Last updated: August 26, 2026
1. General provisions
This Privacy Policy sets out the rules for processing the personal data of users of the CottonLine online store available at:
and the rules for the use of cookies and similar technologies.
CottonLine respects the privacy of individuals using the Store and makes every effort to ensure that personal data is processed in accordance with applicable laws, in particular:
– Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (“GDPR”)
– the Act of July 12, 2024 – Electronic Communications Law
– consumer protection regulations
– tax and accounting regulations.
The Controller takes appropriate organizational and technical measures to protect personal data against loss, unauthorized access, disclosure, alteration or destruction.
2. Data Controller
The Controller of personal data is:
CodeCraft Studio Tomasz Kempa
Łańcut 37-100, ul. Skotnik 17
TAXID: 8151801541
REGON: 365937735
BDO: 000742577
E-mail: office@cottonline.pl
Phone: +48883943473
The registered office address and other identification details of the Controller are available in the Store and in the company information.
Contact regarding personal data:
E-mail: office@cottonline.pl
For matters concerning the processing of personal data, exercising rights under the GDPR or privacy protection, you can contact the Controller using the e-mail address indicated above.
3. What personal data do we process?
Depending on how you use the Store, we may process, in particular:
– first and last name
– company name
– delivery address
– billing address
– country
– NIP number
– e-mail address
– telephone number
– order information
– payment and transaction information
– shipment details
– information provided when contacting the Store's customer service
– user account data
– session data
– IP address
– information concerning the device and browser
– data concerning the use of the Store
– information stored in cookies or the device's local storage – in accordance with the user's selected consent settings.
The scope of the processed data depends on whether the user makes a purchase, has an account, contacts customer service, uses the chat or has given consent for analytics or marketing.
4. Purposes and legal bases for data processing
We process personal data for the following purposes:
4.1. Creating and managing a customer account
If the user creates an account in the Store, their data is processed for the purpose of creating and managing the account, enabling login and providing access to order history and other account functions.
Legal basis: Article 6(1)(b) GDPR – performance of a contract or taking steps at the request of the data subject prior to entering into a contract.
4.2. Order processing
Data is processed for the purpose of:
– accepting and processing an order
– preparing the product for shipment
– contacting the user regarding the order
– processing payments
– delivering the shipment
– handling returns and complaints
– maintaining transaction-related documentation.
Legal basis: Article 6(1)(b) GDPR.
Providing the data necessary to process an order is voluntary; however, failure to provide such data may make it impossible to conclude or perform the contract.
4.3. Payments
For online payments, we use Stripe services.
Stripe may process data related to payments and transactions, including information concerning the amount, country, e-mail address and other information required to process and secure the transaction.
With regard to payment data, Stripe may act as an independent data controller, in accordance with its own privacy rules.
For bank transfer payments, we process the data contained in the transaction documentation, in particular information provided together with the transfer.
4.4. Order delivery
For the purpose of delivering orders, we may transfer data to courier companies and logistics operators, in particular:
– InPost / InPost International, including through the API and ShipX solutions we use.
The scope of the transferred data may include:
– first and last name
– delivery address
– telephone number
– e-mail address
– pickup point / Parcel Locker details
– shipment information.
Legal basis: Article 6(1)(b) GDPR.
4.5. Issuing invoices and fulfilling tax obligations
Data is processed for the purpose of issuing accounting documents, maintaining sales documentation and fulfilling obligations arising from tax and accounting regulations.
For this purpose, we use, among others, the inFakt system.
The scope of data may include, among others:
– first and last name or company name
– NIP number
– address
– country
– transaction details.
Legal basis: Article 6(1)(c) GDPR.
4.6. Customer service and contact
Data provided when contacting CottonLine, including through forms, e-mail or chat, is processed for the purpose of providing a response, handling inquiries, assisting in the purchasing process and providing after-sales service.
We use Tawk to provide chat support.
The following may be processed as part of a conversation:
– conversation content
– IP address
– technical information
– data voluntarily provided by the user.
Legal basis: Article 6(1)(b) GDPR – if the contact concerns taking steps at the user's request or performing a contract – or Article 6(1)(f) GDPR, if processing is necessary to handle an inquiry, ensure security or defend against claims.
4.7. Order-related notifications
We use the Resend service to send transactional messages.
Through this service, we may send, among others:
– order confirmations
– information regarding shipping cost calculations
– information about the order status
– other messages necessary to process the order.
Legal basis: Article 6(1)(b) GDPR.
4.8. Analysis of the use of the Store
If the user provides the appropriate consent, we use Google Analytics, launched through Google Tag Manager.
