PRIVACY POLICY

Last updated: 19.09.2025

This Privacy Policy provides essential information about the purposes, methods of processing, and security of your personal data as a user of the website: metaloove.com (hereinafter referred to as the "Website"). By reading this Privacy Policy, you will learn who is the controller of your personal data, what personal data is collected by the Website, for what purposes it is used, and how it is protected.

§1. Basic Information

The controller of your personal data is: Piotr Boroń conducting business activity under Article 5 of the Act of March 6, 2018 on Polish Entrepreneurs' Law, with registered address at al. Solidarności 68/121, 00-240 Warsaw, Poland. Contact with the Controller is possible through: Email: [email protected] Phone :+48 574 489 947 You can review the terms of service for electronic services here: www.metaloove.com/regulamin For users outside the EU: This privacy policy also serves as our Privacy Notice under applicable data protection laws in your jurisdiction, including but not limited to the California Consumer Privacy Act (CCPA) for California residents and other applicable state and federal laws in the United States, as well as Japan's Personal Information Protection Act (PIPA).

§2. Data Processing Principles

The Controller processes personal data in accordance with the following principles: Based on legal grounds and in accordance with law (legality); Fairly and honestly (fairness); Transparently for the data subject (transparency); For specific purposes and not "in reserve" (purpose limitation); No more than necessary (data minimization); With care for data accuracy (accuracy); No longer than necessary (storage limitation); Ensuring appropriate data security (integrity and confidentiality).

§3. Purposes, Legal Bases, and Scope of Data Processing

We will process your data: For contact purposes - to provide you with a response to your message sent directly by email, through a form, via social media channels, or in response to telephone contact, based on the Controller's legitimate interest related to the necessity of providing you with a response; For marketing purposes - solely based on your explicit consent; To provide access to free materials that can be downloaded from the Website; To create and maintain your user account; To fulfill your order - based on the concluded sales contract (by successfully placing an order, a contract is concluded in which we act as the seller and you as the buyer), as well as based on legal provisions that we are obliged to execute in connection with the concluded sales contract; To fulfill orders for personalized posters and puzzles - processing data contained in materials provided by you (photos, texts) to create personalized products, based on the concluded contract; To realize your rights arising from complaint handling or the right to withdraw from the contract; For publication of your comments and product reviews available in our store, based on your consent and the Controller's legitimate interest related to the ability to comment on website content; For technical purposes using cookies (technical cookies), based on the Controller's legitimate interest related to the proper operation and functioning of the Website; For statistical and analytical purposes - if you have consented to our use of cookies for analytical purposes (analytical cookies); For marketing purposes - if you have consented to our use of cookies for marketing purposes (marketing cookies); For archiving phone numbers, order contents, invoices, documents, messages, emails, based on the Controller's legitimate interest related to protection against claims; For debt collection purposes in case of non-fulfillment of obligations towards the Controller, securing the Controller's claims and protection against claims of other persons against the Controller, which we consider our legitimate interest; For analysis of anonymous information - information collected through our Website, such as: browser information, operating system, device, time spent on the site, transitions between pages, link clicks, approximate location, age range, gender. This information is anonymized and collected through our partners' analytical systems. It does not allow for identification and attribution to a specific user. Scope of Data Processing: Email/form/social media/telephone contact: We process data contained in your message. Data provision is voluntary, and you can request deletion at any time; User account: We process data provided in the registration form, including: name and surname, email address, phone number, residential address, and purchase history. Providing name, surname, and email address is required for account creation; Online purchases: We process your name and surname, residential address, phone number, email address, and other data in the order form necessary for contract fulfillment; Personalized products: We process materials you provide (photos, texts, graphics) solely for product creation; Comments/reviews: We process your name and email address. Data provision is voluntary, and you can delete your comment at any time; Technical data: IP address and other data stored in cookies. You decide the scope of cookie usage, and you can change preferences anytime.

§4. Automated Decision-Making and Profiling

No Automated Profiling: We do not use automated profiling on the Website to create marketing campaigns based on measuring user activity. While we use analytical systems from our partners (Google), the information and data obtained about your activity on the Website for traffic analysis purposes do not constitute automated profiling, as we cannot make decisions regarding you as a specific user based on this information. For US Users: We do not engage in automated decision-making that produces legal or similarly significant effects concerning you. For Japanese Users: We do not conduct automated processing for profiling purposes that could significantly affect your rights or interests.

§5. Data Recipients and International Data Transfers

Depending on the purpose for which we process your data, recipients of your personal data may include: Government offices and other public institutions, as required by law; Website software provider (hosting, server, domain); User account and purchasing procedure software provider; Online payment intermediaries; Goods transport entities (courier companies); Website programming service providers; Software providers for issuing invoices and electronic documents; Accounting service providers; Legal service providers for protection and securing against claims; Cloud storage software providers; Cookie management software providers; If you consented to analytical cookies: entities providing website traffic analysis software (e.g., Google Analytics). International Data Transfers: Your data is not transferred to countries outside the EEA or international organizations, except for processing by: Google Inc. (USA) - for website traffic analytics in Google Analytics system and providing additional functions related to proper website functioning. See how Google processes and protects your data. This browser add-on allows you to manage the scope and level of data access collected by Google Analytics. For US Users: Data may be processed within the United States by our service providers operating under appropriate data protection agreements. For Japanese Users: Any international transfers comply with Japan's Personal Information Protection Act requirements, including appropriate safeguards for cross-border data transfers. EU Users: All international transfers are conducted with appropriate safeguards under GDPR, including adequacy decisions or appropriate safeguards such as Standard Contractual Clauses.

