Polityka prywatności
Pełna treść tego dokumentu jest obecnie dostępna w języku angielskim.
1. Who is responsible
The data controller for districtzero.app is Milan Čaniga, IČO 02697777, Zeyerova 1086/6, 360 01 Karlovy Vary, Czech Republic (the entity identified in the Impressum, "we"). For any privacy matter, contact us at privacy@districtzero.app.
2. What we collect, why, and on what legal basis
a) Alert subscriptions (Scanner, product watches).
- Data: e-mail address, selected region, alert-type preferences, optional product interests and target prices, consent timestamp, IP address at the moment of consent, confirmation status, unsubscribe token.
- Purpose: sending the price/restock alerts and digests you requested, and proving your consent (GDPR accountability).
- Legal basis: your consent — Art. 6(1)(a) GDPR — given by confirming Scanner subscriptions by e-mail (double opt-in) or explicitly enabling wishlist target alerts in an account with a verified e-mail address. You can withdraw alert consent using the unsubscribe link. Signing in or buying Priority does not itself subscribe you to alerts.
- Retention: until you unsubscribe. After unsubscription we keep a minimal suppression record (e-mail hash, consent/unsubscribe timestamps) to honour your opt-out and document past consent, then delete remaining data within 3 years.
b) Server logs. Our hosting providers process IP addresses and request metadata in short-lived technical logs for security and operation (legitimate interest, Art. 6(1)(f) GDPR).
c) Cookies and tracking. The site uses only strictly-necessary cookies to function — your selected region, interface language, sign-in session, and your cookie-consent choice. These do not require consent. Our consent banner records your preference (necessary only vs. accept all). Anonymised analytics and affiliate attribution load only if you choose "accept all"; we do not use advertising personalisation.
d) Account and Vault. Sign-in uses your e-mail address, signed sign-in links and a session cookie. We store the items you add to your Vault, quantities, owned/wishlist status, purchase and target prices, wishlist entries and related preferences. The signed-out trial collection is saved locally in your browser and transferred to your account when imported. These data display and manage your account and collection. Requested sign-in messages are separate from alert subscriptions.
e) Priority and payments. To match payments to your account and manage paid access, we process your e-mail, Paddle customer, transaction and subscription identifiers, subscription status and paid period. You provide payment details to Paddle. Unsubscribing from alerts does not itself cancel your subscription or delete your account.
f) Optional Telegram connection. If you connect Telegram to Priority, we process a linking token, chat identifier and username to deliver messages to your linked chat.
3. Service providers and data recipients
- Google Cloud / Firebase Firestore (database) — data stored in the EU multi-region eur3; processor under Google Cloud's EU data-processing terms.
- Vercel (website hosting) and Railway (background processing) — infrastructure providers acting as processors.
- Resend (e-mail delivery, USA) — receives your e-mail address to deliver the messages you requested. Transfers outside the EEA rely on the EU Standard Contractual Clauses / EU–US Data Privacy Framework, as applicable.
Paddle processes Priority purchases as Merchant of Record under its Privacy Policy. Telegram delivers messages if you connect it; its service is subject to its Privacy Policy.
We never sell personal data, and we never share it with shops or advertisers.
4. Your rights
Under the GDPR you can, at any time:
- withdraw consent — the unsubscribe link in an alert e-mail does this with one click;
- request access to the data we hold about you, and a portable copy;
- request rectification or erasure;
- object to, or request restriction of, processing;
- lodge a complaint with a supervisory authority — in the Czech Republic the Úřad pro ochranu osobních údajů (uoou.gov.cz), or the authority of your own EU country.
Requests go to the contact in section 1; we respond within one month.
5. What we don't do
- No profiling with legal effects, no automated decision-making about you.
- No data sales, no ad networks, no cross-site tracking.
- No processing of children's data knowingly — the alert service is intended for users 16 and over.
6. Security
Data is stored in access-controlled EU-region infrastructure with encrypted transport, secrets management and the principle of least access. E-mail addresses are additionally referenced internally by cryptographic hash where feasible.
7. Changes
We will post any updates to this policy on this page with a new effective date. Substantial changes affecting alert subscribers will be announced by e-mail.