Privacy policy

Last updated: June 22, 2026

1. General information

This Privacy Policy (hereinafter referred to as the “Policy”) describes how we collect, use, and disclose the personal data of individuals who visit the Tilda Clouds online store, available at [URL] (hereinafter referred to as the “Store”), make purchases through it, or otherwise communicate with us.

The Store operates on the Shopify platform, which provides us with the technical infrastructure necessary to offer online sales services.

In the event of any conflict between the Store Terms and Conditions and this Policy, the Policy shall prevail with respect to the collection, processing, and disclosure of personal data.

Please read this Policy carefully before using the Store.

2. Personal data controller

The controller of your personal data is Chmury Tildy Bożena Frąckowiak, operating a sole proprietorship at ul. Norwida 2/55, 76-200 Słupsk, Poland, Tax Identification Number (NIP): 8391579326 (hereinafter referred to as the “Controller”).

Contact details of the Controller:

Email address: hello@tildaclouds.pl (until an email address in the Store’s domain is launched)
Telephone: 506 870 745
Correspondence address: ul. Norwida 2/55, 76-200 Słupsk, Poland

3. Scope of personal data collected

Depending on how you use the Store, we may collect or process the following categories of personal data:

Contact details – full name, residential/delivery address, billing address, telephone number, and email address.

Financial data – payment card details (processed exclusively by payment service providers), transaction details, and payment methods. The Controller does not store complete payment card details.

Account data – username, password (in encrypted form), preferences, and settings.

Transaction data – products viewed and purchased, shopping cart and wish list contents, purchase history, returns, and exchanges.

Communications – the content of messages sent to the Controller, for example in connection with customer service.

Device and usage data – IP address, browser and operating system type, approximate location, the time and manner in which the Store is used, and pages visited. This data is automatically recorded in server logs.

4. Purposes and legal grounds for processing personal data

4.1 Entering into and performing an agreement for the provision of the Account Service

Data: full name and email address. Legal basis: Article 6(1)(b) of the GDPR. Providing the data is voluntary but necessary to create an account. Without this data, an account cannot be created. The data is processed until the limitation period for claims arising from the agreement expires.

4.2 Entering into and performing a Sales Agreement

Data: full name, email address, telephone number, residential/delivery address, and, optionally, company name and Tax Identification Number (NIP) for business customers. Legal basis: Article 6(1)(b) of the GDPR. Providing the data is voluntary but necessary to place and fulfil an order. The data is processed until the limitation period for claims arising from the Sales Agreement expires.

4.3 Newsletter

Data: email address. Legal basis: Article 6(1)(b) of the GDPR. Providing the data is voluntary but necessary to receive the Newsletter. The data is processed until an objection is successfully raised, the purpose of the processing has been achieved, or the limitation period for claims expires, whichever occurs first. You may unsubscribe from the Newsletter at any time by clicking the unsubscribe link included in each message.

4.4 Handling complaints

Data: full name and email address. Legal basis: Article 6(1)(c) of the GDPR – obligations arising from Article 7a of the Polish Consumer Rights Act and the provisions concerning liability for a product’s non-conformity with the agreement. The data is processed for the duration of the complaint procedure and, where the Customer exercises their rights, until the applicable limitation period expires.

4.5 Email notifications related to the performance of agreements

Data: email address. Legal basis: Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in informing Customers about activities related to the performance of agreements. The data is processed until an objection is successfully raised or the purpose of the processing has been achieved.

4.6 Handling Customer enquiries

Data: first name, email address, and any other data included in the message. Legal basis: Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in responding to enquiries. The data is processed until an objection is successfully raised or the purpose of the processing has been achieved.

4.7 Product availability notifications

Data: email address. Legal basis: Article 6(1)(f) of the GDPR – the Controller’s legitimate interest. The data is processed until an objection is successfully raised or the purpose of the processing has been achieved.

4.8 Tax and accounting obligations

Data: full name/company name, residential/registered office address, and Tax Identification Number (NIP). Legal basis: Article 6(1)(c) of the GDPR – obligations arising from tax law and the Polish Accounting Act. The data is processed for five years from the end of the year in which the deadline for payment of tax for the previous year expired.

