Privacy Policy

1. Introductory Provisions

Your trust is important to us, which is why we place great emphasis on personal data protection. These Privacy Policy provide detailed information on how we handle your personal data when using our services through the online store [store name].

These policies are in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Act No. 110/2019 Coll. on the processing of personal data, and other applicable legislation.

2. Personal Data Controller

Store name: Tipsy.cz

Operator: Quang Thang Bui

Registered office: Štanderova 887/1, 199 00, Prague 9 - Letňany

Company ID: 05833825

VAT ID: CZ9303154245

Registered in the Trade Register: Prague 18 Municipal District Office

Phone: +420 773 153 199

E-mail: tipsycz2025@gmail.com

Data Box ID: emzajh2

3. What Personal Data We Process

We process the following categories of personal data:

Identification data: first name, surname, date of birth, age (age verification for alcohol and e-cigarette sales)

Contact details: address, e-mail, phone number

Purchase and transaction data: order history, payment method, delivery information

Loyalty program data: registration and customer section usage data

Login data: username, password (encrypted)

Technical data: IP address, cookies, access logs (see separate document Cookie Policy)

4. Legal Basis and Purposes of Processing

We process your data based on the following legal grounds and for these purposes:

Purpose of Processing

Legal Basis

Conclusion and performance of the purchase contract

Art. 6(1)(b) GDPR

Compliance with legal obligations (e.g. tax, accounting)

Art. 6(1)(c) GDPR

Age verification for alcohol and e-cigarette sales

Art. 6(1)(c), (e) GDPR (compliance with legal obligation, task carried out in the public interest)

Management of customer account and loyalty program

Art. 6(1)(b) GDPR (necessary for contract performance)

Marketing purposes (newsletter distribution)

Art. 6(1)(a) GDPR (consent)

Protection of legal claims

Art. 6(1)(f) GDPR (legitimate interest)

Technical/necessary cookies

Art. 6(1)(f) GDPR (legitimate interest)

Functional, analytical and marketing cookies

Art. 6(1)(a) GDPR (consent)

Your consent is revocable at any time using the contact details above or, in the case of newsletter subscription, also by sending an e-mail to info@activefishing.cz

You can also unsubscribe from the newsletter by clicking the unsubscribe link in every marketing e-mail.

5. Retention Period of Personal Data

We retain your personal data only for as long as is necessary to fulfill the purposes of processing:

Order data incl. payment and transaction details: 10 years from the last order (according to tax and accounting regulations).

Customer account data: as long as the account is active.

Marketing data: until consent is withdrawn; no longer than 5 years.

Cookie data: according to the rules outlined in the Cookie Policy.

6. Recipients and Sharing of Personal Data

Your personal data may be shared with the following categories of recipients:

  • IT and hosting service providers
  • Carriers and logistics companies
  • Accounting and tax advisors
  • Marketing service providers
  • Public authorities (e.g. tax office, Czech Trade Inspection Authority) where required by law
  • Payment processing companies
  • PPL CZ s.r.o.

A specific list of recipients of personal data in a given case will be provided to the data subject upon exercising their right of access (see below).

7. Transfers to Third Countries

Personal data recipients may be persons who:

  • are involved in delivering goods/services or processing payments based on the contract,
  • provide e-shop operation services (Shoptet) and other services related to the operation of the e-shop,
  • provide marketing services.

We generally do not transfer your personal data to third countries outside the EU or to international organizations, except in cases where services use servers outside the EU (e.g. Google Analytics), always under the condition of ensuring an adequate level of protection according to Art. 46 et seq. GDPR.

8. Data Subject Rights

  • You have the following rights under Articles 12–22 of the GDPR:
  • Right of access to your personal data (Art. 15)
  • Right to rectification of inaccurate or incomplete data (Art. 16)
  • Right to erasure of personal data (so-called "right to be forgotten", Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object to processing (Art. 21)
  • Right to withdraw consent to processing (Art. 7(3))
  • Right not to be subject to automated decision-making, including profiling (Art. 22)
  • Right to lodge a complaint with a supervisory authority (Office for Personal Data Protection – www.uoou.cz)

To exercise your rights, please contact us using the contact details above.

If we do not take action on your request in connection with the exercise of your rights without delay and at the latest within one month of receipt of your request, we will inform you of the reasons and you may lodge a complaint with the supervisory authority or seek judicial remedy.

9. Organizational and Technical Measures

We have implemented appropriate technical and organizational measures to ensure the protection of personal data, especially against:

  • unauthorized access,
  • loss,
  • destruction, or
  • misuse.

These measures include, for example, password encryption, two-factor authentication for admin access, regular system updates, employee training, data pseudonymization, and regular backups.

10. Cookies

Our website uses cookies. Details on their use, including options for refusal or preference settings, can be found in the separate document Cookie Policy.

11. Changes to the Policy

These policies may be updated from time to time. We recommend checking them regularly. We will inform you of any significant changes in an appropriate manner (e.g., through your customer account or on our website).