This is a courtesy translation. In case of any discrepancy, the Polish-language version of this document is legally binding.
Oczep.pl privacy and cookie policy
Version 2.0 — effective from 14 July 2026.
1. Data controller
The controller of personal data processed in the Oczep.pl service (https://oczep.pl and https://app.oczep.pl — the “Service”) is Bartłomiej Dąbrowski, ul. Lipińskiego 25/76, Lublin, Poland — the “Controller”.
Contact for personal-data matters: bartlomiejdabrowski2000@gmail.com.
2. What data we process
- Account data: email address, password (stored only as a cryptographic hash — we do not know your password), the technical account type (carpenter for new accounts), email verification status.
- Google sign-in (if you use it): the Google account identifier and the email address provided by Google.
- Billing data: selected plan, Stripe customer, subscription and transaction identifiers, subscription status and period, amount and currency, billing details entered in Stripe Checkout, and information needed to handle payments, refunds and complaints. Complete card details are processed by Stripe and are not received by the Service.
- Project content: building-project data entered in the application (floor plans, walls, materials, cut settings). As a rule this is not personal data, but it is stored within your account.
- Technical data: standard server logs (IP address, date and time of the request, browser information) — to the extent necessary to ensure security and diagnostics.
- Statistical data: anonymized visit and feature-usage events — without cookies (see section 8).
Providing data is voluntary but necessary to create and use an account.
3. Purposes and legal bases of processing
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running the account, providing the Service (projects, cut plan, exports) | Art. 6(1)(b) — performance of a contract |
| Sending transactional emails (address verification, account notifications) | Art. 6(1)(b) — performance of a contract |
| Ensuring security, error diagnostics, server logs | Art. 6(1)(f) — legitimate interest of the Controller |
| Handling complaints and correspondence | Art. 6(1)(b) or (f) |
| Visit and usage statistics (cookieless analytics — see section 8) | Art. 6(1)(f) — legitimate interest of the Controller |
| Subscription, payment, refund and accounting administration | Art. 6(1)(b) and (c) |
We do not run marketing, do not profile users and do not make automated decisions producing legal effects.
4. Data recipients
We entrust data only to entities necessary for the Service to operate:
- Hetzner Online GmbH (Germany) — hosting of the application and database; servers located in the European Union,
- Resend, Inc. (USA) — sending transactional emails; the transfer of data to the USA takes place on the basis of the European Commission decision on the EU–US Data Privacy Framework or standard contractual clauses,
- Google Ireland Ltd. — only if you use Google sign-in,
- Stripe group companies — Checkout, recurring payments, fraud prevention and refunds; Stripe may act as a processor or separate controller in accordance with its privacy policy.
We do not sell data and do not share it with other entities, unless such an obligation results from the law.
5. Retention period
- Account data and projects — for as long as you have an account; after the account is deleted, data is removed promptly, at the latest within 30 days (subject to backups, which are overwritten cyclically).
- Server logs — up to 90 days.
- Correspondence (including complaints) — for the limitation period of any claims.
- Payment data and accounting records — for the period required by tax and accounting laws and until related claims become time-barred.
Note: the Service is in a development phase (beta) — test data may be cleared periodically, which we try to announce in advance.
6. Your rights
You have the right to: access your data, rectify it, erase it, restrict processing, data portability and object to processing based on legitimate interest. To exercise these rights, write to the Controller’s contact address.
You can request deletion of your account at any time by email — we do not require a reason.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl).
7. Cookies and similar technologies
The Service uses only cookies and technologies necessary for the service to work. We do not use analytics, marketing or third-party cookies — which is why we do not display a cookie consent banner: under the Polish Electronic Communications Law, storing information necessary to provide the service requested by the user does not require consent.
| Name | Type | Purpose | Period |
|---|---|---|---|
karkas_refresh |
httpOnly cookie (app.oczep.pl) | keeping the logged-in session (token refresh) | 30 days |
| browser storage (PWA cache / IndexedDB) | local storage | running the offline “job site” view | until browser data is cleared |
The information site (https://oczep.pl) does not set any cookies.
If we introduce tools requiring consent in the future (e.g. marketing tools), we will update this policy and ask for consent.
8. Visit statistics (analytics)
To measure traffic in the Service we use the self-hosted Umami tool — it runs entirely on our own server and no data is passed to any third parties. Umami does not use cookies and does not track users across websites. We collect only aggregate statistics (pages visited, traffic source, browser and device type, approximate country) and product events (e.g. registration, creating a project, starting a cut-plan calculation). The IP address is not stored permanently — it is used only to derive an anonymous visit identifier, rotated daily, from which your identity cannot be reconstructed. The legal basis is the Controller’s legitimate interest (Art. 6(1)(f) GDPR): measuring use of the Service and improving how it works.
9. Security
We apply technical and organizational measures appropriate to the risk, in particular: encryption of transmission (HTTPS), storing passwords only as hashes, session tokens in an httpOnly cookie inaccessible to scripts, and restricting access to the infrastructure.
10. Changes to the policy
We will inform you of significant changes to this policy by email or by a notice in the Service. The current version is always available in the Service.