PRIVACY AND COOKIES POLICY

PRIVACY AND COOKIES POLICY 
FutonLove 
www.futonlove.com 


I. General information

  1. This document specifies the privacy principles applicable in the Online Shop www.futonlove.com (hereinafter referred to as the “Online Shop”).
  2. For the purposes of data protection legislation, we are the data controller of your personal data - Pascall sp. z o.o. with its registered seat ul. Główna 6, 61-005 Poznań (Poland), Vat number: PL7822281750, REGON: 634533620 KRS: 0000181823, E-mail: contact@futonlove.com.
  3. Personal information collected by the data controller shall be processed in accordance with the provisions of the Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46 / EC (GDPR).
  4. The data controller collects information provided voluntarily by the Online Shop Customers. However, the provision of marked personal data is a condition for placing an order, while the consequence of not ordering will be the inability to order products in the store.
  5. Moreover, the data controller may record the information about connection parameters, like IP addresses, for technical purposes, for server administration and for collection of general, statistical demographic information (e.g. about the region from which the connection comes), and for security purposes.
  6. The data Controller shall make an extra effort in order to protect privacy and information about the Online Shop Customers provided to him. The data Controller shall exercise due diligence when selecting and applying appropriate technical measures, including those of programming and organizational nature, in order to protect the processed data, and in particular he shall protect the data from unauthorized access, disclosure, loss and destruction, unauthorized modification, and also from their processing with the breach of the applicable provisions of law.
  7. Personal data will be processed in accordance with the principles of art. 5 GDPR.
    Personal data will be:
    • processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
    • collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; (‘purpose limitation’);
    • adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);
    • accurate and, where necessary, kept up to date (‘accuracy’);
    • kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; (‘storage limitation’);
    • processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).
  8. In the case of transferring personal data to entities based outside the EEA, the Controller ensures that the requirements set out in Chapter 5 of the GDPR are applied, including the application of appropriate transfer safeguards in the form of standard contractual clauses adopted based on a decision of the European Commission.
  9. The data controller will always post information about changes to the Privacy Policy in the Online Shop. With each change, a new version of the Policy will appear with a new date.

II. Purpose for Processing

  1. The basis for the processing of the Customer's Personal Data is primarily the necessity to perform the contract to which he is a party or the need to take action at his request prior to its conclusion (Article 6 par 1 (b) of GDPR).
  2. The data controller may place marketing information about his/her Goods or services on the Online Shop’s website. Such content shall be displayed by the data controller in accordance with Article 6 section 1 letter f of the GDPR, in accordance with the legitimate interest pursued by the data controller, in publishing the content related to the services provided and the promotional content of the actions in which the data controller is involved. At the same time, the action does not infringe the rights and freedoms of the Customers/Users, the Customers/Users expect to receive similar content, or even expect it or it is their direct purpose to visit the website(s) of the Online Shop.
  3. Account:
    1. The Customer/User may not place in the Online Shop or provide the Seller with content, including opinions and other data of an illegal nature. The Customer/User gets access to the Account after registration.
    2. When registering, the Customer/User provides the account type or gender, name, surname, company name, NIP number, data for issuing a sales document, shipping data, e-mail address and choose a password. The Customer/User assures that the data provided by him/her in the registration form are correct. Registration requires that Customer/User read the Regulations carefully and mark on the registration form that he/she has read the Regulations and fully accepts all provisions.
  4. Newsletter:
    1. The Customer/User may give his/her consent to receive commercial information electronically by ticking the appropriate option in the registration form or at later date in the appropriate tab. In the case of such consent, the Customer/User shall receive information (Newsletter) of the Online Shop as well as other commercial information sent by the Seller to the Customer’s/User’s email address.
    2. The Customer/User may unsubscribe from the Newsletter at any time by unchecking the appropriate box on his/her Account page or by going to the form https://futonlove.com/en/newsletter.html, clicking the appropriate link in the content of each Newsletter or through the Customer Service Office.
  5. In other purposes, the Customer's Personal Data may be processed on the basis of:
    1. applicable law when processing is necessary to fulfil the legal obligation of the Controller e.g. when based on tax regulations or accounting one, The Controller settles concluded sales contracts (Article 6 (1) (c) GDPR).
    2. indispensable for purposes other than those mentioned above resulting from legitimate interests pursued by the Controller or by a third party, to determine, assert or defend claims, market and statistical analyses Article 6 (1) (f) GDPR).

