookies

We use only essential cookies (cart, authentication, site-password unlock). No advertising or cross-site tracking. See our Cookies policy for details.

Changes to this policy

We will post any material changes on this page and update the "Last updated" date. If changes are significant, we will email registered customers in advance.