Privacy policy

Privacy Policy of the GGM Tools Online Store

Date of last update: 15 July 2026

This Privacy Policy describes the rules for processing personal data of users of the online store available at ggmtools.com, customers, persons contacting the Seller, and recipients of marketing communications.

The controller of personal data is G&M KKA TRADING Sp. z o.o. The policy also covers data processing related to order handling, payments, delivery, customer accounts, communications, analytics, advertising, sales integrations, and the use of Google, Meta, and TikTok services.

Table of Contents

  1. Data Controller
  2. Scope of collected data
  3. Data sources
  4. Purposes and legal bases of processing
  5. Recipients of data
  6. Shopify, Google, Meta and TikTok
  7. Store management support tools
  8. Data transfers outside the EEA
  9. Data retention period
  10. Profiling and advertising
  11. Cookies and tracking technologies
  12. Rights of data subjects
  13. Right to lodge a complaint
  14. Data security
  15. Children's data
  16. Changes to the Privacy Policy
  17. Contact

1. Data Controller

The controller of personal data is:

G&M KKA TRADING Limited Liability Company
ul. Bukowa 18
05-850 Szeligi, Poland

KRS: 0001171739
NIP: 1182305584
REGON: 541673616

e-mail: office@ggmtools.com
tel.: +48 791 743 533

The Controller decides on the purposes and means of processing personal data, except where a specific service provider acts as an independent controller based on applicable regulations or its own terms of service.

2. Scope of Processed Data

Depending on how you use the store, we may process the following categories of data:

  • first and last name;
  • company name, legal form, tax ID, EU VAT number, REGON or other registration data;
  • residential address, registered office, billing address and delivery address;
  • e-mail address and telephone number;
  • customer account data and activity history;
  • data relating to orders, products, payments, returns and complaints;
  • information required for issuing an invoice or other accounting document;
  • content of correspondence, messages, contact forms and customer service conversations;
  • delivery information, parcel receipt and tracking numbers;
  • IP address, device identifiers, advertising identifiers and cookie identifiers;
  • device type, operating system, browser, language and approximate location;
  • information about how the site is used, including visited subpages and products;
  • events such as product view, add to cart, payment initiation and purchase;
  • traffic source, advertising campaign data and referral parameters;
  • language, currency, market and marketing consent preferences;
  • other data voluntarily provided to the Controller.

The Controller does not store full payment card data when payment is handled by an external payment operator. Such data is processed directly by the relevant payment service provider in accordance with its own rules.

3. Data Sources

Personal data may be obtained:

  • directly from the user when placing an order;
  • when creating or using a customer account;
  • through contact forms, chat, e-mail and telephone;
  • during communication via WhatsApp or other provided channels;
  • from sales platforms, marketplaces or social networks;
  • from payment operators in connection with payment confirmation or status;
  • from carriers and logistics operators in connection with delivery;
  • automatically when using the website;
  • through cookies, pixels, tags and similar technologies;
  • from providers of advertising, analytics and technology services;
  • from public registers, where necessary to verify a business.

4. Purposes and Legal Bases of Processing

Purpose of processing Legal basis
Handling pre-order enquiries, preparing offers and quotes Art. 6(1)(b) GDPR – pre-contractual measures; Art. 6(1)(f) GDPR – legitimate interest in handling correspondence
Accepting and fulfilling orders, delivery, payment processing and order-related contact Art. 6(1)(b) GDPR – performance of contract
Managing the customer account Art. 6(1)(b) GDPR – provision of account service
Issuing and storing invoices, accounting documents and tax returns Art. 6(1)(c) GDPR – compliance with legal obligations of the Controller
Handling complaints, withdrawals, returns, warranty and service cases Art. 6(1)(b) and (c) GDPR – performance of contract and legal obligations; Art. 6(1)(f) GDPR – establishment, exercise and defence of claims
Preventing fraud, abuse, unauthorised transactions and security incidents Art. 6(1)(f) GDPR – legitimate interest of the Controller in protecting the store, customers and transactions
Debt recovery, defence against claims and conducting proceedings Art. 6(1)(f) GDPR – establishment, exercise or defence of claims
Sales statistics, store operation analysis and service quality improvement Art. 6(1)(f) GDPR – legitimate interest; where access to user's device is required – prior consent
Displaying ads, measuring effectiveness, remarketing and personalising ad content Art. 6(1)(a) GDPR – user consent
Sending newsletters, offers and electronic marketing communications Art. 6(1)(a) GDPR – consent; electronic communication requirements also apply
Fulfilling data protection obligations, including handling user requests Art. 6(1)(c) GDPR – legal obligation; Art. 6(1)(f) GDPR – documenting proper compliance

Where processing is based on consent, it may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

5. Recipients of Data

Personal data may be shared with entities that support the Controller in running the store, only to the extent necessary to perform specific tasks.