Google Analytics may process, among others:
– information about pages visited
– events related to the use of the Store
– cookie identifiers
– information about the device and browser
– information concerning how the Store is used.
Analytics is activated in accordance with the user's consent settings.
Legal basis: Article 6(1)(a) GDPR – the user's consent.
The user may withdraw or change their consent through the cookie settings available in the Store.
5. Marketing and Google Customer Reviews
If the user gives marketing consent, appropriate advertising and remarketing tags may be activated in the Store.
As part of the Google Customer Reviews feature, we may provide Google with data necessary to handle an invitation to submit a review, in particular the e-mail address, order number and country.
This functionality is activated in accordance with the marketing consent settings.
Legal basis: Article 6(1)(a) GDPR.
Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
6. Google Tag Manager and Google Consent Mode
The Store uses Google Tag Manager (GTM) to manage tags used in the Store.
Before analytical and marketing tags are activated, the Store communicates the user's consent status to Google in accordance with the Google Consent Mode v2 mechanism.
By default, categories related to analytics and advertising are set as not permitted until the user makes an appropriate decision.
After the user's decision is changed, the consent status is updated.
The loading of the tag management mechanism itself may involve the processing of basic technical data, such as the IP address, device information or request headers.
7. Service providers and data recipients
Depending on the purpose of processing, data may be transferred or made available to entities supporting CottonLine's operations.
These include, in particular:
– Provider – Purpose
– Cloudflare – hosting, infrastructure, CDN, security
– Supabase – database, authentication, data storage
– Stripe – online payments
– InPost / InPost International – shipment delivery
– inFakt – invoicing and sales documentation
– Google – analytics, tag management, reviews and – with consent – marketing
– Tawk.to – chat support
– Resend – transactional message delivery
– Von Halsky / Allegro – processing orders from marketplaces, where applicable.
Data may also be disclosed to entities authorized under applicable law, in particular public authorities, if such an obligation arises from legal provisions.
8. Transfer of data outside the European Economic Area
Some service providers used by CottonLine may process data outside the European Economic Area.
In such cases, the Controller takes the measures required by the GDPR to ensure an appropriate level of data protection, in particular by using – depending on the specific provider and transfer:
– adequacy decisions
– Standard Contractual Clauses (SCCs)
– appropriate additional safeguards
– other mechanisms provided for by the GDPR.
Detailed information regarding transfer mechanisms may also be available in the data protection documentation of individual providers.
9. Data retention period
We retain personal data for no longer than is necessary to fulfil the purpose for which it was collected, taking into account legal obligations and the possibility of pursuing and defending claims.
In particular:
– Data related to orders
We retain it for the period necessary to process the order, provide after-sales service and for the period required by law.
Accounting documentation
We retain documents and data related to tax and accounting obligations for the period required by law.
Account data
We retain account data until the account is deleted, subject to data that must be retained for a longer period under the law or for the purpose of pursuing or defending claims.
Contact data
We retain data related to correspondence for the period necessary to handle the matter and subsequently for a period justified by the nature of the matter or potential claims.
Analytical and marketing data
They are processed in accordance with the consent provided and the retention rules applicable to the relevant providers.
The Controller applies the principle of storage limitation and does not retain personal data for longer than is necessary for a given purpose.
10. Rights of the data subject
To the extent provided for by the GDPR, the user has the following rights:
– the right to access their data
– the right to obtain a copy of their data
– the right to rectify their data
– the right to erase their data
– the right to restrict processing
– the right to data portability
– the right to object to processing
– the right to withdraw consent at any time if processing is based on consent
– the right to lodge a complaint with a supervisory authority.
The right to erase data is not absolute. In particular, the Controller may be required to continue retaining certain data due to a legal obligation or the need to establish, pursue or defend claims.
11. Right to object
If data is processed on the basis of the Controller's legitimate interest, the user may object for reasons related to their particular situation.
If data is processed for direct marketing purposes, the user may object to such processing at any time.
12. Withdrawal of consent
If data processing is based on consent, the user may withdraw it at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
In the case of cookies and similar technologies, settings can be changed using the:
“Cookie settings” function available in the Store footer.
13. Cookies and local storage
The Store uses cookies and local data storage technologies (localStorage).
We use the following categories:
Cookies and necessary technologies
They are used to ensure the proper functioning of the Store, in particular:
– maintaining the user's session
– login handling
– shopping cart functionality
– remembering the language
– remembering the currency
– supporting guest shopping
– ensuring security.
Necessary technologies do not require consent if their use is necessary to provide a service requested by the user or to ensure its proper functioning. Polish law provides an exception to the consent requirement, among others, for storing information necessary to perform a service requested by the user.
14. Chat Tawk
The Store uses Tawk as a customer service tool.
