Privacy Policy
Last updated: August 21, 2026
This policy covers the lowca-okazji.com website and the Łowca mobile app (published as Item Hounter) for Android and iOS. It is one service with one controller — the data, purposes and legal bases below apply to both, and what is specific to the phone is in section 4.
In short: we need your email address to send alerts, and the content of your watches to know what to look for. We do not sell data and do not profile you for advertising. The website runs ad measurement tools from Meta and Google — but only once you click “Accept” in the consent banner. If you click “Reject”, we do not start them at all. Details in section 10.
1. Who is the controller
The controller of your personal data within the meaning of the GDPR (Regulation 2016/679) is:
Damian Jabłoński tribe
ul. Modlińska 61/106, 03-199 Warszawa, Poland
Tax ID (NIP): 5243008010 · Company ID (REGON): 528741561
Contact: team@lowca-okazji.com,
phone +48 606 904 443
We have not appointed a data protection officer — for all matters regarding personal data, write to the address above.
2. What data we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, encrypted password | Creating and managing the account, logging in | Art. 6(1)(b) GDPR — performance of the service agreement |
| Watch content (what you're looking for), chosen condition and frequency | Searching for listings and preparing alerts | Art. 6(1)(b) GDPR — performance of the agreement |
| Google sign-in data (email address, Google account identifier and — if you share them — your name and profile picture), only if you choose “Sign in with Google” | Creating the account and signing in without a separate password | Art. 6(1)(b) GDPR — performance of the agreement |
| Push notification token issued by Firebase Cloud Messaging (an identifier of the app installation on your device) and the platform: “android” or “ios” | Delivering an alert as a notification on your phone | Art. 6(1)(b) GDPR — performance of the agreement |
| History of sent alerts | So you don't get the same listing twice | Art. 6(1)(b) GDPR — performance of the agreement |
| Purchase history (pack, amount, status, payment session identifier) and points balance | Settling the purchase, crediting points, purchase history visible on your account | Art. 6(1)(b) GDPR — performance of the agreement; Art. 6(1)(c) GDPR — accounting and tax obligations |
| App usage events: opening its main screens (watch list, advisor chat, found offers, points-pack screen) and the confirming taps — creating a watch and, on the website, since the mobile app does not sell points, tapping “Buy” — with the account identifier, pack name (purchases only) and timestamp | Seeing which step — from opening the app to a purchase — people drop out at. These are our own counters, written to our own database — we only ever read them in aggregate, never per person. We use no Google Analytics and no third-party analytics of any kind | Art. 6(1)(f) GDPR — legitimate interest: improving the service |
| Technical logs (IP address, time, errors) | Security, incident diagnostics, limiting abuse | Art. 6(1)(f) GDPR — our legitimate interest |
| Email address (after termination of the agreement, if applicable) | Defense against claims, settlements | Art. 6(1)(f) and (c) GDPR |
Providing your email address and password is voluntary but necessary — without them it is not possible to create an account or deliver an alert.
3. Data from listings and artificial intelligence
To assess whether a given offer is a good deal, we retrieve publicly available listings from OLX, Vinted, Otodom and Otomoto (and prices of new products from Ceneo). The content of a listing — title, description, price, location, seller type — is sometimes personal data of the person who posted it. We process it on the basis of Art. 6(1)(f) GDPR (legitimate interest: delivering the user the listing information they requested). We do not build seller profiles and do not use this data for any other purpose.
To evaluate listings we use a language model (AI) provided by OpenAI, L.L.C. The model reads the content of the listing and the search phrase, and returns a structured evaluation: whether it's the right item, which variant, and what pros and cons follow from the description.
What we do not send to the AI model: your email address, account identifier, or any information that would let the query be linked to you. Only the search phrase and the content of the listings reach the model — with no context on who is asking.
4. The mobile app: permissions and device data
The Łowca app for Android and iOS is the same service as the website — one account, the same watches and the same points. What follows applies specifically to the phone.
- Permissions we ask for
- Only permission to send notifications (POST_NOTIFICATIONS on Android 13+, the system prompt on iOS). You can decline — the app keeps working and alerts then arrive by email only. You can withdraw the permission at any time in your system settings.