4.9 Obligations arising from personal data protection legislation

Data: full name and contact details. Legal basis: Article 6(1)(c) of the GDPR. The data is processed until the limitation periods for claims arising from breaches of data protection legislation expire.

4.10 Establishing, pursuing, or defending against claims

Data: full name/company name, email address, residential/registered office address, Polish national identification number (PESEL), and Tax Identification Number (NIP). Legal basis: Article 6(1)(f) of the GDPR – the Controller’s legitimate interest. The data is processed until the applicable limitation periods for claims expire.

4.11 Analysing activity in the Store and administering the Store

Data: IP address, date and time of visits, operating system and browser type, approximate location, time spent in the Store, and products and pages viewed. Legal basis: Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in ensuring the proper operation and improvement of the Store. The data is processed until an objection is successfully raised or the purpose of the processing has been achieved.

4.12 Direct marketing and personalised advertising

Data: email address, Store activity data, and hashed contact details used in connection with Meta Enhanced Conversions. Legal basis: Article 6(1)(a) of the GDPR – consent granted through the cookie management panel. The data is processed until consent is withdrawn. The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

Note regarding Meta Pixel with Enhanced Conversions: as part of this functionality, encrypted (hashed) contact details, such as an email address or telephone number, are transferred to Meta Platforms for matching with user profiles on Facebook and Instagram. Due to the scope of this processing, its sole legal basis is consent under Article 6(1)(a) of the GDPR, rather than the Controller’s legitimate interest.

5. Data security and protection

The Controller applies modern organisational and technical security measures to provide the highest possible level of personal data protection and processes personal data in accordance with the GDPR and the Polish Act of May 10, 2018 on the Protection of Personal Data.

Please note that no security measures are perfect, and we cannot guarantee the absolute security of transmitted data. We strongly advise against sending sensitive information through insecure communication channels. The User is responsible for maintaining the confidentiality of their account login details.

6. Recipients of personal data

Personal data may be disclosed to the following categories of recipients:

  • Shopify Inc. – the Store platform operator (for details, see Section 7);
  • online payment service providers – to the extent necessary to process transactions;
  • courier companies and logistics providers – to the extent necessary to deliver orders;
  • the newsletter service provider – [Klaviyo / Mailchimp / other tool used];
  • Google LLC – in connection with Google Analytics 4;
  • Meta Platforms Ireland Limited – in connection with Meta Pixel with Enhanced Conversions;
  • the company providing accounting services;
  • public authorities – where disclosure is required by generally applicable law, a final court judgment, or an administrative decision.

7. Relationship with Shopify

The Store is operated using Shopify Inc. (151 O’Connor Street, Ottawa, Ontario, Canada). Shopify collects and processes the User’s personal data as a data processor acting on our behalf and, in relation to its own platform services, as an independent controller.

To provide advanced Shopify functionalities, Shopify may use data collected during the User’s interactions with our Store, other merchants, and the Shopify platform. In such cases, Shopify is independently responsible for processing this data.

More information about Shopify’s privacy practices: https://privacy.shopify.com/pl.

Shopify’s User Rights Portal: https://privacy.shopify.com/pl.

8. Transfers of data to third countries

Personal data may be transferred outside the European Economic Area to the following entities:

  • Shopify Inc. (Canada) – a country recognised by the European Commission as providing an adequate level of data protection under Decision 2002/2/EC;
  • Google LLC (USA) – data is transferred on the basis of Standard Contractual Clauses under Article 46(2)(c) of the GDPR and the EU–U.S. Data Privacy Framework;
  • Meta Platforms, Inc. (USA) – data is transferred on the basis of Standard Contractual Clauses under Article 46(2)(c) of the GDPR and the EU–U.S. Data Privacy Framework.

You may obtain a copy of the safeguards applied by contacting the Controller.

9. Cookies and similar technologies

What are cookies?

Cookies are small text files stored on your device when you visit the Store. They may be accessed by the Controller’s systems and by the systems of third parties whose services the Controller uses.

