1. Who is responsible for your data
The data controller is:
- simplegarden.blog
We are an individual conducting small-scale unregistered business activity under Polish law. We are not required to appoint a data protection officer; contact us directly at the address above with any privacy question.
This policy explains what we do with personal data when you visit the site, buy a product, or contact us.
Purchases are completed on the Payhip platform, which processes data both on our behalf and in its own right — see section 4.
2. What we collect
When you buy: your name, email address, billing country, and order details. Payment is handled by Stripe; we receive confirmation that payment succeeded, plus the last four digits and type of card. We never receive or store your full card number.
When you contact us: your email address and whatever you choose to write.
When you browse: we use no analytics or tracking tools. We do not measure visits, we do not profile visitors, and we set no cookies that would require your consent.
The server hosting this site records standard logs containing your IP address, the date and time of the request, and your browser type. These logs are generated automatically by the server software, exist solely to keep the site secure and working, and are not analysed by us or combined with any other data.
We do not knowingly collect data from children under 16. If you believe a child has provided us with data, contact us and we will delete it.
3. Why we use it, and on what legal basis
Processing your order and delivering the file Legal basis: performance of a contract, Art. 6(1)(b) GDPR Retention: duration of the contract plus the limitation period
Keeping the sales records and tax documentation required of us Legal basis: legal obligation, Art. 6(1)(c) GDPR Retention: 5 years from the end of the tax year
Handling complaints, withdrawal requests and conformity claims Legal basis: legal obligation and legitimate interest, Art. 6(1)(c) and (f) GDPR Retention: 3 years from resolution
Answering your emails Legal basis: legitimate interest, Art. 6(1)(f) GDPR Retention: 2 years from last contact
Keeping the site secure and working (server logs) Legal basis: legitimate interest, Art. 6(1)(f) GDPR Retention: per our hosting provider’s policy, typically up to [30] days
Preventing fraud and payment abuse Legal basis: legitimate interest, Art. 6(1)(f) GDPR Retention: 1 year
Establishing or defending legal claims Legal basis: legitimate interest, Art. 6(1)(f) GDPR Retention: until claims are time-barred
Providing your email address is necessary to receive the product. Without it we cannot deliver the file.
4. Who we share it with
We do not sell your personal data. We share it only with:
- Payhip Ltd (United Kingdom) — storefront, checkout, file delivery, and, for EU and UK digital sales, reseller of record. Payhip acts both as our processor and, for its own purposes and tax obligations, as an independent controller.
- Stripe — payment processing and fraud prevention. Stripe acts as an independent controller for these purposes.
- Hostinger— hosting this website, acting as our processor under a data processing agreement.
- Public authorities, where we are legally required to disclose.
We do not use Google Analytics or any other analytics tool, and we run no tracking-based advertising.
5. Transfers outside the European Economic Area
Some providers above are established outside the EEA, or use infrastructure that is.
Transfers to the United Kingdom are covered by the European Commission’s adequacy decision for the UK.
Transfers to the United States rely on either the EU–US Data Privacy Framework, where the recipient is certified under it, or on the European Commission’s Standard Contractual Clauses together with supplementary technical measures.
6. Your rights
Under the GDPR you have the right to:
- access your data and obtain a copy;
- rectify inaccurate or incomplete data;
- erase your data where one of the grounds in Art. 17 applies — note that we cannot delete sales records we are legally required to keep;
- restrict processing in the circumstances set out in Art. 18;
- data portability for data processed by automated means on the basis of consent or contract;
- object to processing based on legitimate interest, on grounds relating to your particular situation;
- lodge a complaint with a supervisory authority.
We do not carry out automated decision-making producing legal effects concerning you. Stripe runs automated fraud checks on transactions as part of processing payment.
7. If you are in the United States
If you are a resident of California or another US state with comparable legislation, you have rights to know what personal information we collect, to request its deletion, to correct it, and not to be discriminated against for exercising those rights.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
8. Security
We use providers that maintain encryption in transit and at rest, we restrict access to order data, and we use strong authentication on our accounts. No system is perfectly secure and we cannot guarantee absolute security. If a breach occurs that is likely to result in a high risk to your rights, we will notify you without undue delay.
9. Changes
We may update this policy. The current version is always published at simplegarden.blog with the revision date at the top.
If we later add an analytics tool, a contact form, a newsletter, or embedded third-party content, we will update this policy and, where required, introduce a consent mechanism.
10. Contact
simplegarden.contact@gmail.com
Last updated: 29 August 2026