Documents

Privacy Policy

Version 2.2 · In force since: 25 September 2026

Questo documento è disponibile in polacco e in inglese. Qui sotto trovi la versione inglese.

01Data controller

The controller of personal data within the meaning of the GDPR (Regulation (EU) 2016/679) is Custom Service, ul. Bielska 107, 32-652 Bulowice, Poland, NIP (tax ID) 5492373228, REGON 528250567, operating the Restrikt service at sankcje.exportsy.pl and restrikt.eu (the Service).

For personal data matters, write to kontakt@restrikt.eu. The controller has not appointed a data protection officer, as it is not required to (Art. 37 GDPR).

02What data, why, on what basis and for how long

Below are all the processes in which the Service processes personal data. „Deleted automatically” means a daily database job performs the deletion.

ProcessDataPurpose and legal basisRecipientsHow long
Account and sign-inemail address, Account identifier, sign-in dates; the authentication provider's sign-in log also contains the IP addressproviding the Account at your request, Art. 6(1)(b) GDPRSupabase (database and authentication), Resend (emails)until you delete the Account (button in the Account) or at your request
Profile and subscriptionplan, Stripe customer and subscription identifiers, end of the billing period; optionally name, company, VAT numberperformance of the contract, Art. 6(1)(b) GDPRSupabase, Stripeuntil the Account is deleted; billing data as in the „Payments” row
Payments and invoicesemail address, billing details and address entered in the Stripe checkout, VAT number, amount, payment identifiers, report order content (the query)performance of the contract, Art. 6(1)(b) GDPR; invoices and accounting, Art. 6(1)(c) GDPRStripe, Supabase, Resend (report delivery)accounting records 5 years from the end of the tax year; the report link works for 12 months, pack credits are valid for 12 months; after the Account is deleted, orders are kept without the email address
Check history (while signed in)query text, match type (code or name), result, matched CN code, regime, date and timeAccount feature, Art. 6(1)(b) GDPRSupabaseuntil you delete it in the Account („Delete check history”) or the Account is deleted
Watched codes (Account)CN code, your own label, date added, notifications sentAccount feature, Art. 6(1)(b) GDPRSupabase, Resend (change emails)until the code is removed from the list or the Account is deleted
Code alert without an Accountemail address, CN code, language, sign-up source, confirmation and unsubscribe tokens; a consent record on confirmation and unsubscribe (purpose, text version, source, date)consent confirmed by clicking a link, Art. 6(1)(a) GDPRSupabase, Resendconfirmed: until unsubscribed; unconfirmed: 30 days, deleted automatically
Result sent by emailemail address, query, language, form source, campaign parameters (UTM) from the page addresssending the result at your request, Art. 6(1)(b) GDPRSupabase, Resend12 months from the last interaction, deleted automatically (unless you gave marketing consent)
Contact formemail address, message, languageresponding to the enquiry, our legitimate interest, Art. 6(1)(f) GDPRSupabase, Resend (notification to us)12 months from submission, deleted automatically
Consultation requestname, email address, company, CN code or goods, case description, case type, languagesteps taken at your request before entering into a contract, Art. 6(1)(b) GDPRSupabase, Resend (notification to us)12 months from submission, deleted automatically; longer, if a contract is concluded, as for the contract
Marketing (newsletter)email address, sign-up source; consent record: purpose, granted or withdrawn, consent text version, source, dateconsent, Art. 6(1)(a) GDPR, given in a separate box that is not ticked by default; consent record: Art. 6(1)(c) and (f) GDPR (accountability)MailerLite, Supabaseuntil consent is withdrawn; the consent record for as long as it may be needed to show that consent was given
Security and rate limitingIP address in the attempt counter, request type; for forms with bot protection a Cloudflare Turnstile token and the IP addressprotecting the Service against abuse, Art. 6(1)(f) GDPRSupabase, Cloudflare (when protection is enabled), Vercel (hosting logs)attempt counter up to 2 days, deleted automatically; hosting logs according to Vercel settings
Free check limita random identifier in a cookie; in the database only its hash (HMAC) or the Account identifier, number and dates of checks, without query text and without IPproviding the service within the Free Plan, Art. 6(1)(b) and (f) GDPRSupabaseno automatic deletion, because the limit does not renew; the hash does not let us identify you
Visit statisticsevents (e.g. page view, completed check, checkout started) with language, entry source (UTM) and a random session identifier kept only in tab memory; without email addresses, IP and Account identifiersimproving the Service, our legitimate interest, Art. 6(1)(f) GDPRSupabase, Vercel (Web Analytics, no cookies)aggregated data, without data that identifies you
Error reportspage path, request method and identifier, error description; email addresses and phone numbers are removed before sendingkeeping the Service working, Art. 6(1)(f) GDPRour error monitoring serviceuntil the issue is resolved

03Email address: each purpose separately

  1. Entering your address in the contact form, a consultation request, when sending a result by email or when signing up for an alert does not sign you up for a newsletter.
  2. You receive the newsletter (MailerLite) only if you tick the separate marketing consent box. The box is not ticked by default. We keep a consent record: purpose, consent text version, source and date.
  3. Change alerts for a code are sent through Resend, not MailerLite. An alert recipient does not receive other campaigns because of it.
  4. Providing data is voluntary, but without an email address we cannot send a result, an alert, a sign-in link or a reply.

