Privacy Policy
This Privacy Policy explains how Meest Post sp. z o.o. processes personal data of persons using the website, portal, mobile application and services available under the Polonez marketing name.
Polonez is a marketing name used for the website, web portal, mobile application, and the services provided through them. It does not refer to or constitute a separate legal entity.
1. Data Controller
The controller of personal data is:
Meest Post sp. z o.o. with its registered office in Warsaw, entered in the register of entrepreneurs of the National Court Register under KRS number 0001027880, share capital: PLN 10,000.00, hereinafter referred to as the “Controller” or “we”.
The Controller has appointed a Data Protection Officer. The Data Protection Officer can be contacted at: [email protected].
2. Scope of the Policy
This Policy applies to the processing of personal data in connection with the use of Polonez services, in particular:
- the website,
- the portal for creating and managing shipments,
- the mobile application,
- the user account,
- the shipment calculator,
- contact forms,
- shipment creation forms,
- the address book and list of recipients,
- shipment tracking,
- newsletter and marketing communication,
- payment handling, complaints, returns and claims.
3. Who may use the services
The shipment service is not directed at children. An account and an order for the service may be created only by an adult with full legal capacity.
If we learn that an account has been created by a minor, we may take steps to restrict access to the account or delete the data, unless legal provisions require further retention of the data.
4. Sources of personal data
We obtain personal data primarily:
- directly from the user during registration, login, profile completion, shipment creation, contact with us or subscription to marketing communication;
- from the user who provides the recipient’s data;
- from entities involved in handling the shipment, payment, customs clearance or delivery;
- automatically when the user uses the website, portal or application, for example through cookies, device identifiers, technical logs or analytical tools.
5. What data we process
The scope of data depends on how our services are used.
5.1. Registration and login data
For account creation and login, we may process:
- email address,
- telephone number,
- authentication data,
- one-time verification code,
- account identifier,
- information about the login method,
- data related to login through Google or Apple, if the user selects such a login method,
- technical data related to login and account security.
The use of selected portal or application functionalities requires creating an account or logging in to an existing account. Placing an order without an account is not available.
5.2. User profile and sender data
As part of the user profile and sender data, we may process:
- first name,
- middle name, if provided,
- last name,
- email address,
- telephone number,
- account settings, such as language, currency and units of measurement,
- history of shipments and orders created under the account,
- saved addresses and recipients.
5.3. Address data
As part of address data, we may process:
- address name,
- country,
- address found through the address search tool, if the user uses it,
- state, region or province,
- postal code,
- city,
- street,
- house or building number,
- apartment, unit or room number, if provided,
- information whether the address has been marked as default.
5.4. Recipient data
For shipment delivery purposes, we may process recipient data provided by the sender, in particular:
- first and last name,
- address,
- telephone number,
- email address,
- data necessary to deliver the shipment,
- data saved in the recipient address book, if this functionality is used.
The sender should provide recipient data only where the sender is authorised to provide such data for the purpose of creating and delivering the shipment.
5.5. Shipment data
In connection with shipment handling, we may process:
- shipment number,
- sender and recipient data,
- method of sending and delivery,
- place of sending and delivery,
- weight, dimensions and declared value,
- description of contents,
- shipment status information,
- information about events in the delivery process,
- data concerning surcharges, returns, non-delivery or complaints.
5.6. Customs data and data concerning shipment contents
For shipments requiring customs handling, we may process and disclose to appropriate logistics partners, customs clearance service providers and public authorities:
- sender data: first name, last name, telephone number, email address and address,
- recipient data: first name, last name, telephone number, email address and address,
- information about the shipment contents, including product name, HS code, quantity, weight, country of origin, value and other information required by customs, tax, export, import regulations or the law of the country of delivery.
These data are processed to prepare documentation, invoices and declarations, and to fulfil obligations related to customs clearance and shipment delivery.
5.7. Payment data
For payment for the service, we process data necessary to handle the payment, in particular:
- payment amount,
- selected payment method,
- transaction identifier,
- payment status,
- information necessary to assign the payment to the order,
- information about any surcharges, refunds or payment complaints.
Payment for the service is made in advance using available electronic payment methods, in particular payment card, PayPal, Apple Pay and Google Pay.
Payment handling may be performed through an external payment service provider, in particular ZEN.COM, or other providers appropriate for the selected payment method.
The Controller does not store full user payment card details. Card data and other data necessary to authorise payment are processed by the payment service provider in accordance with its rules and security requirements. The Controller receives information necessary to handle the order, in particular the transaction identifier and payment status.
5.8. Contact and complaint data
If the user contacts us, submits a complaint, reports a technical issue or sends us a question, we may process:
- first and last name,
- email address,
- telephone number,
- shipment number,
- order data,
- content of correspondence,
- attachments,
- data concerning the complaint, claim or report,
- information on how the matter was handled.
