Toolero Privacy Policy
Last updated: July 15, 2026
This Privacy Policy describes how personal data is processed in the Toolero service.
1. Data Controller
The data controller is Devmade Michał Piotrowicz, ul. Malwowa 21/2, 62-051 Wiry, Poland, NIP: 5993150077, REGON: 381527338, email: kontakt@toolero.pl (hereinafter: "Controller"). The Controller has not appointed a Data Protection Officer.
2. Data Collected
We collect the following data:
- Registration data: first name, last name, email, company name
- Social login data: when logging in via Google or Apple - first name, last name, email address and account identifier provided by the provider (Art. 14 GDPR)
- Usage data: activity logs, rental information
- Technical data: IP address, browser type, cookies
- Marketing page analytics: anonymous session and visitor identifiers, pages visited, scroll depth, CTA button clicks, traffic source (referrer, UTM parameters), device type. This data is collected only on marketing pages (outside the application panel) and is used to analyze website effectiveness. Until registration, data is fully anonymous - not linked to any natural person.
- Meta Pixel (Facebook): on marketing pages we use Meta Pixel to measure the effectiveness of advertising campaigns on the Meta platform (Facebook, Instagram). The pixel collects anonymous visit data (page views) and enables creation of advertising audiences. The pixel is loaded only after accepting analytics cookies and does not operate in the application panel.
- Data from a started registration: if you enter your email in the first step of account creation, we store the address itself - also if you do not complete the registration. At that stage the address is not linked to the analytics data described above; the link is created only once an account exists. If you tick marketing consent, we additionally store the date and IP address of that consent in order to demonstrate it was given (Art. 7(1) GDPR).
3. Purpose of Processing
We process data for:
- Service provision (Art. 6(1)(b) GDPR)
- Legal obligations (Art. 6(1)(c) GDPR)
- Marketing of own services - commercial information (tips, product news) is sent to your email address only with your prior consent (Art. 6(1)(a) GDPR in conjunction with Art. 10 of the Polish Act on Providing Services by Electronic Means). You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing before it (Art. 7(3) GDPR).
- Contacting you about a started but unfinished registration - if you enter your email in the first step of account creation and do not complete the process, we may send a reminder with a link to finish it. The basis is steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR). This message is purely transactional and contains no advertising - we send those only after you give the consent referred to in point 3.
- Marketing website traffic analysis to improve the service (Art. 6(1)(f) GDPR - legitimate interest)
- Sending structured invoices to the National e-Invoice System (KSeF) on behalf of the User (Art. 6(1)(b) GDPR)
- We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
4. Your Rights
You have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time (Art. 7(3) GDPR)
5. Data Retention
We retain data:
- Account data: for duration of Service + 30 days
- Billing data: 5 years (legal requirement)
- Logs: according to selected plan (1-5 years)
- Email address from a started but unfinished registration: 90 days, after which we delete it if no account was created
- Data of people who gave marketing consent (together with the consent record): until consent is withdrawn or an objection is raised
6. Data Sharing
Data may be shared with:
- OVH (hosting, file storage) - EU/EEA
- Google Ireland Limited (email, analytics, Google account login) - EU/EEA
- Meta Platforms Ireland Limited (Meta Pixel - advertising campaign analytics, marketing pages only, after cookie consent) - EU/EEA
- Payment providers
- Government authorities as required by law
Data may be transferred outside the European Economic Area (EEA) in connection with infrastructure service providers (e.g. hosting, cloud services). Transfers are based on Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) or adequacy decisions (Art. 45 GDPR).
7. Security
We implement appropriate technical and organizational measures:
- SSL/TLS encryption
- Secure password hashing
- Regular backups
- Access control
8. Contact
For data protection matters contact: kontakt@toolero.pl
You have the right to lodge a complaint with supervisory authority.