PRIVACY AND COOKIES POLICY
PRIME AUTO ONLINE STORE
Version dated 4 September 2026
Effective from the date of publication on the Website
§1. General Information
-
This Privacy and Cookies Policy sets out the rules governing the processing of personal data of persons using the online store operated under the Prime Auto brand, available at:
-
This Policy applies in particular to persons who:
-
visit the Website;
-
place Orders;
-
have a Customer Account;
-
contact the Seller;
-
use the contact form or callback function;
-
submit complaints, returns or warranty claims;
-
subscribe to the newsletter or other marketing communications;
-
use the “Notify me when available” function;
-
publish reviews;
-
contact Prime Auto through social media or messaging applications;
-
represent business Customers.
-
-
The Controller processes personal data in accordance with:
-
Regulation (EU) 2016/679 of the European Parliament and of the Council, hereinafter referred to as the GDPR;
-
the Polish Personal Data Protection Act of 10 May 2018;
-
the Polish Electronic Communications Law of 12 July 2024;
-
other applicable provisions of Polish and European Union law.
-
-
The Controller applies the principle of data minimisation and processes only data that is adequate and necessary for the specified purposes.
§2. Definitions
-
Controller – Prime Cars Accessories Spółka z ograniczoną odpowiedzialnością.
-
Website / Store – the Prime Auto online store available at https://primeauto-eu.com/.
-
User – any person visiting or using the Website.
-
Customer – any person making or intending to make a purchase through the Website.
-
Account – an individual account created by the User on the Website.
-
Cookies – files or other information stored on the User's terminal device or information accessed by the Website on that device.
-
Necessary Cookies – technologies required for the proper operation of the Website or for providing a service expressly requested by the User.
-
Optional Cookies – in particular analytical, marketing or personalisation technologies that are not necessary for the basic operation of the Website.
-
EEA – European Economic Area.
§3. Personal Data Controller
-
The Controller of personal data is:
Prime Cars Accessories Spółka z ograniczoną odpowiedzialnością
ul. Cegielniana 4A/15
30-404 Kraków
Poland
Tax ID (NIP): 6793364590
REGON: 544606738
KRS: 0001238186
-
In matters concerning personal data, you may contact the Controller:
E-mail:
info@primeauto-eu.com
Correspondence address:
Prime Cars Accessories Sp. z o.o.
ul. Cegielniana 4A/15
30-404 Kraków
Poland
Telephone:
+48 12 300 21 18
-
If the Controller appoints a Data Protection Officer, the current contact details of the Data Protection Officer will be published on the Website.
§4. Categories of Personal Data Processed
The Controller may process in particular the following categories of data:
-
Identification data, including:
-
first name;
-
surname;
-
company name;
-
tax identification number;
-
details of a representative of a business entity.
-
-
Contact details, including:
-
e-mail address;
-
telephone number;
-
correspondence address;
-
delivery address;
-
billing address.
-
-
Account data, including:
-
Account identifier;
-
Order history;
-
saved Products;
-
Account settings;
-
login information.
-
-
Order and transaction data, including:
-
Order number;
-
Products ordered;
-
price;
-
payment method;
-
delivery method and address;
-
Order fulfilment history;
-
information concerning returns and payments.
-
-
Payment and settlement data, to the extent necessary to process transactions, accounting and refunds.
-
Where payment is processed by an external payment operator, the data required to authorise the transaction may be processed directly by that operator under its own rules. The Controller primarily receives information necessary to confirm and settle the payment.
-
Vehicle-related data, where required to select a Product, including:
-
make;
-
model;
-
model year;
-
year of manufacture;
-
vehicle version;
-
equipment version;
-
bed length;
-
cab type;
-
VIN;
-
vehicle photographs;
-
technical information provided by the Customer.
-
-
A VIN and vehicle information may constitute personal data where they can be linked to an identifiable natural person.
-
Complaint, return and warranty data, including:
-
description of the issue;
-
photographs;
-
recordings;
-
correspondence;
-
proof of purchase;
-
vehicle information;
-
information necessary to settle a complaint or return.
-
-
Communication data, including the content of e-mails, forms, customer service communications and messages sent through social media or messaging applications.
-
Technical data, including:
-
IP address;
-
device information;
-
browser type and version;
-
operating system;
-
session identifiers;
-
login data;
-
system logs;
-
information concerning use of the Website;
-
cookie identifiers or similar technologies.
