Privacy policy
Âme Dare respects your privacy. This policy explains what personal data we collect, why, how long we keep it and what rights you have.
It is written in accordance with Regulation (EU) 2016/679 (GDPR) and the Polish Act on the Protection of Personal Data of 10 May 2018.
01
Controller
Ame Dare brand by Darya Yersh
ul. Kolejowa 43, 01-210 Warszawa, Poland
NIP 5273189387 · REGON 543078800
contact@amedare.com
We have not appointed a data protection officer; we are not required to. For any question about your data, write to the address above.
02
What We Collect
| Category | Data |
|---|---|
| Identity | First name, last name |
| Contact | Email, delivery and billing address, phone number if you give one |
| Order | Order number and contents, sizes, order history, correspondence with us |
| Payment | Transaction identifier, payment method type, last four digits of the card, billing address, payment status. We never receive or store your full card number |
| Account | Login credentials in encrypted form, saved addresses, preferences |
| Returns | Reason for return, condition assessment, photographs of the piece |
| Technical | IP address, browser and device type, operating system, pages viewed, referring page, cookie identifiers |
| Marketing | Newsletter subscription, record and date of consent, opens and clicks |
We do not collect special categories of data — data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data or data concerning sexual orientation. Please do not send us such data.
Providing identity, contact, address and payment data is necessary to conclude and perform a sales contract; without it we cannot process an order. Providing a phone number and subscribing to the newsletter are voluntary.
03
Why We Process It
| Purpose | Legal basis |
|---|---|
| Concluding and performing your order, delivery, payment | Art. 6(1)(b) GDPR — performance of a contract |
| Handling withdrawals, returns, refunds and complaints | Art. 6(1)(b) and 6(1)(c) GDPR — contract and legal obligation |
| Managing your account | Art. 6(1)(b) GDPR |
| Answering enquiries you send us | Art. 6(1)(b) or 6(1)(f) GDPR — legitimate interest in responding |
| Invoices, tax and accounting records | Art. 6(1)(c) GDPR — legal obligation |
| Newsletter and marketing emails | Art. 6(1)(a) GDPR — your consent |
| Website analytics and performance | Art. 6(1)(a) GDPR — your consent via the cookie banner |
| Website security and fraud prevention | Art. 6(1)(f) GDPR — legitimate interest |
| Establishing, exercising or defending legal claims | Art. 6(1)(f) GDPR — legitimate interest |
04
Automated Decision-Making
We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Our platform and payment providers apply automated fraud-risk scoring to orders. A high score does not automatically cancel an order — it is flagged for our review, and any decision to decline an order is taken by us. You may contact us to have such a decision reviewed.
05
Who Receives Your Data
We share your data only with providers who need it to deliver a service to us. They act as processors under written data processing agreements and may not use your data for their own purposes.
| Recipient | Purpose |
|---|---|
| Shopify International Ltd. (Ireland) and Shopify Inc. (Canada) | Platform, hosting, orders |
| Shopify International Ltd. and Stripe Payments Europe, Ltd. (Ireland) | Payments |
| UPS, DHL, DPD and our shipping-label provider | Delivery |
| Klaviyo, Inc. (United States) | Newsletter and marketing email |
| Intuition Machines, Inc. (hCaptcha) | Bot protection |
| Bro Prospero Sp. z o.o. (Poland) | Accounting and tax records |
| Legal advisers | Establishing or defending claims |
| Public authorities | Where we are legally obliged to disclose |
We do not sell your personal data.
06
Transfers Outside the EEA
Some of our providers are established outside the European Economic Area, or use infrastructure outside it. In particular, Shopify is a Canadian company operating global infrastructure that includes the United States, and Klaviyo and hCaptcha are established in the United States.
Where data is transferred outside the EEA, we rely on an adequacy decision of the European Commission where one covers the recipient — including the decision on Canada for commercial organisations and the EU–US Data Privacy Framework for certified US recipients — or on standard contractual clauses approved by the European Commission, together with supplementary measures where required.
You may ask us for details of the safeguards applied to a specific transfer.
07
How Long We Keep It
| Data | Retention period |
|---|---|
| Order, invoice and accounting records | 5 years from the end of the calendar year in which the tax was due — Article 86 of the Polish Tax Ordinance and Article 74 of the Accounting Act |
| Order and correspondence data kept to defend claims | Up to 6 years from performance of the contract — Article 118 of the Polish Civil Code |
| Returns and complaint records, including condition photographs | 6 years from resolution |
| Account data | While your account is open, then up to 6 years for the limitation period above |
| Newsletter subscription | Until you withdraw consent; proof of consent and withdrawal kept a further 3 years |
| Enquiries sent through the contact form | 3 years from the last message, unless they relate to an order |
| Website analytics | Up to 14 months |
| Server and security logs | 12 months |
When a retention period ends, data is deleted or irreversibly anonymised.
08
Your Rights
You have the right to:
- access your data and obtain a copy;
- have inaccurate data rectified and incomplete data completed;
- have your data erased, where one of the grounds in Article 17 GDPR applies;
- restrict processing, in the situations set out in Article 18 GDPR;
- data portability — receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest. Where you object to processing for direct marketing, we stop without exception;
- withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before it;
- lodge a complaint with a supervisory authority.
To exercise any of these rights, write to contact@amedare.com. We may ask you to confirm your identity where we cannot otherwise establish it.
We respond without undue delay and in any event within one month of receiving your request. Where a request is complex, or where we receive a number of requests from you, we may extend that period by up to two further months and will tell you within the first month if we do (Article 12(3) GDPR).
The supervisory authority in Poland is the Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. You may also complain to the authority in your own country of residence.
09
Newsletter
You may subscribe to our newsletter by giving your email address and confirming your consent. We use double opt-in: after subscribing you receive an email asking you to confirm, and we do not add you to the list until you do.
Every newsletter contains an unsubscribe link. You may also unsubscribe by writing to us. Unsubscribing takes effect without delay and at no cost.
Marketing by electronic means is sent in accordance with the Polish Electronic Communications Law.
10
Cookies
Essential cookies keep the website working — the basket, checkout, login and security. They cannot be switched off.
Analytics and marketing cookies are set only after you consent through the cookie banner. Analytics show us how the site is used. Marketing cookies link your visits to your newsletter subscription, so that we can send fewer and more relevant emails, including a reminder if you leave something in your basket.
We do not use advertising cookies for networks such as Meta or Google Ads. If we introduce them, we will update this policy first.
You can change or withdraw your cookie consent at any time via the Preferences link in the cookie banner, and you can block or delete cookies in your browser settings — although some parts of the website may then not work correctly.
11
Security
We apply technical and organisational measures appropriate to the risk, including encrypted transmission (TLS), access limited to those who need it, strong authentication on administrative accounts, and providers selected for their security standards. No system is completely secure, but we take the protection of your data seriously.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours, and we will notify you without undue delay where the risk is high (Articles 33 and 34 GDPR).
12
Children
The website is intended for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has provided us with personal data, write to us and we will delete it.
13
Changes
We may update this policy. The current version is always published here, with the date of the last update below. Where a change materially affects your rights, we will notify you by email or by a notice on the website before it takes effect.
Contact
Ame Dare brand by Darya Yersh
ul. Kolejowa 43, 01-210 Warszawa, Poland
contact@amedare.com · @amedare.brand
Last updated: 17 August 2026