Privacy Policy
1. Introduction
Welcome to The Boost ("we," "us," or "our"). We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and other applicable data protection legislation.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our online store at the-boost-2.myshopify.com, place an order, or otherwise interact with our services. It applies to all visitors, customers, and users of our website.
By using our website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our website.
2. Data Controller
The data controller responsible for your personal data is:
The Boost
ul. Marszałkowska 100
00-026 Warsaw, Poland
Email: contact@theboost.store
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at the email address above.
3. What Data We Collect
We collect and process the following categories of personal data:
3.1 Personal Data
- Full name (first and last name)
- Email address
- Phone number
- Shipping address
- Billing address
3.2 Order Data
- Products purchased and order history
- Payment information (processed securely by our payment providers; we do not store full credit card numbers)
- Transaction records and invoices
- Order status and delivery information
3.3 Technical Data
- IP address
- Browser type and version
- Device type and operating system
- Screen resolution
- Referring website URL
- Pages visited and time spent on our website
3.4 Cookies and Tracking Data
- Session identifiers
- Shopping cart contents
- User preferences
- Analytics data (see Section 7 for details)
4. How We Use Your Data
We use your personal data for the following purposes:
4.1 Processing and Fulfilling Orders
- Processing your purchases and payments
- Arranging shipping and delivery of your orders
- Providing order confirmation and tracking information
- Handling returns, refunds, and exchanges
4.2 Communicating About Orders
- Sending order confirmation emails
- Providing shipping updates and delivery notifications
- Responding to your inquiries and support requests
- Notifying you of any issues with your order
4.3 Improving Our Website and Services
- Analyzing website usage patterns to improve user experience
- Optimizing our product offerings
- Troubleshooting technical issues
- Conducting internal research and analytics
4.4 Legal Obligations
- Complying with tax and accounting requirements
- Responding to lawful requests from authorities
- Preventing fraud and ensuring security
- Enforcing our Terms of Service
5. Legal Basis for Processing (GDPR Art. 6)
We process your personal data based on the following legal grounds under Article 6 of the GDPR:
5.1 Contract Performance — Art. 6(1)(b)
Processing is necessary for the performance of a contract with you, specifically to fulfill your orders, process payments, arrange shipping, and provide customer support related to your purchases.
5.2 Legitimate Interest — Art. 6(1)(f)
Processing is necessary for our legitimate interests, including improving our website, preventing fraud, ensuring network security, and conducting business analytics. We carefully balance our interests against your rights and freedoms.
5.3 Consent — Art. 6(1)(a)
Where we rely on your consent (for example, for marketing communications or non-essential cookies), you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
5.4 Legal Obligation — Art. 6(1)(c)
Processing is necessary to comply with our legal obligations, including tax reporting, accounting regulations, and responding to lawful requests from public authorities.
6. Third-Party Data Processors
We share your personal data with the following third-party service providers who process data on our behalf. Each processor is contractually obligated to protect your data and use it only for the specified purposes:
6.1 Shopify Inc.
Our e-commerce platform. Shopify processes your personal and order data to operate our online store. Shopify's privacy practices are governed by their Privacy Policy.
6.2 PayPal (Europe) S.à r.l. et Cie, S.C.A.
Payment processing provider. PayPal processes your payment information to complete transactions securely. For more information, see PayPal's Privacy Policy.
6.3 Klarna Bank AB
Payment processing provider offering flexible payment options. Klarna processes your personal and payment data to facilitate transactions. See Klarna's Privacy Policy for details.
6.4 CJ Dropshipping
Order fulfillment partner. CJ Dropshipping receives your name, shipping address, and order details to fulfill and ship your orders. Their data processing is limited to what is necessary for order fulfillment.
6.5 Shipping Carriers
Various shipping and logistics companies (including but not limited to DHL, DPD, and other carriers) receive your name, shipping address, and contact details to deliver your orders.
7. Cookies
Our website uses cookies and similar technologies to ensure proper functionality and improve your experience.
7.1 Essential Cookies
These cookies are strictly necessary for the operation of our website. They include:
- Session cookies — maintain your browsing session
- Cart cookies — remember items in your shopping cart
- Authentication cookies — keep you logged in to your account
- Security cookies — help prevent fraudulent activity
Essential cookies cannot be disabled as they are required for the website to function.
7.2 Analytics Cookies
We use Shopify Analytics to understand how visitors interact with our website. These cookies collect information such as pages visited, time spent on pages, and how you arrived at our site. This data is aggregated and anonymized where possible.
7.3 Managing and Disabling Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to:
- View what cookies are stored and delete them individually
- Block third-party cookies
- Block cookies from specific sites
- Block all cookies
- Delete all cookies when you close your browser
Please note that disabling essential cookies may affect the functionality of our website, including the ability to place orders.
8. Data Transfers Outside the EU
Some of our third-party service providers are based outside the European Economic Area (EEA). When your personal data is transferred outside the EEA, we ensure appropriate safeguards are in place:
8.1 Shopify Inc. (Canada/United States)
Shopify processes data in Canada and the United States. Transfers to the US are protected under the EU-US Data Privacy Framework. Shopify is also bound by Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate data protection.
8.2 Standard Contractual Clauses
Where the EU-US Data Privacy Framework does not apply, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission (Decision 2021/914) to safeguard your personal data during international transfers. These clauses contractually obligate the data recipient to protect your data to EU standards.
You may request a copy of the safeguards in place by contacting us at contact@theboost.store.
9. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:
9.1 Order Data
Order records, invoices, and transaction data are retained for the period required by applicable tax and accounting legislation (typically 6 to 10 years, depending on jurisdiction), after which they are securely deleted.
9.2 Account Data
If you create an account, your personal data is retained until you request deletion of your account. Upon receiving a deletion request, we will erase your data within 30 days, except where retention is required by law.
9.3 Technical Data
Technical data such as IP addresses, browser information, and usage logs are retained for up to 12 months for security and analytics purposes, after which they are anonymized or deleted.
10. Your Rights Under the GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data:
10.1 Right of Access (Art. 15)
You have the right to obtain confirmation as to whether your personal data is being processed and, if so, to request access to that data along with information about how it is used.
10.2 Right to Rectification (Art. 16)
You have the right to request correction of inaccurate personal data and to have incomplete data completed.
10.3 Right to Erasure / Right to Be Forgotten (Art. 17)
You have the right to request the deletion of your personal data where it is no longer necessary for the purpose it was collected, where you withdraw consent, or where there is no overriding legitimate ground for processing.
10.4 Right to Restrict Processing (Art. 18)
You have the right to request restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
10.5 Right to Data Portability (Art. 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
10.6 Right to Object (Art. 21)
You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes. Upon objection, we will cease processing unless we demonstrate compelling legitimate grounds.
10.7 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
10.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. If you are located in Poland, the relevant authority is:
Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2
00-193 Warsaw, Poland
Website: https://uodo.gov.pl
You may also contact the supervisory authority in your country of residence within the EU/EEA.
11. Contact for Data Requests
To exercise any of your rights under the GDPR, or if you have any questions or concerns about how we process your personal data, please contact us:
The Boost — Data Protection
Email: contact@theboost.store
Address: ul. Marszałkowska 100, 00-026 Warsaw, Poland
We will respond to your request within 30 days. In exceptional circumstances, we may extend this period by an additional 60 days, in which case we will inform you of the extension and the reasons for it.
12. Changes to This Policy
We reserve the right to update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date below and, where appropriate, notify you via email or a prominent notice on our website.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
Last Updated: February 2026