-
Marketing and analytics data, where the User has provided the required consent, including information about:
-
pages visited;
-
Products viewed;
-
clicks;
-
source of entry to the Website;
-
interactions with advertisements;
-
purchasing preferences.
§5. Purposes and Legal Bases for Processing Personal Data
The Controller may process personal data for the following purposes:
| Purpose of processing | Legal basis |
|---|---|
| Taking steps at the Customer's request prior to entering into an Agreement | Article 6(1)(b) GDPR |
| Entering into and performing a Sales Agreement | Article 6(1)(b) GDPR |
| Operating the Customer Account and providing electronic services | Article 6(1)(b) GDPR |
| Selecting a Product for a vehicle, including analysis of VIN and technical data | Article 6(1)(b) GDPR and, in other cases, Article 6(1)(f) GDPR |
| Delivery fulfilment | Article 6(1)(b) GDPR |
| Payment and refund processing | Article 6(1)(b) and (c) GDPR |
| Issuing and storing invoices and accounting and tax documents | Article 6(1)(c) GDPR |
| Handling withdrawal from Agreements, complaints and consumer rights | Article 6(1)(b) and (c) GDPR |
| Handling manufacturer warranties | Article 6(1)(b) GDPR or Article 6(1)(f) GDPR |
| Responding to enquiries before purchase | Article 6(1)(b) GDPR |
| Responding to other correspondence | Article 6(1)(f) GDPR |
| Operating the callback function | Article 6(1)(b) or (f) GDPR |
| Operating the “Notify me when available” function | Article 6(1)(b) GDPR |
| Ensuring Website security and preventing fraud and abuse | Article 6(1)(f) GDPR |
| Maintaining technical logs and diagnosing errors | Article 6(1)(f) GDPR |
| Establishing, pursuing or defending legal claims | Article 6(1)(f) GDPR |
| Contact with representatives of B2B Customers | Article 6(1)(f) GDPR |
| Publishing and moderating reviews | Article 6(1)(b) or (f) GDPR |
| Newsletter and electronic marketing | Article 6(1)(a) GDPR and, where applicable, Article 398 of the Polish Electronic Communications Law |
| Analytics using optional cookies | Article 6(1)(a) GDPR and Article 399 of the Polish Electronic Communications Law |
| Advertising, remarketing and marketing profiling using optional technologies | Article 6(1)(a) GDPR and Article 399 of the Polish Electronic Communications Law |
| Keeping evidence of consents and the manner in which they were obtained | Article 6(1)(f) GDPR |
§6. Legitimate Interests of the Controller
Where the legal basis for processing is Article 6(1)(f) GDPR, the Controller's legitimate interests may include in particular:
-
ensuring the security of the Website and transactions;
-
preventing fraud and abuse;
-
handling correspondence and enquiries;
-
managing business relationships;
-
defending against claims and pursuing claims;
-
ensuring the proper operation of IT systems;
-
carrying out basic business analyses not requiring consent for optional cookies;
-
protecting the rights of the Controller, Customers and third parties;
-
retaining evidence of actions taken, consents granted and information provided where necessary to demonstrate compliance with law.
§7. Voluntary Provision of Data
-
Providing personal data is generally voluntary.
-
However, providing certain data may be necessary in order to:
-
enter into an Agreement;
-
fulfil an Order;
-
deliver a Product;
-
issue an invoice;
-
create an Account;
-
process a return or complaint;
-
confirm Product compatibility;
-
respond to an enquiry.
-
-
Failure to provide data necessary for a specific activity may make it impossible to carry out that activity.
-
Consent to marketing and consent to optional cookies are voluntary and may not be made a condition for making an ordinary purchase, unless a specific functionality inherently requires a particular technology.
§8. Sources of Personal Data
The Controller obtains personal data primarily:
-
directly from the User or Customer;
-
through the Order Form, Account, contact forms and other Website functions;
-
through e-mail, telephone communication or communication via social media;
-
from payment operators in relation to transaction status;
-
from carriers in relation to information necessary for fulfilment and confirmation of delivery;
-
from manufacturers, suppliers or warranty service providers in connection with complaints or warranties;
-
from publicly available registers, in particular when verifying business entity information.
§9. Recipients of Personal Data
-
Personal data may be disclosed to entities supporting the Controller in conducting its business.
