Effective date: 07 October 2025
This Privacy Policy explains how finespirits.pl (operated by Jellyfish Media Sp. z o.o., Al. Jana Pawła II 27, 00-867 Warsaw, Poland) collects and processes your personal data when you visit our website, place orders, contact us, or subscribe to our marketing communications. We respect your rights and process personal data in accordance with Regulation (EU) 2016/679 (GDPR).
If anything here is unclear, contact us at: [email protected]
Who is the data controller?
Jellyfish Media Sp. z o.o.
Al. Jana Pawła II 27, 00-867 Warsaw, Poland
Email: [email protected]
What data we collect
- Identification and contact details (first and last name, address, phone number, email) — when you place an order, create an account, or contact us.
- Order and transaction details — products purchased, delivery details, communications related to the order.
- Technical data — IP address and basic log information used for security and diagnostic purposes, and for aggregated statistics (e.g., approximate region).
- Cookies and similar technologies — used to adapt the service to your needs, support essential site functions, measure traffic, and (if you consent) run marketing activities. You can disable cookies in your browser at any time.
- We do not store sensitive payment data such as your full credit card number on our systems.
When you can provide (or refuse) data
- Guest checkout (no account): after we complete and settle your order, we remove personal identifiers from our store database and retain only the sales document required for tax and accounting purposes.
- Account registration / Client database (optional): if you create an account, we store your data to make future purchases faster and to manage your preferences.
- Marketing communications (optional): you may subscribe to our newsletter or consent to receive email/SMS/social messages and to limited profiling for offers. You can withdraw consent or unsubscribe at any time.
Purposes and legal bases for processing
- To conclude and perform a contract (order handling, delivery, customer service) — GDPR Art. 6(1)(b).
- To comply with legal obligations (tax/accounting retention, complaint handling) — GDPR Art. 6(1)(c).
- For our legitimate interests (site security, fraud prevention, service analytics, defense of claims) — GDPR Art. 6(1)(f).
- Based on your consent (newsletter, SMS, campaign messages, cookies used for marketing/profiling where required) — GDPR Art. 6(1)(a). You can withdraw consent at any time without affecting prior processing.
Processors and recipients
To operate our communications and campaigns, we entrust processing to the following supplier:
Omnisend Limited, company registration number 6567194, Unit A3, Gateway Tower, 32 Western Gateway, London, E16 1YL, United Kingdom
Email: [email protected]
— We use the Omnisend platform (email marketing and marketing automation) to send newsletters and to run email, SMS, and web push campaigns initiated by us. Omnisend acts as our processor under a data processing agreement (DPA) concluded with us.
Other typical recipients may include delivery couriers, payment providers, hosting and security partners, IT support, and professional advisors — only where necessary and under appropriate contracts.
International data transfers
Data processed in Omnisend may be stored on servers located in the United Kingdom, outside the European Economic Area (EEA). Such transfers take place on the basis of:
the European Commission implementing decision confirming an adequate level of protection of personal data in the United Kingdom, renewed on 19 December 2025,
and technical and organizational measures implemented by Omnisend (e.g., encryption in transit and at rest, role-based access controls, multi-factor authentication, monitoring and vulnerability testing).
Omnisend operates as a group of affiliated companies, including entities established in Lithuania and the United States. To the extent that affiliates located outside the EEA and outside countries covered by an adequacy decision may access the data, such transfers take place on the basis of the European Commission Standard Contractual Clauses (SCCs), which form part of our data processing agreement with Omnisend. Transfers are limited to what is necessary for the purposes described above.
Cookies, analytics, and tracking
We use tracking codes to analyze website statistics and (with your consent where required) to conduct marketing activities via Omnisend. You can manage cookies through your browser settings and your consent choices on our site. Disabling certain cookies may affect site functionality. For more details, see our Cookie Policy.
Retention periods
Orders and invoices: retained for the period required by tax and accounting law.
Customer accounts: retained while the account is active; deleted upon your request (subject to legal retention).
Marketing data (newsletter/SMS/web push campaigns): retained until you withdraw consent or object, and for a short period after to maintain suppression lists.
Technical logs and security records: retained for a period adequate for security, diagnostics, and fraud prevention.
Your rights
Under the GDPR, you have the right to:
access your data and receive a copy,
rectify inaccurate or incomplete data,
erase data (“right to be forgotten”) in cases provided by law,
restrict processing,
data portability (to receive your data in a structured, commonly used, machine-readable format and transmit it to another controller),
object to processing based on our legitimate interests (including profiling) and to direct marketing at any time,
withdraw consent at any time (where processing is based on consent),
lodge a complaint with the supervisory authority in Poland (President of the Personal Data Protection Office).
To exercise your rights, email us at [email protected] or write to our postal address.
Profiling and automated decisions
If you consent to marketing, we may use limited profiling (e.g., segmenting by purchase history or engagement) to tailor offers. This does not produce legal or similarly significant effects for you. You can object or withdraw consent at any time.
Data security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. Our staff are trained in data protection and follow internal procedures designed to maintain confidentiality and integrity.
Links and third-party services
Our website may contain links to third-party sites or services. Those have their own privacy rules. We are not responsible for their practices and encourage you to review their policies.
Changes to this Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or business developments. Changes apply from the date of publication on this page. Material changes may be communicated via email or on-site notice.
Contact
For any privacy questions or requests, contact:
Email: [email protected]
Address: Jellyfish Media Sp. z o.o., Al. Jana Pawła II 27, 00-867 Warsaw, Poland
