Privacy policy

Kloniko operates the store and website, including all related information, content, features, tools, products and services, to provide the User with a tailored shopping experience (the "Services"). The Kloniko store is powered by Shopify technology, which allows us to offer the Services to the User.

This Privacy Policy describes how we collect, use and disclose the personal data of a User who visits and uses the Services, makes purchases through them or otherwise communicates with us. In the event of a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy applies to the collection, processing and disclosure of the User's personal information.

Please read this Privacy Policy carefully. By using and accessing the Services, the User confirms that they are familiar with this Privacy Policy and understand the rules for collecting, using and disclosing their data described in it.

1. Data controller

The controller of the User's personal data is Kloniko, with its registered office at: ul. POZNAŃSKA 55, lok. 31, JAWCZYCE, 05-850, POLAND

Data protection contact: support@kloniko.store

General e-mail: support@kloniko.store

Under applicable data protection law, we are the controller of the User's personal information.

2. Personal information we collect and process

By "personal information" we mean information that identifies the User or can reasonably be linked to them. Personal information does not include information collected anonymously or information that has been anonymised in a way that makes it impossible to identify the User.

2.1. Contact details

Name and surname, address, billing address, shipping address, phone number and e-mail address.

2.2. Financial data

Credit card, debit card and financial account numbers, payment card details, transaction details, payment methods, payment confirmations and other payment data.

2.3. Account information

Username, password, security questions, preferences and settings.

2.4. Transaction information

Items the User views, adds to the cart, adds to a wish list, purchases, returns, exchanges or cancels, as well as past transactions.

2.5. Communication with us

Information provided in communication with us, e.g. when sending enquiries to customer support.

2.6. Device information

Information about the customer's device, browser or network connection, IP address and other unique identifiers.

2.7. Usage information

Information about the customer's interaction with the Services, including how and when they use or navigate the Services.

2.8. IP address and User-Agent

As part of our consent registration and audit system, we collect the User's IP address and browser User-Agent data. This data is used for security purposes, consent verification and keeping an audit log. IP addresses are automatically anonymised 6 months after collection.

3. Sources of personal information

We may collect personal information from the following sources:

  • Directly from the User — including when creating an account, visiting or using our Services, communicating with us or otherwise providing us with personal information.
  • Automatically through the Services — including from the User's device when using our products or services, and through the use of cookies and similar technologies.
  • From service providers — where we work with them to operate certain technology and where they collect or process the User's personal information on our behalf.
  • From our partners or other third parties.

4. Purposes and legal bases of processing

4.1. Providing, tailoring and improving the Services

We use the User's personal information to provide the Services, including performing the contract concluded with the User, processing payments, fulfilling orders, remembering preferences, sending account-related notifications, processing purchases, returns and exchanges, creating and maintaining the User's account, arranging shipping, enabling the publication of reviews and creating a personalised shopping experience.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

4.2. Marketing and advertising

We may use personal information for marketing and promotional purposes, such as sending marketing communications by e-mail, text message or traditional mail, and displaying online advertising.

Legal basis: Art. 6(1)(a) GDPR — the User's consent.

4.3. Security and fraud prevention

We use personal information to authenticate accounts, ensure secure payments, and detect and investigate potentially fraudulent or illegal activity.

Legal basis: Art. 6(1)(f) GDPR — the controller's legitimate interest.

4.4. Communication with the User

We use personal information to provide customer service, answer questions and maintain business relationships.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract; Art. 6(1)(f) GDPR — legitimate interest.

4.5. Legal reasons

We use personal information to comply with applicable law, respond to legitimate legal processes, including requests from law enforcement or government institutions, conduct investigations and enforce our terms and policies.

Legal basis: Art. 6(1)(c) GDPR — legal obligation; Art. 6(1)(f) GDPR — legitimate interest.

4.6. Session analytics (Microsoft Clarity)

Some pages may have Microsoft Clarity enabled, which records mouse movements, clicks, scrolling and behaviour patterns. Microsoft Clarity is loaded only after the User's explicit consent given via the cookie banner.

Legal basis: Art. 6(1)(a) GDPR — consent.

Summary of purposes and legal bases:

Purpose of processing

Legal basis (GDPR)

Order fulfilment and personalisation

Art. 6(1)(b) — performance of a contract

AI photo analysis (biometric data)

Art. 9(2)(a) — explicit consent

Storing photos for order fulfilment

Art. 6(1)(b) — performance of a contract

Marketing and advertising

Art. 6(1)(a) — consent

Security and fraud prevention

Art. 6(1)(f) — legitimate interest

Improving service quality and analysing preferences

Art. 6(1)(f) — legitimate interest

Session analytics (Microsoft Clarity)

Art. 6(1)(a) — consent

Legal compliance

Art. 6(1)(c) — legal obligation

5. Consent registration (Art. 7 GDPR)

Our system automatically records every consent given by the User. As part of consent registration we record the following information:

  • Consent type: photo_processing (photo processing), biometric (biometric data), print_upload (print upload), analytics (analytics).
  • Date and time the consent was given.
  • The User's IP address at the time consent was given.
  • The User's browser User-Agent.
  • The version of the Privacy Policy the User consented to.