-
Categories of recipients may include in particular:
-
IT infrastructure and hosting providers;
-
online store platform and IT service providers;
-
e-mail and communication service providers;
-
payment operators, banks and payment organisations;
-
courier companies and logistics operators, in particular entities making deliveries for Prime Auto;
-
accounting service providers;
-
law firms and advisers;
-
customer service system providers;
-
manufacturers, distributors and Product suppliers;
-
entities handling complaints or warranties;
-
customs agencies and freight forwarders where necessary for a specific transaction;
-
analytics and marketing tool providers – only to the extent permitted by law and relevant consents;
-
public authorities, courts, tax authorities, law enforcement authorities or other authorised bodies where disclosure is required by law.
-
-
Prime Auto currently makes available, among others, Visa, Mastercard, Przelewy24 and BLIK payment methods, while deliveries may be carried out by external carriers.
-
The Controller discloses to individual recipients only the data necessary for the relevant purpose.
§10. Foreign Manufacturers and Suppliers
-
Prime Auto cooperates with manufacturers and suppliers located in various countries, including in particular the USA, Canada, Australia, Mexico and other countries.
-
The mere fact that a Product is imported from abroad does not mean that Customer data is automatically transferred to the foreign manufacturer.
-
Personal data may be transferred to a foreign manufacturer or supplier only where genuinely necessary, for example in order to:
-
confirm Product compatibility;
-
fulfil an Individual Order;
-
process a complaint;
-
conduct a warranty procedure;
-
arrange direct delivery to the Customer where agreed.
-
-
In such cases, the scope of data transferred is limited to the minimum necessary to achieve the relevant purpose.
§11. Transfers of Personal Data Outside the EEA
-
In connection with the use of technology providers or cooperation with foreign manufacturers and suppliers, personal data may in certain cases be transferred outside the EEA.
-
Such transfers are carried out only on a legal basis provided for in Chapter V of the GDPR.
-
Depending on the circumstances, the Controller may rely in particular on:
-
a European Commission adequacy decision;
-
Standard Contractual Clauses adopted by the European Commission;
-
other appropriate safeguards provided for by the GDPR.
-
-
In relation to recipients in the United States, data may be transferred on the basis of the EU–US Data Privacy Framework adequacy decision where the specific recipient participates in that framework.
-
Where a recipient in the United States is not covered by the relevant adequacy decision, the Controller applies other appropriate GDPR mechanisms where a transfer is necessary.
-
Information concerning safeguards applied to a specific transfer may be obtained by contacting the Controller.
§12. Data Retention Periods
-
Personal data is retained no longer than necessary for the purpose for which it was collected.
-
In particular:
a) data relating to performance of an Agreement – for the period of performance of the Agreement and thereafter for the period necessary to comply with legal obligations and protect against claims;
b) accounting and tax documents – for the period required by applicable tax and accounting regulations;
c) complaint, return and warranty data – for the period required to handle the matter and thereafter for the period necessary to protect and pursue claims;
d) Account data – for the duration of the Account and, after its deletion, to the extent necessary to comply with legal obligations and protect against claims;
e) enquiry data – for the duration of correspondence and thereafter for a period justified by the nature of the matter;
f) data relating to newsletters or other consent-based marketing – until consent is withdrawn or the relevant marketing activity ends;
g) data processed on the basis of a legitimate interest in direct marketing – until an effective objection is submitted or the purpose of processing ceases;
h) data relating to the “Notify me when available” function – until the notification is sent, the User unsubscribes from the service, or the period reasonably justifying further waiting for Product availability expires;
i) evidence of consents and declarations – for the period necessary to demonstrate the lawfulness of the Controller's actions;
j) cookie-related data – for the lifetime of the relevant cookie or until consent is withdrawn, depending on the type of technology.
-
After expiry of the relevant periods, personal data is deleted or anonymised unless further retention is required by law.
§13. Rights of the Data Subject
-
Subject to the conditions specified in the GDPR, a data subject may have the following rights:
-
the right of access to personal data;
-
the right to receive a copy of personal data;
-
the right to rectification;
-
the right to completion of personal data;
-
the right to erasure;
-
the right to restriction of processing;
-
the right to data portability;
-
the right to object;
-
the right to withdraw consent;
-
the right to lodge a complaint with a supervisory authority.
-
-
The scope of the individual rights depends, among other things, on the legal basis and purpose of processing.
-
Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
-
Where personal data is processed for direct marketing purposes, the data subject may object to such processing at any time. After an effective objection, personal data will no longer be processed for that purpose.
§14. Identity Verification When Exercising Rights
-
The Controller takes care to ensure that personal data is not disclosed to unauthorised persons.
-
Where the Controller has reasonable doubts concerning the identity of the person submitting a request relating to personal data, the Controller may request additional information necessary to confirm that person's identity.
