Documents
Privacy policy
What I collect about you, why, who else sees it, how long I keep it, and how to say no.
Version of 8 September 2026
The full business details (legal name, NIP, address) will be filled in once confirmed. For now the text uses working placeholders.
1. Who is responsible for your data
I am Anna Vaskov, a sole trader registered in Poland (Warszawa, Polska, NIP: to be confirmed), and I run https://flowerlover.club. I decide what happens to the data described here, which makes me the data controller under the GDPR.
The rules I follow are the GDPR, the Polish Personal Data Protection Act and the Polish Electronic Communications Law, which governs what a site may store on your device. I have not appointed a data protection officer; the business is small enough that I answer myself.
For anything about your data write to info.flowerloverclub@gmail.com, or send a letter to the address above.
2. Visiting the site
The site runs on Cloudflare’s network. To deliver a page and block abuse, Cloudflare sees your IP address and the technical details of each request (browser, page requested, time) and keeps short-lived logs of them. My own server logs on Cloudflare record errors and request paths for a few days, without names or contact details.
On your first visit a small script reads your browser’s language settings and sends you to the Ukrainian, Polish or English version. That happens entirely in your browser and nothing is stored, unless you choose a language in the header: then the cookie flc_lang remembers the choice for a year.
Legal basis: my legitimate interest in running a site that works, stays secure and opens in your language (art. 6(1)(f) GDPR).
3. Statistics: which pages lead to orders
I use PostHog on its EU cloud (servers in Frankfurt) to see which pages and buttons lead to orders. Requests go through this site’s own domain rather than PostHog’s; the data still ends up with PostHog.
Each visit records the pages you open, the page you came from and any campaign tags in the link, your browser and device type, screen size and language, the landing variant you saw, which buttons you pressed, which plan you picked, whether you opened the checkout and whether a purchase completed, with the plan and amount. When an order is paid, the same facts arrive once more from Stripe’s confirmation, so revenue joins the visit.
All of this hangs off a random identifier created for the browser tab; it is not linked to your name, email, phone or address, none of which reach PostHog. PostHog receives your IP address with each request and uses it to estimate your country and city. There is no session recording, no automatic capture of what you type and no tracking across other sites.
If your browser sends the Do Not Track or Global Privacy Control signal, nothing is recorded. You can also block site data for flowerlover.club or use a content blocker. Every page keeps working the same way.
Legal basis: my legitimate interest in knowing whether the site and my Instagram posts bring in orders (art. 6(1)(f) GDPR). You can object at any time, see section 11.
4. What is stored in your browser
The site sets no advertising or tracking cookies, and nothing that follows you between visits or across sites, so it shows no cookie banner. This is everything it stores:
| Name | What it does | Kept for |
|---|---|---|
flc_lang (cookie) | remembers the language you picked in the header | 1 year, set only when you pick one |
flc.sid | random identifier of the visit for the statistics above | until you close the tab |
flc.attribution | the page you landed on, where you came from and campaign tags, so an order can be matched to its source | until you close the tab |
ph_…_posthog | PostHog’s state for the visit: the same random identifier and the current session | until you close the tab |
flc.purchased.… | marks that a purchase was already counted, so refreshing the thank-you page does not count it twice | until you close the tab |
The entries that end when you close the tab live in the browser’s session storage, not in cookies. Stripe’s checkout page sets its own cookies under Stripe’s domain; Stripe’s cookie policy covers them.
5. Ordering and paying
The checkout page is run by Stripe. There you enter your name, email address, phone number, delivery address, a preferred delivery window, an optional note and your payment details. Card numbers, BLIK codes and bank logins go to Stripe only; I never see them. Stripe is certified under PCI DSS, the card industry’s security standard.
What I see in my Stripe dashboard: everything except the full payment details, plus the payment status, the amount and, for subscriptions, the renewal dates. I use it to prepare and deliver your bunch, to contact you about the delivery, to handle changes, cancellations, complaints and refunds, and to keep the records tax law requires.
I attach a few facts about your visit to the payment: the plan, the language, the page you landed on, where you came from, campaign tags, the landing variant and the random visit identifier from section 3. They tell me which channel brought the order and are not used for anything else.
Stripe also processes your data for its own purposes as an independent controller: preventing fraud (it checks your IP address, device and payment history and may decline a payment automatically), complying with financial regulations and, if you choose it, saving your details in Stripe Link for future checkouts. Stripe’s privacy policy explains that part. Stripe sends the payment confirmation and receipts by email.
The thank-you page shows your plan, the delivery Saturday and the amount, fetched from Stripe using the order reference in the page address. It does not show your address or contact details.
Legal basis: performing the contract you entered into when you ordered (art. 6(1)(b) GDPR); for the visit facts attached to the payment, my legitimate interest in knowing what works (art. 6(1)(f) GDPR).
6. Delivering and staying in touch
On Friday and Saturday I use your phone number and the delivery note to tell you when I am coming, by SMS, phone call or the messenger you wrote to me on, and your address to plan the route. I copy the addresses for the day into my route plan and delete that copy once the deliveries are done.
