PRIVACY AND COOKIES POLICY OF THE ONLINE STORE “THEBLACKPILLOW.COM”
Effective as of: August 12, 2026
INTRODUCTION
This Privacy Policy sets out the rules for the processing and protection of personal data of Users and Buyers using the online store operating at the address www.theblackpillow.com (hereinafter referred to as the “Store”).
The Store is deeply committed to protecting your privacy and ensuring the security of your personal data. We process your data in strict compliance with the General Data Protection Regulation (EU) 2016/679 (hereinafter referred to as “GDPR”), the Polish Act of 10 May 2018 on the Protection of Personal Data, and the Polish Act of 12 July 2024 – Electronic Communications Act (Prawo komunikacji elektronicznej – “PKE”).
§ 1. THE DATA ADMINISTRATOR & CONTACT DETAILS
-
The Administrator of the personal data collected through the Store is: Wojciech Oleksiejuk, operating a sole proprietorship (jednoosobowa działalność gospodarcza) registered in the Central Register and Information on Economic Activity (CEIDG) of the Republic of Poland under the business name: Falco Wojciech Oleksiejuk, with its registered office at: ul. Płocka 15/80, 01-231 Warsaw, Poland, NIP (Tax Identification Number): PL5272749832, REGON: 362943505 (hereinafter referred to as the “Administrator”).
-
You can contact the Administrator regarding any queries related to personal data processing, cookie management, or to exercise your rights under the GDPR via:
-
Postal Address: Falco Wojciech Oleksiejuk, ul. Płocka 15/80, 01-231 Warsaw, Poland
-
Email Address: hello@theblackpillow.com
-
§ 2. CATEGORIES OF PERSONAL DATA PROCESSED
Depending on your interactions with the Store (browsing, sending a contact form, subscribing to the newsletter, or making a purchase), the Administrator may process the following categories of personal data:
-
Transactional and Ordering Data: First name, last name, billing address, exact shipping/delivery address, e-mail address, telephone number, tax identification number (NIP/VAT number for businesses or European VAT-OSS purposes), IP address, and details of purchased items.
-
Newsletter and Marketing Data: E-mail address, registration date, double opt-in confirmation status, and email interaction metrics (e.g., opens, clicks).
-
Contact Form Data: Name, e-mail address, subject, and any other voluntary information entered into contact forms powered by Fluent Forms.
-
Technical and Browsing Data: IP address, geographical location (inferred from IP for tax and VAT-OSS destination auditing), browser type and version, operating system, referral source, length of visit, page views, and website navigation paths.
§ 3. PURPOSES, LEGAL BASES, AND RETENTION PERIODS OF PROCESSING
The processing of your personal data is carried out for the following distinct purposes, under specific legal bases, and for defined retention periods:
3.1. Execution of the Sales Contract
-
Purpose: To process, manufacture, pack, ship, and deliver your ordered microplastic-free bedding items, as well as to communicate with you regarding order statuses.
-
Legal Basis: Article $6(1)(b)$ GDPR – processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
-
Retention Period: For the duration of the contract performance and until the statutory limitation periods for claims under the sales contract have expired (typically $2$ years under the Polish Civil Code, but extended up to $3$ or $6$ years for cross-border transactions under national laws of Sweden, Ireland, etc., in accordance with EU E-commerce Legal Compliance).
3.2. Compliance with Statutory Tax and Accounting Obligations
-
Purpose: To issue invoices, process payments, and maintain mandatory accounting ledgers.
-
Legal Basis: Article $6(1)(c)$ GDPR – processing is necessary for compliance with a legal obligation to which the Administrator is subject (under Polish tax laws and the EU VAT-OSS system).
-
Retention Period: In accordance with the cross-border audit guidelines set forth in EU E-commerce Legal Compliance, transaction records, invoice metadata, and geographical proofs of delivery used for EU VAT-OSS declarations must be retained securely for a period of $10$ years from the end of the year in which the transaction took place.