-
The scope of information requested will be limited to the minimum necessary for verification.
-
As a rule, exercise of rights under the GDPR is free of charge.
-
However, where a request is manifestly unfounded or excessive, in particular because of its repetitive nature, the Controller may, in accordance with the GDPR:
-
charge a reasonable fee taking into account the administrative costs involved; or
-
refuse to act on the request.
-
-
The Controller bears the burden of demonstrating that a request is manifestly unfounded or excessive.
§15. Time Limit for Exercising Rights
-
The Controller provides information concerning action taken on a request without undue delay and, as a rule, no later than one month after receipt of the request.
-
Where the nature of the request or the number of requests so requires, this period may be extended in accordance with the GDPR.
-
The data subject will be informed of any extension and the reasons for it within the period required by the GDPR.
§16. Right to Lodge a Complaint
-
If a person believes that their personal data is being processed in breach of the GDPR, they have the right to lodge a complaint with a supervisory authority.
-
The supervisory authority in Poland is:
President of the Personal Data Protection Office
Personal Data Protection Office
ul. Stanisława Moniuszki 1A
00-014 Warsaw
Poland
-
Exercising the right to lodge a complaint does not exclude other legal remedies available to the data subject.
§17. Electronic Marketing and Newsletter
-
The Controller may send commercial information or direct marketing by e-mail, electronic messaging, telephone or other telecommunications terminal equipment only to the extent permitted by applicable law.
-
Where prior consent of the User is required, marketing communications will not be sent without obtaining such consent.
-
Marketing consent:
-
is voluntary;
-
may be withdrawn at any time;
-
may not be pre-selected;
-
should be separated from other types of consent where required by law.
-
-
The User may unsubscribe from the newsletter, among other methods, by using the appropriate link included in the message or by contacting the Controller.
-
Withdrawal of marketing consent does not affect fulfilment of Agreements already entered into or the Controller's statutory obligations.
§18. Profiling and Automated Decision-Making
-
The Controller may analyse information concerning the User's activity on the Website in order to:
-
personalise content;
-
prepare statistics;
-
measure advertising effectiveness;
-
present advertising tailored to interests,
-
provided there is an appropriate legal basis and, where required, the User has consented to the relevant technologies.
-
Such activities may constitute profiling within the meaning of the GDPR.
-
The Controller does not make decisions concerning Customers based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them, unless in the future the Controller expressly informs Users about such processing in accordance with the GDPR.
§19. Cookies – General Information
-
The Website uses Cookies and similar technologies.
-
They may be used in particular to:
-
ensure operation of the shopping cart;
-
maintain sessions;
-
enable Account login;
-
remember settings;
-
provide security;
-
analyse traffic;
-
measure Website effectiveness;
-
carry out marketing and remarketing activities.
-
-
Cookies may be placed directly by the Controller or by third parties.
-
Merely using the Website does not constitute automatic consent to all categories of Cookies.
§20. Categories of Cookies
The Website may use the following categories:
1. Necessary Cookies
These technologies are required for:
-
proper operation of the Store;
-
session maintenance;
-
shopping cart operation;
-
completion of the purchase process;
-
ensuring security;
-
remembering privacy choices.
Necessary Cookies may be used without the User's consent where the conditions provided for by applicable law are met.
2. Functional Cookies
These technologies are used to provide additional features, remember preferences or facilitate use of the Website.
Where they are not necessary to provide a service expressly requested by the User, they are activated only after obtaining the required consent.
3. Analytical Cookies
These technologies help the Controller understand how the Website is used, for example the number of visits, popularity of individual pages and how Users navigate through the Website.
Where they involve storing or accessing information on a terminal device, they are activated only after consent has been obtained.
4. Marketing Cookies
These technologies may be used to:
-
measure advertising effectiveness;
-
conduct remarketing;
-
create audience groups;
-
tailor advertising to interests.
They are activated only after the required consent has been obtained.
§21. Third-Party Tools
-
The Website may use tools provided by third parties.
-
The Website uses, among other tools, Google Tag Manager for technical tag management.
-
Implementation of Google Tag Manager does not in itself constitute authorisation to activate any analytics or marketing tools without an appropriate legal basis.
-
Analytics and marketing tags requiring consent should only be activated after the User selects the appropriate settings.
-
The Website may also use external elements, such as maps, multimedia content, social media functions or analytics tools.
-
Where such an element results in the use of optional Cookies or other technologies requiring consent, its activation depends on the User's consent.