5.9. Marketing data
If consent to marketing communication is given, we may process:
- email address,
- telephone number,
- user identifier,
- information about consents given,
- date and source of consent,
- date of subscription confirmation, if double opt-in is used,
- information about withdrawal of consent,
- information about messages sent,
- data concerning interactions with marketing communication, e.g. message opening or link clicking, if such data are collected by the marketing tool.
Marketing communication may include email, SMS, web push and in-app notifications.
5.10. Technical data, cookies and analytical data
When the user uses the website, portal or application, we may process:
- IP address,
- cookie identifiers,
- device identifiers,
- browser type and version,
- operating system,
- date and time of visit,
- activity data on the website, in the portal or application,
- diagnostic data,
- technical logs,
- error information,
- security-related data.
We may use in particular tools such as Google Analytics, reCAPTCHA, Firebase, Firebase Crashlytics, AppsFlyer and SendPulse.
5.11. Mobile application data
When the mobile application is used, we may process:
- device identifier,
- technical device data,
- diagnostic data,
- application error data,
- push notification tokens,
- information about notification settings,
- data concerning interactions with the application.
The application may use location data only when the user opens the map and gives the appropriate consent in the device settings. Location data are not stored after the map function is used, unless the user independently saves a specific address or point as part of an order or the address book.
6. Purposes and legal bases for data processing
We process personal data for the following purposes:
- Purpose: account creation and management; data categories: registration data, login data, profile data; legal basis: Article 6(1)(b) GDPR.
- Purpose: user authentication and account security; data categories: email, telephone, verification code, logs, technical data; legal basis: Article 6(1)(b) and (f) GDPR.
- Purpose: acceptance and performance of a shipment order; data categories: sender, recipient, shipment, address and contact data; legal basis: Article 6(1)(b) GDPR.
- Purpose: organisation of transport, delivery, storage and logistics handling; data categories: sender, recipient, shipment data, statuses, address data; legal basis: Article 6(1)(b) GDPR.
- Purpose: customs, export, import and tax handling; data categories: sender data, recipient data, shipment contents data, customs documents; legal basis: Article 6(1)(c) GDPR and Article 6(1)(b) GDPR.
- Purpose: payment handling; data categories: transaction identifier, payment status, payment method, amount; legal basis: Article 6(1)(b) GDPR.
- Purpose: accounting and tax settlements; data categories: order data, payment data, accounting documents; legal basis: Article 6(1)(c) GDPR.
- Purpose: handling user contact; data categories: contact data, inquiry content, correspondence; legal basis: Article 6(1)(b) or (f) GDPR.
- Purpose: handling complaints, returns, non-deliveries and claims; data categories: shipment data, contact data, documents, correspondence; legal basis: Article 6(1)(b), (c) or (f) GDPR.
- Purpose: pursuing and defending claims; data categories: order, shipment, payment, complaint and correspondence data; legal basis: Article 6(1)(f) GDPR.
- Purpose: ensuring the security of the website, portal, application and services; data categories: logs, IP, technical data, security data; legal basis: Article 6(1)(f) GDPR.
- Purpose: preventing abuse; data categories: account data, order data, payment data, logs, technical data; legal basis: Article 6(1)(f) GDPR.
- Purpose: analytics and statistics; data categories: cookie data, technical data, activity data; legal basis: user consent or Article 6(1)(f) GDPR, depending on the type of tool.
- Purpose: marketing communication; data categories: email, telephone, consents, marketing dispatch data; legal basis: Article 6(1)(a) GDPR and consent required by electronic communication regulations.
- Purpose: push notifications; data categories: push token, device settings, account identifier; legal basis: user consent or Article 6(1)(b)/(f) GDPR, depending on the type of notification.
- Purpose: application diagnostics and error removal; data categories: technical data, device data, error data; legal basis: Article 6(1)(f) GDPR.
The Controller’s legitimate interest consists in particular in ensuring service security, handling inquiries, pursuing and defending claims, preventing abuse, conducting internal analyses and ensuring the proper operation of the website, portal and application.
7. Is providing data mandatory
Providing data is voluntary, but certain data are necessary to:
- create an account,
- log in to the account,
- place an order,
- send and deliver a shipment,
- handle payment,
- perform customs clearance,
- handle a complaint,
- respond to an inquiry,
- comply with legal obligations.
Failure to provide data required to perform the service may prevent account creation, order placement, shipment creation, payment processing, customs clearance or shipment delivery. Providing data for marketing purposes is voluntary.
