PRIVACY POLICY AND COOKIES POLICY
TRIPFLI
https://tripfli.com
I. THE OPERATOR
Maciej Ząbczyk AFFVANI
Giedlarowa 1143
37-300 Leżajsk, Poland (EU)
VAT number: 8161714654
REGON: 522738405
e-mail: help@tripfli.com
II. GENERAL INFORMATION
This document outlines the privacy principles applicable to the online service Tripfli – https://tripfli.com – regarding the collection, processing, and use of personal data obtained by the Data Controller.
Personal data is processed in accordance with Regulation (EU) 2016/679 (GDPR).
Pursuant to Article 4(7) of the GDPR, the Data Controller is Maciej Ząbczyk AFFVANI, Giedlarowa 1143, 37-300 Leżajsk, Poland (EU), VAT number: 8161714654, REGON: 522738405, e-mail: help@tripfli.com.
The Data Controller makes every effort to protect the privacy of website users.
III. PRINCIPLES OF PERSONAL DATA PROCESSING
Personal data is processed in accordance with Article 5 of the GDPR:
• Lawfully, fairly, and transparently
• For specified, legitimate purposes only
• Limited to what is necessary
• Accurate and up to date
• Stored no longer than necessary
• Secure and protected from unauthorized access
IV. THE PERSONAL DATA WE COLLECT AND USE
Your personal data is only used when one of the following conditions applies:
a) You have provided consent
b) It is necessary for a contract
c) There is a legal obligation
d) It protects vital interests
e) It serves the public interest
f) It is based on legitimate interestCategories of data processed:
o Identity data (first name, last name, date of birth, gender)
o Contact details (email, phone number)
o Passport details (passport number, issuing country, expiry date)
o Travel information (arrival date, purpose, length of stay)
o Device data (IP address, browser, device type, OS, logs)
o Payment details (not stored by us)
V. LEGAL BASIS FOR PROCESSING PERSONAL DATA
We process your personal data based on the following legal grounds:
o Art. 6(1)(a) GDPR – consent
o Art. 6(1)(b) GDPR – performance of a contract
o Art. 6(1)(c) GDPR – legal obligation
o Art. 6(1)(f) GDPR – legitimate interestThe primary basis is contract performance.
Data may also be processed:
o For legal compliance (e.g., tax/accounting)
o For legitimate interests (e.g., legal claims, statistics, marketing)
VI. DATA RETENTION PERIOD
Data is stored only as long as necessary for the purpose it was collected.
Data collected by consent is processed until consent is withdrawn.
Contract-related data is processed during the contract and limitation period under Polish Civil Code.
VII. DATA RECIPIENTS
Data recipients include:
o Employees, contractors, accountants, IT providers, payment processors, banks, marketing firms, telecoms, law firms, public authoritiesIf data is transferred outside the EEA, we ensure GDPR Chapter V safeguards (e.g., standard contractual clauses).
VIII. YOUR DATA RIGHTS
You have the right to:
• Access your data (Art. 15)
• Correct your data (Art. 16)
• Delete your data (“right to be forgotten” – Art. 17)
• Restrict processing (Art. 18)
• Data portability (Art. 20)
• Object to processing (Art. 21)
You may withdraw your consent at any time without affecting prior lawful processing.
You also have the right to lodge a complaint with the data protection authority (UODO in Poland).
IX. COOKIES POLICY
Cookies are used on the website.
Cookies are small files stored on your device to help the website function.
Cookies help remember preferences and improve functionality.
The cookies we use are safe and do not contain viruses.
Some cookies collect information that may qualify as personal data when combined with other identifiers.
Cookies help tailor content, including ads, to your preferences.
Types of Cookies by Duration:
• Session cookies – stored temporarily, deleted when browser is closed
• Persistent cookies – remain on your device until manually deleted
Types of Cookies by Purpose:
• Necessary – essential for website operation (processed under Art. 6(1)(f) GDPR)
• Statistical – help analyze user behavior (based on consent – Art. 6(1)(a))
• Marketing – personalize ads and campaigns (based on consent – Art. 6(1)(a))Cookies from third-party services (e.g., Google Ads, Stripe, Zoho) may also be used.
Users can manage cookie preferences in browser settings.
Restricting cookies may limit website functionality.
To manage cookies in your browser, refer to instructions from: Firefox, Chrome, Safari, Internet Explorer / Edge.
X. PROFILING AND AUTOMATED DECISION-MAKING
Your personal data may be subject to profiling for marketing and service improvement purposes.
Profiling involves automated processing of your data to evaluate certain personal aspects, such as interests or behavior on the website.
The result of profiling may be the personalization of displayed content, including offers and advertisements tailored to your preferences.
Profiling does not produce legal effects concerning you or similarly significantly affect you.
You have the right to object to profiling and automated decision-making at any time.
XI. CHANGES TO THIS POLICY
We reserve the right to update this policy as necessary. Updates will be published on our homepage.
This version is effective as of July 16, 2025.