§22. Consent Management Panel
-
The User should be able to independently select categories of optional Cookies.
-
The consent mechanism should allow at least:
-
acceptance of optional Cookies;
-
rejection of optional Cookies;
-
selection of individual categories;
-
subsequent modification of the User's decision.
-
-
Withdrawal of consent should be as easy as giving consent.
-
Changing the User's decision concerning Cookies does not affect the lawfulness of operations performed before consent was withdrawn.
-
Current information concerning the technologies used, their providers, purposes and duration should be available through the “Cookie Settings” panel.
§23. Browser Settings
-
Independently of the consent management panel, the User may also manage Cookies through browser settings.
-
Browser settings do not replace the Controller's consent mechanism in circumstances where consent is legally required.
-
Restricting Necessary Cookies may cause certain Website functionalities to operate incorrectly.
§24. Social Media and Messaging Applications
-
Prime Auto may operate profiles on social media and allow contact through messaging applications, including, for example, Facebook, Instagram or WhatsApp.
-
If the User contacts Prime Auto through such a platform, the Controller processes the data received for the purpose of:
-
communicating with the User;
-
responding to an enquiry;
-
handling an Order or complaint;
-
managing a business relationship.
-
-
The provider of the relevant social media platform or messaging service may independently process the User's personal data under its own privacy rules.
-
Use of external platforms is also subject to their respective terms and privacy policies.
§25. Reviews
-
Where the User publishes a review on the Website, the Controller may process:
-
the content of the review;
-
the author's first name or identifier;
-
technical data necessary to secure the review function;
-
information necessary to verify whether the review originates from an actual Customer, where such a mechanism is used.
-
-
Order information used to verify a review does not need to be publicly disclosed.
-
A review may be published publicly in accordance with the rules applicable to reviews on the Website.
§26. Data Security
-
The Controller applies appropriate technical and organisational measures proportionate to the risk involved in the processing of personal data.
-
Such measures may include in particular:
-
access controls;
-
restricting access to authorised persons only;
-
securing data transmission;
-
backups where justified;
-
system updates;
-
security monitoring;
-
data processing agreements where required;
-
minimisation of the scope of personal data processed.
-
-
No method of data transmission or storage can guarantee absolute security; however, the Controller applies safeguards appropriate to the nature, scope, context and purposes of the processing.
§27. Personal Data Breaches
-
In the event of a personal data breach, the Controller takes the actions required under the GDPR.
-
Where the statutory conditions are met, the Controller notifies the President of the Personal Data Protection Office of the breach.
-
Where a breach is likely to result in a high risk to the rights or freedoms of a person, the Controller will inform that person in accordance with applicable law.
§28. Children's Data
-
Prime Auto's offer is not directed at children.
-
The Controller does not intend to knowingly collect through the Store personal data of children who are not legally capable of independently entering into the relevant Agreement.
-
If the Controller becomes aware that data has been provided by a person who was not authorised to perform the relevant act, appropriate measures will be taken in accordance with applicable law.
§29. Changes to this Privacy Policy
-
This Policy may be amended in particular in the event of:
-
changes in applicable law;
-
changes in the way personal data is processed;
-
introduction of new Website functionalities;
-
changes in service providers;
-
changes in technologies used;
-
the need to clarify information provided to Users.
-
-
The current version of the Policy will be published on the Website together with its effective date.
-
Material changes concerning the use of personal data may additionally be communicated to Users in an appropriate manner.
-
An amendment to this Policy does not automatically change the legal basis for processing personal data collected previously.
-
Where a new consent is required for a new use of personal data, the Controller will obtain such consent before commencing the relevant processing.
§30. Contact Regarding Privacy Matters
For all matters concerning:
-
processing of personal data;
-
exercise of rights under the GDPR;
-
marketing;
-
Cookies;
-
withdrawal of consent;
you may contact the Controller:
Prime Cars Accessories Spółka z ograniczoną odpowiedzialnością
ul. Cegielniana 4A/15
30-404 Kraków
Poland
E-mail: info@primeauto-eu.com
Telephone: +48 12 300 21 18
§31. Final Provisions
-
This Privacy Policy provides information concerning the rules governing the processing of personal data by Prime Cars Accessories Sp. z o.o.
-
Matters not regulated by this Policy are governed by the GDPR, the Polish Personal Data Protection Act, the Polish Electronic Communications Law and other applicable regulations.
-
This Policy should be read together with:
-
the Online Store Terms and Conditions;
-
Cookie Settings;
-
information provided in connection with specific forms or functionalities where required.
-