Skip to main content

CakeMarket Privacy Policy (Poland)

Last updated: July 2026

Country and language

Legal documentation is maintained separately per country; this document applies to the Polish market (pl.cakemarket.app). The Polish version is the source and governing text, and this English page is its 1:1 courtesy translation. The corresponding document for the Hungarian market is in the Hungary section.

§ 1. Controller and scope

1.1. The data controller is Marton Szaplonczay, a natural person conducting unregistered business activity (działalność nierejestrowana) in Poland, correspondence address ul. Piaszczysta 29/66, 31-226 Kraków, Poland, e-mail kontakt@cakemarket.app. Data are processed in accordance with the GDPR, the Polish Personal Data Protection Act, the Act on Providing Services by Electronic Means and applicable sector-specific legislation.

1.2. CakeMarket operates as a marketplace for made-to-order cakes: it handles accounts, requests, offers, orders, messages, online payments via Stripe, notifications, reviews, seller organisations and an admin panel.

§ 2. Data categories

AreaData
Accountfirst and last name, e-mail, phone, role, language, profile photo, password stored as a hash or OAuth provider login data
Guestsserver-issued guest-session identifier and secret token, order tracking token, account attachment data
Organisationsname, address, coordinates, e-mail, phone, seller legal status, NIP where supplied/required, legal name, invoicing address, Stripe Connect data, pickup locations, delivery and deposit configuration; for unregistered Sellers, date of birth and declaration acceptance timestamp
Food-authority proofprivately uploaded sanitary-inspection (Sanepid) document, issuer, reference number, covered address, activity scope, expiry date, badge level and review notes
Requests and ordersdate, servings, event type, flavour preferences, special requirements, food/allergen information supplied by the Seller, delivery address, reference photos, selected visualisations, statuses, amounts and cancellations
PaymentsStripe PaymentIntent/Transfer identifiers, payment type, amounts, commission, status, refunds; no full card data
CommunicationBuyer–Seller messages, e-mail and in-app notifications
Reviewsratings, comments, linked orders
Technicallogs, IP address, device/browser data, localStorage, service worker, security events, map/address data from Google Places
PurposeGDPR basis
operating accounts and guest sessions and providing the servicesArt. 6(1)(b)
handling requests, offers, orders, messages and transactional notificationsArt. 6(1)(b)
payments, technical escrow, refunds and payouts via StripeArt. 6(1)(b) and (f)
settlements, accounting and tax obligationsArt. 6(1)(c)
administration of Organisations, legal-status controls and food-authority proof/badges, security and abuse preventionArt. 6(1)(b), (c) and (f), depending on the datum and obligation
reviews, ranking and marketplace improvementArt. 6(1)(f)
AI visualisations and cake-design suggestionsArt. 6(1)(b) or (f), depending on the feature
direct marketing or a newsletter, if launchedArt. 6(1)(a) or (f), in line with electronic-communication rules

§ 4. Data sharing within the marketplace

4.1. Buyers see the Organisation data needed to choose a Seller: name, profile, portfolio photos, rating, any admin-issued badge, pickup locations, delivery range, Offer content, price, Deposit percentage, the proposed image and the Seller's messages. Buyers never receive the uploaded certificate, its URL or its expiry date. A badge means only that CakeMarket reviewed the submitted document for display; it is not an inspection or guarantee.

4.2. Sellers see the Buyer data needed to prepare an Offer and fulfil an Order: name or guest designation, contact details provided for the order, Request description, date, servings, flavour preferences, special requirements and allergens, reference photos, selected visualisations, the delivery address or the chosen pickup location, message history, payment status and Order status.

4.3. Authorised CakeMarket administrators see user, Organisation, request, offer, order, payment, message, review and optional certificate data to the extent needed to operate the platform, ensure security, moderate content, process refunds, review badge requests and provide support. A private certificate is also available to active administrators of the Organisation, but not to ordinary members or customers.

§ 5. Providers and processors

Provider / categoryData and purposeNotes
Cloudflare Workers / application hostingrequest handling, technical logs, security, CDNapplication hosting and infrastructure
Cloudflare D1 / databaseaccount, guest, Organisation, request, offer, order, payment, message, review and notification datamain production database; SQLite/better-sqlite3 may be used locally
Cloudflare Images / file storageportfolio photos, reference photos, generated or uploaded cake imageswhen configured; smaller files may be stored in the database
Stripe and Stripe Connectpayment data, PaymentIntents, refunds, transfers, Seller onboarding status, data required by Stripe/KYCCakeMarket does not store full card data
Resende-mail address, subject, content and metadata of transactional messagesin production; in development messages may be logged instead of sent
Google OAuthGoogle account identifier, e-mail and login dataonly if the user chooses Google sign-in
Google Places / Mapsaddress queries, geocoding data, coordinates and map previewsfor address autocomplete, delivery distance and maps
AI provider / Gemini and image-generation servicestheme description, preferences, reference photos, Seller notes, generated images and suggestionsfor cake visualisation; do not enter data unnecessary for the design
Fakturownia.plOrganisation and invoicing data, CakeMarket platform-fee amount, invoice items and settlement statusused only for CakeMarket's platform-fee invoice issued to the Seller after Order completion; the Seller issues any invoice or receipt for the cake to the Buyer
Legal and tax providersinvoicing data, payments and documents required by lawafter business registration and once settlement handling is implemented

5.1. Data are not sold. Transfers outside the EEA take place only with appropriate safeguards, such as an adequacy decision, the Data Privacy Framework or standard contractual clauses.

§ 6. Retention

DataPeriod
account, legal-status declaration and food-authority prooffor as long as the account/Organisation exists, then up to 30 days unless legal obligations or the establishment, exercise or defence of claims require longer retention
guest requestsup to 90 days from the last activity, or until attached to an account/deleted
orders, payments, invoicingfor the period required by tax and accounting law, as a rule 5 years from the end of the tax year
messages and support recordsfor as long as needed to handle the Order, defend claims and keep the marketplace safe
technical logsfor the period necessary for security and diagnostics

§ 7. Data subject rights

7.1. You have the right of access, rectification, erasure, restriction, portability, objection and withdrawal of consent.

7.2. Requests can be submitted through the Service or via the operator's contact details. We respond, as a rule, within one month.

7.3. A complaint may be lodged with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw.

§ 8. Profiling and automation

8.1. CakeMarket may sort offers by price, ratings and certification level. Sorting helps present offers, but the Buyer chooses the Seller themselves.

8.2. The Service does not make decisions producing legal effects based solely on automated processing within the meaning of Article 22 GDPR.

§ 9. Security

9.1. We apply technical and organisational measures, including HTTPS, data validation, role-based access control, password hashing, session tokens, restricted access to panels and logging of payment and order events.

9.2. Details of cookies and similar technologies are described in the Cookie Policy.