CakeMarket Privacy Policy (Poland)
Last updated: July 2026
Legal documentation is maintained separately per country; this document applies to the Polish market (pl.cakemarket.app). The Polish version is the source and governing text, and this English page is its 1:1 courtesy translation. The corresponding document for the Hungarian market is in the Hungary section.
§ 1. Controller and scope
1.1. The data controller is Marton Szaplonczay, a natural person conducting unregistered business activity (działalność nierejestrowana) in Poland, correspondence address ul. Piaszczysta 29/66, 31-226 Kraków, Poland, e-mail kontakt@cakemarket.app. Data are processed in accordance with the GDPR, the Polish Personal Data Protection Act, the Act on Providing Services by Electronic Means and applicable sector-specific legislation.
1.2. CakeMarket operates as a marketplace for made-to-order cakes: it handles accounts, requests, offers, orders, messages, online payments via Stripe, notifications, reviews, seller organisations and an admin panel.
§ 2. Data categories
| Area | Data |
|---|---|
| Account | first and last name, e-mail, phone, role, language, profile photo, password stored as a hash or OAuth provider login data |
| Guests | server-issued guest-session identifier and secret token, order tracking token, account attachment data |
| Organisations | name, address, coordinates, e-mail, phone, seller legal status, NIP where supplied/required, legal name, invoicing address, Stripe Connect data, pickup locations, delivery and deposit configuration; for unregistered Sellers, date of birth and declaration acceptance timestamp |
| Food-authority proof | privately uploaded sanitary-inspection (Sanepid) document, issuer, reference number, covered address, activity scope, expiry date, badge level and review notes |
| Requests and orders | date, servings, event type, flavour preferences, special requirements, food/allergen information supplied by the Seller, delivery address, reference photos, selected visualisations, statuses, amounts and cancellations |
| Payments | Stripe PaymentIntent/Transfer identifiers, payment type, amounts, commission, status, refunds; no full card data |
| Communication | Buyer–Seller messages, e-mail and in-app notifications |
| Reviews | ratings, comments, linked orders |
| Technical | logs, IP address, device/browser data, localStorage, service worker, security events, map/address data from Google Places |
§ 3. Purposes and legal bases
| Purpose | GDPR basis |
|---|---|
| operating accounts and guest sessions and providing the services | Art. 6(1)(b) |
| handling requests, offers, orders, messages and transactional notifications | Art. 6(1)(b) |
| payments, technical escrow, refunds and payouts via Stripe | Art. 6(1)(b) and (f) |
| settlements, accounting and tax obligations | Art. 6(1)(c) |
| administration of Organisations, legal-status controls and food-authority proof/badges, security and abuse prevention | Art. 6(1)(b), (c) and (f), depending on the datum and obligation |
| reviews, ranking and marketplace improvement | Art. 6(1)(f) |
| AI visualisations and cake-design suggestions | Art. 6(1)(b) or (f), depending on the feature |
| direct marketing or a newsletter, if launched | Art. 6(1)(a) or (f), in line with electronic-communication rules |
§ 4. Data sharing within the marketplace
4.1. Buyers see the Organisation data needed to choose a Seller: name, profile, portfolio photos, rating, any admin-issued badge, pickup locations, delivery range, Offer content, price, Deposit percentage, the proposed image and the Seller's messages. Buyers never receive the uploaded certificate, its URL or its expiry date. A badge means only that CakeMarket reviewed the submitted document for display; it is not an inspection or guarantee.
4.2. Sellers see the Buyer data needed to prepare an Offer and fulfil an Order: name or guest designation, contact details provided for the order, Request description, date, servings, flavour preferences, special requirements and allergens, reference photos, selected visualisations, the delivery address or the chosen pickup location, message history, payment status and Order status.
4.3. Authorised CakeMarket administrators see user, Organisation, request, offer, order, payment, message, review and optional certificate data to the extent needed to operate the platform, ensure security, moderate content, process refunds, review badge requests and provide support. A private certificate is also available to active administrators of the Organisation, but not to ordinary members or customers.
§ 5. Providers and processors
| Provider / category | Data and purpose | Notes |
|---|---|---|
| Cloudflare Workers / application hosting | request handling, technical logs, security, CDN | application hosting and infrastructure |
| Cloudflare D1 / database | account, guest, Organisation, request, offer, order, payment, message, review and notification data | main production database; SQLite/better-sqlite3 may be used locally |
| Cloudflare Images / file storage | portfolio photos, reference photos, generated or uploaded cake images | when configured; smaller files may be stored in the database |
| Stripe and Stripe Connect | payment data, PaymentIntents, refunds, transfers, Seller onboarding status, data required by Stripe/KYC | CakeMarket does not store full card data |
| Resend | e-mail address, subject, content and metadata of transactional messages | in production; in development messages may be logged instead of sent |
| Google OAuth | Google account identifier, e-mail and login data | only if the user chooses Google sign-in |
| Google Places / Maps | address queries, geocoding data, coordinates and map previews | for address autocomplete, delivery distance and maps |
| AI provider / Gemini and image-generation services | theme description, preferences, reference photos, Seller notes, generated images and suggestions | for cake visualisation; do not enter data unnecessary for the design |
| Fakturownia.pl | Organisation and invoicing data, CakeMarket platform-fee amount, invoice items and settlement status | used only for CakeMarket's platform-fee invoice issued to the Seller after Order completion; the Seller issues any invoice or receipt for the cake to the Buyer |
| Legal and tax providers | invoicing data, payments and documents required by law | after business registration and once settlement handling is implemented |
5.1. Data are not sold. Transfers outside the EEA take place only with appropriate safeguards, such as an adequacy decision, the Data Privacy Framework or standard contractual clauses.
§ 6. Retention
| Data | Period |
|---|---|
| account, legal-status declaration and food-authority proof | for as long as the account/Organisation exists, then up to 30 days unless legal obligations or the establishment, exercise or defence of claims require longer retention |
| guest requests | up to 90 days from the last activity, or until attached to an account/deleted |
| orders, payments, invoicing | for the period required by tax and accounting law, as a rule 5 years from the end of the tax year |
| messages and support records | for as long as needed to handle the Order, defend claims and keep the marketplace safe |
| technical logs | for the period necessary for security and diagnostics |
§ 7. Data subject rights
7.1. You have the right of access, rectification, erasure, restriction, portability, objection and withdrawal of consent.
7.2. Requests can be submitted through the Service or via the operator's contact details. We respond, as a rule, within one month.
7.3. A complaint may be lodged with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw.
§ 8. Profiling and automation
8.1. CakeMarket may sort offers by price, ratings and certification level. Sorting helps present offers, but the Buyer chooses the Seller themselves.
8.2. The Service does not make decisions producing legal effects based solely on automated processing within the meaning of Article 22 GDPR.
§ 9. Security
9.1. We apply technical and organisational measures, including HTTPS, data validation, role-based access control, password hashing, session tokens, restricted access to panels and logging of payment and order events.
9.2. Details of cookies and similar technologies are described in the Cookie Policy.