No products in the cart.
I. General Provisions
This Privacy Policy sets out the principles for processing personal data obtained when you, as a Customer, visit the francineandmat.com online store (hereinafter referred to as the “Online Store“), when making purchases, and fulfilling contracts. The Policy also provides information on the origin and use of information about you as a Customer collected through cookies, and provides information on the exercise of rights and options available under applicable data protection laws.
Definitions
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data
and on the free movement of such data, and repealing Directive 95/46/EC.
Online Store – the francineandmat.com website operated by the Administrator at Kamionek Wielki 40D, 82-340 Tolkmicko.
Customer – a natural person, legal person, or organizational unit without legal personality to which specific provisions grant legal capacity, who places an Order within the Store. For the purposes of these terms and conditions, Customer also means an entity using services provided electronically, browsing the Online Store’s assortment without placing an order.
Administrator – The personal data controller is NB Partners Sp. z o.o. Kamionek Wielki 40D, 82-340 Tolkmicko KRS 0001166835, NIP 5783177590, REGON 541416954
II. Processing of Personal Data
In connection with the operation of the Online Store, the Administrator processes personal data related to account creation, the process of placing an order, its acceptance and fulfillment of the sales contract, withdrawal from the contract, complaints, as well as personal data related to services provided electronically.
Below we present the scope, purposes, and legal basis for processing personal data
- Customers using the website who do not have a Customer Account.
Personal data of Customers using the Online Store is processed, including IP addresses or other identifiers collected through cookies or similar technologies.
Data is processed for the following purposes:a) for analytical and statistical purposes – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of conducting analyses of Customer activity in the Online Store and the manner of account use, as well as their preferences in order to improve or modify applied functionalities;
b) for the purpose of establishing and pursuing claims or defending against them – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of protecting its rights; - Account Registration in the Online Store
Basic personal data that is collected and processed includes: name and surname, telephone number, email address. In the case of entrepreneurs, data in the form of the entrepreneur’s company name is also collected and processed. Providing basic data is necessary to create a Customer account and enable the provision of the Account service in the Online Store.In addition, if such data is provided by the Customer, the following data is processed: residential address, delivery address (if different from the residential address), in the case of entrepreneurs also the address of the place of business/registered office, NIP number.
When using the account, we collect as Data Administrator additional data such as purchase history, data used to issue proof of purchase, preferred and used payment methods (if payment method selection is enabled).
Personal data is processed for the following purposes:
a) to create an individual account and manage that account, to provide services related to maintaining and operating an account in the Service – the legal basis for processing is the necessity of processing for the performance of a contract (Article 6(1)(b) GDPR);
b) for analytical and statistical purposes – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of conducting analyses of Customer activity in the Online Store and the manner of account use, as well as their preferences in order to improve or modify applied functionalities;
c) for the purpose of establishing and pursuing claims or defending against them – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of protecting its rights.
- Placing an Order in the Online Store, for the purpose of concluding a sales contract, for the purpose of performing the sales contract.
Personal data that is processed includes: name and surname, residential address, delivery
address (if different from the residential address), telephone number, email address. In the case of entrepreneurs, the following data is collected and processed: entrepreneur’s company name, address of the place of business/registered office, delivery address (if different from the registered office address), NIP number, telephone number, email address, and name and surname.Providing data is voluntary; however, it is necessary to place an order and conclude a sales contract and its performance. Failure to provide data makes it impossible to place an order or conclude a sales contract.
Personal data is processed for the following purposes:
a) placing an order, concluding a sales contract, performing the contract – legal basis – necessity for the conclusion and performance of the contract (Article 6(1)(b) GDPR);
b) for the purpose of fulfilling obligations specified by law, in particular tax law – legal basis Article 6(1)(c) GDPR);
c) for the purpose of establishing and pursuing claims or defending against them – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of protecting its rights;
d) for analytical and statistical purposes – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of conducting analyses of Customer activity in the Online Store, orders placed, and preferences for the development of the Online Store’s business.
- Handling complaints regarding Products and services provided electronically.
