Back to Uselist · PL/en

Operator (Imprint): Roman Usov · Enskild firma (sole proprietorship) registered in Sweden · Postal address: [to be filled before public launch — see TASK-0177] · Personnummer / Org. nr: [to be filled] · VAT (where applicable): [OSS registration via Skatteverket] · Email: [email protected]

Privacy Policy · Poland

Effective date: 2026-05-10 · Jurisdiction: Poland (PL)

1. Controller

The data controller is Roman Usov, a sole proprietorship (enskild firma) registered in Sweden, operating Uselist. Contact: [email protected].

Under GDPR Article 37 we are not required to designate a Data Protection Officer. Privacy questions are handled directly by the controller.

2. What we process and why

DataPurposeLawful basis
Telegram ID, name, optional photo URLAccount identification, login via Telegram Login WidgetContract (GDPR Art. 6(1)(b))
Email (optional)Billing, support communicationsContract
Item descriptions, photos, pricesInventory storageContract
Card detailsPayment processing — handled directly by StripeContract
Country, language, planLocalization, marketplace selection, plan-based feature gatingContract
IP address (hashed for signup), browser fingerprintAnti-abuse, fraud prevention, rate limitingLegitimate interest (GDPR Art. 6(1)(f))
Product analytics eventsUnderstand feature usage to improve the ServiceConsent (GDPR Art. 6(1)(a)) — opt-in via cookie banner

3. Sub-processors

ProcessorRoleRegion
Cloudflare, Inc.CDN, WAF, DNSEU edge
Stripe Payments Europe, Ltd.Payment processingIreland (EU)
Telegram Messenger LLPBot platform, Login WidgetMulti-region
Google Ireland Ltd. (Gemini)AI inferenceEU + US
PostHog Inc. (Cloud EU)Product analytics — opt-in onlyEU (Frankfurt + Helsinki)
Hetzner Online GmbHServer hostingFinland / Germany (EU)
Cloudflare R2Photo storageEU

4. Cross-border transfers

Most processing happens in the EU/EEA. Telegram (multi-region) and Google (US fallback regions) may transfer data outside the EEA. Such transfers rely on Standard Contractual Clauses (Commission Decision (EU) 2021/914) and the EU-U.S. Data Privacy Framework where applicable.

5. Retention

6. Your rights (GDPR Articles 15–22)

7. Cookies and similar technologies

Strictly necessary cookies are set without consent. Analytics cookies (PostHog) are set only after explicit acceptance via the cookie banner; consent can be withdrawn via Settings → Privacy.

8. Security

TLS for all traffic; secrets encrypted at rest; no plaintext passwords; API tokens rotate. We notify affected users and the supervisory authority of personal-data breaches likely to result in risk per GDPR Articles 33–34.

9. Right to lodge a complaint

You may lodge a complaint with the Polish supervisory authority for personal data:

Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
[email protected] · +48 22 531 03 00 · uodo.gov.pl

You may also contact the supervisory authority of your habitual residence or place of work in any EU member state.

10. Changes

We may update this Privacy Policy. Material changes affecting your data will be communicated by email or in-app at least 30 days before they take effect.

11. Contact

Privacy questions, data subject requests, security disclosures: [email protected].