justONECARD icon
  • Pricing
  • Contact
  • FAQ
PL/EN
Get Started
Back to Home
GDPR & Privacy

Privacy Policy

justONECARD Website & Mobile Application

Introduction

JUST ONE Sp. z o.o. (hereinafter referred to as the "Service Provider" or "We") is committed to protecting and respecting your privacy. This Privacy Policy sets out the principles under which we process your personal data collected in connection with your use of our Website and Application. Please read the following carefully to understand what data we process, for what purpose, for how long, and what rights you have under Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

§ 1. Data Controller

The controller of your personal data is JUST ONE Sp. z o.o. You can contact the Controller directly via email at: contact@justonecard.pl.

§ 2. Scope of Policy

This Privacy Policy applies to your use of:

  • justONECARD mobile application (hereinafter referred to as the Application),
  • justONECARD website (hereinafter referred to as the Website),
  • Services provided via the Website and Application (hereinafter referred to as the Services).

A. Information Provided by the User (Profile Data)

Data CategoryPurpose of ProcessingLegal Basis (GDPR)
Mandatory Data

First name, Last name, Email address, Password (hashed form)

Account registration, performance of the Service Agreement, enabling authentication and identification within the Partner networkNecessity for contract
(Art. 6(1)(b) GDPR)
Optional Data

Age, Gender

Personalization of Partner Offers, user experience optimization, statistical analysisUser Consent
(Art. 6(1)(a) GDPR)
Social Login Data

Google, Apple, Facebook

Enabling fast, convenient login and registrationNecessity for contract
(Art. 6(1)(b) GDPR)

B. Automatically Collected Data (Technical & Location Data)

Data CategoryPurpose of ProcessingLegal Basis (GDPR)
Location (Geolocation)

Precise data on the User's current location

Providing core Services (e.g. showing nearby Partners, automatic reward collection), direct marketingUser Consent
(Art. 6(1)(a) GDPR)
Device Information

Device type, unique ID, operating system, browser type, time zone

App optimization for the User's device, technical diagnostics, ensuring service securityLegitimate Interest
(Art. 6(1)(f) GDPR)
Activity Information

Time spent at Partners, reward collection history, offer usage, communication data

Account management, calculating & managing Rewards, monitoring service usageNecessity for contract
(Art. 6(1)(b) GDPR)

§ 3. Restrictions and Revocation of Geolocation Consent

Collection of Location data occurs solely upon active consent granted by the User in their device's operating system (e.g. iOS, Android). The User has the right to withdraw consent to location sharing at any time by changing the settings on their Device. Revoking consent may result in the inability to access certain features of the Services that require the User's location.

§ 4. Partners

justONECARD remains the data controller of Users' personal data when using the Services.

Partners cooperating with justONECARD do not receive personal data of Users that would allow direct identification. In connection with cooperation with Partners, only anonymized statistical data and aggregated analyses may be shared, used specifically to evaluate loyalty program effectiveness, develop Offers, and analyze service usage.

Information provided to Partners does not allow for the identification of a specific User or linking data to a specific natural person.

§ 5. Other Data Recipients

Your personal data may be disclosed only to the following categories of recipients, where necessary to achieve the purposes specified in this Privacy Policy or required by applicable law:

  • Payment Service Providers – to the extent necessary to process electronic payments,
  • Advisors and Auditors – in the scope of legal, accounting, tax, and consulting services,
  • Capital Group Entities – solely where necessary for the proper provision of Services or organizational and legal duties,
  • Public Authorities and other authorized entities – where such obligation arises from legal provisions.

§ 6. Data Transfers Outside the EEA

Personal data may be transferred and stored outside the European Economic Area (EEA) only provided that an adequate level of protection required by the GDPR is ensured. Transfers are carried out based on Standard Contractual Clauses (SCC) approved by the European Commission.

§ 7. Data Retention Period

Users' personal data will be stored for the duration of the Service Agreement. Following termination of the Agreement, data may be retained for the period necessary to comply with legal obligations and equal to the statutory limitation period for claims (as a rule, up to 3 years).

§ 8. Cookies and Tracking Technologies

The Website and Application may use small files commonly known as "Cookies" and other tracking technologies. Cookies primarily serve to optimize Website performance, collect statistical data, and customize content to User preferences. Users may change Cookie settings in their browser at any time.

§ 9. Your Rights

In connection with the processing of your personal data, you are entitled to the following rights under GDPR:

👁️

Right of Access

Right to obtain information on what personal data we process and to receive a copy.

✏️

Right to Rectification

Right to request correction or completion of inaccurate or incomplete personal data.

🗑️

Right to Erasure

"Right to be Forgotten" – requesting deletion of data when no longer needed for legal/contractual purposes.

⏸️

Right to Restriction

Right to request suspension of processing of your personal data for a specified period.

✋

Right to Object

Objection to processing based on Legitimate Interest or direct marketing activities.

📦

Right to Data Portability

Receiving a copy of your data in a structured, commonly used, machine-readable format.

🔄

Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.

§ 10. Lodging a Complaint with a Supervisory Authority

If you consider that the processing of your personal data violates the provisions of the GDPR, you have the right to lodge a complaint with a supervisory authority in Poland. The supervisory authority is the President of the Personal Data Protection Office (PUODO).

§ 11. Contact

Questions, comments, and requests regarding this Privacy Policy should be addressed via email to: contact@justonecard.pl.

justONECARD

Simple loyalty for modern venues

Navigation

HomePricingContactFAQ

Legal

Privacy PolicyTerms & ConditionsStatus

Contact

Contact Formkontakt@justonecard.pl

JUST ONE Sp. z o.o.

© 2026 JUST ONE Sp. z o.o. All rights reserved.