The following personal data is processed: name and surname, residential address, delivery address, telephone number, email address. Additionally, it may be necessary to provide a bank account number for refunds. In the case of entrepreneurs, the entrepreneur’s company name, address of the place of business: registered office, and NIP number are also collected and processed. Data is processed for the following purposes:
a) for the purpose of performing the contract and handling complaints – legal basis – necessity for the performance of the contract and handling the complaint process (Article 6(1)(b) GDPR);b) for analytical and statistical purposes – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of conducting analyses, planning and business development, including processes of building the Administrator’s reputation, analyses of Customer activity in the Online Store, orders placed, and preferences for the development of the Online Store’s business;
- Newsletter Subscription
Data in the form of an email address is processed. Providing data is voluntary; failure to provide data makes it impossible to subscribe to the newsletter service and for the Store to provide the service electronically.Data is processed for the following purposes:
a) for the purpose of concluding and performing a newsletter subscription agreement, the subject of which is a service provided electronically;
Legal basis – consent of the data subject to the performance of the Newsletter service agreement (Article 6(1)(a) GDPR); Consent may be withdrawn at any time.
b) for analytical, statistical, and marketing purposes – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of conducting analyses for the purposes of planning and business development, including processes of building the Administrator’s reputation;c) for the purpose of establishing and pursuing claims or defending against them – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of protecting its rights; for the purpose of concluding and performing a newsletter subscription agreement, the subject of which is a service provided electronically
- Reviews
Data in the form of an email address is processed.Providing data is voluntary; failure to provide data makes it impossible for the Store to provide the review service electronically.
Data is processed for the following purposes:
a) for the purpose of concluding and performing an agreement to provide an electronic service in the form of the ability to review Products – legal basis (Article 6(1)(b) GDPR);
b) for the purpose of establishing and pursuing claims or defending against them – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of protecting its rights;
c) for the purpose of fulfilling obligations specified by law (Article 6(1)(c) GDPR);
d) for analytical purposes – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of conducting analyses for the purposes of planning and business development, including processes of building the Administrator’s reputation, analyses of Customer activity in the Online Store, orders placed, and preferences for the development of the Online Store’s business.
- Customer satisfaction surveys through completion of customer satisfaction questionnaires
Data in the form of an email address provided during Customer Account registration is processed. Consent to participate in a customer satisfaction survey is voluntary. Consent given may be withdrawn at any time.Data is processed for the purpose of:
a) Customer consent to complete and submit a Customer satisfaction survey – legal basis (Article 6(1)(a) GDPR).
b) for analytical and statistical purposes – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), consisting of examining Customer satisfaction, in order to enable the Administrator to ensure and maintain high quality service and the level of Customer satisfaction with Products and services. Conducting analyses for internal purposes, planning and business development, including processes of building the Administrator’s reputation. - Marketing
If the Customer consents to receiving marketing information via email, SMS, or other electronic means of communication, the Customer’s personal data will be processed for the purpose of sending such information.Data is processed for the purpose of pursuing the legitimate interest of the Administrator, consisting of advertising its activities and advertising the Products offered.
The legal basis for data processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR) in connection with the consent given by the Customer to send commercial information electronically.
The Customer may object to the processing of data for direct marketing purposes at any time.
- Processing for the purpose of defending against claims or pursuing claims
The Administrator processes personal data for the purpose of defending against potential claims that the Customer may direct against the Administrator or for the purpose of pursuing claims against the Customer, e.g., in connection with unpaid amounts for the sale of goods. We may process personal data to prevent unlawful conduct on the Online Store website or to conduct investigations in such cases.The legal basis for processing personal data is Article 6(1)(f) GDPR, i.e., processing is necessary for the purposes of the legitimate interests pursued by the Administrator, which are indicated above. The legal basis for processing may also be Article 6(1)(c) GDPR, i.e., a legal obligation incumbent on the Administrator.
- Cookies
The Administrator uses solutions and tools used for analytical and marketing purposes. Below is basic information about these tools.The Store website uses cookies to ensure its proper functioning, improve functionality, analyze traffic, and conduct marketing activities. A cookie is a file containing information that is placed in the memory of a device by the website you visit as a Customer.
Cookies enable websites to function. In addition, cookies provide data that allows us to better understand and recognize Customer needs, customize displayed content, and improve service quality. Cookies may originate both from our online store (first-party cookies) and from trusted partners (third-party cookies), including Google (Analytics, Tag Manager), Meta (Facebook Pixel). Importantly, you can change your cookie settings in your web browser at any time. Restricting the use of cookies may affect some store functions, particularly the order placement process and account login.
