Skip to content

Documents

Privacy Policy

We treat your data with the same care we put into packing our pieces. Here is what we collect, why, on what basis and for how long — and what your rights are.

1. Data controller

The controller of your personal data is AKW GROUP Spółka z ograniczoną odpowiedzialnością with its registered office in Trzebnica, ul. Fiołkowa 7, 55-100 Trzebnica, Poland, KRS 0001259161, tax ID 9151840777 (“we”, “Sari Bali”).

For data protection matters write to office@saribali.com or by post to the address above. We have not appointed a data protection officer — the scale and nature of our processing do not require one.

2. What data we collect and where it comes from

Pre-order reservation and back-in-stock notification: e-mail address, quantity, optional notes, site language and the country determined from your network location (country code only, no IP address).

Order and customer account: name, delivery and billing address, e-mail, phone, invoice details (including company name and tax ID), order history, tracking number. Card, BLIK or transfer data go only to our payment provider Stripe — we never see or store them; from Stripe we receive only the payment status, the last digits of the card and the verification result.

Founders’ Club (newsletter): e-mail address, language, date and source of sign-up. Contact form: name, e-mail, message.

How you found us: on your first visit we store in your browser (localStorage) the entry channel — e.g. search engine, AI assistant, social media, campaign link (utm parameters) — and the landing page. This record contains no personal or device identifier; we attach it to a reservation, sign-up or order solely to learn which channels work.

Anonymous visit statistics: the sequence of pages and product views within one visit, linked to a random session identifier in sessionStorage (gone when the tab closes). We do not store IP addresses or anything that could identify you. Your IP address is processed transiently by the hosting provider (security logs, abuse protection, rate limits) and never enters our database.

Data from third parties: Stripe passes us the payment status and risk assessment result; the carrier passes us the delivery status. We do not obtain any other data about you from external sources.

3. Purposes and legal bases

Accepting and handling pre-order reservations, performing the contract of sale and running your account, including contact about delivery — Article 6(1)(b) GDPR (contract or pre-contractual steps).

Issuing invoices, accounting, handling complaints and withdrawals, product-safety obligations — Article 6(1)(c) GDPR (legal obligation).

Founders’ Club newsletter and availability notifications — Article 6(1)(a) GDPR (consent), which you can withdraw at any time via the link in any message or by writing to us; withdrawal does not affect the lawfulness of earlier processing.

Replying to messages, protection against abuse and bots, payment fraud prevention, anonymous visit statistics, analysis of customer acquisition channels, and establishing, exercising and defending legal claims — Article 6(1)(f) GDPR (our legitimate interest: running and developing the shop securely).

We do not make decisions about you based solely on automated processing that would produce legal effects. Our payment provider Stripe automatically assesses fraud risk (Stripe Radar) and may decline a transaction — it does so as an independent controller, and you can choose another payment method or contact us.

4. Who we share data with

Only with entities necessary to run the shop, under data-processing agreements (processors) or as independent controllers: Vercel Inc. (hosting, server functions, Vercel Analytics), Neon Inc. (shop database), Stripe Payments Europe Ltd. (payments and fraud prevention — independent controller), Resend Inc. (transactional e-mails and newsletter), Apaczka sp. z o.o. and the carriers performing delivery (DPD, DHL, GLS, UPS, pallet carriers — independent controllers for the delivery), our accounting office and, in the event of a dispute, a law firm. We disclose data to public authorities only where required by law.

Some of these providers have servers outside the European Economic Area (USA). Transfers are based on the European Commission’s adequacy decision (EU-U.S. Data Privacy Framework) or on standard contractual clauses approved by the Commission; a copy of the safeguards is available on request. We do not sell your data and do not share it with advertising networks.

5. How long we keep data

Pre-order reservations: until fulfilled or cancelled, then up to 12 months in case of questions. Orders, invoices and complaint correspondence: 5 years from the end of the tax year in which the invoice was issued (tax law), and for claims — until the limitation period expires (generally 6 years). Customer account: until you delete it. Marketing consents: until withdrawn; afterwards we keep only proof that consent was given and withdrawn, for 3 years. Contact-form messages: up to 12 months after the matter is closed. Anonymous visit statistics: 24 months. Hosting security logs: up to 30 days.

6. Your rights

You have the right to access your data and obtain a copy, to rectification, erasure (“right to be forgotten”), restriction of processing, data portability (for data processed on the basis of a contract or consent), to object to processing based on legitimate interest — including at any time to direct marketing — and to withdraw consent at any time. Just e-mail office@saribali.com; we reply without undue delay and at the latest within one month.

You also have the right to lodge a complaint with a supervisory authority: in Poland the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl), or, if you live in another EU country, the supervisory authority there.

Providing data is voluntary, but without an e-mail address we cannot accept a reservation, and without a delivery address and invoice details we cannot fulfil an order. The shop is not directed at persons under 16 and we do not knowingly collect their data.

7. Cookies and browser storage

We use only files and entries strictly necessary for the site to work, which under Article 5(3) of Directive 2002/58/EC do not require consent: the cart and account session cookie (Payload, up to 2 days), the language cookie (NEXT_LOCALE), the preview-access cookie (up to 30 days), Stripe cookies on the payment page (fraud prevention), and localStorage/sessionStorage entries with recently viewed items, the chosen theme, the dismissed announcement bar, the anonymous visit identifier and the entry channel. None of them tracks you across other companies’ sites.

We use no advertising cookies and no cookie-based third-party analytics, which is why we show no consent banner. Vercel Analytics measures visits without cookies and without identifying individuals (anonymised request hash, no IP address stored). Fonts are served from our own server — we do not connect to Google Fonts. If we ever introduce tools that require consent, we will ask for it first.

8. Security and changes to this policy

The connection to the site is encrypted (HTTPS, HSTS). Only the people running Sari Bali have access to the shop admin panel, after login with lockout on failed attempts; database data is encrypted at rest and in transit. Public forms are protected against bots (rate limits, honeypot fields). If a personal data breach were likely to result in a high risk to your rights, we would inform you without undue delay.

We update this policy when tools or laws change. The date of the last change is shown below; we announce material changes on the site and inform account holders by e-mail.

Last updated: 8 September 2026