Privacy
A small shop with limited data collection
Last updated: July 23, 2026
1. Data controller
The controller is Agnieszka Janarek, conducting business as TROMPLO Agnieszka Janarek, 7 Jana Kowalika Street, Niegoszowice, 32-064, post Rudawa, Poland. NIP: 5130241087. REGON: 361915607. Contact: contact@tromplo.com, +48 509 217 119.
2. Data collected
The public sales pages can be read without an account. The shop does not use advertising trackers, marketing pixels, or a newsletter form. Hosting and security systems may process IP address, browser and device information, request time, referring page, and basic diagnostic logs.
For purchases, the shop processes the checkout reference, order email, payment status, amount, currency, tax status, payment and transaction identifiers, delivery status, access expiry, download count, and support correspondence. It never receives or stores complete card or PayPal credentials.
3. Purposes and legal bases
Order and delivery data are processed to conclude and perform the contract, provide both PDFs, send the confirmation and recovery email, and handle support (Article 6(1)(b) GDPR). Data required for accounting, tax, and other statutory duties are processed to comply with legal obligations (Article 6(1)(c) GDPR). Security, rate-limiting, fraud prevention, service diagnostics, and the establishment or defence of claims rely on the controller's legitimate interests (Article 6(1)(f) GDPR).
Providing an order email and the information required by Stripe is necessary to purchase and receive the ebook. Without it, the contract cannot be completed. Purchase data are not used to add the customer to a marketing list.
4. Service providers and transfers
Data are disclosed only as needed to providers supporting this shop: Stripe for checkout, payment, tax, receipts, and fraud prevention; Resend for the transactional delivery email and the seller's automatic paid-order notification; the website's hosting and storage providers; and professional advisers, accountants, banks, or public authorities where required.
Some providers may process data outside the European Economic Area. Where this occurs, transfers are made under the provider's applicable safeguards, such as an adequacy decision or standard contractual clauses. The PDF files are not attached to the delivery email and are not supplied to the email provider.
5. Retention
Secure browser and email recovery access expires after 30 days. Order, payment-confirmation, and accounting records are retained for the periods required by tax, accounting, consumer-protection, and limitation-of-claims rules, generally up to six years after the contract is performed. Support correspondence may be retained for up to three years after the contact ends, or longer where needed for an active claim. Provider logs may follow the provider's documented retention schedule.
6. Cookies and security
The shop uses only strictly necessary technical storage. After a verified purchase or recovery link, it places an opaque, HttpOnly, Secure, SameSite cookie in the browser so the private PDFs can be downloaded. No advertising or cross-site tracking cookies are used. Reasonable technical and organizational safeguards protect stored order and delivery data.
7. Your GDPR rights
Subject to the conditions in applicable law, you may request access, rectification, erasure, restriction, or portability of your data and may object to processing based on legitimate interests. Where processing relies on consent, consent may be withdrawn without affecting earlier lawful processing. Some records cannot be deleted while the controller must retain them by law or for legal claims.
Requests can be sent to contact@tromplo.com. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), uodo.gov.pl.
8. Automated decisions and external services
Tromplo Books does not use order data for profiling or decisions producing legal or similarly significant effects. Stripe may apply automated fraud, authentication, tax, or payment controls under its own terms. Requests concerning data Stripe controls directly may need to be addressed to Stripe.