Privacy Policy
PRIVACY POLICY
Last updated: 21 August 2026
This Privacy Policy sets out the rules for processing the personal data of people using the Chako Lab online store, available at https://chakolab.shop (the “Store”), including visitors to the Store, people creating a customer account, placing orders, signing up for the newsletter, using product availability notifications and contacting us.
We care about our users’ privacy and process personal data in accordance with applicable law, in particular:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”);
- the Act of 10 May 2018 on the Protection of Personal Data;
- the Act of 12 July 2024 – Electronic Communications Law (the “PKE”).
1. Personal data controller
The controller of personal data is:
BEAUTEX SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
ul. Prezydenta Gabriela Narutowicza 51/11
90-130 Łódź, Poland
NIP: 7252335784
REGON: 526482227
KRS: 0001060943
Tel.: +48 790 382 334
E-mail: contact@chakolab.shop
hereinafter referred to as the “Controller”, “we” or “Chako Lab”.
For matters concerning the protection of personal data, this Privacy Policy or the exercise of rights under the GDPR, you can contact us at:
or in writing to the Controller’s registered address.
2. What personal data we process
The scope of the data processed depends on how the Store is used.
We may process in particular:
- first name and surname;
- e-mail address;
- telephone number;
- delivery address;
- invoice address;
- company name, NIP and other company details, if needed to issue an invoice;
- data relating to the order and the products purchased;
- order history;
- information about the delivery method selected;
- information about the payment and the payment status;
- data related to the customer account;
- data provided when signing up for the newsletter;
- data provided when signing up for a product availability notification;
- the content of correspondence conducted with us;
- data provided via the forms available in the Store;
- IP address;
- information about the device, browser and operating system;
- online identifiers;
- data on how the Store is used;
- data recorded by means of cookies and similar technologies;
- other data provided to us voluntarily by the user.
As a rule, we do not receive or store the user’s full payment card details. The data necessary to process the payment is handled by the payment service providers.
3. Purposes and legal bases for processing data
3.1. Placing and processing orders
We process personal data in order to:
- accept the order;
- confirm the order;
- conclude and perform the sales contract;
- prepare the order;
- process the payment;
- arrange delivery;
- communicate about the order;
- handle a return or other activities directly related to performing the contract.
The legal basis for processing is Article 6(1)(b) GDPR – processing necessary for the conclusion or performance of a contract.
Providing the data required when placing an order is voluntary but necessary in order to process it.
3.2. Payments
Payments in the Store are handled via Shopify Payments and the payment methods available and activated within that service.
Depending on the options available, these may include in particular card payments, accelerated payment methods and local payment methods.
The data necessary to carry out the transaction may be transferred to Shopify, payment service providers, banks, card organisations and other entities involved in processing the selected payment method.
The data may be processed, among other purposes, in order to:
- process the payment;
- confirm the transaction status;
- handle refunds;
- prevent fraud;
- ensure transaction security;
- fulfil obligations arising from the law on payment services and the prevention of abuse.
The basis for processing on the Controller’s side is, depending on the situation:
- Article 6(1)(b) GDPR – performance of a contract;
- Article 6(1)(c) GDPR – legal obligation;
- Article 6(1)(f) GDPR – the Controller’s legitimate interest in ensuring transaction security and preventing abuse.
Some payment service providers may process data as separate controllers in accordance with their own legal obligations and privacy policies.
3.3. Delivery of orders
In order to complete the delivery, we transfer the data necessary to deliver the parcel to the logistics operator.
The Store uses in particular the services of InPost.
Depending on the delivery method selected, the following may be transferred, among others:
- first name and surname;
- telephone number;
- e-mail address;
- delivery address;
- details of the selected Paczkomat or pick-up point;
- other information necessary for the correct delivery of the parcel.
The legal basis is Article 6(1)(b) GDPR – performance of the contract concluded with the customer.
3.4. Customer account
The Store makes it possible to create a customer account.
We process data related to the account in order to:
- create and maintain the account;
- enable logging in;
- provide access to account functionalities;
- present information related to orders;
- make using the Store easier.
The legal basis is Article 6(1)(b) GDPR – provision of the account service.
The user may cancel the account in accordance with the functionalities available in the Store or by contacting us at contact@chakolab.shop.