IP addresses stored in the consent register are automatically anonymised after 6 months.

6. Disclosure of personal information

In certain circumstances we may disclose the User's personal information to third-party companies for legitimate purposes:

  • Shopify — the e-commerce platform, suppliers and other third parties providing services on our behalf (IT management, payment processing, data analysis, customer service, cloud storage, fulfilment and shipping).
  • Vercel — frontend (website) hosting.
  • AI analysis server (image.kloniko.store) — processing face photos to match figure parameters.
  • Backend server (api.kloniko.store) — storing order configuration and photos. Hosting: [specify backend hosting provider].
  • Microsoft Clarity — session analytics and recording of user interactions (only after the User's consent; Microsoft servers, possible transfer outside the EEA).
  • Business and marketing partners — to provide marketing services and display advertising.
  • Where the User instructs us to disclose certain information to third parties, requests it or consents to it.
  • With our affiliates or within our corporate group.
  • In connection with a business transaction such as a merger or bankruptcy, to fulfil legal obligations.

We do not pass the User's personal data to third parties for marketing purposes in the context of the Kloniko Builder.

7. Relationship with Shopify

The Services are hosted by Shopify, which collects and processes personal information about the User's access to and use of the Services. Information provided through the Services will be transferred to and shared with Shopify and third parties that may be located in countries other than the User's country of residence.

To secure, develop and improve our business, we use certain advanced Shopify features. Shopify may use personal information collected during the User's interactions with our Store, with other merchants and with the Shopify platform. In such circumstances, Shopify is responsible for processing the User's personal information.

More information: https://privacy.shopify.com/en

8. Appendix: the Kloniko figure Builder

This section supplements the general Privacy Policy and concerns the processing of personal data when using the Kloniko figure Builder (the "Builder").

8.1. Photos uploaded by the User

When using the Builder, the User may upload the following photos:

  • Face photos — for manual painting of the figure's face by our artist or automatic matching of figure parameters by AI.
  • Photos for the torso print — to create an individual print on the figure.
  • Pet photos — for manual painting of the pet figure based on the photo (reference photo).
  • Custom backgrounds and decorative images — for frame personalisation.

Each of the above photo types requires the User's separate consent before upload (consent types: photo_processing, print_upload).

8.2. Biometric data (special category of data)

If the User uses the photo-based figure matching feature (AI), the photo is analysed by an artificial intelligence system. As part of this analysis we automatically extract: gender, hair type and colour, skin tone, eye colour, facial features (beard, glasses, facial expression).

This data constitutes biometric data within the meaning of Art. 9 GDPR and is processed solely on the basis of the User's explicit consent (Art. 9(2)(a) GDPR), given before the photo is uploaded (consent type: biometric).

8.3. Figure configuration

When the Builder is used, we save the selected figure parameters: skin colour, head type, hairstyle, hair colour, eyes, eyebrows, lips, beard, glasses, torso colour, leg type and colour, accessories, keychain, carabiner, print type and content (front/back), face creation mode (manual/from photo).

8.4. Frame data

If the User creates a frame with figures, we additionally process: the colour, size and orientation of the frame, the configuration of each figure in the frame, names/captions under the figures, comments for the designer, custom background and decorative elements.

8.5. Builder technical data

  • localStorage — the figure/frame configuration is stored in the User's browser so that work can continue after the page is refreshed. This data is not sent to the server until an order is placed.
  • Session identifier (photo_id) — generated during AI photo analysis.

9. Data retention period

The table below sets out the retention periods for individual categories of data:

Data type

Retention period

Photos uploaded by the User

Automatic deletion 12 months after the order is created (together with files)

Figure/frame configuration

Automatic deletion 12 months after the order is created

AI analysis data (photo_id, parameters)

Automatic deletion after 12 months

IP addresses in the audit log

Automatic anonymisation after 6 months

Consent records

Deleted together with the order data (12 months)

Data in the browser's localStorage

Until cleared by the User

Microsoft Clarity data

In accordance with Microsoft's policy

Contact and transaction data

For the period necessary to service the account, provide the Services, meet legal requirements and resolve disputes

All Builder order data is automatically deleted 12 months after creation, together with all related files (photos, prints, previews). IP addresses in audit logs are automatically anonymised after 6 months.

The User may at any time request earlier deletion of their data by contacting us.

10. The User's rights and choices

Depending on their place of residence, the User may have the following rights. These rights are not absolute and may apply only in certain circumstances.