Recipients may include in particular:

  • Shopify as provider of the online store infrastructure;
  • BaseLinker as an order, sales and logistics integration system;
  • operators of sales platforms and distribution channels;
  • Hellmann and other carriers, freight forwarders and logistics operators;
  • payment operators, banks, card issuers and financial institutions;
  • providers of accounting, tax, legal and audit services;
  • providers of hosting, e-mail, backup and security services;
  • providers of chat, communication, form and customer service tools;
  • Meta, including Facebook, Instagram and WhatsApp, as applicable to the functions used;
  • Google, including analytics, advertising, shopping, Merchant Center, Google Ads, Google & YouTube;
  • TikTok, including TikTok for Business and TikTok Shop;
  • providers of consent management and cookie systems;
  • providers of marketing and analytics services;
  • entities entitled to receive data under applicable law;
  • courts, administrative, tax and law enforcement authorities – within the limits of the law.

Not every listed recipient receives all categories of data. The scope depends on the chosen service, payment method, delivery method, communication channel used and consents granted.

6. Shopify, Google, Meta and TikTok

6.1. Shopify

The store runs on the Shopify platform. Shopify may process technical data, account data, order data, payment data, device data and store usage information to the extent necessary for providing e-commerce infrastructure, security, transaction processing and platform functions.

Depending on the specific operation, Shopify may act as a data processor for the Controller or as an independent data controller.

6.2. Google

The store may use Google services, including those related to analytics, advertising, conversion measurement, product display, Google Merchant Center, Google Ads, Google & YouTube and similar functions.

After obtaining the required consent, the following may be transmitted to Google: IP address, device and browser identifiers, cookie identifiers, information about visited pages and products, and purchase events.

6.3. Meta

The store may use Meta services, including Facebook, Instagram, advertising tools, event measurement, catalogue integration and WhatsApp.

After obtaining the required consent, Meta may receive information about website activity, including events relating to product views, add to cart, initiation of the purchase process or purchase.

When communicating via WhatsApp, data provided during the conversation is processed for the purpose of handling the enquiry, order or business relationship. Users should only share data necessary to resolve the matter in their messages.

6.4. TikTok and TikTok Shop

The store may use TikTok, TikTok for Business, TikTok Pixel, event measurement interfaces, product catalogues and TikTok Shop.

Within these services, data may be processed relating to:

  • display of content and products;
  • interactions with ads;
  • adding products to cart;
  • initiation and completion of the purchase process;
  • device, browser, IP address and advertising identifiers;
  • orders placed via TikTok Shop;
  • measurement of advertising campaign effectiveness.

Optional analytics and advertising technologies from Google, Meta and TikTok are activated according to the user's choice in the consent management tool, where consent is required under applicable law.

7. Store Management Support Tools

The Controller may use IT tools that support staff in managing the store, drafting communications, organising information, analysing operational data or performing repetitive tasks.

Such tools' access to information in the store's systems is limited to what is necessary for a specific task and must only occur through authorised users.

The Controller does not use such tools to make decisions against the customer that produce legal effects solely by automated means, without an appropriate legal basis and required safeguards.

8. Data Transfers Outside the European Economic Area

Some technology, analytics, advertising, communication or infrastructure service providers operate internationally. As a result, data may be stored or processed outside the European Economic Area.

Where data is transferred to a country not recognised as providing adequate protection, the transfer is made using a mechanism provided for in Chapter V of the GDPR, in particular:

  • an adequacy decision of the European Commission;
  • standard contractual clauses approved by the European Commission;
  • other legally permissible safeguards;
  • a GDPR derogation, where applicable.

Where applicable, the Controller or service provider applies additional technical and organisational measures to limit the risks associated with data transfer.

9. Data Retention Period

Data is retained only for the period necessary to achieve the purpose for which it was collected, and thereafter for the period required by law or necessary to secure claims.

Data category Primary retention period
Enquiries and offers until the correspondence ends, then for the period necessary to document its course and defend claims
Order and contract data for the duration of contract performance, then until expiry of limitation periods
Tax and accounting documentation for the period required by applicable tax and accounting regulations
Customer account until account deletion or end of service, with possible further retention of legally required data
Complaints and returns until the matter is resolved, then until expiry of the limitation period for related claims
Data processed on the basis of consent until consent is withdrawn, becomes obsolete or the relevant processing purpose ends
Technical and security data for the period necessary for security, incident analysis and protection against abuse

Individual technology providers may apply their own retention periods in accordance with their policies, account settings and applicable regulations.

10. Profiling and Advertising

Where the user gives appropriate consent, data on website activity may be used to create audience segments, measure ad effectiveness, run remarketing and personalise advertising content.

Profiling may involve analysis of information such as:

  • products and categories viewed;
  • products added to cart;
  • history of interactions with the store;
  • traffic source and responses to advertising campaigns;
  • device type and approximate location;
  • purchases made and product interests.