3.3. Customer Relationship Management & Customer Support
-
Purpose: To address inquiries, resolve complaints, and handle contact requests submitted through the website’s contact forms (utilizing Fluent Forms).
-
Legal Basis: Article $6(1)(f)$ GDPR – processing is necessary for the purposes of the legitimate interests pursued by the Administrator (providing excellent user support and managing business communications).
-
Retention Period: For the period necessary to handle and resolve the inquiry, and thereafter for a period of $1$ year to maintain communication continuity, unless the communication results in a sales contract or a formal complaint (which are subject to longer statutory periods).
3.4. Newsletter, Marketing, and Promotional Communications
-
Purpose: To send electronic newsletters containing both informational/educational content (e.g., tips for microplastic-free living, bedding care guides) and promotional/advertising materials (e.g., product updates, discounts, sales).
-
Legal Basis:
-
Article $6(1)(a)$ GDPR – the data subject has given consent to the processing of their personal data for direct marketing purposes.
-
Article $398$ of the Polish Electronic Communications Act (PKE) – requiring explicit, prior, and unbundled consent for the use of electronic communication channels for marketing purposes.
-
-
Retention Period: Until you withdraw your consent (unsubscribe) or object to the processing. You can withdraw your consent at any time, free of charge, by clicking the “Unsubscribe” link in the footer of any newsletter email or by contacting the Administrator directly.
3.5. Website Security, Maintenance, and Defense Against Legal Claims
-
Purpose: To protect the Store’s web infrastructure (utilizing Really Simple Security and LiteSpeed Cache), prevent fraudulent transactions, analyze traffic anomalies, and establish, exercise, or defend against legal claims.
-
Legal Basis: Article $6(1)(f)$ GDPR – processing is necessary for the purposes of the legitimate interests pursued by the Administrator (maintaining a secure, high-performance website, and legally defending the sole proprietorship).
-
Retention Period: For the period required by law for the limitation of legal claims, or up to $3$ years for security logs and website technical telemetry.
§ 4. RECIPIENTS OF PERSONAL DATA (THIRD-PARTY PROCESSORS)
To operate the Store efficiently, the Administrator shares your personal data only with trusted third-party service providers under formal Data Processing Agreements (DPAs) or direct statutory obligations:
-
Payment Gateways:
-
Stripe (operated by Stripe Payments Europe, Ltd.) – handles all secure card and electronic transactions. Transaction and payment details are processed directly by Stripe on their secure servers.
-
-
Logistics and Delivery Partners:
-
DPD (including DPD Polska Sp. z o.o. and its international affiliates).
-
Other shipping services such as DHL, UPS, GLS, or InPost depending on your chosen delivery method and destination country.
-
-
IT Hosting and Security Providers:
-
Hosting servers, email servers, caching systems (LiteSpeed Cache), and security services (Really Simple Security) that maintain the integrity and accessibility of the Store.
-
-
Marketing and Tracking Solutions:
-
Meta Platforms Ireland Ltd. (via PixelYourSite tracking) – for advertising optimization and retargeting, subject to your explicit cookie consent.
-
Google Ireland Ltd. (via Site Kit by Google) – for statistical analytics, search performance tracking, and Google Analytics, subject to your explicit cookie consent.
-
-
State Authorities:
-
Tax offices, auditing institutions, and judicial organs if required by mandatory provisions of national or EU law (e.g., VAT-OSS audits).
-
§ 5. COOKIES, TRACKING TECHNOLOGIES, AND CONSENT MANAGEMENT
-
The Store uses cookies (small text files saved on your browser) and tracking scripts to optimize user experience, secure the checkout workflow, and run marketing campaigns.
-
Categorization of Cookies Used:
-
Strictly Necessary Cookies: Essential for the basic operations of the Store (e.g., maintaining items in your WooCommerce cart, user sessions, security features). These are executed automatically on your browser and do not require consent.
-
Analytical / Statistical Cookies: Track user behavior anonymously (e.g., Google Analytics loaded via Site Kit by Google) to help us understand web traffic patterns and improve performance.
