Privacy Policy — Personal Data Processing Framework for the Cheap Cigarettes Platform
This Privacy Policy sets out how KING SMOKE sp. z o.o. (“the Controller,” “we,” “us”) collects, uses, discloses, retains, and protects personal data of purchasers and website visitors (“Data Subjects,” “you”) in the operation of the Cheap Cigarettes platform. It is issued in compliance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), the Polish Personal Data Protection Act of 10 May 2018 (Ustawa o ochronie danych osobowych), and the Polish Act on the Provision of Electronic Services of 18 July 2002 (Ustawa o świadczeniu usług drogą elektroniczną), as amended from time to time.
Access to this platform, and to this Policy, is restricted to persons who satisfy the minimum legal tobacco acquisition age in their jurisdiction of residence. By accessing the platform or completing a transaction, you confirm that you satisfy this requirement.
Documented processing. Stated retention periods. Full data subject rights under GDPR and applicable US state privacy law.
Last reviewed: 7 August 2026 · Effective date: 7 August 2026 · Framework maintained by: Legal & Compliance Team, KING SMOKE sp. z o.o. · Applies to: all data processing activities conducted by the Controller in connection with the Cheap Cigarettes platform.
Table of Contents
- Data Controller Identity
- Definitions
- Scope of This Policy
- Categories of Personal Data Processed
- Sources of Personal Data
- Purposes of Processing and Legal Bases
- Recipients and Categories of Recipients
- International Data Transfers
- Retention Periods
- Cookies and Tracking Technologies
- Age Verification Data Handling
- Marketing Communications
- Automated Decision-Making and Profiling
- Data Subject Rights Under GDPR
- How to Exercise Your Rights
- Right to Lodge a Complaint with the Supervisory Authority
- Children’s Data
- Security Measures
- California and US State Privacy Rights
- Changes to This Policy
- Contact for Privacy Requests
- Changelog
1. Data Controller Identity
The controller of personal data processed in connection with the Cheap Cigarettes platform is:
- Entity: KING SMOKE sp. z o.o.
- Legal form: sp. z o.o. (spółka z ograniczoną odpowiedzialnością) under the laws of the Republic of Poland
- Registered office: Staromiejska Street 6/10D, Floor 7, Katowice, Silesian, 40-013, PL
- NIP (Tax Identification Number): 9542784480
- REGON (Statistical Number): 36875533100000
- KRS (National Court Register): 0000703707
- Contact for privacy matters: legal@cheap-cigarettes.org
- General support: support@cheap-cigarettes.org
Under Article 37 of GDPR, the appointment of a Data Protection Officer is required for certain categories of controllers. KING SMOKE sp. z o.o. has designated a Privacy Contact within the Legal & Compliance Team who serves as the point of contact for all data protection matters, reachable at the email address above.
2. Definitions
For the purpose of this Policy, the following definitions apply, drawn from Article 4 of GDPR:
- “Personal data” — any information relating to an identified or identifiable natural person.
- “Processing” — any operation performed on personal data, including collection, recording, storage, use, disclosure, and erasure.
- “Controller” — KING SMOKE sp. z o.o., which determines the purposes and means of processing.
- “Processor” — a third party that processes personal data on behalf of the Controller under a Data Processing Agreement.
- “Data Subject” — the identified or identifiable natural person to whom personal data relates.
- “Consent” — freely given, specific, informed, and unambiguous indication of the Data Subject’s agreement to processing.
- “Third country” — any country outside the European Economic Area (EEA).
- “Standard Contractual Clauses” or “SCCs” — the contractual clauses approved by the European Commission for the transfer of personal data to third countries, as adopted under Commission Implementing Decision (EU) 2021/914.
3. Scope of This Policy
This Policy applies to personal data processed by the Controller in connection with:
- Browsing the Cheap Cigarettes website and its content;
- Creation and maintenance of a purchaser account;
- Placement and fulfilment of orders across every product category in the catalog;
- Age verification at the transaction stage;
- Payment processing across all supported payment methods;
- Order dispatch, transit, and delivery through international logistics channels;
- Customer support communications;
- Marketing communications, where the Data Subject has provided consent or where a soft opt-in applies;
- Website analytics, security monitoring, and fraud prevention.
This Policy does not cover data processing conducted by third parties independently of the Controller, including data processing by the Data Subject’s own payment provider, internet service provider, or destination customs authority.
