Order history, a saved phone number and faster checkout.
Theme
Your cart
0 items
We use only strictly necessary cookies and browser storage (sign-in, cart, security). We do not use analytics or advertising cookies. Details in the Privacy Policy.
Legal
Privacy Policy
How we process personal data and which cookies we use
§ 1. Controller
1. The controller of your personal data is Trzeba chleba Bartłomiej Krawczyk (trading name: Trzeba Chleba), address: ul. Wojewódzka 36/38, 40-026 Katowice, NIP: 6343048179, REGON: 540185091 (the Controller). 2. Data protection contact: e-mail kontakt@trzebachleba.pl, phone +48 572 359 415, shop address: ul. Wojewódzka 36/38, 40-026 Katowice. 3. This policy covers the website trzebachleba.pl (the Service) and electronic contact with us. We process data in accordance with the GDPR (Regulation (EU) 2016/679). The Polish version prevails.
§ 2. Orders
1. Data: phone number, optionally an e-mail address (for the confirmation), products, pickup date and time slot, discount code used, order status. 2. Purpose and legal basis: concluding and performing the contract and contacting you about it (Art. 6(1)(b) GDPR); sending the contract confirmation on a durable medium and handling complaints (Art. 6(1)(c)); establishing, exercising or defending claims (Art. 6(1)(f)). 3. Retention: until claims under the contract become time-barred; accounting records - 5 years from the end of the year in which the tax obligation arose. 4. A phone number is required to place an Order; the e-mail address is optional.
§ 3. Account
1. Data: e-mail address, first name, optionally last name, phone number, password hash (we do not know your password), two-factor authentication data, order history; with Google sign-in - the Google account ID and e-mail provided by Google. 2. Purpose and legal basis: maintaining the Account under the contract for electronic services (Art. 6(1)(b) GDPR). 3. Retention: until the Account is deleted, then as described in § 2 for order data.
§ 4. Blocking for uncollected orders
1. Data: phone number, order history (including uncollected Orders) and the reason for the block. 2. Purpose and legal basis: limiting losses and food waste caused by repeatedly uncollected Orders - our legitimate interest (Art. 6(1)(f) GDPR). The rules are set out in § 9 of the Terms. 3. The decision is taken by a member of staff after reviewing the order history. We do not take decisions based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR. 4. Retention: until the block is lifted. You may contest the block and object by contacting us. 5. The Service does not create device fingerprints - blocks apply only to phone numbers.
§ 5. Newsletter
1. Data: e-mail address, date of sign-up and of consent confirmation. 2. Purpose and legal basis: sending the newsletter with commercial information based on your consent (Art. 6(1)(a) GDPR and Art. 398 of the Polish Electronic Communications Law). Sign-up must be confirmed via an e-mail link (double opt-in). 3. You can withdraw consent at any time (“Unsubscribe” link, Account settings, e-mail), without affecting the lawfulness of prior mailings. 4. Retention: until consent is withdrawn; afterwards we may keep a record of giving and withdrawing consent until any claims become time-barred (Art. 6(1)(f) GDPR).
§ 6. Contact form and correspondence
1. Data: first name, e-mail address, subject (optional) and message, plus any other data you choose to share. 2. Purpose and legal basis: replying and corresponding - our legitimate interest (Art. 6(1)(f) GDPR); if the message concerns entering into a contract - Art. 6(1)(b). 3. Retention: until the matter is closed, then no longer than 12 months, unless needed to defend claims.
§ 7. Business cooperation (gastronomy panel, invoices)
1. Data: company details (name, NIP, REGON, address) and data of people acting for the company - name, e-mail, phone number and role in the panel. 2. Purpose and legal basis: concluding and performing the contract with the company (Art. 6(1)(b) GDPR) and, for its staff, our legitimate interest in contacting the business partner (Art. 6(1)(f)); issuing and storing invoices, including sending structured invoices to the National e-Invoice System (KSeF) run by the Minister of Finance (Art. 6(1)(c)). 3. Retention: for the duration of cooperation; invoices and accounting records - 5 years from the end of the tax year.
§ 8. Security and abuse prevention
1. On every visit our servers and Cloudflare process your IP address, browser information and the date and time of the request to keep the Service secure, prevent attacks and rate-limit requests (Art. 6(1)(f) GDPR). Server logs are rotated and overwritten automatically. 2. Forms are protected by Cloudflare Turnstile, which checks that a human is submitting the form. For this Cloudflare processes, among other things, your IP address and browser information, based on our legitimate interest in protecting the Service from bots (Art. 6(1)(f) GDPR).
§ 9. Recipients and transfers outside the EEA
1. We entrust data to service providers under data processing agreements: • server hosting provider: Datalix (datalix.eu), • e-mail provider: Viperhost (viperhost.pl), • Cloudflare, Inc. - CDN, attack protection, access tunnel and Turnstile, • our accounting office and IT service providers - as far as necessary. 2. Data may also be disclosed to authorities entitled by law (e.g. tax authorities, including via KSeF) and - when you sign in with Google or load the map - to Google as a separate controller. 3. Cloudflare and Google may process data in the USA on the basis of the European Commission adequacy decision (EU-U.S. Data Privacy Framework) or standard contractual clauses. 4. We do not sell data or use it for advertising.
§ 10. Cookies and browser storage
1. The Service uses only mechanisms that are strictly necessary for its operation and security. We do not use analytics, advertising or tracking cookies, so we do not ask for consent (Art. 399(3) of the Polish Electronic Communications Law). 2. Cookies: • accessToken - logged-in session, 15 minutes, • refreshToken - keeps you signed in, up to 30 days or until logout, • twoFactorToken - temporary, during two-factor sign-in, • XSRF-TOKEN - protects forms against CSRF attacks, session, • Cloudflare cookies (e.g. __cf_bm, cf_clearance) - bot protection, from 30 minutes to a few hours. 3. Browser storage (localStorage/sessionStorage): cart contents, selected theme, shop filters, entered discount code, form drafts (up to 24 hours), selected company in the gastronomy panel, whether you closed the cookie notice and the page to return to after signing in. This data is not sent to us automatically. 4. The Contact page embeds a Google map. When it is displayed, Google receives your IP address and may set its own cookies under Google's privacy policy. If you do not want this, block third-party cookies in your browser. 5. You can delete or block cookies in your browser; blocking necessary cookies prevents signing in and ordering.
§ 11. Your rights
1. You have the right to access, rectify and erase your data, restrict processing, data portability and to object to processing based on legitimate interest (Arts. 15-21 GDPR). 2. Where processing is based on consent, you may withdraw it at any time. 3. To exercise your rights, write to kontakt@trzebachleba.pl. We reply without undue delay and within one month at the latest. 4. You may lodge a complaint with the President of the Personal Data Protection Office (UODO) (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl).
§ 12. Changes
1. We update this policy when the law or our processing changes. We announce significant changes in the Service and, for Account holders, by e-mail. 2. This version applies from 01.10.2026.