Item Hounter

Privacy Policy

Last updated: August 21, 2026

This policy covers the lowca-okazji.com website and the Łowca mobile app (published as Item Hounter) for Android and iOS. It is one service with one controller — the data, purposes and legal bases below apply to both, and what is specific to the phone is in section 4.

In short: we need your email address to send alerts, and the content of your watches to know what to look for. We do not sell data and do not profile you for advertising. The website runs ad measurement tools from Meta and Google — but only once you click “Accept” in the consent banner. If you click “Reject”, we do not start them at all. Details in section 10.

1. Who is the controller

The controller of your personal data within the meaning of the GDPR (Regulation 2016/679) is:

Damian Jabłoński tribe
ul. Modlińska 61/106, 03-199 Warszawa, Poland
Tax ID (NIP): 5243008010 · Company ID (REGON): 528741561
Contact: team@lowca-okazji.com, phone +48 606 904 443

We have not appointed a data protection officer — for all matters regarding personal data, write to the address above.

2. What data we process and why

DataPurposeLegal basis
Email address, encrypted password Creating and managing the account, logging in Art. 6(1)(b) GDPR — performance of the service agreement
Watch content (what you're looking for), chosen condition and frequency Searching for listings and preparing alerts Art. 6(1)(b) GDPR — performance of the agreement
Google sign-in data (email address, Google account identifier and — if you share them — your name and profile picture), only if you choose “Sign in with Google” Creating the account and signing in without a separate password Art. 6(1)(b) GDPR — performance of the agreement
Push notification token issued by Firebase Cloud Messaging (an identifier of the app installation on your device) and the platform: “android” or “ios” Delivering an alert as a notification on your phone Art. 6(1)(b) GDPR — performance of the agreement
History of sent alerts So you don't get the same listing twice Art. 6(1)(b) GDPR — performance of the agreement
Purchase history (pack, amount, status, payment session identifier) and points balance Settling the purchase, crediting points, purchase history visible on your account Art. 6(1)(b) GDPR — performance of the agreement; Art. 6(1)(c) GDPR — accounting and tax obligations
App usage events: opening its main screens (watch list, advisor chat, found offers, points-pack screen) and the confirming taps — creating a watch and, on the website, since the mobile app does not sell points, tapping “Buy” — with the account identifier, pack name (purchases only) and timestamp Seeing which step — from opening the app to a purchase — people drop out at. These are our own counters, written to our own database — we only ever read them in aggregate, never per person. We use no Google Analytics and no third-party analytics of any kind Art. 6(1)(f) GDPR — legitimate interest: improving the service
Technical logs (IP address, time, errors) Security, incident diagnostics, limiting abuse Art. 6(1)(f) GDPR — our legitimate interest
Email address (after termination of the agreement, if applicable) Defense against claims, settlements Art. 6(1)(f) and (c) GDPR

Providing your email address and password is voluntary but necessary — without them it is not possible to create an account or deliver an alert.

3. Data from listings and artificial intelligence

To assess whether a given offer is a good deal, we retrieve publicly available listings from OLX, Vinted, Otodom and Otomoto (and prices of new products from Ceneo). The content of a listing — title, description, price, location, seller type — is sometimes personal data of the person who posted it. We process it on the basis of Art. 6(1)(f) GDPR (legitimate interest: delivering the user the listing information they requested). We do not build seller profiles and do not use this data for any other purpose.

To evaluate listings we use a language model (AI) provided by OpenAI, L.L.C. The model reads the content of the listing and the search phrase, and returns a structured evaluation: whether it's the right item, which variant, and what pros and cons follow from the description.

What we do not send to the AI model: your email address, account identifier, or any information that would let the query be linked to you. Only the search phrase and the content of the listings reach the model — with no context on who is asking.

4. The mobile app: permissions and device data

The Łowca app for Android and iOS is the same service as the website — one account, the same watches and the same points. What follows applies specifically to the phone.

Permissions we ask for
Only permission to send notifications (POST_NOTIFICATIONS on Android 13+, the system prompt on iOS). You can decline — the app keeps working and alerts then arrive by email only. You can withdraw the permission at any time in your system settings.
Permissions we never ask for
We do not request access to location, contacts, photos, camera, microphone, calendar, SMS, the list of installed apps, or files on your device — and we do not collect any of that data by other means.
Advertising identifiers and tracking
We do not read the advertising identifier (neither the Android Advertising ID nor the IDFA), we do not track you across apps, and we embed no third-party advertising or analytics SDKs. We do not sell or share data with data brokers.
The notification token
We store it only after you sign in, and only to send you an alert. We delete it from our database and invalidate it in Firebase when you sign out or erase your data; a token Google reports as no longer valid is removed automatically on the next send.
Buying points
The mobile app does not sell points: the points screen shows your balance and says that top-ups happen on lowca-okazji.com. Payment there is handled by Mollie B.V. — neither the app nor we ever see your card number or online-banking credentials; those go exclusively to Mollie and your bank or card issuer.
Data stored locally on the device
Your login session (Firebase Authentication) and “when you last opened the results of this watch” markers, which never leave the phone. Both disappear when you sign out and when you uninstall the app.
Age
The service is not directed to children. An account may be created by a person aged 16 or over (see the Terms of Service). We do not knowingly collect data from anyone younger; if we learn of such an account, we delete it.

