Discipline.← Back to the shop

Legal

Privacy and cookies

Effective: 30 September 2026

We collect only what we need to make and deliver your piece. No accounts, no newsletter, no analytics, no advertising trackers, and we never sell your data.

  1. Who is responsible
  2. What we collect and why
  3. Cookies and local storage
  4. Who we share it with
  5. Transfers outside Europe
  6. How long we keep it
  7. Your rights
  8. For US residents
  9. Security
  10. Children
  11. Changes

1. Who is responsible

The controller of your personal data is DynamicDigital sp. z o.o., trading as Discipline., Aleje Jerozolimskie 181B, 02-222 Warszawa, Poland, KRS 0000521993, NIP PL5213678094. For anything about your data, write to hello@discipline.fashion. We are a small business and have not appointed a data protection officer; Yves Benini handles privacy requests personally.

2. What we collect and why

WhenWhatWhyLegal basis (GDPR)
You place an order Name, email, phone number, delivery and billing address, the pieces you chose, amount paid, payment method type and the last four digits of your card (Stripe gives us these, never the full number) To make, ship and support your order, send you the confirmation and tracking, and handle returns Performance of the contract (art. 6(1)(b))
After your order Order and payment records, invoices Accounting and tax obligations Legal obligation (art. 6(1)(c))
You write to us (email or Instagram) or send a return, withdrawal or guarantee claim Your message, contact details, order number and any photos you send To answer you and handle your request Contract (6(1)(b)), our legitimate interest in answering you (6(1)(f)), and legal obligation for withdrawals and guarantees (6(1)(c))
You pay Payment and device data processed by Stripe Payment processing and fraud prevention Contract (6(1)(b)) and legitimate interest in preventing fraud (6(1)(f)). Stripe acts as its own controller for this.
You visit the site IP address, browser type, pages requested, time (server logs) To deliver the site and keep it secure Legitimate interest (6(1)(f))
There's a dispute The relevant order and correspondence To establish, exercise or defend legal claims Legitimate interest (6(1)(f))

We need your name, email, address and phone to deliver an order; without them we can't sell to you. Everything else is optional. We don't use your data for automated decisions that affect you, except that Stripe's automated fraud screening can decline a payment; if that happens, contact us and a person will look at it.

We don't send marketing emails. If we ever start a newsletter, we will only send it to people who opt in.

3. Cookies and local storage

Our site sets no cookies and uses no analytics or advertising trackers, so there is no cookie banner. We use one thing on your device:

NameTypePurposeDuration
discipline-bag2Local storage (stays in your browser, never sent to us)Remembers what's in your bag and your shipping region, which you asked forUntil you empty your bag or clear your browser data

This is strictly necessary for the service you request, so it doesn't need consent under the ePrivacy rules.

When you go to checkout you are on Stripe's payment page (checkout.stripe.com), where Stripe uses its own cookies for payment and fraud prevention. See Stripe's cookie policy.

4. Who we share it with

Only with the companies we need to run the shop, and only what each one needs:

WhoWhat forRole
Stripe Payments Europe, Ltd. (Ireland)Checkout page, payment, fraud prevention, receiptsProcessor for checkout; independent controller for payment processing, fraud and its legal duties (Stripe privacy policy)
Google Ireland Limited (Firebase Hosting and Cloud Functions, servers in Belgium and a global delivery network)Hosting the site and creating the checkout sessionProcessor
Cloudflare, Inc. (USA)Email Routing: receives emails sent to hello@discipline.fashion and forwards them to our mailbox; also runs our domain's DNSProcessor
Resend (USA)Sending our emails: your order confirmation and, if you use it, the withdrawal confirmationProcessor
DHLDelivering your parcel (name, address, phone, email for notifications)Independent controller
Customs authorities of the destination countryImport clearance for deliveries outside the EUIndependent controller
Meta Platforms Ireland Ltd. (Instagram)If you message us on Instagram, Meta processes that conversation. For our Instagram page statistics, Meta and we are joint controllers (Page Insights addendum)Independent / joint controller

We may also disclose data when the law requires it, for example to a court or a tax authority. If the business is ever sold, the buyer would take over your data under this same policy.

5. Transfers outside Europe

Some of our providers (Stripe, Google, Meta, Cloudflare, Resend) are part of US groups and may access data from the United States. Those transfers are covered by the EU-US Data Privacy Framework where the company is certified, and otherwise by the European Commission's Standard Contractual Clauses. If we ship to you outside Europe, your delivery details necessarily go to the carrier and customs in your country (art. 49(1)(b) GDPR). Ask us for a copy of the safeguards if you want one.

6. How long we keep it

DataKept for
Orders, invoices and payment records5 years from the end of the year in which the related tax became due, as Polish tax and accounting law requires
Messages, returns and guarantee claimsUntil the matter is closed, then 2 years; longer only if needed for a dispute. Guarantee-related records until the 2-year guarantee has run out.
Server logsUp to 30 days
Bag in local storageOn your device, until you clear it

7. Your rights

You have the right to:

Write to hello@discipline.fashion. We answer within one month, free of charge, and may ask you to confirm your identity (usually by writing from the email you ordered with).

You can also complain to a data protection authority. Ours is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl. You can also go to the authority in the country where you live or work.

8. For US residents

9. Security

The site runs over HTTPS only. Payments are handled by Stripe, which is certified to PCI DSS Level 1; card numbers never reach us. Access to order data is limited to the people who need it. If a breach ever put your data at risk, we would tell you and the authority as the law requires.

10. Children

The shop is not meant for children under 16, and we don't knowingly collect data from children under 16 (under 13 in the US). If you think a child has given us data, tell us and we will delete it.

11. Changes

If we change how we use your data, we will update this page and its date. If a change is significant, we will say so on the site, and tell customers affected by email.