Documents
Privacy Policy
Version 2.2 · In force since: 25 September 2026
Questo documento è disponibile in polacco e in inglese. Qui sotto trovi la versione inglese.
01Data controller
The controller of personal data within the meaning of the GDPR (Regulation (EU) 2016/679) is Custom Service, ul. Bielska 107, 32-652 Bulowice, Poland, NIP (tax ID) 5492373228, REGON 528250567, operating the Restrikt service at sankcje.exportsy.pl and restrikt.eu (the Service).
For personal data matters, write to kontakt@restrikt.eu. The controller has not appointed a data protection officer, as it is not required to (Art. 37 GDPR).
02What data, why, on what basis and for how long
Below are all the processes in which the Service processes personal data. „Deleted automatically” means a daily database job performs the deletion.
| Process | Data | Purpose and legal basis | Recipients | How long |
|---|---|---|---|---|
| Account and sign-in | email address, Account identifier, sign-in dates; the authentication provider's sign-in log also contains the IP address | providing the Account at your request, Art. 6(1)(b) GDPR | Supabase (database and authentication), Resend (emails) | until you delete the Account (button in the Account) or at your request |
| Profile and subscription | plan, Stripe customer and subscription identifiers, end of the billing period; optionally name, company, VAT number | performance of the contract, Art. 6(1)(b) GDPR | Supabase, Stripe | until the Account is deleted; billing data as in the „Payments” row |
| Payments and invoices | email address, billing details and address entered in the Stripe checkout, VAT number, amount, payment identifiers, report order content (the query) | performance of the contract, Art. 6(1)(b) GDPR; invoices and accounting, Art. 6(1)(c) GDPR | Stripe, Supabase, Resend (report delivery) | accounting records 5 years from the end of the tax year; the report link works for 12 months, pack credits are valid for 12 months; after the Account is deleted, orders are kept without the email address |
| Check history (while signed in) | query text, match type (code or name), result, matched CN code, regime, date and time | Account feature, Art. 6(1)(b) GDPR | Supabase | until you delete it in the Account („Delete check history”) or the Account is deleted |
| Watched codes (Account) | CN code, your own label, date added, notifications sent | Account feature, Art. 6(1)(b) GDPR | Supabase, Resend (change emails) | until the code is removed from the list or the Account is deleted |
| Code alert without an Account | email address, CN code, language, sign-up source, confirmation and unsubscribe tokens; a consent record on confirmation and unsubscribe (purpose, text version, source, date) | consent confirmed by clicking a link, Art. 6(1)(a) GDPR | Supabase, Resend | confirmed: until unsubscribed; unconfirmed: 30 days, deleted automatically |
| Result sent by email | email address, query, language, form source, campaign parameters (UTM) from the page address | sending the result at your request, Art. 6(1)(b) GDPR | Supabase, Resend | 12 months from the last interaction, deleted automatically (unless you gave marketing consent) |
| Contact form | email address, message, language | responding to the enquiry, our legitimate interest, Art. 6(1)(f) GDPR | Supabase, Resend (notification to us) | 12 months from submission, deleted automatically |
| Consultation request | name, email address, company, CN code or goods, case description, case type, language | steps taken at your request before entering into a contract, Art. 6(1)(b) GDPR | Supabase, Resend (notification to us) | 12 months from submission, deleted automatically; longer, if a contract is concluded, as for the contract |
| Marketing (newsletter) | email address, sign-up source; consent record: purpose, granted or withdrawn, consent text version, source, date | consent, Art. 6(1)(a) GDPR, given in a separate box that is not ticked by default; consent record: Art. 6(1)(c) and (f) GDPR (accountability) | MailerLite, Supabase | until consent is withdrawn; the consent record for as long as it may be needed to show that consent was given |
| Security and rate limiting | IP address in the attempt counter, request type; for forms with bot protection a Cloudflare Turnstile token and the IP address | protecting the Service against abuse, Art. 6(1)(f) GDPR | Supabase, Cloudflare (when protection is enabled), Vercel (hosting logs) | attempt counter up to 2 days, deleted automatically; hosting logs according to Vercel settings |
| Free check limit | a random identifier in a cookie; in the database only its hash (HMAC) or the Account identifier, number and dates of checks, without query text and without IP | providing the service within the Free Plan, Art. 6(1)(b) and (f) GDPR | Supabase | no automatic deletion, because the limit does not renew; the hash does not let us identify you |
| Visit statistics | events (e.g. page view, completed check, checkout started) with language, entry source (UTM) and a random session identifier kept only in tab memory; without email addresses, IP and Account identifiers | improving the Service, our legitimate interest, Art. 6(1)(f) GDPR | Supabase, Vercel (Web Analytics, no cookies) | aggregated data, without data that identifies you |
| Error reports | page path, request method and identifier, error description; email addresses and phone numbers are removed before sending | keeping the Service working, Art. 6(1)(f) GDPR | our error monitoring service | until the issue is resolved |
03Email address: each purpose separately
- Entering your address in the contact form, a consultation request, when sending a result by email or when signing up for an alert does not sign you up for a newsletter.
- You receive the newsletter (MailerLite) only if you tick the separate marketing consent box. The box is not ticked by default. We keep a consent record: purpose, consent text version, source and date.
