Datenschutzerklärung

 

Effective Date: 01.10.2026



§ 1

Who We Are and How to Contact Us

 

1.1. The Data Controller responsible for your personal data is STARFALL sp. z o.o., with its registered office at ul. Kalwaryjska 69/9, 30-504 Krakow, Poland, entered the registry under Tax Identification Number: 679329228, hereinafter: "SYXED", "we", "us".

 

1.2. For all matters relating to your personal data, privacy, or to exercise your rights, you can contact our dedicated privacy team:

a)       By email: support@syxed.com

b)      By post: to our registered office address listed in § 1.1.

 

1.3. No DPO Appointed: We have not appointed a formal Data Protection Officer (DPO). All data protection matters are handled directly by the SYXED support team.

 

§ 2

What Data We Collect and Why (Purposes & Legal Bases)

 

Purpose of Processing

Categories of Data

Legal Basis (GDPR)

Account Creation & Maintenance

Email address, first and last name, secure password (hashed), age declaration.

Art. 6(1)(b) (Performance of a contract to provide digital services).

Order Fulfillment & Delivery

Shipping/billing address, phone number, purchased items (size, color).

Art. 6(1)(b) (Performance of a Sales Contract).

Payment Processing

Payment method choice, transaction IDs. (Note: Full credit card numbers are handled directly by providers like Stripe and are not stored by us).

Art. 6(1)(b) (Contract) and Art. 6(1)(f) (Legitimate interest in fraud prevention).

Tax & Accounting Obligations

Invoices, transaction history, billing details.

Art. 6(1)(c) (Compliance with legal obligations under Polish tax law).

Handling Returns & Warranties

Order details, communication history, photos of defects, bank account details for refunds.

Art. 6(1)(b) (Contract) and Art. 6(1)(c) (Consumer protection laws).

Customer Support & Disputes

Content of emails, contact form messages, order notes.

Art. 6(1)(f) (Legitimate interest in resolving customer inquiries and defending claims).

Marketing (Newsletter & Promos)

Email address, name, purchase history.

Art. 6(1)(a) (Your explicit consent).

Site Security & Diagnostics

IP address, device type, browser information, approximate geolocation (country/city derived from IP).

Art. 6(1)(f) (Legitimate interest in securing our infrastructure and preventing DdoS attacks).

Evidentiary Logs (Accountability)

Logs of Terms acceptance, cookie consent logs (timestamp, IP, user agent).

Art. 6(1) and (f) (Proving compliance with GDPR – Art. 7(1)).

 

§ 3

Minors and Parents/Guardians

3.1. Age Thresholds: You must be at least 16 years old to browse the Site. To create an account or place an order, you must explicitly declare that you are 18 years of age or older.

 

3.2. Ages 16-17: If you are between 16 and 17, you may only create an account and place orders with the active involvement and authorization of your Parent or Legal Guardian. The Guardian acts as the contracting party and payer.

 

3.3. Data Deletion: We do not knowingly collect data from children under 16 If we discover that a user under 16 has provided personal data, we will immediately block the account and initiate the deletion of the data.

 

§ 4

Who We Share Your Data With

 

To run a global e-commerce brand, we securely share your data with specialized third-party processors.

Recipient / Partner

Role & Purpose

Data Shared

Region & Transfer Mechanism

Shopify Inc.

E-commerce Platform Hosting & Infrastructure.

All store data (Orders, Accounts, Products, Traffic).

Canada / USA (EU-US Data Privacy Framework / SCCs).

Stripe / PayPal / Klarna

Payment Service Providers (Independent Controllers for KYC/AML).

Transaction IDs, Cart Value, Email, Billing details.

Ireland / USA (SCCs or equivalent mechanisms).

Logistics (e.g., DHL, DPD)

Couriers delivering your orders.

Name, Shipping Address, Phone Number, Email.

EU / Global (Independent Controllers for delivery).

Klaviyo (or similar)

Managing Newsletters & Transactional Emails.

Email, Name, Order History (only if opted-in).

USA (EU-US Data Privacy Framework / SCCs).

Cloudflare Inc.

CDN, DDoS Protection, Web Application Firewall.

IP Address, HTTP traffic metadata.

Global Edge (SCCs).

Meta / TikTok / Google

Advertising Partners (See § 7 and § 8).

Pseudonymous browsing events, hashed emails.

Ireland / USA (SCCs).

 

§ 5

International Data Transfers (Outside the EEA)

 

5.1. Your data may be processed outside the European Economic Area (EEA), primarily in the USA and Canada, due to our use of global infrastructure (e.g., Shopify, Cloudflare).

 

5.2. We ensure your data remains strictly protected by relying on European Commission Adequacy Decisions (such as the EU-US Data Privacy Framework) or by executing Standard Contractual Clauses (SCCs) with our vendors. You can request a copy of the applied safeguards by contacting us at support@syxed.com.



§ 6.

How Long We Keep Your Data

 

We do not hold your data forever. We enforce the following retention periods:

 

a)       Unfinished Accounts / Abandoned Carts: 30 days (unless marketing consent is given to recover the cart).

b)      Customer Account Data: For the duration of your active account.

c)       Tax & Accounting Data (Invoices): 5 years from the end of the calendar year in which the tax obligation arose (mandatory under Polish law).

d)      Warranty & Returns Documentation: For the duration of the 2-year warranty period, plus 1 year to cover late claims or legal disputes.

e)       Marketing Data: Until you withdraw your consent (unsubscribe) or object to processing.

f)        Cookie Consent & Legal Logs: Duration of the account plus up to 3 years after deletion (for accountability).

g)       Technical Logs (Server errors): Maximum of 90 days, then automatically overwritten.

