← Back to homepage

Privacy Policy - Snomi

Version: 2.1 Effective date: 4 August 2026 Data Controller: Łukasz Stolarczyk, ul. Widok 31, 40-118 Katowice Contact: hello@snomi.app


1. General information

1.1. This Policy describes the rules for processing personal data by Łukasz Stolarczyk (Controller), who operates the Snomi Platform at panel.snomi.app and snomi.eu (marketing site; the Polish site is snomi.pl; snomi.app redirects to snomi.pl).

1.2. Processing is carried out in accordance with the GDPR, the Polish Personal Data Protection Act and the Polish Act on the provision of services by electronic means.

1.3. Snomi directs its services to entities conducting business activity (B2B). Personal data concerns persons representing those entities and persons using the free audit.


2. Data Controller

Łukasz Stolarczyk, ul. Widok 31, 40-118 Katowice E-mail: hello@snomi.app Unregistered business activity (Article 5 of the Polish Entrepreneurs Law)


3. What data we collect and for what purpose

3.1. Registration and account

An account may be created by providing an e-mail address and password, or by signing in with a Google account (OAuth). When signing in with Google, we receive basic profile data from Google: e-mail address, first and last name, and Google account identifier. We do not receive the Google account password.

Data Purpose Legal basis Retention
E-mail address Login, identification, correspondence Art. 6(1)(b) GDPR Until account deletion + 30 days
First and last name Personalisation, correspondence Art. 6(1)(b) GDPR Until account deletion + 30 days
Password (hash) Authentication Art. 6(1)(b) GDPR Until account deletion
Google account identifier (when using Google sign-in) Linking Google sign-in to the Account Art. 6(1)(b) GDPR Until Google sign-in is disconnected or the account is deleted
TOTP key (2FA, optional) Two-factor authentication Art. 6(1)(b) GDPR Until 2FA is disabled or the account is deleted

3.2. Billing data

Payments are processed by Stripe. The Controller does not store card numbers.

Data Purpose Legal basis Retention
Stripe customer identifier Subscription management Art. 6(1)(b) GDPR 5 years (tax obligation)
Transaction history Settlements, sales documents Art. 6(1)(c) GDPR 5 years

3.3. Product catalogue data

The User imports product data (main XML feed; optionally a supplemental CSV/TSV feed or Google Sheet). As a rule these are not personal data. If the feed contains personal data, the User is responsible for this and processing is governed by a data processing agreement (DPA).

Data Purpose Legal basis Retention
Catalogue data (products, feeds, descriptions) Provision of the optimisation service Art. 6(1)(b) GDPR For the lifetime of the account; deletion on User request
AI model API keys (optional, encrypted) Use of the User's own AI keys Art. 6(1)(b) GDPR Until deleted by the User

3.4. AI generation history

Data Purpose Legal basis Retention
AI operation metadata (user, store, field, time, credits) Limit billing, history Art. 6(1)(b) GDPR 12 months

AI-generated content is not stored in logs - it is saved only after acceptance by the User as catalogue data.

3.5. Communication and contact form

Data Purpose Legal basis Retention
First name, e-mail, optionally company name, tax ID / NIP, phone, message content Handling enquiries from the contact form, chat and e-mail; pre-contractual steps Art. 6(1)(b) and (f) GDPR 24 months from last contact

3.6. Technical and security logs

To ensure security and proper operation of the Website, we maintain technical logs. Logs are redacted - they do not contain passwords, tokens, API keys or product content.

Data Purpose Legal basis Retention
HTTP request logs: IP address, user/organisation identifier, timestamp Operations, diagnostics, security Art. 6(1)(f) GDPR File rotation approx. 30 days
Authentication event audit (table AuditLog): e-mail address, IP, user and organisation identifiers, event type Security: detecting failed logins, role changes, access evidence Art. 6(1)(f) GDPR 12 months
Login lockout data (brute-force protection): IP address, attempt counters Protection against unauthorised access Art. 6(1)(f) GDPR For as long as needed for protection; deleted after successful login or unlock

Logs may be processed in a log analysis system (Elasticsearch) maintained in the Controller's infrastructure, for diagnostics and security. Access is limited to authorised persons operating the infrastructure.

3.7. Informational website analytics

On snomi.eu pages we use - only with the user's consent - Google Analytics 4 and Google Tag Manager to analyse traffic. We apply IP address anonymisation. The panel.snomi.app panel does not use analytics or marketing tools. Details, including consent and opt-out rules, are set out in the Cookie Policy (snomi.eu/cookies).