The Controller does not make decisions against the user that produce legal effects or similarly significantly affect them solely on the basis of automated processing, unless this is compliant with Art. 22 GDPR and the required safeguards are in place.

11. Cookies and Similar Technologies

The store uses cookies, local browser storage, pixels, tags, device identifiers and other technologies necessary for the store to function, and – after obtaining consent – for analytics, personalisation and advertising.

11.1. Technology categories

  • Necessary – enable the store, cart, payments, login, security and privacy settings to function.
  • Functional – allow selected preferences to be remembered and additional features to be provided.
  • Analytics – used to measure traffic, website usage and store feature effectiveness.
  • Marketing – used for campaign measurement, remarketing, audience building and ad personalisation.

11.2. Consent rules

Technologies not strictly necessary for the store to operate are activated after the user makes the appropriate choice, where consent is required.

Continuing to browse the site, not responding to a banner, or browser default settings are not treated as consent to analytical or marketing tracking technologies.

The user may change or withdraw their preferences at any time using the consent management tool available on the site.

Withdrawal does not affect the lawfulness of technology use prior to the withdrawal.

11.3. Browser settings

The user may also delete or block cookies in their browser settings. However, blocking necessary cookies may prevent the cart, account, payments or other store functions from working properly.

12. Rights of Data Subjects

Under the conditions set out in the GDPR, data subjects may have the right to:

  • obtain confirmation that their data is being processed;
  • access their data and receive a copy;
  • rectify inaccurate or complete incomplete data;
  • erasure of data;
  • restriction of processing;
  • data portability;
  • object to processing based on Art. 6(1)(f) GDPR;
  • object to direct marketing;
  • withdraw consent at any time;
  • not be subject to a decision based solely on automated processing, where the conditions of Art. 22 GDPR are met;
  • lodge a complaint with the competent supervisory authority.

An objection to processing for direct marketing purposes may be raised at any time. After receipt of a valid objection, data will no longer be processed for that purpose.

To exercise a right, please contact the Controller at: office@ggmtools.com.

The Controller may request additional information necessary to confirm the identity of the person submitting a request. The scope of information will be limited to what is necessary for the secure processing of the request.

Some rights may be subject to limitations arising from the GDPR or other regulations, in particular where further data retention is necessary for compliance with a legal obligation or for the establishment, exercise or defence of claims.

13. Right to Lodge a Complaint

Anyone who believes their personal data is being processed unlawfully has the right to lodge a complaint with:

President of the Personal Data Protection Office (UODO)
ul. Stanisława Moniuszki 1A
00-014 Warsaw
Poland

The right to lodge a complaint does not limit the possibility of contacting the Controller beforehand to resolve the matter.

14. Data Security

The Controller applies appropriate technical and organisational measures aimed at protecting data against loss, destruction, unauthorised access, disclosure, alteration or other unlawful processing.

Measures applied may include in particular:

  • encryption of data transmission;
  • access control and restriction of permissions;
  • use of individual user accounts;
  • multi-factor authentication, where available;
  • updating systems and applications;
  • creating backups;
  • security monitoring and event logging;
  • concluding appropriate agreements with service providers;
  • authorising and training persons with access to data;
  • procedures for handling data breaches.

No data transmission or storage method guarantees complete elimination of risk. The Controller adapts security measures to the nature, scope, context and purpose of processing as well as the likelihood and severity of threats.

15. Children's Data

The store's offer is directed primarily at adults, business operators and persons purchasing workshop equipment.

The Controller does not knowingly collect children's data for behavioural advertising purposes or for providing services directed directly at children. If information is received that a child's data has been submitted without the required consent of a legal guardian, the Controller will take appropriate action.

16. Changes to the Privacy Policy

The policy may be updated in the event of changes to regulations, store operations, technologies used, service providers or the way data is processed.

The current version of the policy is published on the store's website with the date of the last update. Changes do not affect the lawfulness of processing carried out before they take effect.

Where the nature of a change requires it, users will be informed appropriately or asked to consent again.

17. Contact Regarding Data Protection

For matters relating to personal data, exercising rights, withdrawing consent or reporting an incident, please contact the Controller:

G&M KKA TRADING Sp. z o.o.
ul. Bukowa 18, 05-850 Szeligi, Poland

e-mail: office@ggmtools.com
tel.: +48 791 743 533

18. Key Legal Acts

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 – GDPR.
  • Directive 2002/58/EC of the European Parliament and of the Council concerning the processing of personal data and the protection of privacy in the electronic communications sector, in particular Art. 5(3).
  • Polish Act of 10 May 2018 on the Protection of Personal Data.
  • Polish Act of 18 July 2002 on the Provision of Electronic Services, to the extent applicable.
  • Polish Act of 12 July 2024 – Electronic Communications Law, to the extent relating to electronic communications and the storing of or accessing information on user devices.

GGM Tools | G&M KKA TRADING Sp. z o.o.
This Privacy Policy is effective from the date indicated at the beginning of the document.