- Permissions we never ask for
- We do not request access to location, contacts, photos, camera, microphone, calendar, SMS, the list of installed apps, or files on your device — and we do not collect any of that data by other means.
- Advertising identifiers and tracking
- We do not read the advertising identifier (neither the Android Advertising ID nor the IDFA), we do not track you across apps, and we embed no third-party advertising or analytics SDKs. We do not sell or share data with data brokers.
- The notification token
- We store it only after you sign in, and only to send you an alert. We delete it from our database and invalidate it in Firebase when you sign out or erase your data; a token Google reports as no longer valid is removed automatically on the next send.
- Buying points
- The mobile app does not sell points: the points screen shows your balance and says that top-ups happen on lowca-okazji.com. Payment there is handled by Mollie B.V. — neither the app nor we ever see your card number or online-banking credentials; those go exclusively to Mollie and your bank or card issuer.
- Data stored locally on the device
- Your login session (Firebase Authentication) and “when you last opened the results of this watch” markers, which never leave the phone. Both disappear when you sign out and when you uninstall the app.
- Age
- The service is not directed to children. An account may be created by a person aged 16 or over (see the Terms of Service). We do not knowingly collect data from anyone younger; if we learn of such an account, we delete it.
5. Who we share data with
We use subprocessors (data processors) bound to us by data processing agreements compliant with Art. 28 GDPR:
| Entity | Role | Scope of data |
|---|---|---|
| Google Ireland Ltd. / Google LLC (Firebase, Google Cloud) | Hosting, authentication (including Sign in with Google), database, delivery of push notifications (Firebase Cloud Messaging) | Email address, account data, watches, push notification token, logs |
| OpenAI, L.L.C. | Evaluating listing content (language model) | Search phrase and listing content — no data identifying the user |
| Resend, Inc. | Sending email messages | Email address, alert content |
| Meta Platforms Ireland Ltd. | Measuring the effectiveness of ads on Facebook and Instagram — the Meta pixel on the website and reporting paid orders directly from our server | Only with your consent. The identifier from the _fbp
cookie, IP address, browser information, the address of the page visited and the event
itself: a visit, creating an account (including whether by email or through Google) or
a purchase together with its amount and order identifier. We do not pass on your email
address — neither in the clear nor as a hash — nor your account identifier. |
| Google Ireland Ltd. (Google Tag Manager, Google Analytics) | Visit statistics and ad effectiveness | Only with your consent. The identifier from the _ga
cookie, IP address, browser information, the subpages visited and the same events as
above. Without consent these tools store nothing on your device. |
| Mollie B.V. | Handling payments for point packs | Email address, amount, order identifier. The Service does not store and does not pass on card numbers or online-banking login data — these go exclusively to Mollie B.V. and the bank or card issuer. Mollie B.V. is headquartered in the Netherlands (EU), so this processing does not involve transferring data outside the EEA. |
We do not sell or share data for marketing purposes with third parties. We may disclose data to state authorities if such an obligation arises from law.
6. Transfers outside the EEA
Some of our subprocessors are headquartered in the United States. The transfer of data takes place on the basis of standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR), and in the case of certified entities — on the basis of the adequacy decision for the EU–US Data Privacy Framework (Art. 45 GDPR). A copy of the safeguards applied is available on request.
7. How long we keep data
- Account data and watches
- For as long as the account exists. After it is deleted — without delay, within 30 days at the latest.
- Memory of sent listings (to avoid repeating alerts)
- 45 days from the last appearance of a given listing, then deleted automatically.
- Purchase history (packs, amounts, confirmations)
- 5 years from the end of the tax year, in accordance with accounting regulations — regardless of account deletion.
- Push notification token
- Until you sign out, withdraw the notification permission, uninstall the app, or erase your data — we delete it immediately in each of those cases.
- App usage events
- For as long as the account exists; deleted together with the rest of the account data.
- Technical logs
- Up to 30 days.
- Data necessary to defend against claims
- Until the statute of limitations for claims expires.
8. Your rights
You have the right to: access your data and obtain a copy of it, rectification, erasure ("the right to be forgotten"), restriction of processing, data portability, and objection to processing based on legitimate interest.
