Privacy Policy - Snomi
Version: 2.4
Effective date: 25 September 2026
Data Controller: Łukasz Stolarczyk, ul. Widok 31, 40-118 Katowice
Contact: hello@snomi.eu
1. General information
1.1. This Policy describes the rules for processing personal data by Łukasz Stolarczyk (Controller), who operates the Snomi Platform at panel.snomi.app and snomi.eu (marketing site; the Polish site is snomi.pl; snomi.app redirects to snomi.pl). The application name in Google Cloud Console is: Snomi.
1.2. Processing is carried out in accordance with the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council), the Polish Personal Data Protection Act and the Polish Act on the provision of services by electronic means.
1.3. Snomi directs its services to entities conducting business activity (B2B). Personal data concerns persons representing those entities and persons using the free audit.
1.4. This Policy also covers the optional Snomi integration with the Google Ads API (section 7). Cookie rules are set out in a separate Cookie Policy (snomi.eu/cookies).
2. Data Controller
Łukasz Stolarczyk, ul. Widok 31, 40-118 Katowice E-mail:
hello@snomi.euUnregistered business activity (Article 5 of the Polish Entrepreneurs Law)
3. What data we collect and for what purpose
3.1. Registration and account
An account may be created by providing an e-mail address and password, or by signing in with a Google account (OAuth). When signing in with Google, we receive basic profile data from Google: e-mail address, first and last name, and Google account identifier. We do not receive the Google account password.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| E-mail address | Login, identification, correspondence | Art. 6(1)(b) GDPR | Until account deletion + 30 days |
| First and last name | Personalisation, correspondence | Art. 6(1)(b) GDPR | Until account deletion + 30 days |
| Password (hash) | Authentication | Art. 6(1)(b) GDPR | Until account deletion |
| Google account identifier (when using Google sign-in) | Linking Google sign-in to the Account | Art. 6(1)(b) GDPR | Until Google sign-in is disconnected or the account is deleted |
| TOTP key (2FA, optional) | Two-factor authentication | Art. 6(1)(b) GDPR | Until 2FA is disabled or the account is deleted |
3.2. Billing data
Payments are processed by Stripe. The Controller does not store card numbers.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Stripe customer identifier | Subscription management | Art. 6(1)(b) GDPR | 5 years (tax obligation) |
| Transaction history | Settlements, sales documents | Art. 6(1)(c) GDPR | 5 years |
3.3. Product catalogue data
The User imports product data (main XML feed; optionally a supplemental CSV/TSV feed or Google Sheet). As a rule these are not personal data. If the feed contains personal data, the User is responsible for this and processing is governed by a data processing agreement (DPA).
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Catalogue data (products, feeds, descriptions) | Provision of the optimisation service | Art. 6(1)(b) GDPR | For the lifetime of the account; deletion on User request |
| AI model API keys (optional, encrypted) | Use of the User's own AI keys | Art. 6(1)(b) GDPR | Until deleted by the User |
3.4. AI generation history
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| AI operation metadata (user, store, field, time, credits) | Limit billing, history | Art. 6(1)(b) GDPR | 12 months |
AI-generated content is not stored in logs - it is saved only after acceptance by the User as catalogue data.
3.5. Communication and contact form
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| First name, e-mail, optionally company name, tax ID / NIP, phone, message content | Handling enquiries from the contact form, chat and e-mail; pre-contractual steps | Art. 6(1)(b) and (f) GDPR | 24 months from last contact |
3.6. Technical and security logs
To ensure security and proper operation of the Website, we maintain technical logs. Logs are redacted - they do not contain passwords, tokens, API keys or product content.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| HTTP request logs: IP address, user/organisation identifier, timestamp | Operations, diagnostics, security | Art. 6(1)(f) GDPR | File rotation approx. 30 days |
Authentication event audit (table AuditLog): e-mail address, IP, user and organisation identifiers, event type |
Security: detecting failed logins, role changes, access evidence | Art. 6(1)(f) GDPR | 12 months |
| Login lockout data (brute-force protection): IP address, attempt counters | Protection against unauthorised access | Art. 6(1)(f) GDPR | For as long as needed for protection; deleted after successful login or unlock |
Logs may be processed in a log analysis system (Elasticsearch) maintained in the Controller's infrastructure, for diagnostics and security. Access is limited to authorised persons operating the infrastructure.
3.7. Informational website and panel analytics
On snomi.eu pages and in the panel.snomi.app panel we use - only with the user's consent - Google Analytics 4 and Google Tag Manager to analyse traffic and measure registration effectiveness. We apply IP address anonymisation. Details, including consent and opt-out rules, are set out in the Cookie Policy (snomi.eu/cookies).
