India Market Online Store Privacy Policy

1. General provisions

  1. This Privacy Policy sets out the rules for the processing of personal data of users of the India Market online store, available at: https://indiamkt.myshopify.com/
  2. The personal data controller is: Chopina 6/LU2, Katowice, 40-095
    e-mail: biuro@indiamarket.pl
    tel.: 0123-456-789
  3. The Administrator exercises due diligence to protect the interests of data subjects, and in particular ensures that the collected data are:
    a) processed in accordance with the law,
    b) collected for specified, lawful purposes and not subject to further processing incompatible with these purposes,
    c) factually correct and adequate in relation to the purposes for which they are processed,
    d) stored in a form which allows identification of data subjects no longer than is necessary to achieve the purpose of processing.
  4. The Administrator processes personal data in accordance with the GDPR and other relevant legal provisions.

2. Contact regarding personal data

  1. In matters concerning the processing of personal data, you can contact the Administrator at the following e-mail address: biuro@indiamarket.pl or by phone: 0123-456-789.
  2. The Administrator has not appointed a Data Protection Officer.

3. Scope of collected data

The Administrator may process the following personal data of users and customers of the Store:

a) name and surname,
b) delivery address,
c) billing address,
d) email address,
e) telephone number,
f) company name,
g) Tax Identification Number,
h) order history,
i) payment details,
j) data provided in the contact form,
k) customer account details.

4. Purposes and legal basis of data processing

Personal data are processed by the Administrator for the following purposes:

  1. execution of orders – pursuant to Article 6(1)(b) of the GDPR, i.e. for the purpose of concluding and performing a contract;
  2. payment processing – pursuant to Article 6(1)(b) of the GDPR;
  3. maintaining and servicing the customer account – pursuant to Article 6(1)(b) of the GDPR;
  4. contacting the customer in matters related to the order, store service, complaints and returns – pursuant to Article 6(1)(b) of the GDPR, and in some cases also Article 6(1)(f) of the GDPR, i.e. the legitimate interest of the Controller;
  5. handling complaints, returns and pursuing or defending against claims – pursuant to Article 6(1)(c) and (f) of the GDPR;
  6. issuing invoices, keeping accounting records and fulfilling tax and accounting obligations – pursuant to Article 6(1)(c) of the GDPR;
  7. statistical analysis of the store's operation and improvement of its functionality – pursuant to Article 6(1)(f) of the GDPR;
  8. the Administrator's own marketing to the extent permitted by law – pursuant to Article 6(1)(f) of the GDPR, and if required by law – also based on the user's consent.

5. Providing data

  1. Providing personal data is voluntary, however, to the extent necessary to place and fulfill an order, set up a customer account, process payments, complaints or contact – it may be necessary to use certain functionalities of the Store.
  2. Failure to provide the data required to achieve a given purpose may result in the inability to conclude a contract, complete an order, issue an invoice, create an account or respond to a message.

6. Data recipients

Personal data may be transferred to entities cooperating with the Controller only to the extent necessary to achieve the purposes of processing, in particular:

a) Shopify – as the store platform provider,
b) PayPro SA / Przelewy24 – as the payment operator,
c) InPost, DHL, DPD – as entities delivering orders,
d) entities providing accounting services or an accounting office,
e) Zoho Mail e-mail provider,
f) entities providing technical, hosting, IT and organizational support, if it is necessary for the functioning of the Store.

7. Transfer of data outside the EEA

  1. Due to the Controller's use of tools and services from technology providers, including Shopify, personal data may be transferred outside the European Economic Area.
  2. In such cases, the Controller applies appropriate safeguards required by law, in particular the mechanisms provided for by the GDPR, such as standard contractual clauses, if required.

8. Data storage period

Personal data is stored for no longer than necessary to achieve the purpose for which it was collected, and thereafter for the period required by law or necessary to pursue or defend against legal claims. In particular:

  1. data related to the execution of orders, settlements, invoices and tax obligations – for the period required by tax and accounting law;
  2. customer account data – until the account is deleted or the purpose of processing ceases;
  3. data related to complaints, returns and claims – for the time necessary to process them and for the limitation period for any claims;
  4. data from the contact form – for the time needed to respond and further process the case, and if the correspondence is of evidentiary significance – also for the limitation period for claims;
  5. data processed for statistical and analytical purposes – for the period necessary to achieve these purposes or until an effective objection is raised, if the basis is a legitimate interest.

9. Rights of data subjects

The data subject has the rights arising from the GDPR, in particular:

a) the right to access data, b) the right to rectify data, c) the right to delete data, d) the right to restrict processing, e) the right to data portability, f) the right to object to data processing based on the legitimate interest of the Controller, g) the right to withdraw consent at any time if the processing is based on consent, provided that the withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal, h) the right to lodge a complaint with the President of the Personal Data Protection Office.

10. Customer account and contact form

  1. Creating a customer account is voluntary, but requires providing the data necessary to create and manage it.
  2. Data provided via the contact form is processed solely for the purpose of handling messages, responding and conducting further correspondence, if necessary.

11. Children's data

The Store is not directed to individuals under the age of 18. The Administrator does not intend to knowingly collect personal data from children without a legal basis and the required consent.

12. Automated decision-making and profiling

Based on the information provided by the Controller, personal data are not used to make decisions about users based solely on automated processing, which would produce legal effects for them or similarly significantly affect them.

13. Data security

The Administrator uses appropriate technical and organizational measures to protect personal data against loss, destruction, disclosure to unauthorized persons, unauthorized modification or unlawful access.

14. Cookies and analytical data

  1. The store may use cookies and similar technologies to ensure the proper operation of the website, improve its functionality, maintain user sessions and conduct statistical analyses.
  2. The Administrator indicates that he uses Google Analytics for the statistical analysis of traffic in the Store.
  3. Detailed information on cookies, analytical technologies, their types, purposes and principles of their management will be presented in a separate Cookies Policy 

15. Changes to the Privacy Policy

  1. The Administrator may change this Privacy Policy in the event of: a) changes in legal provisions, b) changes in the methods of operation of the Store, c) implementation of new technological or organizational tools, d) changes in the scope or purposes of data processing.
  2. The current version of the Privacy Policy is published on the Store's website.

16. Final provisions

  1. This Privacy Policy is effective from March 10, 2026.
  2. In matters not covered by this Privacy Policy, the relevant provisions of Polish and EU law, in particular the GDPR, shall apply.