4. Categories of Personal Data Processed
The following categories of personal data are processed in connection with the platform:
Identity and Contact Data
- Full name
- Email address
- Telephone number (where provided)
- Date of birth or age declaration (for age verification)
Delivery and Billing Data
- Delivery address (street, city, postal code, country)
- Billing address (where different from delivery)
- Recipient name at the delivery address
Order and Transaction Data
- Order reference numbers
- Items ordered, quantities, and prices
- Order timestamps and status history
- Shipping carrier tracking identifiers
- Refund, reshipment, and dispute records
Payment Data
- Payment method selected at checkout
- Transaction reference issued by the payment processor
- Payment status (authorised, cleared, refunded, failed)
- Cryptocurrency wallet addresses provided by the Data Subject for refund purposes
Card numbers, CVV codes, and full payment credentials are processed exclusively by the acquiring gateway and are not stored on the Controller’s systems.
Account Data (Where an Account Is Created)
- Account credentials (email address and hashed password)
- Account preferences and communication settings
- Purchase history linked to the account
Communication Data
- Support requests, dispute submissions, and correspondence with the Controller
- Records of email, telephone, and other communications
Technical Data
- IP address
- Browser type, version, and language
- Device type and operating system
- Referring URL, pages accessed, and interaction data
- Session identifiers
Marketing Data (Where Consent Is Provided)
- Marketing preferences
- Email open and click-through data (for transactional and, where applicable, marketing emails)
- Consent records and consent history
5. Sources of Personal Data
Personal data is obtained from the following sources:
- Directly from the Data Subject — data provided during account registration, order placement, age verification, payment, and customer support communications.
- Automatically through interaction with the platform — technical data (IP address, device information, browsing behaviour), cookie data, and session data.
- From payment processors — transaction confirmations, payment status updates, refund confirmations.
- From shipping carriers — dispatch scans, transit updates, delivery confirmations, and, where applicable, delivery failure notifications.
- From fraud prevention services — risk scores and screening results applied at the transaction stage.
6. Purposes of Processing and Legal Bases
Under Article 6 of GDPR, personal data may be processed only where a valid legal basis applies. The purposes for which the Controller processes personal data, together with the applicable legal basis, are set out below.
| Purpose | Legal Basis (GDPR Article 6) |
|---|---|
| Performance of the sale contract — order acceptance, payment, dispatch, delivery, returns | Article 6(1)(b) — contract performance |
| Age verification at the transaction stage | Article 6(1)(c) — legal obligation (regulatory age restrictions on tobacco sales) |
| Compliance with tax, customs, and accounting obligations | Article 6(1)(c) — legal obligation |
| Fraud prevention and transaction security | Article 6(1)(f) — legitimate interest of the Controller in preventing fraud |
| Customer support and dispute resolution | Article 6(1)(b) — contract performance; Article 6(1)(f) — legitimate interest in providing responsive support |
| Website functionality and technical operation | Article 6(1)(f) — legitimate interest in operating a functional platform |
| Analytics on aggregated website usage | Article 6(1)(a) — consent (where required by ePrivacy) |
| Marketing communications by email | Article 6(1)(a) — consent; or the soft opt-in for existing customers of similar goods under the ePrivacy framework, where applicable |
| Establishment, exercise, or defence of legal claims | Article 6(1)(f) — legitimate interest in the defence of legal claims |
Where the Controller relies on legitimate interest as the legal basis for processing, the Data Subject has the right to object to such processing under Article 21 of GDPR. In such cases, processing is discontinued unless the Controller demonstrates compelling legitimate grounds that override the interests, rights, and freedoms of the Data Subject, or the processing is necessary for the establishment, exercise, or defence of legal claims.
7. Recipients and Categories of Recipients
Personal data is disclosed to the following categories of recipients solely as necessary for the purposes stated above. In every case, third-party recipients act either as independent controllers (in respect of their own regulatory obligations) or as processors under a Data Processing Agreement complying with Article 28 of GDPR.
Payment Processors
Transaction data is transmitted to the payment processors authorised for the platform:
- Card and Revolut acquiring gateway: Network Merchants INC
- PayPal Holdings, Inc.
- Cryptocurrency payment provider: Coinbase Business
Payment processors receive the data required to process the transaction, including transaction amount, transaction reference, and, in the case of card and Revolut transactions, tokenised card details. Card numbers and CVV codes are handled exclusively by the acquiring gateway and are not accessible to the Controller.
