Privacy Policy - Snomi
Version: 2.1
Effective date: 4 August 2026
Data Controller: Łukasz Stolarczyk, ul. Widok 31, 40-118 Katowice
Contact: hello@snomi.app
1. General information
1.1. This Policy describes the rules for processing personal data by Łukasz Stolarczyk (Controller), who operates the Snomi Platform at panel.snomi.app and snomi.eu (marketing site; the Polish site is snomi.pl; snomi.app redirects to snomi.pl).
1.2. Processing is carried out in accordance with the GDPR, the Polish Personal Data Protection Act and the Polish Act on the provision of services by electronic means.
1.3. Snomi directs its services to entities conducting business activity (B2B). Personal data concerns persons representing those entities and persons using the free audit.
2. Data Controller
Łukasz Stolarczyk, ul. Widok 31, 40-118 Katowice E-mail:
hello@snomi.appUnregistered business activity (Article 5 of the Polish Entrepreneurs Law)
3. What data we collect and for what purpose
3.1. Registration and account
An account may be created by providing an e-mail address and password, or by signing in with a Google account (OAuth). When signing in with Google, we receive basic profile data from Google: e-mail address, first and last name, and Google account identifier. We do not receive the Google account password.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| E-mail address | Login, identification, correspondence | Art. 6(1)(b) GDPR | Until account deletion + 30 days |
| First and last name | Personalisation, correspondence | Art. 6(1)(b) GDPR | Until account deletion + 30 days |
| Password (hash) | Authentication | Art. 6(1)(b) GDPR | Until account deletion |
| Google account identifier (when using Google sign-in) | Linking Google sign-in to the Account | Art. 6(1)(b) GDPR | Until Google sign-in is disconnected or the account is deleted |
| TOTP key (2FA, optional) | Two-factor authentication | Art. 6(1)(b) GDPR | Until 2FA is disabled or the account is deleted |
3.2. Billing data
Payments are processed by Stripe. The Controller does not store card numbers.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Stripe customer identifier | Subscription management | Art. 6(1)(b) GDPR | 5 years (tax obligation) |
| Transaction history | Settlements, sales documents | Art. 6(1)(c) GDPR | 5 years |
3.3. Product catalogue data
The User imports product data (main XML feed; optionally a supplemental CSV/TSV feed or Google Sheet). As a rule these are not personal data. If the feed contains personal data, the User is responsible for this and processing is governed by a data processing agreement (DPA).
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Catalogue data (products, feeds, descriptions) | Provision of the optimisation service | Art. 6(1)(b) GDPR | For the lifetime of the account; deletion on User request |
| AI model API keys (optional, encrypted) | Use of the User's own AI keys | Art. 6(1)(b) GDPR | Until deleted by the User |
3.4. AI generation history
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| AI operation metadata (user, store, field, time, credits) | Limit billing, history | Art. 6(1)(b) GDPR | 12 months |
AI-generated content is not stored in logs - it is saved only after acceptance by the User as catalogue data.
3.5. Communication and contact form
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| First name, e-mail, optionally company name, tax ID / NIP, phone, message content | Handling enquiries from the contact form, chat and e-mail; pre-contractual steps | Art. 6(1)(b) and (f) GDPR | 24 months from last contact |
3.6. Technical and security logs
To ensure security and proper operation of the Website, we maintain technical logs. Logs are redacted - they do not contain passwords, tokens, API keys or product content.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| HTTP request logs: IP address, user/organisation identifier, timestamp | Operations, diagnostics, security | Art. 6(1)(f) GDPR | File rotation approx. 30 days |
Authentication event audit (table AuditLog): e-mail address, IP, user and organisation identifiers, event type |
Security: detecting failed logins, role changes, access evidence | Art. 6(1)(f) GDPR | 12 months |
| Login lockout data (brute-force protection): IP address, attempt counters | Protection against unauthorised access | Art. 6(1)(f) GDPR | For as long as needed for protection; deleted after successful login or unlock |
Logs may be processed in a log analysis system (Elasticsearch) maintained in the Controller's infrastructure, for diagnostics and security. Access is limited to authorised persons operating the infrastructure.
3.7. Informational website analytics
On snomi.eu pages we use - only with the user's consent - Google Analytics 4 and Google Tag Manager to analyse traffic. We apply IP address anonymisation. The panel.snomi.app panel does not use analytics or marketing tools. Details, including consent and opt-out rules, are set out in the Cookie Policy (snomi.eu/cookies).
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Website usage data (anonymised IP, events, device) | Traffic analysis, website improvement | Art. 6(1)(a) GDPR (consent) | 14 months |
4. Feed data - Snomi's role
4.1. With regard to the User's product data, Snomi acts as a processor on behalf of the User (the controller of that data).