8. To whom we disclose data
We may disclose personal data to the following categories of recipients:
- carriers, couriers and logistics operators,
- FedEx Express Poland sp. z o.o. and entities within the FedEx network, if they participate in shipment handling,
- entities handling customs clearance, export, import, middle-mile and last-mile transport,
- operators of sending and pickup points,
- parcel locker operators,
- warehousing entities,
- IT system, hosting and cloud infrastructure providers,
- providers of analytical, diagnostic and marketing tools,
- mobile application and SDK providers,
- payment service providers, in particular ZEN.COM and providers appropriate for the selected payment method,
- newsletter and marketing communication service providers, in particular SendPulse,
- login service providers, e.g. Google or Apple, if the user selects such login method,
- law firms, tax advisers, auditors and entities supporting us in pursuing or defending claims,
- customs, tax and administrative authorities, courts, law enforcement authorities and other public authorities where required by law.
We disclose data only to the extent necessary to achieve the relevant purpose.
9. Transfers of data outside the European Economic Area
Due to the international nature of the services, personal data may be transferred outside the European Economic Area, in particular where this is necessary for:
- handling an international shipment,
- customs clearance,
- delivery of the shipment in the destination country,
- tracking support,
- providing technical support,
- using providers of IT, analytical, diagnostic, marketing or payment tools,
- access to systems by authorised IT teams located outside the EEA.
Data may be transferred in particular to the United States, Canada, the United Kingdom, Ukraine or other countries, if justified by the scope of the service, the recipient’s location, the shipment route, the technology provider’s location or the place where the support team operates.
If data are transferred to a country for which the European Commission has issued an adequacy decision, the transfer takes place on the basis of that decision.
If data are transferred to a country for which no adequacy decision has been issued, we apply appropriate safeguards provided for by the GDPR, in particular the European Commission’s standard contractual clauses, additional technical and organisational measures, restricting access to data to authorised persons, data minimisation, transmission encryption, access control and logging, multi-factor authentication, and security and incident handling procedures.
In the case of providers such as Google, Firebase, reCAPTCHA, AppsFlyer, SendPulse or other online service providers, transfers may take place on the basis of mechanisms applied by those providers, including standard contractual clauses, adequacy decisions or other solutions provided for by the GDPR.
10. Cookies and similar technologies
The website, portal and application may use cookies, online identifiers, SDKs, pixels, tags and similar technologies.
These technologies may be used to:
- ensure the proper operation of the website, portal and application,
- maintain the user session,
- remember user settings,
- ensure security,
- detect errors and abuse,
- compile statistics,
- analyse how the services are used,
- measure the effectiveness of marketing activities,
- conduct marketing communication.
We may use in particular the following tools: Google Analytics, reCAPTCHA, Firebase, Firebase Crashlytics, AppsFlyer, SendPulse and technical tools necessary for the operation of the portal and application.
Cookies and similar technologies are divided into necessary, analytical, functional and marketing technologies. Necessary cookies are used on the basis of the Controller’s legitimate interest in ensuring the operation of the services. Analytical, marketing and other technologies not required for the operation of the service are used on the basis of the user’s consent, where such consent is required.
The user may manage cookie consents using the cookie settings panel or in the browser settings.
A detailed list of cookies and similar technologies, including the name, provider, purpose, category and retention period, may be made available in the cookie panel or in a separate cookie table.
11. Google Analytics, reCAPTCHA and Firebase
We may use Google tools such as Google Analytics, reCAPTCHA and Firebase.
Google Analytics helps us analyse how the website, portal or application is used. reCAPTCHA helps protect forms and systems against spam, abuse and automated activity. Firebase and Firebase Crashlytics help operate the mobile application, analyse application performance, detect errors and improve stability.
In connection with the use of these tools, providers may process technical data, online identifiers, device data, activity data and diagnostic data. Data may be transferred outside the EEA in accordance with the rules and transfer mechanisms used by the providers.
12. AppsFlyer
We may use AppsFlyer to analyse application installations, use of the application, campaign effectiveness and user acquisition sources.
For this purpose, technical data, device identifiers, data about interactions with the application and data concerning installation or use of the application may be processed.
13. Newsletter and marketing communication
If the user gives consent, we may send marketing information concerning our services, offers, promotions, news or similar content.
Marketing communication may be conducted by email, SMS, web push and in-app notifications.
Consent to marketing communication is voluntary and may be withdrawn at any time. For the newsletter, we may use a double opt-in mechanism, which means that after subscribing, the user receives a message asking for subscription confirmation.
We may use external providers, in particular SendPulse, to handle marketing communication. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
The user may withdraw consent in particular by clicking the unsubscribe link in the email, changing account or application settings, changing notification settings on the device or contacting us at [email protected].