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Website usage data (anonymised IP, events, device) | Traffic analysis, website improvement, registration measurement | Art. 6(1)(a) GDPR (consent) | 14 months |
4. Feed data - Snomi's role
4.1. With regard to the User's product data, Snomi acts as a processor on behalf of the User (the controller of that data).
4.2. If the feed contains personal data, its processing is governed by a data processing agreement (DPA) - see Terms of Service §18.
5. Free audit
5.1. The free audit is ordered via the form at snomi.eu/free-audit. In the form we process: e-mail address, store URL, feed URL, optionally a phone number and optional description text ("what you want to improve in the feed"). We also record the sender's IP address and the date and content of consents given - to protect against abuse and to demonstrate consents.
5.2. The request is stored in the Controller's request database and forwarded to an internal support mailbox. We send a confirmation of receipt to the provided e-mail address, followed by the audit report.
5.3. Feed data (products from the file indicated in the request) is used to prepare the report. We do not create a permanent account or catalogue for the requesting person.
5.4. We process a phone number only if it was provided together with separate consent to telephone contact. We use the e-mail address for marketing purposes only on the basis of separate consent - until that consent is withdrawn.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| E-mail address, store URL, feed URL, description text | Preparation and sending of the audit report | Art. 6(1)(b) GDPR (pre-contractual steps) | 24 months from the request |
| Phone number (optional) | Telephone contact regarding the audit | Art. 6(1)(a) GDPR (consent) | Until consent is withdrawn, no longer than the period above |
| E-mail address (marketing) | Marketing materials | Art. 6(1)(a) GDPR (consent) | Until consent is withdrawn |
| IP address, consent timestamps | Protection against abuse, accountability of consents | Art. 6(1)(f) GDPR | Same as the request period |
6. AI model providers
6.1. To generate content we transmit necessary product data (titles, descriptions, attributes) to external AI model providers. Depending on configuration and available options, these may include OpenAI, Google (Gemini) or Anthropic.
6.2. The User may use their own API keys - in that case data is processed under the terms of their agreements with the relevant provider.
6.3. We transmit to AI providers only product catalogue data necessary for content generation - we do not transmit user authentication data or Google Ads access credentials. Data retrieved from the Google Ads API (section 7) and profile data from Google sign-in are also not sent to AI providers. To the extent a provider processes data outside the EEA, the mechanisms in section 9 apply.
7. Google Ads API integration (Google user data)
7.1. What this feature is. Snomi is an online SaaS available at panel.snomi.app for auditing and optimising product feeds. The User may optionally connect their Google Ads account to the Platform so that the Snomi panel can show product and campaign performance data alongside feed quality. The connection is not required for core features (import, editing, feed export).
7.2. Authorisation. Connection uses OAuth 2.0. Snomi does not ask for the Google account password and never receives it. The full scope of permissions is shown on the Google consent screen during authorisation. OAuth access and refresh tokens are stored in the Platform infrastructure in encrypted form and are used solely to maintain the connection to the User's account. Access to the infrastructure is limited to persons authorised by the Controller.
7.3. What Google Ads data we process. After consent, Snomi may obtain from Google Ads accounts to which the User has granted access, among other things:
- account structure and settings (campaigns, ad groups, ads, products / listing groups, keywords, exclusions, targeting settings, budgets),
- performance data (impressions, clicks, costs, conversions, conversion value and related product metrics),
- account identifiers needed to link the connection to the store in Snomi.
Depending on the permissions granted by the User, the application may also make changes on those accounts only upon the User's explicit request in the Snomi panel (e.g. actions related to feed and product campaign optimisation).
7.4. What we do not collect. Within the Google Ads API, Snomi does not collect: personal data of the advertiser's end customers, contact data from forms, e-mail content, audience lists, or remarketing data that would enable identification of specific individuals.
7.5. Purposes and legal bases. Google Ads data is used solely to provide and improve features visible in the Snomi interface: analysing product and campaign performance in the context of feed quality, diagnostics, preparing recommendations and reports and - when requested by the User - making changes on the connected account. We do not use this data for any other purpose, in particular:
- we do not sell it or share it with third parties for marketing purposes,
- we do not build marketing databases from it or profile natural persons,
- we do not use it to serve ads, for remarketing or interest-based advertising,
- we do not transfer it for training artificial intelligence models, nor do we send it to AI model providers (section 6),
- we do not use it to determine creditworthiness or for lending purposes,
- we do not sell it or transfer it to data brokers or other information resellers.
The legal basis is necessity for performance of the service agreement (Art. 6(1)(b) GDPR) and - for security and establishment of claims - the Controller's legitimate interest (Art. 6(1)(f) GDPR).
7.6. Storage. Retrieved Google Ads data is stored in the Platform infrastructure (servers and database in the EU, with safeguards described in sections 12-13): in query cache, linked to the User's store, and in reports generated at the User's request. Account data is made available to that User in the panel and in reports because it concerns their account. Data may also be disclosed to entities authorised by law.