You can delete your data yourself in the app — this immediately deletes all related watches, alert history, listing memory, push notification tokens, app usage events, and your profile, and the account itself is deactivated (signing in stops working). The account's e-mail address is kept only as the record of the deactivated account. If you want to come back, or want that record permanently removed too, write to team@lowca-okazji.com; we respond within 30 days.
A separate page walks through it step by step, including what we erase immediately and what we have to keep and for how long: Delete your account and data.
You are also entitled to lodge a complaint with the supervisory authority:
President of the Personal Data Protection Office
(Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
9. Data security
- All communication between the app or the website and our server goes over HTTPS/TLS; we expose no unencrypted entry point.
- Data rests in Google Cloud (Firestore, Firebase Authentication) and is encrypted at rest there. We never store passwords in plain text — Firebase Authentication handles them.
- Firestore security rules are written so that a signed-in user can reach only their own documents; operations on points and payments run in server-side code the app cannot bypass.
- Administrative access to the console and the database is limited to the owner of the service.
- Should a personal data breach nonetheless occur, we will report it to the President of the Personal Data Protection Office within 72 hours and notify you by email where the breach may result in a high risk to your rights.
10. Cookies and device storage
Until August 21, 2026 we used no analytics or advertising tools at all, and this section said outright that we do not ask you for consent to cookies. That has changed. We run ads on Meta and Google, and we need to know which of them bring in people Łowca is genuinely useful to — otherwise we are paying for ads we know nothing about. That is why you will now see a consent banner on the website.
Strictly necessary — always on, no consent needed
The law does not require consent for these mechanisms, because without them the service does not work:
- Login session (Firebase Authentication) — keeps you signed in.
- sessionStorage — carries what you type on the homepage over to the app, so you don't have to type it a second time. It disappears when you close the tab.
lowca.consent.v1(the browser's local storage) — remembers your decision about cookies. We store it also when you refuse: it is the only way not to ask you the same thing on every visit. We do not send it anywhere.- The mobile app uses no cookies — it keeps only the login session and the local markers described in section 4, in app storage on your device. There is no consent banner in the app, because the app contains no analytics or advertising tool at all.
Analytics and marketing — only with your consent
We do not start them until you click “Accept”. Until that moment — and for good, if you click “Reject” — we store nothing on your device beyond the decision itself, and no request goes out to Meta or to Google Analytics.
| Tool | Files | What for | How long |
|---|---|---|---|
| Meta pixel (Meta Platforms Ireland Ltd.) | _fbp |
Linking a click on an ad on Facebook or Instagram with what happened next: a visit to the site, creating an account, buying points. | up to 90 days |
| Google Analytics, started through Google Tag Manager (Google Ireland Ltd.) | _ga, _ga_* |
Visit statistics: how many people came, to which subpages, which ads brought them and how many of them created an account. | up to 2 years |
The legal basis is your consent (Art. 6(1)(a) GDPR and Art. 173 of the Polish Telecommunications Act). Consent is voluntary — refusing it does not limit the website, the app or your account in any way.
Changing your mind
You can withdraw your consent at any time, just as easily as you gave it — with the button below. Withdrawal does not affect what happened earlier, but from that moment on nothing more will be sent.
You can also block or delete cookies in your browser's settings — that works independently of this button.
Server-side purchase reporting
We send the information about a paid point top-up to Meta not from your browser but from our server — because the payment provider confirms the payment only after you have closed its page. We do this only if you have previously given consent to marketing cookies; without consent we send nothing. What goes there is the amount, the currency, the order identifier and the identifiers from the cookies described above together with the IP address — never your email address or account identifier. We delete the IP address from the order right after sending it; the order itself stays, because it is an accounting document (section 7).
11. Automated decisions and profiling
Our system automatically evaluates and ranks listings, not you. We do not make automated decisions about you that produce legal effects or similarly significant effects within the meaning of Art. 22 GDPR.
An offer's evaluation is a hint, not a guarantee. The result is produced by an automatic model based on the content of someone else's listing, which may be inaccurate. The decision to buy is always yours.
12. Changes to the policy
We will inform you of significant changes by email, at the address associated with your account, with at least 14 days' notice. The date of the last update is at the top of the page.