14. Service-related notifications
Regardless of marketing communication, we may send the user messages related to the performance of the service, such as:
- confirmation of account creation,
- login code,
- order confirmation,
- payment information,
- shipment status information,
- customs clearance information,
- complaint information,
- security messages,
- technical information concerning the account or application.
Such messages are sent to perform the contract, ensure security or comply with legal obligations and do not constitute marketing communication.
15. Profiling and automated decisions
We do not make decisions concerning users based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them.
We do not use user data for profiling in order to automatically block accounts or shipments. Decisions concerning shipments, accounts, complaints or customer service are made by authorised employees or collaborators.
For payments, the payment service provider may apply its own security mechanisms, anti-abuse measures and transaction risk assessment. Such actions are carried out in accordance with the rules of the relevant payment provider.
16. How long we retain data
We retain personal data for the period necessary to achieve the purposes for which the data were collected, and subsequently for the period required by law or necessary to pursue or defend claims.
- Account data - for the duration of the account.
- Account data after account deletion - only to the extent necessary to defend claims or comply with legal obligations.
- Order and shipment data - 6 years from the end of the year in which the service was performed or the order was completed.
- Customs data and clearance documents - for the period required by customs, tax or other applicable laws and for the limitation period for claims.
- Payment data, including transaction identifier and payment status - for the period required for accounting, tax or order documentation purposes.
- Complaints and grievances - 6 years from the completion of the complaint or grievance procedure.
- Correspondence from the contact form - until the matter is closed and then for a maximum of 3 years, unless the matter concerns claims.
- Marketing consents - for the duration of marketing communication and, after consent withdrawal, for the period necessary to demonstrate that consent was given and withdrawn.
- Technical logs - as a rule, 12 months, unless longer retention is necessary for security, technical or claim-related reasons.
- Cookies and similar technology data - according to the period specified in the cookie panel or cookie table.
- Application diagnostic data - for the period necessary to analyse and remove errors, according to the settings of the relevant tool.
After the relevant period expires, data are deleted, anonymised or restricted, unless further processing is required by law.
17. Rights of data subjects
A person whose data are processed has the rights resulting from the GDPR, in particular:
- the right of access to data,
- the right to receive a copy of the data,
- the right to rectification of data,
- the right to erasure of data,
- the right to restriction of processing,
- the right to data portability,
- the right to object to data processing,
- the right to withdraw consent at any time, where processing is based on consent,
- the right to lodge a complaint with the President of the Personal Data Protection Office.
To exercise these rights, the Data Protection Officer may be contacted at: [email protected].
The exercise of certain rights may depend on the legal basis for data processing and on the obligations imposed on the Controller. For example, a request for erasure of data may not always be fulfilled immediately if the data are still needed to comply with legal obligations, settlements, complaint handling, or pursuing or defending claims.
18. Right to object
The user has the right to object to the processing of personal data if we process the data on the basis of our legitimate interest.
If an objection is raised, we will stop processing the data unless we demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for establishing, pursuing or defending claims.
If data are processed for direct marketing purposes, the user may object at any time. After such objection, we will no longer process the data for that purpose.
19. Data security
We apply technical and organisational measures appropriate to the risk related to the processing of personal data.
These measures may include in particular:
- access control for systems,
- granting authorisations only to persons who need access to data,
- transmission encryption,
- user authentication,
- recording events and logs,
- IT infrastructure safeguards,
- backups,
- incident handling procedures,
- contracts with service providers,
- limiting the scope of data disclosed to third parties,
- periodic security reviews.
Access to data is granted only to persons and entities that need it to perform their tasks.
20. Data of shipment recipients
If the user provides the recipient’s data, the user does so for the purpose of performing the delivery service.
We process recipient data to the extent necessary to create the shipment, prepare documents, handle customs clearance, transport, delivery, contact regarding the shipment, handle a complaint, return or non-delivery, and comply with legal obligations.
The shipment recipient may exercise their GDPR rights by contacting the Data Protection Officer at [email protected].
21. Data disclosed to public authorities
In certain situations, we may be required to disclose personal data to public authorities, in particular customs authorities, tax authorities, administrative authorities, courts, law enforcement authorities and other authorities authorised by law.
Data are disclosed only where there is an appropriate legal basis.
22. Links to external websites
The website, portal or application may contain links to external websites or services, e.g. payment providers, app stores, login providers or technology partners.
We are not responsible for privacy practices applied by independent third parties. We recommend reading their privacy policies before using their services.
23. Changes to the Privacy Policy
We may update this Privacy Policy in the event of changes in law, the scope of services, functionality of the website, portal or application, technology providers, the way data are processed, or organisational changes on the Controller’s side.
The current version of the Privacy Policy is published on the website.
If a change is material, we may also inform users through another available channel, e.g. through the user account, email or an in-app message.
This Privacy Policy enters into force on 13 July 2026.