PRIVACY POLICY
The short version. There are no accounts, no advertising and no tracking on this site. We do not use analytics or third-party cookies. We keep what is needed to take a payment, show the leaderboard, and satisfy tax and anti-fraud obligations — nothing else.
1. WHO IS RESPONSIBLE FOR YOUR DATA
The controller of your personal data (administrator danych osobowych) is the operator identified at the foot of this page. For any privacy matter, including exercising your rights, write to kontakt@nush.pl.
We have not appointed a Data Protection Officer, as we are not required to do so. Privacy requests are handled by the operator directly.
2. WHAT DATA WE PROCESS
We process only the following:
- Your nickname, if you choose to provide one instead of remaining anonymous. This is displayed publicly. Please do not use your real name or any information you do not want to be public.
- Purchase details: the amount, the currency, the payment status, and the date and time of the payment.
- Payment identifiers generated by Stripe (checkout session and payment intent references), used to match a payment to a refund, dispute or receipt.
- Technical and security data: your IP address and request metadata, processed transiently to apply rate limits and prevent abuse, and recorded in server logs.
We never receive or store your card number. Card details are entered on Stripe's own checkout page and are processed by Stripe as an independent controller. Your email address is collected by Stripe for the receipt; it is held by Stripe, not by us.
There are no user accounts, so we hold no passwords and no profile data.
3. WHY WE PROCESS IT, AND ON WHAT LEGAL BASIS
Under Article 6(1) of the GDPR:
- To perform the contract with you — taking payment, adding your purchase to the global total, and displaying your nickname on the leaderboard.
Legal basis: Article 6(1)(b) — performance of a contract. - To meet our accounting and tax obligations — keeping records of sales, VAT and refunds.
Legal basis: Article 6(1)(c) — compliance with a legal obligation. - To keep the Service secure and prevent abuse — rate limiting, fraud and chargeback prevention, and investigating misuse.
Legal basis: Article 6(1)(f) — our legitimate interest in protecting the Service and preventing fraud. - To establish, exercise or defend legal claims — including responding to complaints, refunds, disputes and chargebacks.
Legal basis: Article 6(1)(f) — our legitimate interest in defending our rights.
Providing a nickname is entirely optional; you can purchase anonymously. Providing payment data is necessary to complete a purchase — without it, no purchase can be made.
4. WHO WE SHARE DATA WITH
We do not sell your data and we do not share it for advertising. Data is shared only with:
- Stripe — payment processing. Stripe acts as an independent controller for payment data under its own privacy policy.
- Our hosting and database provider — which stores the site and the payment records on our behalf, as a processor under a data processing agreement.
- Public visitors — but only your nickname and the purchase amount, if you chose not to be anonymous.
- Authorities, advisers or auditors — where we are legally required to disclose, or where necessary to establish or defend a legal claim.
5. TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA
Stripe is a global payment provider and may process data in the United States and elsewhere outside the EEA. Such transfers are protected by the European Commission's Standard Contractual Clauses and, where applicable, by the EU–US Data Privacy Framework. You may request a copy of the relevant safeguards from us at any time.
6. HOW LONG WE KEEP IT
- Payment records (amount, status, timestamps, Stripe references): kept for 5 years from the end of the tax year in which the payment was made, as required by accounting and tax law.
- Nicknames on the public leaderboard: displayed for as long as the Service operates, or until you ask us to anonymise the entry.
- Server and security logs: kept for a short operational period, normally no more than 90 days, unless retained longer for a specific security or legal investigation.
- Rate-limiting data: held only in memory and discarded within minutes.
Note that anonymising a leaderboard entry removes the nickname from public view, but the underlying payment record must be retained for the statutory period above.
7. YOUR RIGHTS
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data ("right to be forgotten"), where we have no overriding legal obligation to keep it;
- restrict processing in certain circumstances;
- data portability — to receive data you provided in a structured, machine-readable format;
- object to processing based on our legitimate interests, on grounds relating to your particular situation.
To exercise any of these, email kontakt@nush.pl. We will respond within one month. We may ask you for the Stripe receipt reference so we can locate the right record — we cannot identify you from a nickname alone.
Removing a nickname is quick: ask us and we will replace it with "ANONYMOUS" on the public leaderboard.
8. COMPLAINING TO A SUPERVISORY AUTHORITY
If you believe we have handled your data unlawfully, you may lodge a complaint with a data protection supervisory authority — in Poland, the Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland (https://uodo.gov.pl). You may also complain to the authority in the EU country where you live or work.
9. COOKIES AND SIMILAR TECHNOLOGIES
This site does not use analytics, advertising, profiling or tracking cookies, and it does not embed third-party trackers, social widgets or advertising pixels. Because we set no non-essential storage, no cookie consent banner is required.
Your browser may hold strictly necessary technical storage needed for the page to function. When you are redirected to Stripe's checkout page, Stripe sets its own cookies necessary for payment processing and fraud prevention, governed by Stripe's privacy policy.
10. AUTOMATED DECISION-MAKING
We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. Stripe operates automated fraud screening on payments as part of its own service; if a payment is declined by that screening, you may contact us and we will look into it.
11. CHILDREN
The Service is not directed at children and purchases require you to be 18 or over. We do not knowingly process the data of children. If you believe a child has made a purchase, contact us and we will refund it and delete the associated data as far as the law allows.
12. SECURITY
The Service is served over HTTPS. Payment card data never reaches our servers. Access to the payment database is restricted to the operator, and administrative access is protected by a separate secret. No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the limited data we hold.
13. CHANGES TO THIS POLICY
We may update this policy. The current version is always published on this page, with the date of the last change shown at the top.
OPERATOR
Mikołaj Wolski and Łukasz Michalak
Independent operators based in Poland.
Email: kontakt@nush.pl