 

§ 7

Marketing Pixels and Analytics

 

If you grant your explicit consent via our cookie banner, we use tracking technologies ("pixels") to measure the effectiveness of our advertising campaigns and to show you personalized ads.

a)       Meta Pixel (Facebook & Instagram): We use the Meta Pixel provided by Meta Platforms Ireland Ltd. It allows Meta to identify you as a visitor to our Site and display targeted SYXED advertisements to you on Facebook and Instagram. The collected data is anonymous to us, but Meta may link it to your social media profile.

b)      TikTok Pixel: We use the TikTok Pixel to present you with interest-based ads on the TikTok platform and create statistical reports.

c)       Google Analytics & Ads: We utilize Google tools to understand how users navigate our Site and to serve ads that match your fashion preferences.

d)      Opt-out: You can manage your ad preferences directly in your Meta, TikTok, or Google account settings, or withdraw your cookie consent on our Site at any time.

 

§ 8

Custom Audiences

 

8.1. To provide you with highly relevant streetwear drops and promotions, we may use tools like "Facebook Custom Audience" or "Google Ads Customer Match".

 

8.2. How it works: We transmit your email address or phone number in an encrypted (hashed) format to Meta or Google. If you are a registered user of these platforms with the same contact details, you may see our sponsored posts.

 

8.3. Your Control: The platforms cannot decrypt this data if you are not their user. You can opt out of this specific targeting at any time by contacting us at support@syxed.com.



§ 9

Social Media Profiles

 

9.1. Our Fanpages: SYXED maintains public profiles on social media platforms including Instagram, Facebook, and TikTok. When you interact with our profiles, both SYXED and the platform operator process your data.

 

9.2. Page Insights: Platform operators (like Meta) provide us with anonymized statistical data ("Insights") about our audience's demographics and interaction rates to help us optimize our content.

 

9.3. Joint Controllers: For the creation of these Insights, SYXED and the respective platform operator act as Joint Data Controllers under the GDPR. You can exercise your GDPR rights regarding this processing directly against the platform operators or by contacting us.



§ 10

Automated Decision Making and AI Transparency

 

10.1. No AI Pricing: SYXED does not use artificial intelligence or automated profiling to dynamically inflate or individualize the prices of Products based on your personal behavior, browsing history, or location.

 

10.2. Automated Fraud Prevention: Our payment gateways (e.g., Stripe) use automated algorithms to detect fraudulent transactions (e.g., mismatched IP and billing address). If your payment is automatically blocked, you have the right to request a manual review by a human operator by contacting our support team.



§ 11

Cookies and Tracking Technologies

 

11.1. Use of Cookies: Our Site uses cookies and similar tracking technologies to ensure the proper functioning of the Site, analyze user traffic, and tailor marketing campaigns. 

 

11.2. Required Cookies: These cookies are necessary for the site to function properly, including capabilities like logging in and adding items to the cart. They are always active, cannot be switched off in our systems, and do not require your consent.

 

11.3. Personalization Cookies: With your explicit consent, these cookies store details about your actions to personalize your next visit to the website.

 

11.4. Marketing Cookies: With your explicit consent, these cookies are used by us and our partners, including Shopify, to optimize marketing communications and show you ads on other websites.

 

11.5. Analytics Cookies: With your explicit consent, these cookies help us understand how you interact with the site. We use this data to identify areas to improve.

 

11.6. Cookie Consent Banner (CMP): Upon your first visit to the Site, you will be presented with a cookie consent banner. Personalization, Marketing, and Analytics cookies are blocked by default. They will only be deployed if you explicitly click "Accept" or manually opt-in via the "Manage preferences" centre. You also have the option to easily "Decline" all non-essential tracking.

 

11.7. Managing and Withdrawing Consent: You have the absolute right to change your cookie preferences or withdraw your consent at any time without detriment. You can do this by clicking the "Manage preferences" or "Cookie Settings" link located in the footer of our Site, or by clearing your web browser's cookie cache.

 

§ 12

Your Rights Under GDPR

 

You have the following rights regarding your personal data. We will respond to your requests within one month:

a)       Access (Art. 15): Request a copy of all data we hold about you.

b)      Portability (Art. 20): Request your data in a structured, machine-readable format.

c)       Rectification (Art. 16): Update your details directly in your account settings.

d)      Erasure (Art. 17): Request the deletion of your account and data. (Note: We cannot delete data that we are legally required to keep, e.g., invoices for tax purposes).

e)       Restriction (Art. 18): Ask us to temporarily freeze the processing of your data.

f)        Withdrawal of Consent (Art. 7(3)): Unsubscribe from our newsletter at any time. This does not affect the legality of processing prior to withdrawal.

g)       Right to Object (Art. 21): You can object to processing based on our legitimate interests. You have an absolute right to object to direct marketing at any time.

h)      Right to Complain: If you believe we process your data unlawfully, you have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland, or with your local EU supervisory authority.

 

§ 13

 Changes to This Policy

 

We may update this Privacy Policy to reflect changes in our processes or legal requirements. We will notify registered users of significant changes via email at least 14 days before they take effect.