Shipping Carriers
Dispatch and delivery data is transmitted to the shipping carriers engaged for international logistics, including:
- Registered postal operators in the country of origin
- Destination-country postal networks or partnering local carriers
- Poczta Polska, EMS
Shipping carriers receive the data required to route and deliver the consignment, including recipient name, delivery address, telephone number (where provided), and, where required by the destination jurisdiction, contents declaration for customs purposes.
Customs and Tax Authorities
Where required by the destination jurisdiction, contents declarations and, where applicable, purchaser identification data are transmitted to customs authorities in accordance with cross-border trade regulations.
Fraud Prevention Services
Transaction data may be shared with fraud prevention services engaged by the Controller or by the payment processors, for the purpose of risk screening and fraud detection.
Technology and Communications Providers
- Web hosting and content delivery provider: Contabo
- Email delivery service: Brevo
- Analytics provider: Google Analytics
Professional Advisors
Personal data may be disclosed to external legal, accounting, tax, or audit advisors where necessary in connection with the Controller’s professional obligations.
Public Authorities
Personal data may be disclosed to competent public authorities where required by applicable law, including in response to lawful orders from courts, tax authorities, customs authorities, or law enforcement bodies.
8. International Data Transfers
Certain of the recipients identified above are established outside the European Economic Area (EEA). Transfers of personal data to third countries are conducted under the safeguards required by Chapter V of GDPR:
- Adequacy decisions. Where the European Commission has issued an adequacy decision under Article 45 of GDPR in respect of the recipient country, transfers are conducted on that basis. Current adequacy decisions apply to, among others, the United Kingdom, Switzerland, Canada (commercial organisations), and Japan.
- Standard Contractual Clauses. Where no adequacy decision applies, transfers are conducted under the Standard Contractual Clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914).
- EU-U.S. Data Privacy Framework. Where the recipient is established in the United States and has certified under the EU-U.S. Data Privacy Framework, transfers are conducted on that basis in accordance with the adequacy decision of 10 July 2023.
A copy of the applicable safeguard for a specific transfer may be requested from the Privacy Contact identified in Section 21.
9. Retention Periods
Personal data is retained for no longer than necessary for the purposes for which it was collected, and in accordance with applicable legal retention obligations. The following retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Order and transaction records | 5 years from the end of the tax year in which the transaction occurred | Polish accounting law and tax record retention obligations |
| Payment transaction data | 5 years from the end of the tax year | Anti-money laundering and tax record retention obligations |
| Age verification records | 5 years from the transaction, or as required by applicable tobacco regulatory law | Regulatory compliance |
| Customer support correspondence | 3 years from the closure of the support case | Legitimate interest in defence of legal claims; general limitation period under Polish law |
| Account data (active accounts) | Duration of the account plus 3 years from account closure | Contract performance and defence of legal claims |
| Marketing consent records | Until consent is withdrawn, plus 3 years for demonstration of prior consent | Accountability under Article 7 of GDPR |
| Website analytics data | Up to 14 months in identifiable form, then aggregated | Legitimate interest in platform improvement |
| Server logs and technical security data | Up to 12 months | Legitimate interest in platform security |
| Marketing email interaction data | 2 years from the last interaction, unless consent is withdrawn earlier | Consent-based marketing operation |
Where the retention period expires, personal data is either securely deleted or anonymised such that it no longer identifies a natural person.
10. Cookies and Tracking Technologies
The platform uses cookies and similar technologies. Cookies are small data files stored on the Data Subject’s device by the browser. The Controller uses cookies in the following categories:
Strictly Necessary Cookies
Required for the operation of the platform, including session management, cart persistence, security, and load balancing. These cookies do not require consent under the ePrivacy framework because they are essential to providing the service explicitly requested by the Data Subject.
Functional Cookies
Enable enhanced functionality, including remembering preferences and settings. Deployed only with consent.
Analytics Cookies
Support aggregated measurement of website usage. Deployed only with consent. Analytics data is collected in a form that does not, in itself, identify individual Data Subjects.
Marketing Cookies
Where deployed, marketing cookies support conversion measurement and retargeting. Deployed only with consent.
Consent to non-essential cookies is collected through the cookie consent banner on the platform. Consent may be withdrawn at any time through the cookie settings interface accessible from the site footer, or through the browser’s own cookie management settings. Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal.
11. Age Verification Data Handling
The platform is restricted to persons who satisfy the minimum legal tobacco acquisition age applicable in their jurisdiction of residence. The minimum age threshold enforced on the platform is 21 years.