04Payments

Payment takes place on the Stripe Checkout page. You enter full card details at Stripe; they do not reach our server or database. From Stripe we receive customer, subscription and payment identifiers, the email address, the amount and the payment status.

05Providers (data recipients)

ProviderScope
Vercel Inc.hosting of the Service, hosting logs, cookieless visit statistics
Supabase Inc.database and authentication; the database project runs in an EU region (Paris, eu-west-3)
Stripepayments, subscriptions, invoices; Stripe processes some data as a separate controller (e.g. fraud prevention) under its own policy
Resendsending emails: sign-in links, results, reports, alerts, notifications to us
MailerLitenewsletter, only after marketing consent
Cloudflarebot protection for forms (Turnstile), when enabled

Providers process data on our instructions under data processing agreements, unless stated otherwise above. Public authorities may also receive data where the law requires it.

06Transfers outside the EEA

Some providers are based in, or use sub-processors in, the USA (including Vercel, Resend, Supabase, Stripe, Cloudflare). Where data leaves the European Economic Area, the basis is a mechanism under Chapter V GDPR used by these providers in their agreements, in particular standard contractual clauses or certification under the EU-U.S. Data Privacy Framework. We will provide information on the mechanism for a specific provider on request sent to kontakt@restrikt.eu.

07Cookies and browser storage

The Service does not use advertising cookies or tracking pixels and does not use advertising tools. Visit statistics (Vercel Web Analytics and our event counter) work without cookies. Below is everything the Service stores in your browser.

NameTypePurposeLifetimeNature
sb-…-auth-tokencookieAccount sign-in and session (also the helper …-code-verifier during sign-in)until sign-out, at most about 400 daysnecessary, only after sign-in
restrikt_lookupcookie (HttpOnly)recognising the browser for the free check limit400 daysnecessary, set on the first check
NEXT_LOCALEcookiechosen language1 yearnecessary, after changing language
restrikt_cookie_noticelocalStorageremembering that you closed the cookie noticeuntil browser data is clearednecessary
restrikt_quota_seenlocalStorageshowing the limit bar after the first checkuntil browser data is clearednecessary
restrikt_req:…sessionStoragethe same request identifier after a page refresh, so a refresh does not use up another check; the key contains the query textuntil the tab is closednecessary
restrikt_reports_boughtsessionStorageshowing the plan offer after a report purchaseuntil the tab is closedfunctional, only after a purchase
restrikt_install_dismissedlocalStorageremembering that you closed the app install promptuntil browser data is clearedfunctional, saved after your click
restrikt_internallocalStorage and cookieexcluding our team's devices from statisticscookie 1 year, localStorage until browser data is clearedset manually, only on team devices

Necessary entries serve the service you ask for and do not require consent. Functional entries are created only after your action and are not used for tracking. When a form has bot protection, Cloudflare Turnstile loads its own script to assess whether a human is filling in the form. You can delete cookies and browser storage in your browser settings; deleting the session cookie signs you out of the Account.

08Your rights

You have the right to:

  1. access to your data and a copy of it (Art. 15 GDPR),
  2. rectification (Art. 16 GDPR),
  3. erasure (Art. 17 GDPR),
  4. restriction of processing (Art. 18 GDPR),
  5. portability of data we process on the basis of a contract or consent (Art. 20 GDPR),
  6. objection to processing based on legitimate interest (Art. 21 GDPR),
  7. withdrawal of consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3) GDPR): the unsubscribe link in the message, the button in the Account or an email to us,
  8. lodging a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland (Art. 77 GDPR).

09How to delete data or the Account

  1. You can delete your check history yourself in the Account with the „Delete check history” button. You can remove a watched code from the list in the Account.
  2. You can unsubscribe from alerts and the newsletter with the link in every message.
  3. You can withdraw marketing consent in the Account with the „Withdraw consent” button. We will then also unsubscribe you from the MailerLite list.
  4. You can delete the Account yourself in the Account with the „Delete Account” button, after typing the Account email address. We then immediately delete the Account, check history, watched codes, profile details, alert subscriptions, form enquiries, lead data and unused pack credits, and ask MailerLite to delete your data. We cancel an active subscription in Stripe immediately, with no further charges. Orders and payments are kept without your email address because we must retain them for accounting purposes. The record of withdrawn consent is also kept, as proof that we respected your decision.
  5. Send other data requests to kontakt@restrikt.eu from the address the request concerns. If you write from another address, we will confirm the request by a message to the Account address.
  6. We respond without undue delay, within one month at the latest. Data we must keep by law (e.g. invoices) is retained for the required period.

10Automated decisions and security

We do not take decisions about you based solely on automated processing and do not profile you within the meaning of Art. 22 GDPR. A check result concerns a goods code, not a person.

We use encrypted connections (TLS), row-level access control in the database (each user sees only their own Account data), service keys only on the server side and attempt limits on forms.

11Changes to this Policy

We update this Policy when the way we process data changes. The current version is at restrikt.eu/en/polityka-prywatnosci. See also the Terms of Service.

← Back to the home page