Privacy policy

Âme Dare respects your privacy. This policy explains what personal data we collect, why, how long we keep it and what rights you have.

It is written in accordance with Regulation (EU) 2016/679 (GDPR) and the Polish Act on the Protection of Personal Data of 10 May 2018.


01

Controller

Ame Dare brand by Darya Yersh
ul. Kolejowa 43, 01-210 Warszawa, Poland
NIP 5273189387 · REGON 543078800
contact@amedare.com

We have not appointed a data protection officer; we are not required to. For any question about your data, write to the address above.


02

What We Collect

Category Data
Identity First name, last name
Contact Email, delivery and billing address, phone number if you give one
Order Order number and contents, sizes, order history, correspondence with us
Payment Transaction identifier, payment method type, last four digits of the card, billing address, payment status. We never receive or store your full card number
Account Login credentials in encrypted form, saved addresses, preferences
Returns Reason for return, condition assessment, photographs of the piece
Technical IP address, browser and device type, operating system, pages viewed, referring page, cookie identifiers
Marketing Newsletter subscription, record and date of consent, opens and clicks

We do not collect special categories of data — data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data or data concerning sexual orientation. Please do not send us such data.

Providing identity, contact, address and payment data is necessary to conclude and perform a sales contract; without it we cannot process an order. Providing a phone number and subscribing to the newsletter are voluntary.


03

Why We Process It

Purpose Legal basis
Concluding and performing your order, delivery, payment Art. 6(1)(b) GDPR — performance of a contract
Handling withdrawals, returns, refunds and complaints Art. 6(1)(b) and 6(1)(c) GDPR — contract and legal obligation
Managing your account Art. 6(1)(b) GDPR
Answering enquiries you send us Art. 6(1)(b) or 6(1)(f) GDPR — legitimate interest in responding
Invoices, tax and accounting records Art. 6(1)(c) GDPR — legal obligation
Newsletter and marketing emails Art. 6(1)(a) GDPR — your consent
Website analytics and performance Art. 6(1)(a) GDPR — your consent via the cookie banner
Website security and fraud prevention Art. 6(1)(f) GDPR — legitimate interest
Establishing, exercising or defending legal claims Art. 6(1)(f) GDPR — legitimate interest

04

Automated Decision-Making

We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

Our platform and payment providers apply automated fraud-risk scoring to orders. A high score does not automatically cancel an order — it is flagged for our review, and any decision to decline an order is taken by us. You may contact us to have such a decision reviewed.


05

Who Receives Your Data

We share your data only with providers who need it to deliver a service to us. They act as processors under written data processing agreements and may not use your data for their own purposes.

Recipient Purpose
Shopify International Ltd. (Ireland) and Shopify Inc. (Canada) Platform, hosting, orders
Shopify International Ltd. and Stripe Payments Europe, Ltd. (Ireland) Payments
UPS, DHL, DPD and our shipping-label provider Delivery
Klaviyo, Inc. (United States) Newsletter and marketing email
Intuition Machines, Inc. (hCaptcha) Bot protection
Bro Prospero Sp. z o.o. (Poland) Accounting and tax records
Legal advisers Establishing or defending claims
Public authorities Where we are legally obliged to disclose

We do not sell your personal data.


06

Transfers Outside the EEA

Some of our providers are established outside the European Economic Area, or use infrastructure outside it. In particular, Shopify is a Canadian company operating global infrastructure that includes the United States, and Klaviyo and hCaptcha are established in the United States.

Where data is transferred outside the EEA, we rely on an adequacy decision of the European Commission where one covers the recipient — including the decision on Canada for commercial organisations and the EU–US Data Privacy Framework for certified US recipients — or on standard contractual clauses approved by the European Commission, together with supplementary measures where required.

You may ask us for details of the safeguards applied to a specific transfer.


07

How Long We Keep It

Data Retention period
Order, invoice and accounting records 5 years from the end of the calendar year in which the tax was due — Article 86 of the Polish Tax Ordinance and Article 74 of the Accounting Act
Order and correspondence data kept to defend claims Up to 6 years from performance of the contract — Article 118 of the Polish Civil Code
Returns and complaint records, including condition photographs 6 years from resolution
Account data While your account is open, then up to 6 years for the limitation period above
Newsletter subscription Until you withdraw consent; proof of consent and withdrawal kept a further 3 years
Enquiries sent through the contact form 3 years from the last message, unless they relate to an order
Website analytics Up to 14 months
Server and security logs 12 months

When a retention period ends, data is deleted or irreversibly anonymised.


08

Your Rights

You have the right to:

  • access your data and obtain a copy;
  • have inaccurate data rectified and incomplete data completed;
  • have your data erased, where one of the grounds in Article 17 GDPR applies;
  • restrict processing, in the situations set out in Article 18 GDPR;
  • data portability — receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
  • object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest. Where you object to processing for direct marketing, we stop without exception;
  • withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before it;
  • lodge a complaint with a supervisory authority.

To exercise any of these rights, write to contact@amedare.com. We may ask you to confirm your identity where we cannot otherwise establish it.

We respond without undue delay and in any event within one month of receiving your request. Where a request is complex, or where we receive a number of requests from you, we may extend that period by up to two further months and will tell you within the first month if we do (Article 12(3) GDPR).

The supervisory authority in Poland is the Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. You may also complain to the authority in your own country of residence.


09

Newsletter

You may subscribe to our newsletter by giving your email address and confirming your consent. We use double opt-in: after subscribing you receive an email asking you to confirm, and we do not add you to the list until you do.

Every newsletter contains an unsubscribe link. You may also unsubscribe by writing to us. Unsubscribing takes effect without delay and at no cost.

Marketing by electronic means is sent in accordance with the Polish Electronic Communications Law.


10

Cookies

Essential cookies keep the website working — the basket, checkout, login and security. They cannot be switched off.

Analytics and marketing cookies are set only after you consent through the cookie banner. Analytics show us how the site is used. Marketing cookies link your visits to your newsletter subscription, so that we can send fewer and more relevant emails, including a reminder if you leave something in your basket.

We do not use advertising cookies for networks such as Meta or Google Ads. If we introduce them, we will update this policy first.

You can change or withdraw your cookie consent at any time via the Preferences link in the cookie banner, and you can block or delete cookies in your browser settings — although some parts of the website may then not work correctly.


11

Security

We apply technical and organisational measures appropriate to the risk, including encrypted transmission (TLS), access limited to those who need it, strong authentication on administrative accounts, and providers selected for their security standards. No system is completely secure, but we take the protection of your data seriously.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours, and we will notify you without undue delay where the risk is high (Articles 33 and 34 GDPR).


12

Children

The website is intended for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has provided us with personal data, write to us and we will delete it.


13

Changes

We may update this policy. The current version is always published here, with the date of the last update below. Where a change materially affects your rights, we will notify you by email or by a notice on the website before it takes effect.


Contact

Ame Dare brand by Darya Yersh
ul. Kolejowa 43, 01-210 Warszawa, Poland

contact@amedare.com · @amedare.brand

Last updated: 17 August 2026