Age verification is conducted at the transaction stage as a condition of purchase completion. The following data is processed for age verification purposes:
- Date of birth or age declaration provided by the purchaser
- Where a third-party age verification provider is used: verification result and reference identifier only, without disclosure of the underlying identity data to the Controller
- Age verification timestamp linked to the order record
Age verification records are retained for 5 years from the transaction date in accordance with regulatory compliance obligations. Where age verification cannot be satisfied, the transaction is not completed and no permanent age verification record is created.
12. Marketing Communications
Marketing communications are sent only where the Data Subject has provided prior consent, or where the soft opt-in exception under the ePrivacy framework applies (existing customers of similar goods, with a clear and free-of-charge opt-out at every communication).
Each marketing communication contains an unsubscribe link enabling the Data Subject to withdraw consent at no cost and with a single action. Unsubscribe requests are processed within 24 hours of receipt.
Transactional emails required for the operation of the platform — including order confirmations, dispatch notifications, delivery updates, and customer support responses — are not marketing communications and are sent on the basis of contract performance under Article 6(1)(b) of GDPR.
13. Automated Decision-Making and Profiling
The Controller uses automated processes at the transaction stage for the purpose of fraud detection and payment authorisation. These automated processes include:
- Automated payment authorisation through the acquiring gateway, including 3D Secure authentication
- Automated fraud risk scoring at the transaction stage
- Automated destination eligibility checks against restricted jurisdiction lists
Where an automated process results in the decline of a transaction, the Data Subject has the right under Article 22 of GDPR to obtain human review of the decision, to express their point of view, and to contest the decision. Requests for human review should be submitted to the Privacy Contact identified in Section 21.
14. Data Subject Rights Under GDPR
Data Subjects located in the European Economic Area, the United Kingdom, and Switzerland have the following rights in respect of personal data processed by the Controller:
- Right of access (Article 15) — to obtain confirmation as to whether personal data concerning the Data Subject is processed, and to receive a copy of that data.
- Right to rectification (Article 16) — to obtain the correction of inaccurate or incomplete personal data.
- Right to erasure (Article 17) — to obtain the deletion of personal data where one of the grounds specified in Article 17(1) applies, subject to the exceptions in Article 17(3), including retention required for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.
- Right to restriction of processing (Article 18) — to obtain the restriction of processing in specified circumstances.
- Right to data portability (Article 20) — to receive personal data provided to the Controller in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
- Right to object (Article 21) — to object to processing based on legitimate interest, and to object to processing for direct marketing purposes.
- Right to withdraw consent (Article 7(3)) — where processing is based on consent, to withdraw consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.
- Right not to be subject to solely automated decision-making (Article 22) — to obtain human review of decisions producing legal or similarly significant effects that are based solely on automated processing.
15. How to Exercise Your Rights
To exercise any right under Section 14, submit a request to the Privacy Contact:
- Email: legal@cheap-cigarettes.org
- Postal address: Staromiejska Street 6/10D, Floor 7, Katowice, Silesian, 40-013, PL
To enable a response, the request should include:
- The Data Subject’s identity, sufficient to verify the request;
- The specific right being exercised;
- Any additional details enabling the Controller to locate the relevant records (order references, account email, etc.).
The Controller responds to requests within one month of receipt, in accordance with Article 12(3) of GDPR. Where the request is complex or where multiple requests are received, this period may be extended by a further two months, in which case the Data Subject is notified of the extension and its reasons within one month of the original request.
No fee is charged for a Data Subject request. Where a request is manifestly unfounded or excessive, the Controller may charge a reasonable fee or refuse to act, in accordance with Article 12(5) of GDPR.
16. Right to Lodge a Complaint with the Supervisory Authority
Data Subjects have the right to lodge a complaint with a supervisory authority under Article 77 of GDPR. The competent supervisory authority for KING SMOKE sp. z o.o. is:
- Authority: Urząd Ochrony Danych Osobowych (UODO) — Personal Data Protection Office
- Address: ul. Stawki 2, 00-193 Warszawa, Poland
- Website: https://uodo.gov.pl/
- Complaint form: available through the UODO website
Data Subjects habitually resident in another Member State of the European Union may also lodge a complaint with the supervisory authority of that Member State.
17. Children’s Data
The platform is restricted to persons who satisfy the minimum legal tobacco acquisition age applicable in their jurisdiction of residence. The Controller does not knowingly collect personal data from any person below the age of 21 years, and any account or order identified as having been created by a person below that age is voided and any associated data is deleted, subject to any retention required for the establishment, exercise, or defence of legal claims.