4.2. If the feed contains personal data, its processing is governed by a data processing agreement (DPA) - see Terms of Service §18.
5. Free audit
5.1. The free audit is ordered via the form at snomi.eu/free-audit. In the form we process: e-mail address, store URL, feed URL, optionally a phone number and optional description text ("what you want to improve in the feed"). We also record the sender's IP address and the date and content of consents given - to protect against abuse and to demonstrate consents.
5.2. The request is stored in the Controller's request database and forwarded to an internal support mailbox. We send a confirmation of receipt to the provided e-mail address, followed by the audit report.
5.3. Feed data (products from the file indicated in the request) is used to prepare the report. We do not create a permanent account or catalogue for the requesting person.
5.4. We process a phone number only if it was provided together with separate consent to telephone contact. We use the e-mail address for marketing purposes only on the basis of separate consent - until that consent is withdrawn.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| E-mail address, store URL, feed URL, description text | Preparation and sending of the audit report | Art. 6(1)(b) GDPR (pre-contractual steps) | 24 months from the request |
| Phone number (optional) | Telephone contact regarding the audit | Art. 6(1)(a) GDPR (consent) | Until consent is withdrawn, no longer than the period above |
| E-mail address (marketing) | Marketing materials | Art. 6(1)(a) GDPR (consent) | Until consent is withdrawn |
| IP address, consent timestamps | Protection against abuse, accountability of consents | Art. 6(1)(f) GDPR | Same as the request period |
6. AI model providers
6.1. To generate content we transmit necessary product data (titles, descriptions, attributes) to external AI model providers. Depending on configuration and available options, these may include OpenAI, Google (Gemini) or Anthropic.
6.2. The User may use their own API keys - in that case data is processed under the terms of their agreements with the relevant provider.
6.3. We transmit to AI providers only product catalogue data necessary for content generation - we do not transmit user authentication data. To the extent a provider processes data outside the EEA, the mechanisms in section 8 apply.
7. Data recipients
| Provider | Role | Location |
|---|---|---|
| Stripe | Payment operator | USA (SCC) |
| Cloudflare | CDN, protection, network tunnel | USA/EU (SCC) |
| Cloudflare R2 | Storage of files and encrypted database backups | EU |
| OVH | Hosting of application servers and database | EU |
| Google (Google sign-in) | OAuth authentication - if the User chooses this method | USA (SCC) |
| Google (GA4 / GTM) | Informational website analytics - only with consent | USA (SCC) |
| Google (Gemini) | AI model | USA (SCC) |
| OpenAI | AI model | USA (SCC) |
| Anthropic | AI model | USA (SCC) |
| SMTP provider | System e-mail (confirmations, notifications, reports) | EU / USA (SCC) |
The log analysis system (Elasticsearch) is maintained in the Controller's infrastructure and is not a separate data recipient.
Personal data is not sold or shared with third parties for marketing purposes.
8. Transfers of data outside the EEA
8.1. Some providers listed in section 7 are based in the USA. Transfers are based on Standard Contractual Clauses (SCC) approved by the European Commission or an adequacy decision.
8.2. Information on the safeguards applied may be obtained by contacting the Controller.
9. Rights of data subjects
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent at any time (without affecting the lawfulness of processing before withdrawal).
Account deletion results in deletion of account and catalogue data. Some data processed for security and compliance (authentication audit logs, IP lockout data) is retained for its retention period even after account deletion - on the basis of legitimate interest (security, establishment and defence of claims). After that period the data is deleted.
Requests: hello@snomi.app. We handle them within 30 days (with a possible extension of 60 days in justified cases).
You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa.
10. Profiling
We do not make automated decisions concerning Users that produce legal effects. Feed quality scoring relates to product data, not to persons.
11. Data security
We apply, among other measures: TLS encryption, password hashing (bcrypt), encryption of API keys and 2FA secrets (AES-256-GCM), role-based access control (OWNER/ADMIN/MEMBER/VIEWER), data isolation between organisations, redaction of sensitive data in logs, authentication event auditing, brute-force protection (IP lockout), optional two-factor authentication (2FA) and session token versioning.
12. Backups
We create encrypted database backups (GPG encryption, storage in Cloudflare R2 in the EU). Backups cover the entire database and are retained for 14 days, after which they are deleted. Data deleted from the application may remain in backups until those backups expire.
13. Cookies
The rules for using cookies are set out in a separate Cookie Policy (snomi.eu/cookies).
14. Changes to the Policy
We will notify you of material changes on the Website or by e-mail at least 14 days in advance. The current version is available at snomi.eu/privacy-policy.
Łukasz Stolarczyk - Snomi, Katowice