Privacy Policy
Last updated: 01.10.2026
This Policy explains what personal data we process when you use poihaly.com, for what purposes and on what legal basis, who receives it, how long we keep it and what rights you have. It is provided under Article 13 of the General Data Protection Regulation (GDPR).
1. Controller and contact
The controller of your personal data is Ivan Obodianskyi, a sole trader (jednoosobowa działalność gospodarcza, CEIDG), NIP 5223295851, REGON 528428640, address: ul. Zdzisława Beksińskiego 6/38, 03-184 Warszawa, Polska.
For any data protection matter, email [email protected] or call +48 600 438 284.
2. Data we process
Contact data: name, email, phone number.
Passenger data needed for the ticket: passenger names, seat, boarding and alighting points and, optionally, addresses for door-to-door pickup and a note to the carrier.
Account data: email, password hash, sign-in sessions.
Payment status. Card data is handled only by Stripe — we never see your card number.
Messages sent via the contact form and your email for the newsletter.
Technical data: IP address, device and browser data, cookies.
3. Purposes and legal bases
Booking a ticket, performing the contract and running your account — Art. 6(1)(b) GDPR (performance of a contract).
Meeting legal obligations, in particular accounting and tax — Art. 6(1)(c) GDPR (legal obligation).
Security of the service, fraud prevention, handling complaints and claims, service messages — Art. 6(1)(f) GDPR (legitimate interests).
Analytics cookies (Google Analytics) and the newsletter — Art. 6(1)(a) GDPR (consent). You can withdraw consent at any time; this does not affect the lawfulness of processing before withdrawal.
4. Who receives the data
The carrier of the booked trip — it receives passenger data to perform the carriage and is a separate controller of that data.
If the carrier has turned this on, booking notifications may be delivered to its staff via Telegram.
Processors acting on our behalf:
Contabo GmbH — server hosting, data centre in the EU (France/Germany).
Cloudflare, Inc. (USA) — CDN, site security and encrypted daily backups in Cloudflare R2.
Brevo (Sendinblue SAS, France) — sending emails.
Stripe Payments Europe, Ltd. (Ireland) — payment processing.
Google Ireland Ltd. (Ireland) — Google Analytics, only with your consent.
We do not sell your personal data.
5. Transfers outside the EEA
Cloudflare, Google and Telegram may process data outside the European Economic Area.
Such transfers rely on the EU-US Data Privacy Framework or on Standard Contractual Clauses.
6. Retention
Booking and accounting data — 5 years from the end of the calendar year.
Account data — until the account is deleted.
Contact-form messages — up to 2 years.
Newsletter email — until you unsubscribe.
Analytics data — as described in the Cookie Policy, up to 2 years.
7. Your rights
You have the right to access, rectify and erase your data, to restrict its processing, to data portability, to object to processing and to withdraw consent.
To exercise your rights, email [email protected].
You can delete your account yourself in the account settings.
8. Complaint to the supervisory authority
You have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, PUODO), ul. Stawki 2, 00-193 Warszawa.
9. Cookies
We use cookies. Analytics cookies are set only with your consent. Details are in the Cookie Policy at /cookies.
10. Providing data is voluntary
Providing data is voluntary but necessary to book a ticket. Without it we cannot complete the booking.
11. Automated decision-making
We do not make decisions about you based solely on automated processing and do not carry out profiling that has legal effects for you.
12. Children
The service is not intended for children under 16 to create accounts.
13. Changes to this Policy
We may update this Policy. The current version is always published on this page with its last-updated date.
14. Effective date
This Policy applies from 01.10.2026.