7.7. Retention. We retain Google Ads data for as long as the account remains connected to the Platform (and for as long as needed to provide the related feature). After disconnecting the account or deleting the store / User account, we delete OAuth tokens and stored Google Ads data (subject to backups in section 13). Reports downloaded by the User remain at their disposal.
7.8. Revoking access. The User may disconnect the Google Ads account in the Snomi panel at any time. Independently, the Google account owner may revoke the application's access at https://myaccount.google.com/permissions. After access is revoked, Snomi can no longer retrieve data or make changes on that account.
7.9. Compliance with Google policies. The rules for using Google data (for the Google Ads integration and Google sign-in) are described in section 7a.
7a. Google user data - Limited Use
7a.1. This section applies to all data Snomi receives from Google APIs: profile data from Google sign-in (section 3.1) and data from the Google Ads API (section 7).
7a.2. Snomi's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7a.3. In particular, we use Google user data solely to provide and improve user-facing features in Snomi. We do not use it, or transfer it to others, for: serving ads (including personalised ads, retargeting or interest-based advertising), selling to data brokers or other information resellers, determining creditworthiness or lending purposes, or training generalised (non-personalised) artificial intelligence or machine learning models.
7a.4. Humans do not read this data unless: the User gives explicit consent (e.g. in a support request), it is necessary for security purposes (e.g. investigating abuse), it is required by law, or the data has been aggregated and anonymised for Platform operations.
7a.5. We notify Users about changes in how Google data is used in accordance with section 15, before they take effect.
8. Data recipients
| Provider | Role | Location |
|---|---|---|
| Stripe | Payment operator | USA (SCC) |
| Cloudflare | CDN, protection, network tunnel | USA/EU (SCC) |
| Cloudflare R2 | Storage of files and encrypted database backups | EU |
| OVH | Hosting of application servers and database | EU |
| Google (Google sign-in) | OAuth authentication - if the User chooses this method | USA (SCC) |
| Google (Google Ads API) | Access to the User's Google Ads account data after their OAuth consent | USA (SCC) |
| Google (GA4 / GTM) | Landing and panel analytics (incl. registration) - only with consent | USA (SCC) |
| Google (Gemini) | AI model | USA (SCC) |
| OpenAI | AI model | USA (SCC) |
| Anthropic | AI model | USA (SCC) |
| SMTP provider | System e-mail (confirmations, notifications, reports) | EU / USA (SCC) |
The log analysis system (Elasticsearch) is maintained in the Controller's infrastructure and is not a separate data recipient.
Personal data is not sold or shared with third parties for marketing purposes. We do not rent Google Ads API data or share it with an intermediary that would call Google on behalf of multiple parties outside providing the Snomi Service to that User.
9. Transfers of data outside the EEA
9.1. Some providers listed in section 8 are based in the USA. Transfers are based on Standard Contractual Clauses (SCC) approved by the European Commission or an adequacy decision.
9.2. Information on the safeguards applied may be obtained by contacting the Controller.
10. Rights of data subjects
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent at any time (without affecting the lawfulness of processing before withdrawal).
Account deletion results in deletion of account and catalogue data. Some data processed for security and compliance (authentication audit logs, IP lockout data) is retained for its retention period even after account deletion - on the basis of legitimate interest (security, establishment and defence of claims). After that period the data is deleted.
Data protection requests: hello@snomi.eu. We handle them within 30 days (with a possible extension of 60 days in justified cases).
You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa.
11. Profiling
We do not make automated decisions concerning Users that produce legal effects. Feed quality scoring relates to product data, not to persons.
12. Data security
We apply, among other measures: TLS encryption, password hashing (bcrypt), encryption of API keys, 2FA secrets and OAuth tokens (AES-256-GCM), role-based access control (OWNER/ADMIN/MEMBER/VIEWER), data isolation between organisations, redaction of sensitive data in logs, authentication event auditing, brute-force protection (IP lockout), optional two-factor authentication (2FA) and session token versioning.
13. Backups
We create encrypted database backups (GPG encryption, storage in Cloudflare R2 in the EU). Backups cover the entire database and are retained for 14 days, after which they are deleted. Data deleted from the application may remain in backups until those backups expire.
14. Cookies
The rules for using cookies are set out in a separate Cookie Policy (snomi.eu/cookies).
15. Changes to the Policy
We will notify you of material changes on the Website or by e-mail at least 14 days in advance. The current version is always available at https://snomi.eu/privacy-policy. For Google Cloud Console (Application privacy policy link) use the Polish canonical URL https://snomi.pl/polityka-prywatnosci. The effective date is shown in the header.
Łukasz Stolarczyk - Snomi, Katowice