III. The personal data we collect and use.

  1. We ensure that the collection and use of your personal data is lawful. Therefore, for the purposes listed below, we only use your personal data if one of the following conditions apply:
    1. You have given us your consent.
    2. We need your personal data for the performance of a contract you enter into with us, such as when you purchase a product through the website.
    3. We need to comply with legal obligations.
    4. We need to protect your vital interests.
    5. Your data is necessary for the public interest, or
    6. We have a legitimate interest in processing the personal data.
  2. In order to perform the Distance Selling Agreement, the Seller processes:
    1. information concerning the User's device in purpose to ensure the correct functioning of the services: IP address of the computer, information contained in cookies or other similar technologies, session data, web browser data, device data, data concerning activity on the website, including on individual subpages.
    2. geolocation data, if the User has consented to the service provider's access to geolocation. The geolocation data is used to provide more tailored offers of Goods and services.
    3. users’ personal data: name, surname, registered office address, correspondence address, e-mail address, telephone number, Tax Identification Number (NIP), bank account number or other personal data required by the Administrator in the purchasing process.
  3. This information does not contain identity data of the Users, but in combination with other information may constitute personal information. Therefore, the data controller extends full GDPR protection to them.

IV. Term of Personal Data Processing

  1. In compliance with the applicable legal provisions, we process your personal data for a term of time that is necessary to meet the designated purpose. After such term, the personal data of Customers will be irrevocably deleted or destroyed.
  2. Personal data processed covered by the consent statement will be processed until the consent is revoked.
  3. We process personal data during the term of the agreement, as well as during a period of expiry of claims resulting from the provisions of the Polish Civil Code.


V. Recipients of personal data

  1. Recipients of the Customer's personal data may by entities performing the order at the Seller's request and handling it, such as: shipment companies, accounting companies, suppliers of the goods, assembly services, providers of IT solutions, payment processing companies, banks, companies providing marketing services, telecommunication providers, law offices, authorized state authorities.
  2. Electronic payment operator:
    1. IdoPayments sp. z o.o. with its registered office at 30 Piastów Avenue, 71-064 Szczecin,
    2. Klarna Bank AB (publ),Sveavägen 46, 111 34 Stockholm, Sweden.
    3. PayPal (Europe) S.à r.l. et Cie, S.C.A. 22-24 Boulavard Royal L-2449 Luxembourg,
  3. Transaction data, including personal data, may be transferred to IdoPayments/Klarna/PayPal to the extent necessary to handle payment for the order. The Customer has the right to access their data and correct it. The provision of data is voluntary and at the same time necessary for the use of the website.