-
Marketing / Target Cookies: Track user visits across websites to build a profile of your interests and show you relevant ads (e.g., Meta Pixel loaded via PixelYourSite).
-
-
Complianz | GDPR/CCPA Cookie Consent Framework:
-
The Store utilizes the Complianz Consent Management Platform (CMP).
-
No non-essential cookies (analytical or marketing, including Meta Pixel and Google Analytics) will be placed or executed on your browser unless you provide active, explicit, and informed consent via the cookie banner.
-
The cookie banner is designed without “dark patterns.” The button to “Deny” or “Reject All” trackers has the same visual prominence, color, and size as the “Accept All” button.
-
You can change, adjust, or withdraw your cookie preferences at any time by clicking the persistent Complianz cookie settings icon visible in the footer of the Store.
-
§ 6. NEWSLETTER SUBSCRIPTION AND THE DOUBLE OPT-IN SYSTEM
-
By entering your email address in our newsletter sign-up form, you request to receive our email newsletter containing informational content on microplastics-free living as well as commercial and promotional campaigns for the Store’s products.
-
Double Opt-In (DOI) Mandate:
-
To prevent unauthorized registrations, the Store utilizes a strict Double Opt-In mechanism.
-
After submitting your email, you will receive an automated confirmation email. Your subscription will only become active once you click the unique verification link contained in that email.
-
If you do not click the confirmation link within $7$ calendar days, your data will be permanently deleted from our temporary registration list.
-
-
Opt-Out Right:
-
You can withdraw your marketing consent at any time. An easy, one-click unsubscribe link is present in the footer of every single email we send.
-
Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
-
§ 7. DATA SUBJECT RIGHTS Under GDPR
As a data subject residing within the European Union, you enjoy robust, enforceable rights regarding your personal data. You have the right to request:
-
Right of Access (Art. $15$ GDPR): To obtain confirmation from the Administrator as to whether your personal data is being processed, and to receive a copy of your processed data.
-
Right to Rectification (Art. $16$ GDPR): To obtain the immediate correction of inaccurate or incomplete personal data.
-
Right to Erasure (“Right to be Forgotten” – Art. $17$ GDPR): To obtain the deletion of your personal data, provided that the data is no longer necessary for the purposes for which it was collected, or if processing lacks a valid legal basis (subject to statutory retention exceptions like the $10$-year VAT-OSS auditing rule).
-
Right to Restriction of Processing (Art. $18$ GDPR): To request that we limit the processing of your data under specific statutory conditions (e.g., if you contest the accuracy of the data).
-
Right to Data Portability (Art. $20$ GDPR): To receive your personal data in a structured, commonly used, and machine-readable format, and to transmit those data to another controller.
-
Right to Object (Art. $21$ GDPR): To object to data processing carried out based on legitimate interests (Art. $6(1)(f)$ GDPR) or for direct marketing purposes.
-
Right to Lodge a Complaint: You have the absolute right to lodge a formal complaint with a supervisory authority if you believe your personal data is being processed unlawfully.
-
In Poland, the supervisory authority is: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw, Poland (Website: https://uodo.gov.pl).
-
Alternatively, you may contact the data protection authority in your country of habitual residence.
-
§ 8. DATA SECURITY
-
The Administrator employs strict technical and organizational measures to protect personal data from accidental loss, destruction, alteration, unauthorized access, or disclosure.
-
The Store utilizes secure data-transmission protocols. All transactional areas, checkouts, registration forms, and contact forms are encrypted using a high-grade Secure Sockets Layer (SSL) / TLS connection.
-
Security architecture is actively audited and hardened using the integrated Really Simple Security framework to mitigate brute-force attempts, injection attacks, and database vulnerabilities.
§ 9. AMENDMENTS TO THIS PRIVACY POLICY
-
The Administrator reserves the right to update this Privacy Policy to reflect changes in legal regulations, technical advancements of the website, or updates in third-party processing integrations.
-
The current version of the Privacy Policy is always accessible via a dedicated, persistent link in the footer of the Store’s website. Any updates will become effective on the date specified in the document header.