Where a parent, legal guardian, or other adult believes that a person below the age threshold has provided personal data to the platform, the matter should be reported to the Privacy Contact identified in Section 21 for prompt investigation and deletion.
18. Security Measures
The Controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing, in accordance with Article 32 of GDPR. These measures include:
- Transport-layer encryption (TLS 1.3) for all data in transit;
- Encryption at rest for stored personal data;
- PCI-DSS compliant handling of card transactions through a certified acquiring gateway, with tokenisation of card data;
- Access controls limiting personnel access to personal data on a need-to-know basis;
- Multi-factor authentication for administrative access;
- Logging and monitoring of access to production systems;
- Regular security assessments and vulnerability management;
- Data Processing Agreements with all third-party processors under Article 28 of GDPR;
- Personal data breach response procedures in accordance with Articles 33 and 34 of GDPR, including notification of the supervisory authority within 72 hours of becoming aware of a reportable breach.
No security measure can guarantee absolute security. In the event of a personal data breach that is likely to result in a high risk to the rights and freedoms of Data Subjects, affected Data Subjects will be notified without undue delay in accordance with Article 34 of GDPR.
19. California and US State Privacy Rights
This Section applies to Data Subjects habitually resident in the United States, and specifically to residents of jurisdictions with state-level privacy legislation, including California (California Consumer Privacy Act as amended by the California Privacy Rights Act, “CCPA/CPRA”), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with equivalent frameworks.
Data Subjects covered by this Section have the following rights, in addition to any rights granted under state law:
- Right to know what categories of personal information are collected, used, disclosed, and, where applicable, sold or shared, and the sources and purposes.
- Right to access a copy of the specific pieces of personal information collected.
- Right to delete personal information, subject to the exceptions under applicable state law.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information for cross-context behavioural advertising purposes.
- Right to limit the use of sensitive personal information to purposes strictly necessary for the provision of the service requested.
- Right to non-discrimination in the exercise of privacy rights.
The Controller does not sell personal information as the term “sale” is defined under CCPA/CPRA. The Controller does not knowingly sell or share personal information of consumers under 16 years of age.
To exercise any of the above rights, submit a request to the Privacy Contact identified in Section 21. Requests are processed within 45 days of receipt, with a possible 45-day extension where necessary and with notice to the Data Subject.
20. Changes to This Policy
This Policy may be updated to reflect changes in data processing activities, changes to third-party processors, updates to applicable law, or operational changes. Material changes will be identified in the Changelog at Section 22 of this page, with an effective date not less than 14 calendar days from the date of publication of the revised Policy.
Where changes to the processing activities are material and require additional legal basis (for example, a new consent-based processing purpose), the Controller will obtain the additional legal basis before commencing the new processing.
Data Subjects are directed to consult this page at the time of interaction with the platform. Continued use of the platform after the effective date of a revised Policy constitutes acknowledgement of the revised terms of processing, save that Data Subjects retain all rights set out at Section 14 in respect of the revised processing.
21. Contact for Privacy Requests
All privacy requests, data subject rights requests, and privacy-related correspondence should be directed as follows:
- Entity: KING SMOKE sp. z o.o.
- Attention: Privacy Contact — Legal & Compliance Team
- Email (privacy): legal@cheap-cigarettes.org
- Email (general support): support@cheap-cigarettes.org
- Postal address: Staromiejska Street 6/10D, Floor 7, Katowice, Silesian, 40-013, PL
- NIP: 9542784480
- REGON: 36875533100000
- KRS: 0000703707
- Standard response window: within one month for GDPR requests (Article 12(3)); within 45 days for CCPA/CPRA requests; within 24 hours on operational days for general support.
22. Changelog
- 7 August 2026 — Comprehensive rewrite. Full alignment with GDPR Article 13 disclosure requirements. Polish company details (KING SMOKE sp. z o.o.) and Polish supervisory authority (UODO) integrated. Retention periods stated per data category. International data transfer safeguards documented. Third-party recipients identified by category. Age verification data handling section added. CCPA/CPRA and US state privacy rights section added. Automated decision-making disclosure added. Cookie consent framework referenced.
A copy of the version of this Policy in force at the time of any given interaction is retained on the Controller’s records. Data Subjects may request a copy of any prior version from the Privacy Contact.