Deleting the account does not mean the automatic deletion of all data related to previous orders, where further storage of that data is required by law or necessary to establish, pursue or defend claims.
3.5. Invoices, accounting and legal obligations
We also process transaction data in order to fulfil accounting and tax obligations and other obligations arising from the law.
The legal basis is Article 6(1)(c) GDPR – compliance with a legal obligation to which the Controller is subject.
3.6. Returns, complaints and after-sales service
Personal data may be processed in order to:
- handle returns;
- examine complaints;
- give effect to consumer rights;
- handle the seller’s liability for the conformity of the goods with the contract;
- handle any guarantee;
- conduct communication concerning the products purchased.
The legal basis is, depending on the situation:
- Article 6(1)(b) GDPR;
- Article 6(1)(c) GDPR;
- Article 6(1)(f) GDPR.
3.7. Contacting us
If a user contacts us by e-mail, telephone, the contact form or another available channel, we process the data they provide in order to conduct correspondence and respond.
If the contact concerns the conclusion or performance of a contract, the basis for processing is Article 6(1)(b) GDPR.
In other cases, the basis is our legitimate interest in conducting communication and handling enquiries – Article 6(1)(f) GDPR.
3.8. Newsletter and marketing communication
The user may voluntarily sign up for the Chako Lab newsletter.
For this purpose we may process in particular:
- e-mail address;
- information about the newsletter sign-up;
- technical information necessary to demonstrate the consent given;
- information about unsubscribing from the newsletter.
The newsletter may contain, among other things:
- information about new products;
- information about product availability;
- promotions and offers;
- information about Chako Lab;
- marketing and commercial content.
The basis for processing data in connection with the newsletter sign-up is Article 6(1)(a) GDPR – the user’s consent.
Commercial information and direct marketing are sent by e-mail on the basis of the user’s prior consent in accordance with Article 398 of the Electronic Communications Law.
Signing up for the newsletter is voluntary.
The user may unsubscribe from the newsletter at any time:
- via the unsubscribe link in the message;
- by contacting us at contact@chakolab.shop.
Withdrawing consent is as easy as giving it and does not affect the lawfulness of processing carried out before it was withdrawn.
3.9. Product availability notification
The Store makes it possible to sign up for a “Notify me when the product is available” notification.
If the user uses this function, their contact details will be processed in order to send the requested notification about a specific product becoming available again.
The legal basis is Article 6(1)(b) GDPR – performance of the service requested by the user.
Data provided solely in order to receive a product availability notification will not be used to send the newsletter or other marketing content, unless the user separately consents to this.
3.10. Store security and prevention of abuse
Technical data, data on user activity and information related to transactions may be processed in order to:
- ensure the security of the Store;
- protect customer accounts;
- detect and prevent fraud;
- counteract abuse;
- protect IT systems;
- protect the rights of the Controller and of customers.
The legal basis is Article 6(1)(f) GDPR – the Controller’s legitimate interest.
3.11. Establishing, pursuing and defending claims
Data may be stored and used where this is necessary to establish, pursue or defend against claims.
The legal basis is Article 6(1)(f) GDPR – the Controller’s legitimate interest in protecting its rights.
4. Shopify
The Chako Lab store runs on the Shopify platform.
In connection with the use of Shopify, users’ data may be processed by Shopify and by entities providing services to Shopify, to the extent necessary to ensure the operation of the Store.
This may include in particular:
- displaying the Store;
- operation of the basket;
- maintaining customer accounts;
- carrying out the purchase process;
- storing information related to orders;
- handling payments;
- ensuring security;
- preventing fraud;
- operating the technical infrastructure;
- the correct operation of the Shopify functions used by the Store.
In connection with this, Shopify may process, among other things:
- identification data;
- contact details;
- information about orders;
- IP address;
- data relating to the device and browser;
- online identifiers;
- data on the use of the Store.
With regard to the data of customers from the European Economic Area, Shopify’s services are provided in particular by Shopify International Limited, established in Ireland.
Shopify may also use affiliated entities and sub-processors that process data in accordance with the rules set by Shopify.
Detailed information on how Shopify processes data can be found in the current privacy documents made available by Shopify.
5. Recipients of personal data
Personal data may be transferred to entities whose services are necessary to operate the Store.