- Change alerts for a code are sent through Resend, not MailerLite. An alert recipient does not receive other campaigns because of it.
- Providing data is voluntary, but without an email address we cannot send a result, an alert, a sign-in link or a reply.
04Payments
Payment takes place on the Stripe Checkout page. You enter full card details at Stripe; they do not reach our server or database. From Stripe we receive customer, subscription and payment identifiers, the email address, the amount and the payment status.
05Providers (data recipients)
| Provider | Scope |
|---|---|
| Vercel Inc. | hosting of the Service, hosting logs, cookieless visit statistics |
| Supabase Inc. | database and authentication; the database project runs in an EU region (Paris, eu-west-3) |
| Stripe | payments, subscriptions, invoices; Stripe processes some data as a separate controller (e.g. fraud prevention) under its own policy |
| Resend | sending emails: sign-in links, results, reports, alerts, notifications to us |
| MailerLite | newsletter, only after marketing consent |
| Cloudflare | bot protection for forms (Turnstile), when enabled |
Providers process data on our instructions under data processing agreements, unless stated otherwise above. Public authorities may also receive data where the law requires it.
06Transfers outside the EEA
Some providers are based in, or use sub-processors in, the USA (including Vercel, Resend, Supabase, Stripe, Cloudflare). Where data leaves the European Economic Area, the basis is a mechanism under Chapter V GDPR used by these providers in their agreements, in particular standard contractual clauses or certification under the EU-U.S. Data Privacy Framework. We will provide information on the mechanism for a specific provider on request sent to kontakt@restrikt.eu.
07Cookies and browser storage
The Service does not use advertising cookies or tracking pixels and does not use advertising tools. Visit statistics (Vercel Web Analytics and our event counter) work without cookies. Below is everything the Service stores in your browser.
| Name | Type | Purpose | Lifetime | Nature |
|---|---|---|---|---|
| sb-…-auth-token | cookie | Account sign-in and session (also the helper …-code-verifier during sign-in) | until sign-out, at most about 400 days | necessary, only after sign-in |
| restrikt_lookup | cookie (HttpOnly) | recognising the browser for the free check limit | 400 days | necessary, set on the first check |
| NEXT_LOCALE | cookie | chosen language | 1 year | necessary, after changing language |
| restrikt_cookie_notice | localStorage | remembering that you closed the cookie notice | until browser data is cleared | necessary |
| restrikt_quota_seen | localStorage | showing the limit bar after the first check | until browser data is cleared | necessary |
| restrikt_req:… | sessionStorage | the same request identifier after a page refresh, so a refresh does not use up another check; the key contains the query text | until the tab is closed | necessary |
| restrikt_reports_bought | sessionStorage | showing the plan offer after a report purchase | until the tab is closed | functional, only after a purchase |
| restrikt_install_dismissed | localStorage | remembering that you closed the app install prompt | until browser data is cleared | functional, saved after your click |
| restrikt_internal | localStorage and cookie | excluding our team's devices from statistics | cookie 1 year, localStorage until browser data is cleared | set manually, only on team devices |
Necessary entries serve the service you ask for and do not require consent. Functional entries are created only after your action and are not used for tracking. When a form has bot protection, Cloudflare Turnstile loads its own script to assess whether a human is filling in the form. You can delete cookies and browser storage in your browser settings; deleting the session cookie signs you out of the Account.
08Your rights
You have the right to:
- access to your data and a copy of it (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- portability of data we process on the basis of a contract or consent (Art. 20 GDPR),
- objection to processing based on legitimate interest (Art. 21 GDPR),
- withdrawal of consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3) GDPR): the unsubscribe link in the message, the button in the Account or an email to us,
- lodging a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland (Art. 77 GDPR).
09How to delete data or the Account
- You can delete your check history yourself in the Account with the „Delete check history” button. You can remove a watched code from the list in the Account.
- You can unsubscribe from alerts and the newsletter with the link in every message.
- You can withdraw marketing consent in the Account with the „Withdraw consent” button. We will then also unsubscribe you from the MailerLite list.
- You can delete the Account yourself in the Account with the „Delete Account” button, after typing the Account email address. We then immediately delete the Account, check history, watched codes, profile details, alert subscriptions, form enquiries, lead data and unused pack credits, and ask MailerLite to delete your data. We cancel an active subscription in Stripe immediately, with no further charges. Orders and payments are kept without your email address because we must retain them for accounting purposes. The record of withdrawn consent is also kept, as proof that we respected your decision.
- Send other data requests to kontakt@restrikt.eu from the address the request concerns. If you write from another address, we will confirm the request by a message to the Account address.
- We respond without undue delay, within one month at the latest. Data we must keep by law (e.g. invoices) is retained for the required period.
10Automated decisions and security
We do not take decisions about you based solely on automated processing and do not profile you within the meaning of Art. 22 GDPR. A check result concerns a goods code, not a person.
We use encrypted connections (TLS), row-level access control in the database (each user sees only their own Account data), service keys only on the server side and attempt limits on forms.
11Changes to this Policy
We update this Policy when the way we process data changes. The current version is at restrikt.eu/en/polityka-prywatnosci. See also the Terms of Service.