§6. Data Retention Period

We cannot specify a single period for data processing, as it depends on the purpose: Contact messages: Until you request deletion or object to processing, or until we determine our legitimate interest has been fulfilled; User accounts: Until you delete your account; Sales data: 6 years from the sale date due to legal-tax obligations; Personalized product materials: For the period necessary to fulfill the order, then deleted unless you consent to longer storage for potential reorders; Comments/reviews: Until deletion by you or us. Additional Retention Information for Different Jurisdictions: California Residents: We retain personal information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Japanese Users: Data retention complies with Japan's Personal Information Protection Act requirements.

§7. User Rights

All Users Have the Right to: Access to your data content and the right to rectification, deletion, restriction of processing; Data portability; Object to processing; Withdraw consent at any time and in any form (except where processing is necessary for contract performance, legal compliance, or legitimate interests). EU Users Additional Rights (GDPR): Right to lodge a complaint with the supervisory authority (President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland). California Residents Additional Rights (CCPA/CPRA): Right to know what personal information is collected; Right to delete personal information; Right to opt-out of the sale of personal information (Note: We do not sell personal information); Right to non-discrimination for exercising privacy rights; Right to limit use of sensitive personal information. Japanese Users Additional Rights: Right to request disclosure of personal information; Right to request correction or deletion; Right to request suspension of use; Right to request suspension of provision to third parties. Exercising Your Rights: Contact us at [email protected] to exercise any of these rights. We will respond within the timeframes required by applicable law (typically 30 days for GDPR requests, 45 days for CCPA requests). More information about personal data protection can be found at: www.uodo.gov.pl

§8. Information About Cookies

We use cookies on our Website. We have installed a plugin that allows you to independently manage the scope of personal data processing through cookies. Thanks to this functionality, you can easily and intuitively adjust data processing settings to your preferences. What are Cookies: Cookies are small text files stored on users' devices while browsing the website. They facilitate Website use, improve service quality, and enable traffic and user behavior analysis. Types of Cookies: Persistent cookies: Stored on the user's device for a specified time or until deleted by the user; Session cookies: Deleted after closing the browser; First-party cookies: Used for proper Website operation, content personalization, user preference storage, and statistics analysis; Third-party cookies: Used by external analytical tools. Cookie Control: Users have the right to control and limit cookie usage. Most web browsers allow cookie management, including blocking, restricting, or deleting cookies. Detailed cookie management information can be found in your browser settings. Important: Disabling or restricting cookies may affect Website functionality and service quality.

§9. Why We Use Cookies

Website usability comfort: Cookies significantly impact website usability comfort; Content personalization: Cookies allow content adaptation to user preferences and interests; Settings memory: Cookies remember user-selected settings like language, layout, or colors; Login functionality: Cookies store logged-in user information; Session maintenance: Cookies track user activity across different subpages; Performance optimization: Cookies analyze traffic and user behavior for performance optimization.

§10. Technical Cookies Functions

User session maintenance: Enable session continuity while navigating the Website; User preference memory: Store information about user preferences (language, font size, color settings); Form handling: Support form functionality (login, registration, contact forms); Website performance optimization: Monitor Website performance and loading speed; Security: Help ensure Website and user security, including identity verification and protection against CSRF attacks.

§11. Analytical Cookies Functions

Website traffic measurement: Monitor visits, unique users, and page views; User behavior analysis: Collect information about user navigation, time spent on pages, navigation paths; Conversion optimization: Identify Website elements affecting business goal achievement; User segmentation: Group users by various criteria for better content and offer adaptation; A/B testing: Compare two Website versions to determine which better meets objectives.

§12. Cloudflare Services

Our Website uses services provided by Cloudflare, Inc. (headquarters: 101 Townsend St, San Francisco, CA 94107, USA), which include: CDN (Content Delivery Network) Services: Cloudflare provides a global network of servers that cache and deliver our Website content, improving loading speed and performance. DDoS Protection: Cloudflare protects our Website from DDoS attacks and other security threats. Security Services: Cloudflare provides additional security layers, including protection against bots and malicious traffic. Data Processing by Cloudflare: In providing these services, Cloudflare may process the following data: User's browser IP address Information about the country of origin of traffic Operating system and browser information Network traffic and performance data Security and threat information Legal Basis: Data processing by Cloudflare is based on the Controller's legitimate interest related to ensuring security, performance, and stability of the Website operation. Data Recipient: Cloudflare, Inc. as a data processor acting on behalf of the Controller. International Data Transfers: Cloudflare is a US-based entity. Data transfers are conducted based on appropriate safeguards, including Standard Contractual Clauses (SCC) approved by the European Commission. Data Retention: Cloudflare retains data according to its privacy policy, available at: https://www.cloudflare.com/privacypolicy/ User Rights: In relation to data processing by Cloudflare, users retain all rights under applicable data protection laws, including the right to access, rectification, deletion, and restriction of processing.

§13. Additional Information for Specific Jurisdictions

For California Residents: This privacy policy serves as our CCPA Privacy Notice. We have not sold personal information in the preceding 12 months and do not sell personal information. For Japanese Users: This policy complies with Japan's Personal Information Protection Act. We are committed to handling your personal information appropriately and securely according to Japanese law. Contact Information: For any questions about this Privacy Policy or to exercise your rights, contact us at: [email protected] Effective Date: 19.09.2025 Last Updated: 19.09.2025 This Privacy Policy is available in multiple languages. In case of conflicts between versions, the English version shall prevail for international users, while the Polish version remains authoritative for Polish users.