This is a courtesy translation. In case of any discrepancy, the Polish version of this policy prevails.
We respect the privacy of everyone who uses Spacerent. Below we explain what data we collect, why, on what legal basis and how you can manage it. This document fulfils the information duty under art. 13 and 14 GDPR (Regulation (EU) 2016/679).
1. Data controller
The controller of your personal data is MADD Marcin Kisieliński, jednoosobowa działalność gospodarcza wpisana do CEIDG, ul. Kajki 10-12, Olsztyn, VAT ID 7422297084. Data protection contact: prywatnosc@madd.im.
2. What we process
- Account data - email address, first and last name, account type, optionally phone number, profile photo, company details (name, VAT ID, website) and bio.
- Listing data - listing text, photos, price, location (including the map pin coordinates) and the contact details you publish.
- Correspondence - messages sent through the contact form and the inbox, together with the details they contain (name, email, phone).
- Technical data - IP address, browser and system type, request date and time, stored in server logs; a session identifier in cookies.
- Payment data - amount, description and date of a purchase, its status and the identifiers issued by the payment provider; for invoices also the buyer's name, VAT ID and address. We never see your card number or CVC - those go straight to the payment provider.
- Company verification data - name, VAT ID, REGON/KRS and address, which we compare against the public register.
Providing data is voluntary but necessary for some features: no email address means no account, no listing content means no publication.
3. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Running the account and providing the Service | art. 6(1)(b) GDPR - performance of a contract | until the account is deleted |
| Publishing listings and connecting interested parties with advertisers | art. 6(1)(b) GDPR | until the listing or account is deleted |
| Handling messages from people without an account | art. 6(1)(f) GDPR - legitimate interest (enabling contact) | up to 24 months from the last message |
| Security, abuse detection, server logs | art. 6(1)(f) GDPR | up to 12 months |
| Handling complaints and defending against claims | art. 6(1)(c) and (f) GDPR | until the limitation periods expire |
| Providing and settling paid services | art. 6(1)(b) GDPR (contract) | for the duration of the service |
| Tax and accounting duties (proof of purchase, invoices) | art. 6(1)(c) GDPR with art. 74 of the Polish Accounting Act | 5 years from the end of the accounting year |
| Company verification (register check) | art. 6(1)(b) and (f) GDPR | while the verification is valid, plus one year |
4. Recipients
- The hosting provider running the Service (processor, under an art. 28 GDPR agreement).
- The outgoing mail provider handling notifications and password resets.
- Stripe Payments Europe, Ltd. (Dublin, Ireland) - the payment provider. We pass on the buyer's email address, the amount and the service description; card details go directly to Stripe. Stripe acts as a separate controller for fraud prevention and as a processor for handling the payment. Policy: stripe.com/privacy.
- inFakt sp. z o.o. (Kraków, Poland) - the invoicing system, acting as a processor under a data processing agreement (art. 28 GDPR). After every paid service we pass on the data needed to issue an invoice: the name or company name, billing address, VAT id (where given) and the email address inFakt sends the document to. Terms: infakt.pl/polityka-prywatnosci.
- The National e-Invoicing System (KSeF) run by the Polish Ministry of Finance - issued invoices are sent to KSeF where VAT law requires it. The basis is art. 6(1)(c) GDPR (legal obligation); the invoice data then becomes available to the National Revenue Administration.
- Our accountants and the tax authorities, for accounting documents.
- Other users - contact details published in a listing are visible to every visitor, and contact-form messages are delivered to the advertiser.
- Authorities entitled under the law, upon their request.
We do not sell data and we do not share it for marketing. We use no third-party analytics or advertising tools.
5. Transfers outside the EEA
Data is processed on servers within the EEA. Fonts, stylesheets and JavaScript libraries are served from our own domain, so your browser does not connect to third-party providers (such as Google Fonts) to render this site.
Payments. Stripe Payments Europe operates from Ireland but may transfer data within its group to the United States, under the European Commission's standard contractual clauses and the Data Privacy Framework.
The exception is map tiles fetched from OpenStreetMap Foundation servers when you open a map view - your IP address and the map area you are viewing reach OSM. This relies on art. 6(1)(f) GDPR (presenting the property location). OSM policy: osmfoundation.org.
6. Your rights
- access to your data and a copy of it (art. 15);
- rectification (art. 16) - account data can be edited in profile settings;
- erasure, the “right to be forgotten” (art. 17) - you can delete the account yourself;
- restriction of processing (art. 18);
- data portability (art. 20) - the dashboard exports all your data as JSON;
- objection to processing based on legitimate interest (art. 21);
- lodging a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland) or your local supervisory authority.
We handle requests without undue delay and within one month at the latest. Write to prywatnosc@madd.im.
7. Cookies and browser storage
We only use files that are strictly necessary for the Service to work. There are no analytics, marketing or profiling cookies, which is why we do not ask for consent - necessary cookies are exempt under the ePrivacy Directive.
| Name | Role | Lifetime |
|---|---|---|
sessionid | keeps you signed in | up to 2 weeks |
csrftoken | protects forms against CSRF | 1 year |
django_language | remembers the chosen language | 1 year |
theme (localStorage) | remembers light or dark mode | until you clear it |
cookie-notice (localStorage) | remembers that you dismissed the cookie notice | until you clear it |
You can block cookies in your browser settings - sign-in and forms will then stop working correctly.
8. Profiling and automated decisions
We make no decisions about you based solely on automated processing, including profiling, that would produce legal effects (art. 22 GDPR). Search results are sorted by the criteria you choose yourself.
9. Security
- All traffic runs over HTTPS (TLS) with HSTS enabled.
- Passwords are stored only as cryptographic hashes.
- Access to data is limited to authorised people, to the extent needed to run the Service.
- We keep regular backups of the database and uploaded files.
10. Changes to this policy
We update this policy when the law or the scope of processing changes. The current version is effective from 2026-07-30 and is always available at this address.