These may include in particular:
- Shopify International Limited and other entities belonging to the Shopify group;
- entities processing data on behalf of Shopify;
- Shopify Payments providers;
- banks and financial institutions;
- payment card organisations;
- providers of the selected payment methods;
- InPost and other logistics operators, if used to complete the delivery;
- hosting and IT infrastructure providers;
- e-mail service providers;
- providers of newsletter tools;
- providers of applications and integrations used in the Store;
- providers of services relating to customer accounts and product availability notifications;
- the accounting office;
- accountants;
- tax advisers;
- law firms;
- other professional advisers;
- public authorities, courts and other authorised entities, where the obligation to disclose data arises from the law.
Entities processing data on our instructions process it solely to the extent resulting from the agreements concluded and the instructions given.
Some entities, in particular payment service providers, banks or logistics operators, may act as separate data controllers to a certain extent.
6. Transfers of data outside the European Economic Area
Because we use global technology providers, in particular Shopify and entities cooperating with Shopify, certain personal data may be processed outside the European Economic Area (the “EEA”).
Where data is transferred to a country outside the EEA, this takes place in accordance with the requirements of the GDPR, in particular on the basis of:
- a European Commission decision confirming an adequate level of data protection;
- standard contractual clauses approved by the European Commission;
- other data transfer mechanisms permitted by the GDPR.
Where a service provider uses other lawful transfer mechanisms, the rules specified by that service provider and the applicable law apply.
7. Data retention period
We store personal data for no longer than is necessary to achieve the purpose for which it was collected, taking into account the Controller’s legal obligations.
In particular:
Data related to orders
– for the time necessary to perform the contract and then for the period arising from tax and accounting regulations and the limitation period for any claims.
Accounting and tax documentation
– for the period required by applicable law.
Data related to complaints and returns
– until the given case is closed and then for the relevant limitation period for claims.
Data related to the customer account
– for the period the account is maintained and then for the period necessary to settle any claims or fulfil legal obligations.
Newsletter data
– until consent is withdrawn or the newsletter is unsubscribed from, with the possibility of continuing to store limited information necessary to demonstrate that consent was given or withdrawn.
Data relating to product availability notifications
– for the period necessary to deliver the requested notification and then for the period technically necessary to close that service.
Data processed on the basis of a legitimate interest
– until that interest ceases or an effective objection is raised, unless there are overriding legitimate grounds for further processing.
Data processed on the basis of consent
– until it is withdrawn, unless there is another legal basis for further processing of the data.
8. User rights
Depending on the basis and nature of the processing, the data subject has the rights set out in the GDPR, in particular:
- the right of access to data;
- the right to receive a copy of the data;
- the right to rectification of data;
- the right to erasure of data;
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing;
- the right to withdraw consent;
- the right to lodge a complaint with the supervisory authority.
To exercise these rights, you can contact us at:
In cases justified by the need to protect data, we may ask for additional information enabling us to confirm the identity of the person making the request.
Right to object
Where data is processed on the basis of Article 6(1)(f) GDPR, the user may object to such processing on grounds relating to their particular situation.
Where data is processed for direct marketing purposes, the user has the right to object to such processing at any time.
Withdrawal of consent
Where processing takes place on the basis of consent, the user may withdraw it at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before it was withdrawn.
9. Right to lodge a complaint
If a user believes that their data is being processed in breach of the law, they have the right to lodge a complaint with:
the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO)
in accordance with the rules laid down in applicable law.
10. Provision of data is voluntary
Providing personal data is, as a rule, voluntary.
However, when using certain services, providing some data may be necessary in order to:
- place and process an order;
- make a payment;
- deliver the parcel;
- issue an invoice;
- maintain a customer account;
- examine a complaint;
- receive a reply to an enquiry;
- receive a product availability notification.
Failure to provide the required data may make it impossible to perform the given service.
Signing up for the newsletter is entirely voluntary and is not a condition for making a purchase.
11. Automated decision-making and profiling
As a rule, the Controller does not take decisions in relation to users based solely on automated processing of data that would produce legal effects concerning them or similarly significantly affect them.
Certain technologies provided by Shopify, or other tools used in the future, may serve to analyse user activity, ensure security, detect fraud, personalise content or carry out marketing activities.
Where the use of a given technology requires the user’s consent, it will only be activated after the appropriate consent has been obtained in accordance with applicable law.
