Shop privacy policy

Last updated: 26 September 2026

This page explains what data the shop.adaraz.com shop collects, why, who we share it with and how long we keep it. We keep it short and specific - if anything is unclear, write to us.

Cookies in the shop

1. Who is responsible for your data

The controller is ADARAZ P.S.A., ul. Towarowa 23, 43-100 Tychy, Poland, entered in the National Court Register (KRS) under number 0001261520, VAT ID PL6463032324 ("we").

For anything about personal data write to contact@adaraz.com or by post to our registered address. We have not appointed a data protection officer.

2. What this policy covers

It covers the shop.adaraz.com shop: visits to the site and orders for RAZ-RCP-1 readers, RFID cards and fobs, and RCP-CLOUD subscriptions. We sell to businesses, so we mainly process data of people acting on behalf of a business - sole traders, employees placing an order - and of people visiting the shop.

Data that you or your employees enter into RCP-CLOUD (e.g. employee data and working time records) is processed on your behalf under a data processing agreement. This policy does not describe it.

3. What data we collect

  • Order details you enter in the payment window: email address, phone number, company name, tax ID, billing address, delivery address (for readers) and order notes.
  • Order history: products, amounts, order number, dates, payment method and result. We never see card numbers or bank login details - they go only to the payment provider.
  • Where you came from: landing page, referring page and campaign parameters from the page address (e.g. utm_source, gclid) - we save them with the order.
  • With your consent: Google Analytics identifiers (client_id, session_id) saved with the order, and what you agreed to in the cookie banner.
  • A hash of your IP address (cryptographic, not the address itself) - to limit how many orders one customer can have open at the same time.
  • Technical visit data: IP address, browser and device type, pages visited - in server logs, in bot protection and, with your consent, in Google Analytics.
  • Correspondence: whatever you write to us.

Providing data is voluntary, but without an email address, invoice details and a delivery address we cannot fulfil the order.

4. Why we process data and on what legal basis

  • Accepting and fulfilling the order: payment, shipping, starting the subscription, contact about the order - Art. 6(1)(b) GDPR (contract) or, when you act on behalf of a business, Art. 6(1)(f) GDPR (our legitimate interest in performing the contract with your business).
  • Invoices, accounting and taxes - Art. 6(1)(c) GDPR (obligations under tax and accounting law).
  • Complaints, warranty, pursuing and defending claims - Art. 6(1)(f) GDPR.
  • Shop security: protection against bots and abuse, order limits, server logs - Art. 6(1)(f) GDPR.
  • Replying to messages - Art. 6(1)(f) GDPR, or (b) when they concern a contract.
  • Cookie-free visit statistics and checking which sources and campaigns bring orders - Art. 6(1)(f) GDPR.
  • Google Analytics and Google Ads with cookies - your consent: Art. 6(1)(a) GDPR and Art. 399 of the Polish Electronic Communications Law.

5. Payments

Payments are handled by Stripe Payments Europe, Limited (Dublin, Ireland): card, BLIK and Przelewy24. The payment window on our site belongs to Stripe - that is where you enter your order details. Stripe also processes payment data as a separate controller, e.g. to prevent fraud and meet legal obligations - see https://stripe.com/privacy

When you pay with Przelewy24, payment data also goes to PayPro S.A. of Poznań, the operator of Przelewy24. For subscriptions Stripe stores your payment method to collect the next payments. After you pay, Stripe sends you a confirmation email.

6. Google Analytics and Google Ads (with consent)

If you agree in the banner, we use Google Analytics 4 (statistics) and Google Ads (measuring ad performance), provided by Google Ireland Limited. Google then receives information about your visit: pages visited, products viewed, starting a payment and the purchase (order number, products, amount), cookie identifiers and device data. Google Analytics 4 does not store IP addresses.

If the Google script does not run or you do not come back to the page after paying, our server sends the purchase to Google Analytics - only if you agreed to statistics. With marketing consent the same applies to the Google Ads conversion, together with the ad click identifier.

With marketing consent we also pass SHA-256 hashes of the email address and phone number from the order to Google Ads (enhanced conversions). Google matches them against Google accounts to tell whether the purchase came from an ad. We never send the address or number itself.

Without your consent the Google tag sends only signals without cookies or identifiers, which Google uses to estimate statistics in aggregate. You can withdraw consent at any time with the "Cookie settings" button in the footer. Withdrawal does not affect the lawfulness of what happened before.

More about how Google uses data: https://policies.google.com/technologies/partner-sites

7. Bot protection and cookie-free statistics

When you place an order we check that a human is doing it with Cloudflare Turnstile (Cloudflare, Inc.). It processes your IP address and browser data - see https://www.cloudflare.com/privacypolicy/

We also count visits with umami, running on our own server in the European Union. It stores nothing in your browser and creates no identifiers.

8. Who we share data with

  • Payment providers: Stripe and PayPro (Przelewy24).
  • Google - only with your consent (section 6) - and Cloudflare (section 7).
  • Companies working on our behalf: providers of email, text messaging, servers, invoicing and accounting software, our accounting office and legal advisers.
  • The courier company - company name, delivery address and phone.
  • Authorities, when the law requires it, e.g. the tax administration, including through the Polish National e-Invoice System (KSeF).

We do not sell data.

9. Transfers outside the European Economic Area

Google, Stripe and Cloudflare may also process data in the USA. The basis is the European Commission adequacy decision (EU-US Data Privacy Framework), in which these companies participate, and standard contractual clauses. Write to us for a copy of the safeguards.

10. How long we keep data

  • Paid orders and invoices: 5 years from the end of the calendar year in which the tax payment deadline passed, or until a dispute ends.
  • RCP-CLOUD subscription: for the duration of the contract, then as for paid orders.
  • Unpaid orders (abandoned, expired, failed): up to 6 months.
  • IP address hash: as long as the order it is saved with.
  • Correspondence: until the matter is resolved or, if it concerns an order, as long as the order.
  • Google Analytics: 14 months. Cookies: as described on the cookies page.
  • Server logs: briefly, usually no longer than a few weeks.

11. Your rights

  • access to your data and a copy of it,
  • rectification,
  • erasure or restriction of processing,
  • data portability, where we process data under a contract or consent,
  • objection to processing based on our legitimate interest,
  • withdrawal of consent at any time,
  • a complaint to the Polish supervisory authority, the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or the authority in your country.

To use your rights, write to contact@adaraz.com. We reply within one month.

12. Automated decisions

We do not make decisions with legal effects on you solely by automated means. Bot protection may automatically stop a suspicious order - write to us and we will handle it manually. With marketing consent Google may tailor the ads it shows you.

13. Changes to this policy

When we change how we process data, we will update this page and the date at the top. If a change needs new consent, we will ask for it in the banner.