Controller
The controller is Timur Timofeev, company ID 23929871, registered at Děčínská 552/1, 18000 Praha, Czechia, e-mail [email protected], phone +420725091764.
We process personal data under the GDPR and related Czech law.
Data we process
- Account and profile: e-mail, first and last name, display name, profile image, linked-provider identifier and, optionally, date of birth and gender.
- Account settings: communication preferences, saved billing and delivery addresses, session data and security-method metadata.
- Orders: contact details, phone, addresses, ordered goods, delivery, payment, order status and related accounting documents.
- Payment, delivery, invoicing, complaint, return and customer-support data.
- Technical and security data required for store operation, cart, sign-in, abuse prevention, language settings and cookie consent.
Google and Facebook sign-in
When you use social sign-in, the selected provider gives us an account identifier, the e-mail required to create an account and, when available, your first name, last name, display name and profile image.
We receive your date of birth and gender only if you explicitly allow Google or Facebook to provide them.
If you do not provide these optional details, they remain empty and you can add, change or clear them in your account at any time.
We use Google or Facebook data only to create and manage your account, prefill your profile and checkout, and secure sign-in. We do not use it for advertising, sell it or transfer it to data brokers.
Purposes and legal bases
- Creating and maintaining an account, sign-in, checkout prefilling and performing a contract or taking steps before entering one.
- Processing orders, payment, delivery, complaints and support, and meeting accounting, tax and other legal obligations.
- Securing the service, preventing fraud and protecting legal rights on the basis of our legitimate interests.
- Optional date of birth, gender, marketing and non-essential cookies are processed on the basis of consent where consent is required; it may be withdrawn at any time.
Retention
We keep profile data, saved addresses, preferences and social-account connection data while the account exists, until they are deleted or no longer needed.
Revoking access at Google or Facebook prevents future access, but does not by itself necessarily erase details already stored in your profile. You can edit or clear them in your account or request account deletion.
Communication is usually kept for up to 6 months after the last message. Order, accounting and tax data are kept as required by law, usually up to 10 years; legally required order records may remain after account deletion.
Recipients and transfers
- Hosting and technical-infrastructure providers.
- Google LLC or Meta Platforms, Inc. when you select social sign-in; they also process authentication under their own privacy terms.
- Payment providers, especially GoPay or the currently active provider.
- Carriers and logistics partners, especially Packeta/Zasilkovna.
- Accounting and invoicing services, especially Fakturoid, and e-mail providers.
- Public authorities where required by law. Some providers may process data outside the EEA using applicable safeguards under their terms.
Your choices and rights
- In your account you can correct your first and last name, date of birth and gender, clear optional values, and manage addresses and communication preferences.
- You can revoke Mystery Scoop access in your Google or Facebook account settings.
- You may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent where the statutory conditions apply.
- Send requests concerning your rights to [email protected]. You may complain to the Czech Office for Personal Data Protection.
Requesting data deletion
You can request deletion of your personal data or your entire customer account by e-mailing [email protected]. For security, we may reasonably verify your identity before completing the request.
After verification, we delete data that we no longer need or are not required to retain. Your account and access are permanently removed; order, accounting, tax or other records that must be retained by law or to protect legal claims remain stored with restricted use for the necessary period.
Security and final provisions
We use appropriate technical and organisational measures, access controls, secure transmission and audit records. No storage or transmission method can guarantee absolute security.
We have not appointed a data protection officer. We do not make decisions based solely on automated processing or perform profiling with effects under Article 22 GDPR. This policy is effective from 1 April 2026 and was last updated on 9 July 2026.