  • Right of access (Art. 15 GDPR) — the User may request information about what personal data we process about them.
  • Right to rectification (Art. 16 GDPR) — the User may request the correction of inaccurate personal data.
  • Right to erasure (Art. 17 GDPR, the "right to be forgotten") — the User may request the deletion of their personal data, including photos and configurations.
  • Right to restriction of processing (Art. 18 GDPR) — the User may ask for processing to be restricted in certain situations.
  • Right to data portability (Art. 20 GDPR) — the User may receive their data in a machine-readable format.
  • Right to withdraw consent (Art. 7(3) GDPR) — the User may withdraw consent to the processing of biometric data at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
  • Objection to and restriction of processing — the User has the right to ask us to stop or restrict the processing of personal information for certain purposes.
  • Managing communication preferences — the User may opt out of promotional e-mails at any time using the unsubscribe option.
  • Right to lodge a complaint — with the supervisory authority (the President of the Polish Personal Data Protection Office, Prezes UODO).

10.1. Right to erasure — details

At the User's request, we will fully delete the following data:

  • All order data from the database.
  • All uploaded files (photos, prints, previews).
  • All consent records linked to the order.
  • Anonymisation of audit log records (IP addresses and User-Agent will be zeroed out).

To submit a deletion request, contact us at korolkyrylopl@gmail.com, quoting the order ID (the UUID from the link you received). Deletion will be carried out within 30 days in accordance with Art. 17 GDPR.

10.2. Right to data export — details

At the User's request, we will provide an export of all their data in JSON format, covering:

  • The order configuration.
  • All uploaded images (in base64 format).
  • Consent records.
  • Audit log records.

To submit an export request, contact us at support@kloniko.store

We will not discriminate against the User for exercising any of these rights. We may need to verify the User's identity before processing their request. We will respond to the request within the time limit provided by applicable law.

11. Cookies and tracking technologies

11.1. localStorage

The Builder saves the figure and frame configuration in the User's browser localStorage so that work can continue after the page is refreshed. This data is not sent to the server until an order is placed.

11.2. Microsoft Clarity

Some versions of the Builder may have Microsoft Clarity enabled, which records mouse movements, clicks and scrolling, user behaviour patterns, and device and browser information.

Microsoft Clarity is loaded only on the basis of the User's consent given via the cookie banner. The User may choose the "Essential only" option — in which case Clarity will not be loaded. The choice is saved in localStorage and can be changed at any time.

11.3. Cookie banner

On the first visit to the website, the User may choose the scope of cookie consents. This choice is saved in the browser's localStorage and can be changed at any time.

12. Data security

We apply appropriate technical and organisational measures to protect the User's data, including:

  • Encryption of data transmission (HTTPS/TLS) for all connections.
  • Secure storage of photos on the server.
  • Restricting data access to authorised employees only.
  • Using UUIDs instead of sequential identifiers (protection against enumeration).
  • Rate limiting of requests.
  • File storage protection (Origin/Referer verification).
  • Parameterised SQL queries (protection against SQL injection).
  • Security headers (X-Content-Type-Options: nosniff).
  • Regular security reviews.

Please remember that no security measures are perfect or impenetrable and we cannot guarantee "complete security". We advise against using insecure channels to send us sensitive or confidential information.

13. Third-party websites and links

The Services may contain links to websites and other online platforms operated by third parties. If you navigate to websites not affiliated with or controlled by us, please review their privacy policies. We do not guarantee the privacy or security of such websites. Our inclusion of such links does not in itself imply endorsement of the content on those platforms.

14. Children's data

The Services are not intended for use by children. We do not knowingly collect any personal information about children under the age of majority in the User's jurisdiction. If the User is a parent or guardian of a child who has provided us with their personal information, they may contact us to request its deletion.

As of the effective date of this Privacy Policy, we have no actual knowledge of "sharing" or "selling" the personal data of persons under 16 years of age.

15. International data transfers

We may transfer, store and process the User's personal information outside their country of residence.

Some services we use (Microsoft Clarity, Vercel) may process data outside the European Economic Area (EEA).

If we transfer personal information outside the EEA or the United Kingdom, we rely on recognised data transfer mechanisms, such as the European Commission's standard contractual clauses or equivalent arrangements issued by the relevant UK supervisory authority, unless the data is transferred to a country deemed to provide an adequate level of protection.

16. Complaints

If you have complaints about how we process personal data, please contact us using the contact details below. The User may have the right to appeal against our decision or to lodge a complaint with their local data protection authority (the President of the Polish Personal Data Protection Office, Prezes UODO).

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, including to reflect changes in our practices or for other operational, legal or regulatory reasons. We will publish the revised Privacy Policy on this website, update the "Last updated" date and inform the User of the changes in accordance with applicable law.

18. Contact

If you have any questions about our privacy practices or this Privacy Policy, or to exercise any of your rights, please contact us:

  • E-mail (general): support@kloniko.store
  • Address: ul. POZNAŃSKA 55, lok. 31, JAWCZYCE, 05-850, POLAND