VI. Your rights on personal data concerning you

  1. Rights for the data subjects
    1. of access (Article 15 of the GDPR) - to obtain confirmation from the data controller, whether his or her personal data are being processed. If the data about a person is processed, he or she is entitled to access it and to obtain the following information: about the purposes of the processing, the categories of personal data, the recipients or categories of recipients to whom the personal data have been or will be disclosed, about the period of data storage or about the criteria used to determine that period, about the right to request rectification, erasure or restriction of processing of personal data and to object to such processing;
    2. to obtain a copy of the data (Article 15 section 3 GDPR) - to obtain a copy of the data to be processed; the first copy being free of charge. For further copies the data controller may charge a reasonable fee based on administrative costs.
    3. to rectification (Article 16 of the GDPR) - to request the rectification of inaccurate or to supplement incomplete data concerning him or her.
    4. to erase the data (Article 17 of the GDPR) - to request the erasure of his/her personal data if the data controller has not a legal basis for their processing or the data are not necessary for the purposes of processing anymore.
    5. to restriction of processing (Article 18 of the GDPR) - to request a restriction of processing of personal data when:
      • the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data,
      • the processing is unlawful, and the data subject opposes the erasure of the personal data and requests the restriction of their use instead,
      • the data controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims,
      • the data subject has objected to processing pursuant to Article 21 section 1 pending the verification whether the legitimate grounds of the controller override those of the data subject.
    6. to data portability (Article 20 GDPR) - to receive the personal data concerning him or her, which he or she has provided to a data controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the data controller to which the personal data have been provided, where data are processed on the basis of the data subject's consent or on a contract with him/her and where data are processed by automated means;
    7. to object (Article 21 of the GDPR) - to object to the processing of his/her personal data for the legitimate purposes of the controller, on grounds related to his/her specific situation, including profiling. In such case, the data controller shall assess the existence of important legitimate grounds for processing overriding the interests, rights and freedoms of data subjects or grounds for establishing, pursuing or defending claims. If according to the assessment the interests of the data subject will take precedence over the interests of the controller, the data controller shall be obliged to stop processing the data for these purposes.
    8. to withdraw consent at any time and without giving any reason, but the processing of personal data carried out before withdrawal of consent will still remain lawful. Withdrawal of consent shall result in the data controller ceasing to process personal data for the purpose for which the consent was given.
  2. In order to exercise the aforementioned rights, the data subject should contact the data controller, using the contact details provided and inform the data controller, which right and to what extent he/she wants to exercise it.
  3. The data subject has the right to lodge a complaint with the supervisory authority, which in Poland is the President of the Personal Data Protection Office, with its seat in Warsaw, ul. Stawki 2, which can be contacted as follows:
    • address for letters: ul. Stawki 2, 00-193 Warsaw.
    • via the electronic mailbox available on the website: https://www.uodo.gov.pl/pl/p/kontakt;
    • address for letters: helpline: 606-950-000.


COOKIES

  1. The Online Shop performs the functions of obtaining information about Customers, Users and their behaviour in the following way by:
    1. information voluntarily entered on the forms, for purposes arising from the function of the form;
    2. storing cookies (so-called: “cookies") on final device;
    3. collecting web server logs by the Online Shop’s hosting operator (necessary for proper operation of the Online Shop).
  2. Cookie files are IT data, in particular text files, which are stored in the Customer's/ User's final device and are designed to use the Online Shop’ s website. Cookies usually contain the name of the website from which they come from, the time of their storage on the final device and a unique number.
  3. The Online Shop uses cookies only after the Customer/User has given his/her prior consent in this regard. Consent to the use of all cookies by the Online Shop is given by clicking the button: "Close" when the announcement about the use of cookies by the Online Shop is displayed or by closing that announcement.
  4. If the Customer/User does not agree to the use of cookies by the Online Shop, he/she may use the option: "I do not agree", which is also available in the announcement about the use of cookies by the Online Shop or make changes to the settings of the Internet browser, which is currently using by Customer/User (however, this may cause incorrect operation of the Online Shop).
  5. To manage the cookie settings, Customer/User should select web browser/system and follow the instructions: Internet Explorer, Chrome, Safari, Firefox, Opera, Android, Safari (iOS), Windows Phone.
  6. The legal basis for the processing of personal data from cookies is the legitimate interests pursued by the Website’s Operator, consisting in providing high quality services, ensuring the safety of services.
  7. The Online Shop uses two basic types of cookies: session cookies and persistent cookies. Session cookies are temporary files, which are stored in the User's final device until logging out, leaving the Online Shop or switching off the software (web browser). Persistent cookies are stored in a User's device for the time specified in the parameters of cookies or until their removal by the User.