12. Cookies and similar technologies
The Store uses cookies and similar technologies.
Cookies are small pieces of information saved on or read from the user’s device while using a website.
Cookies may be used in particular in order to:
- ensure the correct operation of the Store;
- operate the basket;
- handle the purchase process;
- maintain the user’s session;
- operate the customer account;
- remember certain settings;
- ensure security;
- prevent fraud;
- ensure the functioning of the Shopify infrastructure;
- carry out analytics or statistics, where applicable;
- carry out marketing activities, if the user gives the appropriate consent and such tools are implemented.
12.1. Necessary cookies
Some cookies and similar technologies are necessary for the correct operation of the Store or for the provision of a service expressly requested by the user.
They may serve, among other things, to:
- operate the basket;
- process the order;
- log in to the account;
- ensure security;
- prevent fraud;
- maintain the session;
- provide the basic functions of the Store.
In the cases provided for in Article 399(3) of the Electronic Communications Law, the use of such technologies does not require the user’s consent.
12.2. Optional cookies
Cookies and similar technologies that are not necessary for the correct operation of the Store may be used only after obtaining the required consent of the user.
This applies in particular to technologies used for:
- analytics;
- additional statistics;
- personalisation;
- advertising;
- remarketing;
- measuring the effectiveness of marketing campaigns.
In accordance with Article 399 of the Electronic Communications Law, before they are used the user should receive clear information and the opportunity to give consent.
12.3. Managing consents
If the Store uses cookies that require consent, the user may make their choice via the banner or the privacy settings panel available in the Store.
The user should be able to:
- accept optional cookies;
- reject optional cookies;
- manage individual cookie categories;
- change their decision later.
Withdrawal of consent does not affect the lawfulness of actions carried out before it was withdrawn.
The user may also manage cookies via their browser settings; however, disabling necessary cookies may mean that some functionalities of the Store do not work correctly.
13. Analytics and marketing tools
As at the date of the last update of this Policy, the Store does not use Google Analytics / GA4 or external advertising pixels such as Meta Pixel or TikTok Pixel.
The Store may use the basic technical, statistical, security and order-handling functions available within the Shopify platform.
If in the future we implement additional analytics or marketing tools, in particular:
- Meta Pixel;
- TikTok Pixel;
- Google Ads;
- Google Analytics;
- other advertising, analytics or remarketing systems,
this Privacy Policy will be updated accordingly.
Technologies requiring the user’s consent should not be activated before such consent has been obtained via the cookie management mechanism.
14. Newsletter and marketing cookies
Consent to receive the newsletter is separate from consent to marketing or analytics cookies.
This means that:
- the user may sign up for the newsletter without consenting to marketing cookies;
- consent to marketing cookies does not mean automatic sign-up for the newsletter;
- each of these consents may be withdrawn separately.
15. Data security
We apply appropriate technical and organisational measures intended to protect personal data, proportionate to the nature, scope and risk of the processing.
These measures are intended in particular to protect data against:
- unauthorised access;
- unauthorised disclosure;
- loss;
- alteration;
- destruction;
- accidental or unlawful processing.
We also use the safeguards provided by our technology infrastructure providers, including Shopify and the payment service providers.
16. Links to external websites and services
The Store may contain links to websites, social media platforms or services of third parties.
Once you go to such a website, your data may be processed by its operator in accordance with that operator’s own privacy policy.
The Controller is not responsible for the data processing practices of independent controllers of external websites.
17. Changes to the Privacy Policy
This Privacy Policy may be updated from time to time, in particular in the event of:
- a change in the law;
- a change in the way the Store operates;
- the implementation of new functionalities;
- a change of service providers;
- the implementation of new payment methods;
- the implementation of new analytics or marketing tools;
- a change in the way data is processed.
The current version of the Privacy Policy will be available at https://chakolab.shop.
The date of the last update is indicated at the beginning of the document.
18. Contact
If you have any questions about this Privacy Policy, the protection of personal data or the exercise of rights under the GDPR, please contact:
BEAUTEX SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
ul. Prezydenta Gabriela Narutowicza 51/11
90-130 Łódź, Poland
NIP: 7252335784
KRS: 0001060943
REGON: 526482227
E-mail: contact@chakolab.shop
Tel.: +48 790 382 334