The widget allows the user to contact CottonLine support in real time.
As part of the chat functionality, cookies or localStorage may be used, among others, to maintain session continuity and ensure the proper functioning of the conversation.
Data provided during a conversation may include the content of messages, IP address and data voluntarily provided by the user.
Note: in CottonLine's configuration, Tawk is treated as a necessary functionality for providing support during purchases.
15. Google Analytics analytical cookies
If the user gives consent to analytics, the Store may use, among others, _ga, *ga* and other Google Analytics technologies.
They are used to analyze how the Store is used and to prepare statistics.
Google Analytics is activated only in accordance with the user's consent.
16. Marketing cookies
If the user gives marketing consent, the Store may use Google technologies and other advertising tags used, among others, for:
– conducting advertising campaigns
– measuring advertising effectiveness
– remarketing
– ad personalization.
The user may withdraw consent at any time using the cookie settings.
17. List of basic cookies and technologies
Name / technology | Purpose | Category
– cottonline.consent – storing the consent decision – Necessary
– sb-*-auth-token – maintaining the Supabase session – Necessary
– shopping cart localStorage – shopping cart functionality – Necessary
– language localStorage – remembering the language – Necessary
– currency localStorage – remembering the currency – Necessary
– _ga, ga* – Google Analytics analytics – Analytics
– Google Ads cookies – advertising/remarketing – Marketing
– Tawk cookies – chat operation and continuity – Functional
– Stripe cookies – security and fraud prevention during payment – Necessary for payments
The retention period of individual cookies may depend on the specific technology and provider settings.
18. Consent management mechanism
The Store uses its own consent management mechanism integrated with Google Consent Mode v2.
By default, before obtaining the user's consent:
– ad_storage – denied
– ad_user_data – denied
– ad_personalization – denied
– analytics_storage – denied
– personalization_storage – denied.
Technologies related to functionality and security are activated according to their nature and necessity for the operation of the Store.
After the user makes a decision, the Store sends the updated consent status to the tag management mechanism.
The user's decision is stored locally on the device under the key:
– cottonline.consent
Consent is stored for 12 months, after which the user will be asked to make a new choice.
A change in the version of the consent mechanism may result in the need to select the settings again.
19. Security
CottonLine applies appropriate technical and organizational measures to protect personal data.
In particular, the following mechanisms are used:
– access control
– authentication
– transmission encryption
– infrastructure security
– database access control
– provider infrastructure security mechanisms.
When using Supabase, data access control mechanisms consistent with the system configuration are also applied.
20. Data of persons contacting us on behalf of companies
If a user contacts CottonLine in connection with business activities, the data of individuals representing an entrepreneur or acting on their behalf may also constitute personal data protected under the GDPR.
Such data may be processed for the purpose of conducting business communication, preparing offers, processing orders and handling cooperation.
21. Data originating from marketplaces
If an order originates from a marketplace or another sales channel, order-related data may be transferred to CottonLine's systems for the purpose of processing the order.
This applies in particular to orders originating from:
– Allegro
– Von Halsky,
if these channels are used by CottonLine.
The scope of data depends on the information provided by the relevant marketplace.
22. Automated decision-making and profiling
User data is not used by CottonLine to make decisions producing legal effects or similarly significantly affecting them solely by automated means.
If analytical or advertising mechanisms that may involve profiling are used as part of external services, this takes place in accordance with the rules of the relevant provider and – in cases requiring consent – after obtaining the user's appropriate consent.
23. Children
The Store is not specifically directed at children and does not knowingly collect children's personal data without an appropriate legal basis.
If the Controller becomes aware that data has been provided by a child in a situation where appropriate action by a legal representative was required, it may take steps to delete such data, unless there is another legal basis for retaining it.
24. Right to lodge a complaint
If the user believes that their data is being processed in violation of the GDPR, they have the right to lodge a complaint with the competent supervisory authority.
In Poland, the supervisory authority is:
– President of the Personal Data Protection Office (UODO)
25. Changes to the Privacy Policy
This Privacy Policy may be periodically updated, in particular in the event of:
– changes to the operation of the Store
– introduction of new services
– changes to providers
– changes in legal regulations
– technological changes.
The current version of the Privacy Policy is published on the Store's website.
The date of the latest update is indicated at the beginning of the document.
26. Contact
If you have any questions regarding privacy, the processing of personal data or exercising your rights under the GDPR, please contact:
CodeCraft Studio Tomasz Kempa
Łańcut 37-100, ul. Skotnik 17
TAXID: 8151801541
REGON: 365937735
BDO: 000742577
E-mail: office@cottonline.pl
Phone: +48883943473