Functional cookies (required)

futonlove-com.iai-shop.com
monit_token: 365 days, cookie
Identifies the shop's customer.
shop_monit_token: 30 minutes, cookie
Identifies the shop's customer.
client: 1 days, cookie
Identifies the logged-in customer / basket of the non-logged-in customer.
affiliate: 90 days, cookie
It stores information about the partner ID from which the shop was entered.
ordersDocuments: cookie
Stores information about the print status of a document.
__idsui: 1095 days, cookie
File required for the so-called lightweight login function on the website.
__idsual: 1095 days, cookie
File required for the so-called lightweight login function on the website.
__IAI_SRC: 90 days, cookie
It only stores the source from which the page was accessed.
login: cookie
Stores information about whether the user has logged in to the site.
CPA: 28 days, cookie
Includes information on the variables for the CPA / CPS programmes in which the site participates.
__IAIRSABTVARIANT__: 30 days, cookie
Variant identifier for the A/B test and IdoSell RS engine configuration.
basket_id: 365 days, cookie
The site user's shopping cart identifier, assigned for the duration of the ongoing session.
page_counter: 1 days, cookie
Counter of pages visited.
LANGID: 180 days, cookie
Stores information about the language selected by the site user.
REGID: 180 days, cookie
Stores information about the site user's region.
CURRID: 180 days, cookie
Stores information about the currency of the site selected by the user.
__IAIABT__: 30 days, cookie
It stores the A/B test identifier, for the purpose of testing and improving shop functionality.
__IAIABTSHOP__: 30 days, cookie
It stores the identifier of the shop participating in the A/B test.
__IAIABTVARIANT__: 30 days, cookie
Stores the identifier of the variant drawn as part of the ongoing A/B test.
toplayerwidgetcounter[]: cookie
Stores the number of times a pop up message has been displayed.
samedayZipcode: 90 days, cookie
Stores information about the site user's postcode, which is required to offer courier delivery on the SameDay service.
applePayAvailability: 30 days, cookie
Stores information about whether an ApplePay payment method is available for the user.
paypalMerchant: 1 days, cookie
PayPal account ID.
toplayerNextShowTime_: cookie
Stores information about the time at which the next pop up message is to be displayed. 
rabateCode_clicked: 1 days, cookie
Stores information about the closure of the active discount bar.
freeeshipping_clicked: 1 days, cookie
Stores information about the closing of the free delivery bar.
redirection: cookie
Stores information on the closure of the pop-up message indicating the suggested language for the shop.
filterHidden: 365 days, cookie
When the option to collapse the filter for goods is clicked, it saves which filter is to be collapsed when the goods list is refreshed.
toplayerwidgetcounterclosedX_: cookie
It stores information about closing the pop-up message.
cpa_currency: 60 minutes, cookie
Includes currency information for CPA / CPS programmes in which the site participates.
basket_products_count: cookie
Stores information on the number of products in the basket.
wishes_products_count: cookie
Stores information on the number of products in the favorites list.
remembered_mfa: 365 days, cookie
Stores remembered user information for multi-factor authentication (MFA)
IAI S.A.
iai_accounts_toplayer: 30 days, cookie
Ensures the correct display of the pop up message informing about the IdoAccounts login service (https://www.idosell.com/en/idoaccounts-is-a-system-that-facilitates-the-process-of-logging-in-to-many-stores-with-one-account-and-placing-orders-in-online-stores/).
IdoSell
platform_id: cookie
Stores information about whether the page is displayed in the mobile app.
paypalAvailability_: 1 days, cookie
Stores information on whether a PayPal payment method is available for the user.
ck_cook: 3 days, cookie
Stores information about whether the user of the website has consented to cookies.
IdoAccounts
accounts_terms: 365 days, cookie
Stores information on whether the user has accepted consent to use the IdoAccounts service.
express_checkout_login: 365 days, cookie
CookieNameExpressCheckoutLogin
Google
NID: 180 days, cookie
These cookies (NID, ENID) are used to remember your preferences and other information, such as your preferred language, how many results you prefer to have shown on a search results page (for example, 10 or 20), and whether you want to have Google’s SafeSearch filter turned on. This cookie is also required to offer the Google Pay payment service.
Google reCAPTCHA
_GRECAPTCHA: 1095 days, cookie
This cookie is set by Google reCAPTCHA, which protects our site against spam enquiries on contact forms.
PayPal
ts: cookie
This cookie is generally provided by PayPal and supports payment services on the website.
ts_c: 1095 days, cookie
This cookie is generally provided by PayPal and is used to prevent fraud.
x-pp-s: cookie
This cookie is generally provided by PayPal and supports payment services on the website.
enforce_policy: 365 days, cookie
This cookie is generally provided by PayPal and supports payment services on the website.
tsrce: 3 days, cookie
This cookie is generally provided by PayPal and supports payment services on the website.
l7_az: 60 minutes, cookie
This cookie is necessary for the PayPal login-function on the website.
LANG: 1 days, cookie
This cookie is generally provided by PayPal and supports payment services on the website.
nsid: cookie
Used in the context of transactions on the Website. The cookie is required for secure transactions.



