Introduction
JUST ONE Sp. z o.o. (hereinafter referred to as the "Service Provider" or "We") is committed to protecting and respecting your privacy. This Privacy Policy sets out the principles under which we process your personal data collected in connection with your use of our Website and Application. Please read the following carefully to understand what data we process, for what purpose, for how long, and what rights you have under Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
§ 1. Data Controller
The controller of your personal data is JUST ONE Sp. z o.o. You can contact the Controller directly via email at: contact@justonecard.pl.
§ 2. Scope of Policy
This Privacy Policy applies to your use of:
- justONECARD mobile application (hereinafter referred to as the Application),
- justONECARD website (hereinafter referred to as the Website),
- Services provided via the Website and Application (hereinafter referred to as the Services).
A. Information Provided by the User (Profile Data)
| Data Category | Purpose of Processing | Legal Basis (GDPR) |
|---|---|---|
| Mandatory Data First name, Last name, Email address, Password (hashed form) | Account registration, performance of the Service Agreement, enabling authentication and identification within the Partner network | Necessity for contract (Art. 6(1)(b) GDPR) |
| Optional Data Age, Gender | Personalization of Partner Offers, user experience optimization, statistical analysis | User Consent (Art. 6(1)(a) GDPR) |
| Social Login Data Google, Apple, Facebook | Enabling fast, convenient login and registration | Necessity for contract (Art. 6(1)(b) GDPR) |
B. Automatically Collected Data (Technical & Location Data)
| Data Category | Purpose of Processing | Legal Basis (GDPR) |
|---|---|---|
| Location (Geolocation) Precise data on the User's current location | Providing core Services (e.g. showing nearby Partners, automatic reward collection), direct marketing | User Consent (Art. 6(1)(a) GDPR) |
| Device Information Device type, unique ID, operating system, browser type, time zone | App optimization for the User's device, technical diagnostics, ensuring service security | Legitimate Interest (Art. 6(1)(f) GDPR) |
| Activity Information Time spent at Partners, reward collection history, offer usage, communication data | Account management, calculating & managing Rewards, monitoring service usage | Necessity for contract (Art. 6(1)(b) GDPR) |
§ 3. Restrictions and Revocation of Geolocation Consent
Collection of Location data occurs solely upon active consent granted by the User in their device's operating system (e.g. iOS, Android). The User has the right to withdraw consent to location sharing at any time by changing the settings on their Device. Revoking consent may result in the inability to access certain features of the Services that require the User's location.
§ 4. Partners
justONECARD remains the data controller of Users' personal data when using the Services.
Partners cooperating with justONECARD do not receive personal data of Users that would allow direct identification. In connection with cooperation with Partners, only anonymized statistical data and aggregated analyses may be shared, used specifically to evaluate loyalty program effectiveness, develop Offers, and analyze service usage.
Information provided to Partners does not allow for the identification of a specific User or linking data to a specific natural person.
§ 5. Other Data Recipients
Your personal data may be disclosed only to the following categories of recipients, where necessary to achieve the purposes specified in this Privacy Policy or required by applicable law:
- Payment Service Providers – to the extent necessary to process electronic payments,
- Advisors and Auditors – in the scope of legal, accounting, tax, and consulting services,
- Capital Group Entities – solely where necessary for the proper provision of Services or organizational and legal duties,
- Public Authorities and other authorized entities – where such obligation arises from legal provisions.
§ 6. Data Transfers Outside the EEA
Personal data may be transferred and stored outside the European Economic Area (EEA) only provided that an adequate level of protection required by the GDPR is ensured. Transfers are carried out based on Standard Contractual Clauses (SCC) approved by the European Commission.
§ 7. Data Retention Period
Users' personal data will be stored for the duration of the Service Agreement. Following termination of the Agreement, data may be retained for the period necessary to comply with legal obligations and equal to the statutory limitation period for claims (as a rule, up to 3 years).
§ 8. Cookies and Tracking Technologies
The Website and Application may use small files commonly known as "Cookies" and other tracking technologies. Cookies primarily serve to optimize Website performance, collect statistical data, and customize content to User preferences. Users may change Cookie settings in their browser at any time.
§ 9. Your Rights
In connection with the processing of your personal data, you are entitled to the following rights under GDPR:
Right of Access
Right to obtain information on what personal data we process and to receive a copy.
Right to Rectification
Right to request correction or completion of inaccurate or incomplete personal data.
Right to Erasure
"Right to be Forgotten" – requesting deletion of data when no longer needed for legal/contractual purposes.
Right to Restriction
Right to request suspension of processing of your personal data for a specified period.
Right to Object
Objection to processing based on Legitimate Interest or direct marketing activities.
Right to Data Portability
Receiving a copy of your data in a structured, commonly used, machine-readable format.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
§ 10. Lodging a Complaint with a Supervisory Authority
If you consider that the processing of your personal data violates the provisions of the GDPR, you have the right to lodge a complaint with a supervisory authority in Poland. The supervisory authority is the President of the Personal Data Protection Office (PUODO).
§ 11. Contact
Questions, comments, and requests regarding this Privacy Policy should be addressed via email to: contact@justonecard.pl.