Privacy Policy
Rockworld Store Privacy Policy
1. General Information
This Privacy Policy defines the rules for processing personal data and using cookies in connection with the use of the Rockworld online store available at www.rockworld-carpshop.com.
The data controller is the owner of the Rockworld store. The contact details of the controller are available on the page: www.rockworld-carpshop.com/i,4,kontakt.html
The controller processes personal data in accordance with applicable law, in particular in accordance with:
- The Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR),
- The Act on Providing Services by Electronic Means,
- The Telecommunications Law.
The controller takes special care to protect the interests of data subjects.
---
2. Scope of Processed Data
Depending on how the site is used, the following data may be processed:
- First and last name
- Email address
- Phone number
- Delivery address
- IP address
- Device and browser data
- Data regarding activity on the site
- Data related to order fulfillment
---
3. Purposes and Legal Bases for Data Processing
Personal data is processed for the following purposes:
Order fulfillment
Legal basis: Art. 6(1)(b) GDPR – performance of a contract.
Customer account management
Legal basis: Art. 6(1)(b) GDPR.
Handling complaints and returns
Legal basis: Art. 6(1)(c) GDPR – legal obligations of the controller.
Marketing of own products and services
Legal basis: Art. 6(1)(a) GDPR – user consent.
Newsletter and SMS marketing communication
Legal basis: Art. 6(1)(a) GDPR – user consent.
Website traffic analysis and service optimization
Legal basis: Art. 6(1)(f) GDPR – legitimate interest of the controller.
Ensuring website security
Legal basis: Art. 6(1)(f) GDPR.
---
4. Newsletter and SMS Marketing
Users can subscribe to the newsletter or consent to receive SMS marketing messages.
In such cases, the following data are processed:
- Email address
- Phone number
Data is used solely for sending marketing information regarding Rockworld store’s offers.
Users can withdraw their consent to receive marketing communications at any time.
---
5. Data Recipients
Personal data may be shared with entities cooperating with the Controller to the extent necessary to provide services.
Payment Operators
- PayU
- PayPal
- Autopay
- Przelewy24
- PayPo
- Santander Consumer Bank (installments)
- Credit Agricole (installments)
Courier Companies
- InPost
- DPD
- DHL
- GLS
IT Service Providers
- home.pl – website hosting
- IT service providers supporting store operations
These entities process data only to the extent necessary to provide their services.
---
6. Data Transfer Outside the European Economic Area
Some tools used on the site may result in data being transferred outside the European Economic Area, in particular to the United States.
Data transfer takes place based on:
- Standard Contractual Clauses of the European Commission (SCC),
- EU-US Data Privacy Framework.
---
7. Data Retention Period
Personal data is retained for the period of:
- Order fulfillment and contract management,
- Required by tax and accounting regulations,
- Until withdrawal of consent in case of marketing,
- Until objection to data processing is submitted.
---
8. User Rights
Users have the right to:
- Access their data,
- Rectify data,
- Delete data,
- Restrict processing,
- Data portability,
- Object to data processing,
- Withdraw consent at any time.
Users also have the right to lodge a complaint with the President of the Personal Data Protection Office.
---
9. Cookies and Similar Technologies
The site uses cookies to:
- Ensure proper website functionality,
- Analyze website traffic,
- Conduct marketing activities,
- Remember user preferences.
Upon the first visit, users can consent to the use of specific cookie categories via the consent management panel.
Users can change cookie settings anytime via the consent management panel or their browser settings.
---
Consent Management and Google Consent Mode
The site applies a user consent management mechanism concerning cookies and marketing technologies.
For Google services, the Google Consent Mode is used, allowing transmission to Google systems of the user’s consent status for analytical and marketing data processing.
---
10. Analytical and Marketing Tools Used
When using marketing tools, pseudonymous user profiles may be created based on site usage information.
These profiles are used to display ads tailored to users’ interests (remarketing).
---
Google Analytics 4
The site uses the Google Analytics 4 analytics tool provided by Google Ireland Ltd.
---
Google Search Console
The administrator uses Google Search Console to monitor site visibility in Google search results.
---
Google Ads
The site uses Google Ads to run advertising campaigns and remarketing.
---
Meta Pixel (Facebook Pixel)
The site uses Meta Pixel to analyze the effectiveness of advertising campaigns run on Meta platforms.
---
TikTok Pixel
The site uses TikTok Pixel to analyze the effectiveness of advertising campaigns run on TikTok.
---
Microsoft Clarity
Microsoft Clarity enables analysis of how users interact with the site.
---
Microsoft Advertising
The administrator uses Microsoft Advertising to run advertising campaigns.
---
Hotjar
Hotjar allows analysis of user behavior and website optimization.
---
11. Infrastructure Services and Security
Cloudflare
The site uses Cloudflare services to provide protection against DDoS attacks and accelerate site performance via a CDN network.
---
12. External Content
The site may embed materials from YouTube. When playing videos, the service provider may process user data.
---
13. Data Security
The administrator applies appropriate technical and organizational measures to protect personal data from loss or unauthorized access.
---
14. Privacy Policy Changes
The administrator reserves the right to make changes to this privacy policy.
The current document version is published on the online store website.
Last update: 09.03.2026