5. Who we share data with

We use subprocessors (data processors) bound to us by data processing agreements compliant with Art. 28 GDPR:

EntityRoleScope of data
Google Ireland Ltd. / Google LLC (Firebase, Google Cloud) Hosting, authentication (including Sign in with Google), database, delivery of push notifications (Firebase Cloud Messaging) Email address, account data, watches, push notification token, logs
OpenAI, L.L.C. Evaluating listing content (language model) Search phrase and listing content — no data identifying the user
Resend, Inc. Sending email messages Email address, alert content
Meta Platforms Ireland Ltd. Measuring the effectiveness of ads on Facebook and Instagram — the Meta pixel on the website and reporting paid orders directly from our server Only with your consent. The identifier from the _fbp cookie, IP address, browser information, the address of the page visited and the event itself: a visit, creating an account (including whether by email or through Google) or a purchase together with its amount and order identifier. We do not pass on your email address — neither in the clear nor as a hash — nor your account identifier.
Google Ireland Ltd. (Google Tag Manager, Google Analytics) Visit statistics and ad effectiveness Only with your consent. The identifier from the _ga cookie, IP address, browser information, the subpages visited and the same events as above. Without consent these tools store nothing on your device.
Mollie B.V. Handling payments for point packs Email address, amount, order identifier. The Service does not store and does not pass on card numbers or online-banking login data — these go exclusively to Mollie B.V. and the bank or card issuer. Mollie B.V. is headquartered in the Netherlands (EU), so this processing does not involve transferring data outside the EEA.

We do not sell or share data for marketing purposes with third parties. We may disclose data to state authorities if such an obligation arises from law.

6. Transfers outside the EEA

Some of our subprocessors are headquartered in the United States. The transfer of data takes place on the basis of standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR), and in the case of certified entities — on the basis of the adequacy decision for the EU–US Data Privacy Framework (Art. 45 GDPR). A copy of the safeguards applied is available on request.

7. How long we keep data

Account data and watches
For as long as the account exists. After it is deleted — without delay, within 30 days at the latest.
Memory of sent listings (to avoid repeating alerts)
45 days from the last appearance of a given listing, then deleted automatically.
Purchase history (packs, amounts, confirmations)
5 years from the end of the tax year, in accordance with accounting regulations — regardless of account deletion.
Push notification token
Until you sign out, withdraw the notification permission, uninstall the app, or erase your data — we delete it immediately in each of those cases.
App usage events
For as long as the account exists; deleted together with the rest of the account data.
Technical logs
Up to 30 days.
Data necessary to defend against claims
Until the statute of limitations for claims expires.

8. Your rights

You have the right to: access your data and obtain a copy of it, rectification, erasure ("the right to be forgotten"), restriction of processing, data portability, and objection to processing based on legitimate interest.

You can delete your data yourself in the app — this immediately deletes all related watches, alert history, listing memory, push notification tokens, app usage events, and your profile, and the account itself is deactivated (signing in stops working). The account's e-mail address is kept only as the record of the deactivated account. If you want to come back, or want that record permanently removed too, write to team@lowca-okazji.com; we respond within 30 days.

A separate page walks through it step by step, including what we erase immediately and what we have to keep and for how long: Delete your account and data.

You are also entitled to lodge a complaint with the supervisory authority:
President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.

9. Data security

10. Cookies and device storage

Until August 21, 2026 we used no analytics or advertising tools at all, and this section said outright that we do not ask you for consent to cookies. That has changed. We run ads on Meta and Google, and we need to know which of them bring in people Łowca is genuinely useful to — otherwise we are paying for ads we know nothing about. That is why you will now see a consent banner on the website.

Strictly necessary — always on, no consent needed

The law does not require consent for these mechanisms, because without them the service does not work:

Analytics and marketing — only with your consent

We do not start them until you click “Accept”. Until that moment — and for good, if you click “Reject” — we store nothing on your device beyond the decision itself, and no request goes out to Meta or to Google Analytics.

ToolFilesWhat forHow long
Meta pixel (Meta Platforms Ireland Ltd.) _fbp Linking a click on an ad on Facebook or Instagram with what happened next: a visit to the site, creating an account, buying points. up to 90 days
Google Analytics, started through Google Tag Manager (Google Ireland Ltd.) _ga, _ga_* Visit statistics: how many people came, to which subpages, which ads brought them and how many of them created an account. up to 2 years

The legal basis is your consent (Art. 6(1)(a) GDPR and Art. 173 of the Polish Telecommunications Act). Consent is voluntary — refusing it does not limit the website, the app or your account in any way.

Changing your mind

You can withdraw your consent at any time, just as easily as you gave it — with the button below. Withdrawal does not affect what happened earlier, but from that moment on nothing more will be sent.

You can also block or delete cookies in your browser's settings — that works independently of this button.

Server-side purchase reporting

We send the information about a paid point top-up to Meta not from your browser but from our server — because the payment provider confirms the payment only after you have closed its page. We do this only if you have previously given consent to marketing cookies; without consent we send nothing. What goes there is the amount, the currency, the order identifier and the identifiers from the cookies described above together with the IP address — never your email address or account identifier. We delete the IP address from the order right after sending it; the order itself stays, because it is an accounting document (section 7).

11. Automated decisions and profiling

Our system automatically evaluates and ranks listings, not you. We do not make automated decisions about you that produce legal effects or similarly significant effects within the meaning of Art. 22 GDPR.

An offer's evaluation is a hint, not a guarantee. The result is produced by an automatic model based on the content of someone else's listing, which may be inaccurate. The decision to buy is always yours.

12. Changes to the policy

We will inform you of significant changes by email, at the address associated with your account, with at least 14 days' notice. The date of the last update is at the top of the page.