Publishing a clear, comprehensive Privacy Policy is a mandatory legal requirement under the GDPR for any e-commerce storefront. It serves as your formal fulfillment of the informational obligation specified under Article 13 of the GDPR, explaining exactly how customer data is gathered, handled, stored, and protected.
Below is a structurally sound template tailored for an online store operating on a mybox server framework.
Table of Contents
Privacy Policy Template for an Online Store
I. General Provisions
- This Privacy Policy outlines the rules for collecting, processing, and storing personal data of Users utilizing the online store operating at the web address [Insert Your Shop URL Here] (hereinafter referred to as the “Store”).
- The Data Controller (Administrator) of the personal data gathered via the Store is [Insert Your Company/Full Registered Name Here], with its registered office at [Insert Business Address Here], NIP: [Insert Tax ID Here], REGON: [Insert Business Registry Number Here], KRS: [Insert Court Registry Number, if applicable] (hereinafter referred to as the “Controller”).
- Personal data is processed in structural compliance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR / RODO).
II. Purposes and Lawful Bases for Data Processing
The Controller processes personal data for the following essential business purposes:
- Account Registration & User Profiles: To manage your store profile, process secure logins, and grant access to order tracking panels.
- Lawful Basis: Contractual Necessity - Art. 6(1)(b) GDPR.
- Order Fulfillment & Shipping Logistics: To process transactions, handle checkout totals, arrange courier deliveries, and manage returns or product complaints.
- Lawful Basis: Contractual Necessity - Art. 6(1)(b) GDPR.
- Statutory Accounting & Financial Auditing: To issue legal commercial invoices, manage billing records, and comply with state tax requirements.
- Lawful Basis: Compliance with a Legal Obligation - Art. 6(1)(c) GDPR.
- Newsletter & Marketing Communication: To dispatch promotional campaigns, product alerts, and marketing newsletters based on express opt-in choices.
- Lawful Basis: Explicit Consent - Art. 6(1)(a) GDPR.
- Infrastructure Defense & Fraud Prevention: To analyze system interaction paths, deploy firewall parameters, block automated brute-force attacks, and track potential checkout anomalies.
- Lawful Basis: Legitimate Interest of the Controller - Art. 6(1)(f) GDPR.
III. Categories of Collected Personal Data
The Store collects and processes only the data fields required for running a clean retail interface:
- First name and last name
- Physical delivery address (Street, house number, postal code, city, country)
- Company billing details (Company name, corporate address, NIP number)
- Contact parameters (Email address, telephone number)
- Network tracking telemetry (IP address, system cookie markers, device layouts)
IV. Data Retention Lifecycles
Personal data will not be preserved within database structures indefinitely. The retention scopes are limited to these schedules:
- Transaction Logs & Invoices: Maintained for a minimum of 5 years from the end of the calendar tax year in which the commercial invoice was generated, satisfying mandatory corporate tax and bookkeeping codes.
- User Account Profiles: Retained for the active duration of the user’s registry registration, or until a formal profile deletion request is processed.
- Marketing Information: Processed continuously until the customer clicks an “Unsubscribe” hyperlink or explicitly revokes their consent flag.
V. Categories of Authorized Data Processors (Recipients)
To process sales smoothly, your data may be passed securely to specialized third-party service entities:
- Hosting & Server Partners: Data is stored on secure server volumes managed under a formal Data Processing Agreement (DPA) on the mybox hosting framework.
- Courier & Logistics Services: Delivery data is passed to transport carriers (e.g., DHL, InPost, DPD, UPS) to handle parcel fulfillment.
- Payment Gateways: Financial payment profiles are securely redirected and handled by Tier-1 certified PCI-DSS transaction systems (e.g., Stripe, PayPal, PayU).
- Accounting Platforms: Invoicing data is synchronized with automated digital accounting systems or external bookkeeping offices.
VI. Data Subject Rights
Every individual whose data is managed by the Store holds comprehensive rights that the Controller must execute within a strict 30-day window:
- Right of Access: The right to receive a clear, free export of every data point held on your identity.
- Right to Rectification: The right to modify or fix inaccurate or outdated address profiles.
- Right to Erasure (“To Be Forgotten”): The right to demand absolute removal of personal profiles, provided the records are not subject to conflicting statutory legal tax retention obligations.
- Right to Data Portability: The right to request your personal database rows in a structured, machine-readable layout (like CSV or JSON).
- Right to Object: The right to block behavioral analytics or direct profiling processes based on legitimate business interests.
Users may exercise these rights or file inquiries by contacting the Controller directly at [Insert Your Shop Support Email Here]. Users also preserve the right to lodge a formal complaint with the data protection supervisory authority (UODO in Poland) if they believe their rights have been compromised.
VII. Cookie Management and Tracking Scripts
- The Store uses system cookies-divided into necessary cookies (required for session memory and cart functions), performance analytics, and marketing tracking scripts.
- The Store integrates advanced analytical and script engines (such as Google Analytics 4, Google Tag Manager, and Google Consent Mode v2) to monitor performance safely.
- Marketing, tracking, and personalization scripts remain fully blocked from running until the visitor explicitly grants consent through the main cookie management banner interface.
Technical Integration Checklist for mybox Storefronts
To ensure your Privacy Policy functions as an active technical rulebook rather than a placeholder text block, align your mybox server assets using these production rules:
- Map Checkout Fields Carefully: Ensure fields like phone numbers or business coordinates are flagged as optional items unless they are required to finalize a delivery.
- Configure LiteSpeed Cache Exclusions: Local retail sessions must stay highly insulated. Confirm that your active cart, billing checkout lanes, and account profile folders are excluded from edge caching within your LiteSpeed Cache parameters to protect customer privacy.
- Secure the Mail Path (SMTP): When your storefront generates programmatic messages containing sensitive account metrics-such as password reset tokens, checkout invoices, or file download links-the routing path must be secure. Route your store’s transactional mail through your account configurations using mail.mybox.com to protect your data streams and keep notifications out of spam folders.