Analytics cookies
IAI S.A.
__IAI_AC2: 45 days, cookie
Activity Tracking identifier to collect the history of pre-order sources as well as the source through which the order was placed according to the last click attribution model.
Google Analytics
_ga_: 730 days, cookie
Used by Google Analytics to collect data on the number of times a user has visited the website, as well as dates for the first and most recent visit.
_ga: 730 days, cookie
Registers a unique ID that is used to generate statistical data on how the visitor uses the website.
_gid: 1 days, cookie
Registers a unique ID that is used to generate statistical data on how the visitor uses the website.
_gat: 1 days, cookie
Used to throttle request rate. Analytics anonymizes the IP address.
_dc_gtm_UA-#: 730 days, cookie
Used by Google Tag Manager to control the loading of a Google Analytics script tag. Analytics anonymizes the IP address.
FPLC: 1200 minutes, cookie
Non-HttpOnly cookie version named FPLC with a value hashed from the FPID value.
_gat[_]: 1 minutes, cookie
Used to throttle request rate. If Google Analytics is deployed via Google Tag Manager, this cookie will be named _dc_gtm_.
_gat_gtag: 1 minutes, cookie
Used to analyze visitor browsing habits, flow, source and other information.
__utma: 730 days, cookie
Used to distinguish users and sessions. The cookie is created when the javascript library executes and no existing __utma cookies exists. The cookie is updated every time data is sent to Google Analytics.
__utmb: 30 minutes, cookie
Used to determine new sessions / visits. The cookie is created when the javascript library executes and no existing __utmb cookies exists. The cookie is updated every time data is sent to Google Analytics.
__utmc: cookie
Not used in ga.js. Set for interoperability with urchin.js. Historically, this cookie operated in conjunction with the __utmb cookie to determine whether the user was in a new session/visit.
__utmt: 10 minutes, cookie
Used to throttle request rate.
__utmz: 180 days, cookie
Stores the traffic source or campaign that explains how the user reached your site. The cookie is created when the javascript library executes and is updated every time data is sent to Google Analytics.
__utmv: 730 days, cookie
Used to store visitor-level custom variable data. This cookie is created when a developer uses the _setCustomVar method with a visitor level custom variable. This cookie was also used for the deprecated _setVar method. The cookie is updated every time data is sent to Google Analytics.
AMP_TOKEN: 365 days, cookie
Contains a token that can be used to retrieve a Client ID from AMP Client ID service. Other possible values indicate opt-out, inflight request or an error retrieving a Client ID from AMP Client ID service.
FPID: 730 days, cookie
This cookie is named FPID (First Party Identifier) by default. The value stored in FPID will be used for setting the Client ID in the request to Google’s servers.
_gaexp: 90 days, cookie
Used to determine a user's inclusion in an experiment and the expiry of experiments a user has been included in.
_opt_awcid: 1 days, cookie
Used for campaigns mapped to Google Ads Customer IDs.
_opt_awmid: 1 days, cookie
Used for campaigns mapped to Google Ads Campaign IDs.
_opt_awgid: 1 days, cookie
Used for campaigns mapped to Google Ads Ad Group IDs
_opt_awkid: 1 days, cookie
Used for campaigns mapped to Google Ads Criterion IDs
_opt_utmc: 1 days, cookie
Stores the last utm_campaign query parameter.
_opt_expid: 0.2 minutes, cookie
This cookie is created when running a redirect experiment. It stores the experiment ID, the variant ID and the referrer to the page that's being redirected.
Google Analytics pixel: 999 days, tracking pixel
Pixel measures visits, clicks, and other digital behaviour. This allows to adapt your marketing strategy.
__utmli: 60 days, cookie
The cookie is part of the Enhanced Link Attribution feature that (tries to) distinguish clicks on links to the same destination in the in-page analyses. Contains the id (if any) of the clicked link (or its parent) to be read on the next page, so in-page analyses can tell where on the page the clicked link was located.
Google Maps
SID: 3650 days, cookie
Contain digitally signed and encrypted records of a user’s Google Account ID and most recent sign-in time. The combination of these cookies (SID, HSID) allows Google to block many types of attack, such as attempts to steal the content of forms submitted in Google services.