Data Purpose Legal basis Retention
Website usage data (anonymised IP, events, device) Traffic analysis, website improvement Art. 6(1)(a) GDPR (consent) 14 months

4. Feed data - Snomi's role

4.1. With regard to the User's product data, Snomi acts as a processor on behalf of the User (the controller of that data).

4.2. If the feed contains personal data, its processing is governed by a data processing agreement (DPA) - see Terms of Service §18.


5. Free audit

5.1. The free audit is ordered via the form at snomi.eu/free-audit. In the form we process: e-mail address, store URL, feed URL, optionally a phone number and optional description text ("what you want to improve in the feed"). We also record the sender's IP address and the date and content of consents given - to protect against abuse and to demonstrate consents.

5.2. The request is stored in the Controller's request database and forwarded to an internal support mailbox. We send a confirmation of receipt to the provided e-mail address, followed by the audit report.

5.3. Feed data (products from the file indicated in the request) is used to prepare the report. We do not create a permanent account or catalogue for the requesting person.

5.4. We process a phone number only if it was provided together with separate consent to telephone contact. We use the e-mail address for marketing purposes only on the basis of separate consent - until that consent is withdrawn.

Data Purpose Legal basis Retention
E-mail address, store URL, feed URL, description text Preparation and sending of the audit report Art. 6(1)(b) GDPR (pre-contractual steps) 24 months from the request
Phone number (optional) Telephone contact regarding the audit Art. 6(1)(a) GDPR (consent) Until consent is withdrawn, no longer than the period above
E-mail address (marketing) Marketing materials Art. 6(1)(a) GDPR (consent) Until consent is withdrawn
IP address, consent timestamps Protection against abuse, accountability of consents Art. 6(1)(f) GDPR Same as the request period

6. AI model providers

6.1. To generate content we transmit necessary product data (titles, descriptions, attributes) to external AI model providers. Depending on configuration and available options, these may include OpenAI, Google (Gemini) or Anthropic.

6.2. The User may use their own API keys - in that case data is processed under the terms of their agreements with the relevant provider.

6.3. We transmit to AI providers only product catalogue data necessary for content generation - we do not transmit user authentication data. To the extent a provider processes data outside the EEA, the mechanisms in section 8 apply.


7. Data recipients

Provider Role Location
Stripe Payment operator USA (SCC)
Cloudflare CDN, protection, network tunnel USA/EU (SCC)
Cloudflare R2 Storage of files and encrypted database backups EU
OVH Hosting of application servers and database EU
Google (Google sign-in) OAuth authentication - if the User chooses this method USA (SCC)
Google (GA4 / GTM) Informational website analytics - only with consent USA (SCC)
Google (Gemini) AI model USA (SCC)
OpenAI AI model USA (SCC)
Anthropic AI model USA (SCC)
SMTP provider System e-mail (confirmations, notifications, reports) EU / USA (SCC)

The log analysis system (Elasticsearch) is maintained in the Controller's infrastructure and is not a separate data recipient.

Personal data is not sold or shared with third parties for marketing purposes.


8. Transfers of data outside the EEA

8.1. Some providers listed in section 7 are based in the USA. Transfers are based on Standard Contractual Clauses (SCC) approved by the European Commission or an adequacy decision.

8.2. Information on the safeguards applied may be obtained by contacting the Controller.


9. Rights of data subjects

You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent at any time (without affecting the lawfulness of processing before withdrawal).

Account deletion results in deletion of account and catalogue data. Some data processed for security and compliance (authentication audit logs, IP lockout data) is retained for its retention period even after account deletion - on the basis of legitimate interest (security, establishment and defence of claims). After that period the data is deleted.

Requests: hello@snomi.app. We handle them within 30 days (with a possible extension of 60 days in justified cases).

You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa.


10. Profiling

We do not make automated decisions concerning Users that produce legal effects. Feed quality scoring relates to product data, not to persons.


11. Data security

We apply, among other measures: TLS encryption, password hashing (bcrypt), encryption of API keys and 2FA secrets (AES-256-GCM), role-based access control (OWNER/ADMIN/MEMBER/VIEWER), data isolation between organisations, redaction of sensitive data in logs, authentication event auditing, brute-force protection (IP lockout), optional two-factor authentication (2FA) and session token versioning.


12. Backups

We create encrypted database backups (GPG encryption, storage in Cloudflare R2 in the EU). Backups cover the entire database and are retained for 14 days, after which they are deleted. Data deleted from the application may remain in backups until those backups expire.


13. Cookies

The rules for using cookies are set out in a separate Cookie Policy (snomi.eu/cookies).


14. Changes to the Policy

We will notify you of material changes on the Website or by e-mail at least 14 days in advance. The current version is available at snomi.eu/privacy-policy.


Łukasz Stolarczyk - Snomi, Katowice