1. Necessary (technical)
Enable basic store functionality, login, remembering cart contents, processing orders, and form protection (captcha / honeypot). Without them, the site does not function properly.
woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*, wordpress_logged_in_*, wp-settings-*, wfwaf-authcookie-* (AIOWP Security)
First-party cookies (WordPress / WooCommerce)
Session or up to 48 hours
2. Functional (user preferences)
Remember settings selected by the user, such as language, currency, region, or display preferences. They facilitate personalization of the experience.
pll_language (if WPML or Polylang), store_notice[notice id] (store notice)
First-party cookies
Session / up to 1 year
3. Analytical (statistical)
Collect anonymous data about how the site is used (e.g., number of visits, traffic sources, time spent on the site). They help improve the functionality and offerings of the store.
_ga, _gid, _gat, _gcl_au (Google Analytics), _ga_* (GA4), _dc_gtm_* (Google Tag Manager), _fbp (Facebook Pixel – statistical data), _pin_unauth (Pinterest)
Third-party cookies – Google, Meta (Facebook), Pinterest
From session to 2 years (e.g., _ga = 2 years)
4. Marketing (advertising / remarketing)
Enable customization of ads to user interests (remarketing) based on activity in the store. Data from these cookies may be used by advertising platforms.
_fbp, fr (Facebook), _gcl_aw, _gcl_dc (Google Ads), _pin_unauth, _pinterest_ct_ua (Pinterest Ads)
Third-party cookies – Google, Facebook, Pinterest
from 3 months to 2 years
5. Performance cookies (Tag Manager)
Used by Google Tag Manager for the proper functioning of analytical and marketing tags (e.g., GA4, Pixel, Pinterest). They do not store personal data but serve to activate other tags.
_dc_gtm_*
Third-party cookies (Google)
Session / short-term
6. Security cookies (protective)
Used to protect login forms, prevent spam and abuse (e.g., Captcha, honeypot, login restrictions).
wfwaf-authcookie-* (AIOWP Security), _GRECAPTCHA (if Google reCAPTCHA is used), aiowps_*
First-party cookies or Google (if reCAPTCHA)
Session or up to 1 year
7. Session cookies
Temporary files created for the duration of the visit – store e.g., cart status, login, preferences. Deleted after closing the browser.
PHPSESSID, woocommerce_cart_hash
First-party cookies
Until end of session
8. Persistent cookies
Remain in the browser after the session ends. They allow e.g., automatic login, remembering the cart or preferences on subsequent visits.
wp-settings-*, _ga, _fbp
First-party and third-party cookies
from 1 month to 2 years
Explanations:
- First-party cookies – saved directly by the store’s domain. They mainly serve to ensure functionality (e.g., cart, login).
- Third-party cookies – originate from external service providers, e.g., Google, Meta (Facebook), Pinterest. They are used for traffic analysis, conversion measurement, and marketing activities.
- Google Analytics (GA4) – collects anonymized data about user traffic for statistical analysis.
- Google Tag Manager – does not collect personal data itself but mediates in loading analytical and marketing scripts.
- Facebook Pixel / Pinterest Tag – enable ad customization and tracking effectiveness. Additionally, regarding the following cookies, the following information is provided:
Google Analytics
Google Analytics cookies are files used by Google to analyze how the Customer uses the Online Store to create statistics and reports on the functioning of the Store (they collect information about page visits, which subpages the Customer views, the time the Customer spent on the page, or transitions between individual subpages). Google does not use the collected data to identify the Customer. Information about the scope and principles of data collection in connection with this service can be found at: https://google.com/intl/en/policies/privacy/partners.
Google Ads
Google Ads is a tool that enables us as Data Administrator to measure the effectiveness of advertising campaigns. Google Ads also allows displaying Online Store ads to people who have previously visited the Online Store website. Information on data processing by Google in relation to the above service is available at: https://policies.google.com/technologies/ads?hl=en.
Facebook Pixels
Facebook Pixels are a tool that enables measuring the effectiveness of advertising campaigns carried out by the Administrator on the Facebook portal. It allows data analysis to optimize the Administrator’s marketing activities, including enabling us to direct personalized ads to the Customer on Facebook. Within cookie settings, you can decide whether you consent to our use of Facebook Pixel in your case. Information on data processing by Facebook can be found at this link:
https://www.facebook.com/help/443357099140264?helpref=about_content.