Advertising cookies
futonlove-com.iai-shop.com
RSSID: 180 days, cookie
IdoSell RS user ID, used for the purpose of displaying tailored product recommendations on the website.
__IAIRSUSER__: 60 minutes, cookie
IdoSell RS user ID, used for the purpose of displaying tailored product recommendations on the website.
Google Analytics
__gads: 395 days, cookie
To provide ad delivery or retargeting.

 8. The cookies are used for the following purposes:
1. creating statistics that help to understand how Customers/Users of the Online Shop use the websites, which allows to improve their structure and content;
2. maintaining the Customer/User session (after logging in), thanks to which the Customer/User does not have to re-enter the login and password on each subpage of the Online Shop;
3. defining the Customer's profile in purpose to display product recommendations and matching materials in advertising networks, in particular the Google network.

9. Software for web browsing (web browser) usually by default allows for storing cookies in the User's final device. Customers/Users may change their settings in this area. The web browser allows to remove cookies. It is also possible to automatically block cookie files.
10. Restrictions on the use of cookies may affect some of the functionalities available on the Online Shop's websites.
11. Cookie files placed in the Customer’s/User's final device and may also be used by Online Shop’s advertisers and partners, cooperating with the Online Shop.
12. Cookies may be used by the Google network to display advertisements tailored to the way the Customer/User uses the Online Shop. For this purpose, they can store information about the user's navigation path or time spent on a given page: [https://policies.google.com/technologies/partner-sites](https://policies.google.com/technologies/partner-sites).
13. We recommend that Customer/User should read these companies' privacy policies in purpose to understand the cookies’ usage in the statistics: Privacy Policy - Google Analytics.
14. In terms of information on the Customer’s/ User's preferences collected by the Google's advertising network, the Customer/User can view and edit the information resulting from cookies using the tool: [https://www.google.com/ads/preferences/](https://www.google.com/ads/preferences/)
15. On the website of the OnlineShop there are plug-ins, which can transfer the data of Customers/Users to the data collectors, such as e.g: .
16. In purpose to correctly perform the Distance Selling Agreement, the data controller may make the Customer/User data available to courier entities. The currently available delivery methods in the Online Shop are: [https://futonlove.com./en/delivery](https://futonlove.com./en/delivery).
17. In purpose to correctly perform the Distance Selling Agreement, the data controller may make the Customer/User data available to Internet payment systems. The currently available methods of payment in the form of prepayment in the Online Shop are: [ https://futonlove.com./en/payments](https://futonlove-com.iai-shop.com/en/payments).







11.07.2024

pixel