For what purposes do we use cookies?

Necessary cookies – enable the Store to function properly, including the shopping cart, session, and cookie management panel. These cookies cannot be disabled.

Analytics cookies – enable us to analyse traffic and how the Store is used in order to improve it, including through Google Analytics 4.

Marketing cookies – enable personalised advertising and remarketing, including through Meta Pixel with Enhanced Conversions.

Tools used

Tool Provider Scope of data Retention period
Necessary cookies Controller / Shopify IP address, session data, and cookie settings Primarily for the duration of the session; some remain until manually deleted
Google Analytics 4 Google LLC Number and duration of visits, traffic source, location, and e-commerce events; data anonymised by Google Up to two years or until deleted
Meta Pixel + Enhanced Conversions Meta Platforms Ireland Ltd. Activity in the Store and encrypted contact details (email address/telephone number) used for profile matching; remarketing on Facebook and Instagram Up to three months or until deleted

Managing cookies

During your first visit, we display a consent management panel (cookie banner) through which you may accept or reject individual categories of cookies. You may change your preferences at any time through your browser settings or by reopening the consent panel in the Store.

Disabling necessary cookies may prevent you from using the Store’s essential functions.

Data collected through cookies does not allow the Controller to identify you directly.

10. Children’s data

The Store is not intended for individuals under the age of 18. The Controller does not knowingly collect children’s personal data. If you are the parent or legal guardian of a child who has provided us with their data, please contact us, and the data will be deleted without delay. We do not share or sell the personal data of individuals under the age of 16.

11. Your rights

In connection with the processing of your personal data, you have the following rights:

Right of access – the right to obtain information about the personal data being processed and to receive a copy of it. The first copy is provided free of charge; the Controller may charge a fee corresponding to the administrative costs of providing additional copies.

Right to rectification – the right to request the correction of outdated, incomplete, or inaccurate data.

Right to erasure (the right to be forgotten) – you may request that your data be deleted, among other circumstances, when it is no longer necessary for the purposes for which it was collected, you have withdrawn your consent and there is no other legal basis for processing, the processing is unlawful, or erasure is required to comply with a legal obligation.

Right to restriction of processing – you may request that operations involving your data be restricted, for example while the accuracy of the data is being verified or an objection is being considered.

Right to data portability – where processing is based on consent or is necessary for the performance of an agreement, you have the right to receive your data in a structured, commonly used format, such as CSV, and to transmit it to another controller.

Right to withdraw consent – where processing is based on consent, you may withdraw it at any time through the cookie management panel or by contacting the Controller. The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

Right to object – you have the right to object to processing based on the Controller’s legitimate interest. Following a successful objection, the Controller will cease processing the data for that purpose unless the Controller demonstrates compelling legitimate grounds that override your interests.

Right to lodge a complaint – you have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland, www.uodo.gov.pl) if you believe that the processing of your data infringes the GDPR.

You may exercise your rights by contacting the Controller at the email address specified in Section 2. The Controller will respond to your request within one month of receiving it. This period may be extended by a further two months in the case of complex or numerous requests, and you will be informed of any such extension. We may ask you to verify your identity before fulfilling your request.

We will not discriminate against you for exercising your rights.

12. Links to external websites

The Store may contain links to third-party websites. The Controller is not responsible for the privacy practices or content of these websites. After visiting an external website, please review its privacy policy.

13. Changes to the Privacy Policy

The Controller reserves the right to update this Policy in response to changes in the law, the Controller’s practices, or for other operational and regulatory reasons. The updated Policy will be published in the Store with a new revision date. In the event of material changes, we will notify you in accordance with applicable law.

14. Final provisions

Any matters not governed by this Policy shall be subject to generally applicable personal data protection legislation, in particular the GDPR and the Polish Act of May 10, 2018 on the Protection of Personal Data.

This Policy is effective from June 22, 2026.

Chmury Tildy Bożena Frąckowiak • ul. Norwida 2/55, 76-200 Słupsk, Poland • Tax Identification Number (NIP): 8391579326