11. Changing cookie settings
We use cookies and tracking pixels when you consent to this. If you wish to change cookie settings or delete cookies, you can use the web browser manufacturer’s instructions:
Safari macOS: https://support.apple.com/en-us/guide/safari/sfri11471/mac Safari iOS/iPad OS: https://support.apple.com/en-us/HT201265
Google Chrome: https://support.google.com/chrome/answer/95647?hl=en
Mozilla Firefox: https://support.mozilla.org/en-US/kb/delete-cookies-remove-info-websites-stored
Opera: https://help.opera.com/en/latest/web-preferences/#cookies
Modifying or restricting the use of cookies in your browser may affect the functioning of the site.
Social media
The Administrator processes personal data of persons visiting the Administrator’s profile on Facebook and Instagram. This data is processed in connection with maintaining the profile, including for the purpose of informing about the Administrator’s activities and promoting goods, the Administrator’s activities, as well as for the purpose of communication through functionalities available on social media. The legal basis for processing personal data by the Administrator for this purpose is its legitimate interest (Article 6(1)(f) GDPR), consisting of promoting its own brand and goods, building reputation, conducting analyses for internal purposes, planning and business development, and researching Customer preferences;
III. Period of Personal Data Processing
The period of data processing by the Administrator depends on the legal basis for processing and the purpose of processing.
a) where the basis for processing is the necessity for the conclusion and performance of a contract, data will be processed for the duration of the provision of the service provided electronically or until the completion of the order, and thereafter for a period corresponding to the limitation period for claims;
b) where the basis for processing is legal provisions – the period of their processing is determined by law;
c) in the case of processing data on the basis of the legitimate interest of the Administrator – data is processed for a period enabling its implementation or until an effective objection to data processing is submitted;
d) in the case of consent given – until its withdrawal.
Where processing is necessary for the establishment and pursuit of claims or defense against them, the processing period may be extended for the time necessary to establish and pursue claims or defense against them.
After the data processing period expires, data is deleted or anonymized.
IV. Supervisory Authority for Personal Data
We inform you that the supervisory authority for compliance with the law in the processing of personal data is the President of the Personal Data Protection Office.
V. Rights of Data Subjects
Data subjects have the following rights under the provisions of law:
- Right of access to the content of their personal data and to correct and rectify it;
– on this basis, you may request information about the processing of personal data, including in particular but not exclusively: about the purposes and legal bases of processing, the scope of data held, entities to whom personal data is disclosed, and the planned date of their deletion, about rights to data. - Right to correct or rectify data – you may request correction or rectification of any inconsistencies or errors regarding processed personal data and request completion or updating if the data is incomplete or has changed;
- Right to obtain a copy of data – on this basis, you may request the provision of a copy of personal data. The Administrator provides a copy of the processed data;
- Right to erasure of personal data – applies in cases specified by law, including Article 17 GDPR. On this basis, you may request the deletion of data whose processing is no longer necessary for any of the purposes for which it was collected;
- Right to restriction of processing of personal data applies in the following cases (Article 18 GDPR):
You have the right to restrict the processing of personal data when:
a) you contest the accuracy of your personal data – the Administrator will then restrict their use for the time necessary to verify the accuracy of the data,
b) the processing of data is unlawful, and instead of deleting the data, you request restriction of their use;c) personal data is no longer necessary for the purposes for which it was collected or used, but it is needed by you (the Customer) to establish, pursue, or defend claims;
d) you have objected to the use of data – then restriction occurs for the time necessary to consider whether – due to your particular situation – the protection of your interests, rights, and freedoms outweighs the interests we pursue as Administrator in processing personal data.
- If processing has been restricted, such personal data may be processed, with the exception of storage, only with the consent of the data subject, or for the establishment, exercise, or defense of legal claims.
- Right to data portability
– when data processing is based on consent or on a concluded contract and is carried out automatically, you have the right to receive your personal data that you provided to us as Administrator, in order to send it to another controller. You may also request that personal data be sent by us directly to such controller, if technically feasible. In the event of such a request, we will fulfill the request or refuse to fulfill it without delay, but no later than one month after receiving it. If, due to the complex nature of the request or the number of requests, we are unable to fulfill the request within one month, we will fulfill it within the next two months, informing you in advance within one month of receiving the request – of the intended extension of the deadline and its reasons. You have the right to object to the processing of your data to the extent that we do so on the basis of the legitimate interest of the controller. The objection should be justified, except for an objection concerning direct marketing, which does not need to contain justification. Right to object to their processing in the case of processing data on the basis of the legitimate interest of the Administrator (in particular when processing is for marketing purposes, for analytical and statistical purposes) - Right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office – you have the right to lodge a complaint with the President of the Personal Data Protection Office.
