Last updated: March 2026
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Payment notifications | Contract |
| Feedback messages | Service improvement | Legitimate interest |
| Analytics cookies | Usage statistics | Consent |
| Payment data | Processing transactions | Contract |
| IP address | Security, rate limiting | Legitimate interest |
We share data with GDPR-compliant processors:
Payment card details are processed exclusively by Stripe and never stored on our servers.
Withdraw consent by clearing browser cookies and revisiting the site.
Under GDPR you have the right to: access, rectification, erasure, restriction, portability, and objection.
Contact us at spillsome.coffee/feedback. We respond within 30 days.
We use HTTPS encryption, rate-limited authentication, and row-level database security.
Lodge complaints with the Slovak Office for Personal Data Protection (dataprotection.gov.sk).
We may update this policy. Changes will be posted here with an updated date.