When you send a bunch as a gift, you give me the recipient’s name, address and phone number. I use them only to deliver and to reach the recipient on the day. Please tell the recipient that a delivery is coming and that I have their details from you. Legal basis for the recipient’s data: my legitimate interest in fulfilling your order (art. 6(1)(f) GDPR).
Messages you send me by email land in a Google mailbox; Instagram direct messages are handled by Meta. Both companies process the messages under their own rules; I use them only to answer you and to handle your order.
Legal basis: performing the contract (art. 6(1)(b) GDPR) and, for questions before an order, my legitimate interest in replying to people who write to me (art. 6(1)(f) GDPR).
7. Tax records, invoices and claims
Polish tax law requires me to keep proof of every sale, which includes your name, the amount, the date and, when you ask for an invoice, the details you gave for it. My accountant sees these records. Legal basis: a legal obligation (art. 6(1)(c) GDPR).
Order and message history can also be kept to handle complaints, refunds and disputes for as long as a claim could still be raised by either side. Legal basis: my legitimate interest in establishing, exercising and defending claims (art. 6(1)(f) GDPR).
8. No marketing, no selling
I do not send newsletters or marketing emails, run ads based on your data, build profiles, or sell or rent data to anyone. If I ever want to write to you about anything other than your order, I will ask for your consent first, and you will be able to withdraw it with one click.
Following or messaging @flowerlover.club on Instagram is your relationship with Meta, governed by Instagram’s terms and privacy policy.
9. Who else sees your data
I do not hand data to anyone beyond the companies and people below, unless you ask me to or a public authority is legally entitled to demand it.
| Who | What they handle | Where |
|---|---|---|
| Stripe Payments Europe, Ireland | checkout, payments, subscriptions, receipts and the delivery details entered at checkout | EU, with transfers to Stripe, Inc. in the United States under the EU-US Data Privacy Framework and standard contractual clauses |
| PostHog, United States | visit statistics from section 3 | EU cloud in Frankfurt; support access from the United States covered by standard contractual clauses |
| Cloudflare, United States | hosting, edge logs and the statistics relay | global network, certified under the EU-US Data Privacy Framework |
| Google, Ireland | my email mailbox | EU and United States, certified under the EU-US Data Privacy Framework |
| Meta Platforms, Ireland | Instagram messages, as an independent controller | EU and United States, certified under the EU-US Data Privacy Framework |
| My accountant | sales records required by tax law | Poland |
| The developer who maintains the site | technical access to the site, the statistics and, when something needs fixing, the Stripe dashboard | Poland |
Each of these companies is bound by a data processing agreement or acts under its own privacy policy, as noted. Where data leaves the European Economic Area, it does so under the EU-US Data Privacy Framework or the European Commission’s standard contractual clauses; write to me if you want a copy of the safeguards.
10. How long I keep it
| Data | Kept for |
|---|---|
| Visit statistics in PostHog | as long as I use PostHog; the identifiers are per visit and cannot be tied back to you |
| Order, payment and subscription records in Stripe | 5 years after the end of the tax year of the sale, as Polish tax law requires; Stripe keeps its own copy for as long as financial regulations oblige it to |
| Delivery route copy (address, phone, note) | deleted after the delivery day |
| Emails and Instagram messages about an order | until the order and any complaint are closed, then up to 3 years in case a claim is raised |
| Invoices | 5 years after the end of the tax year in which they were issued |
flc_lang cookie | 1 year |
| Cloudflare logs | a few days |
11. Your rights
You can ask me what I hold about you, have it corrected, have it deleted, have its processing restricted, get a copy in a machine-readable format, or object to the processing I base on legitimate interest, which covers the statistics and the visit facts attached to your payment. If I ever rely on your consent, you can withdraw it at any time without affecting what happened before.
Write to info.flowerloverclub@gmail.com and say which right you are exercising and which data it concerns; I may ask you to confirm the email address you used at checkout. I answer within a month. If a request is unusually complex I may take up to two more months, and I tell you if that happens.
Some data I cannot delete on request: proof of sales must stay for the period tax law sets, and I keep what is needed to defend a claim until it expires.
If you think I have handled your data badly, you can complain to the Polish supervisory authority: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
12. Security
Everything travels over HTTPS. The site itself keeps no database of customers; your order lives in Stripe, which is built for handling payment data. The accounts at the providers above are protected with strong, unique passwords and two-factor login, and only I and the developer who maintains the site can open them.
I do not make automated decisions about you and I do not profile you. The one automated step is Stripe’s fraud check, which can decline a payment; if that happens, try another payment method or write to me.
13. Children
The site is not aimed at children and you must be 18 to order. If you believe a minor has given me their data, write to me and I will delete it.
14. Changes to this policy
When something on this page changes, I update the text and the date at the top. If a change matters for an active subscription, for example a new provider handling your data, I email you before it takes effect.