- Right to withdraw consent to data processing at any time; You have the right to withdraw any consent you have given to the Administrator. Withdrawal of consent takes effect from the moment of withdrawal. Withdrawal of consent does not affect processing carried out lawfully before its withdrawal. Withdrawal of consent may make it impossible to continue using services or functionalities that are provided on the basis of consent.
- A request regarding the exercise of rights to personal data may be submitted:
- by correspondence to the address: NB Partners Sp. z o.o. Kamionek Wielki 40D, 82-340 Tolkmicko
- by email, to the address: kontakt@francineandmat.com
If the Administrator is unable to identify the person submitting the request or determine the content of the request based on the submitted request, it will ask the applicant for additional information.
A response to the request will be provided within one month of its receipt. If it is necessary to extend this deadline, the Administrator will inform about the reasons for such extension.
The response will be provided to the email address from which the request was sent, and in the case of requests sent by correspondence, by letter to the address indicated by the applicant (unless the content of the letter indicates that the response should be sent to the indicated email address).
VII Recipients of Data
Recipients of data in connection with transport, parcel collection devices
In connection with purchases in the Online Store, personal data may be transferred to entities providing transport services, courier services, parcel storage services in automated lockers (parcel lockers) in order to deliver ordered goods.
These are the following entities:
- InPost Sp. z o.o. ulica Pana Tadeusza 4, 30-727 Kraków, number 0000543759
- InPost Paczkomaty Sp. z o.o. ulica Pana Tadeusza 4, 30-727 Kraków, KRS number 0000418380
- DHL – DHL Parcel Polska sp. z o.o. with registered office in Warsaw at ulica Osmańska 2, 02-823 Warszawa, KRS number 0000631916
Recipients of data in connection with making payments
In connection with purchases in the Online Store, personal data may be transferred to entities providing payment services in order to enable payments, make refunds in the event that the Customer has the right to withdraw from the contract, or in other cases specified by law or the Online Store Regulations.
If the Customer chooses payment via the przelewy24 system, their personal data is transferred to the extent necessary for payment processing to PayPro S.A. KRS number 0000347935, https://www.przelewy24.pl/
Other recipients of data
In addition, in connection with the fulfillment of orders and services, personal data may be disclosed to external entities, including in particular suppliers and entities responsible for the operation of IT systems, entities providing legal, accounting, and audit services, entities providing marketing systems, systems for examining Customer satisfaction, systems for analyzing traffic in the Online Store.
In connection with operating the online store and processing data regarding orders placed in the Online Store, the entity providing hosting services (providing a server with a database) is LH.pl Sp. z o.o. ul. ks. Jakuba Wujka 7/26 61-581 Poznań, numer KRS: 0000503852.
Personal data may also be disclosed to insurers if justified in connection with an insurance event and insurance contracts.
Upon request, the Administrator discloses personal data to authorized state or local government bodies, in particular the Police, Prosecutor’s Office, President of the Personal Data Protection Office, and tax offices.
VIII Security of Personal Data
The Administrator takes necessary measures to ensure the security of personal data, in particular, ongoing risk analysis is conducted to ensure that personal data is processed securely, including with the application of appropriate security measures and in a manner ensuring access to data only by authorized persons and only to the extent necessary due to the activities they perform.
IX Transfer of Data Outside the EEA
The Administrator does not directly transfer data outside the European Economic Area. However, in connection with the use of tools provided by Meta (Facebook) and the use of Google tools, personal data in the form of IP addresses and data obtained through cookies or other similar technologies may be transferred outside the European Economic Area by Meta Platforms Ireland Ltd., Google Ireland Ltd.
Data is transferred on the basis of the European Commission’s Standard Contractual Clauses.
X Changes to the Privacy Policy
The Privacy Policy may be changed as needed, in particular in the event of changes to legal provisions, issuance of decisions, recommendations by state authorities. We will inform you about this each time by changing the date in the footer of the policy document and – in certain cases – we will also make additional notifications, for example by sending an email to the Customer or publishing relevant information on the store’s website.





