Privacy and Cookie Policy

Effective date: 15 August 2026

This Privacy and Cookie Policy explains how personal data is collected and used when you visit voidofcoursemoon.com/store, buy a digital calendar, download a purchased file, contact customer support, or choose to receive marketing emails.

1. Who is responsible for your personal data?

The controller of your personal data is Void of Course Moon Site as a registered activity in Poland.

You can contact the controller about privacy or data protection at store@voidofcoursemoon.com.

No Data Protection Officer has been appointed because there is currently no legal requirement to appoint one.

2. What personal data do we collect?

Depending on how you use the store, we may process:

  • Order and identity data: first name, last name, email address, order number, purchased product and time-zone edition, price, currency, discount information, payment status, refund information, and the date and time of the order.
  • Payment-related data: payment method, payment status, transaction identifiers, and limited information returned by the payment provider. Payment details such as full card numbers and card security codes are entered in Stripe’s secure payment environment and are not stored by us.
  • Digital-delivery data: download-link creation, delivery status, and technical records relating to access to the purchased file, where generated by WooCommerce or the hosting environment.
  • Customer-support data: the contents of messages, attachments you choose to send, and information needed to identify and resolve an order or download issue.
  • Newsletter data: email address, first and last name where available, consent status and date, subscription source, unsubscribe status, and — where MailerLite e-commerce features are enabled — relevant purchase and campaign-interaction data.
  • Technical and usage data: IP address, browser and device information, operating system, language, date and time of access, page requests, security logs, cookie identifiers, referring URL, UTM campaign parameters, traffic source, device type, and session page-view information.
  • Records of choices and compliance: acceptance of contractual terms, privacy notices presented at checkout, cookie choices, marketing consent, requests concerning personal data, and evidence needed to demonstrate compliance.

We normally obtain data directly from you, automatically from your device or browser, and from service providers involved in completing your order, including Stripe.

3. Why do we use personal data, and on what legal basis?

PurposePersonal dataLegal basis under the GDPR
Processing an order, receiving payment confirmation, delivering the PDF, providing download access, and handling service requestsIdentity, order, payment-status, delivery, and support dataPerformance of a contract or steps requested before entering into a contract — Article 6(1)(b)
Keeping accounting and tax records and complying with lawful requests from public authoritiesOrder, transaction, identity, and correspondence data required by lawCompliance with a legal obligation — Article 6(1)(c)
Preventing fraud and abuse, securing the website and payments, troubleshooting, creating backups, and establishing, exercising, or defending legal claimsTechnical, security, order, payment-status, and correspondence dataLegitimate interests — Article 6(1)(f). The interests are protecting the store and customers, maintaining reliable services, preventing misuse, and protecting legal rights.
Measuring the source of completed orders through WooCommerce order attributionReferring source, UTM parameters, device type, session page views, and related cookie dataYour consent where required — Article 6(1)(a). If this feature is disabled or configured as strictly session-based under applicable law, processing may instead rely on a legitimate interest only to the extent legally permitted.
Sending product updates, newsletters, and marketing emails through MailerLite; measuring email delivery, opens, and clicks where enabledNewsletter data and campaign-interaction dataYour consent — Article 6(1)(a), together with the applicable rules on electronic marketing. You can withdraw consent at any time.
Using non-essential analytics, marketing, or similar technologies, if added in the futureCookie and usage dataYour consent — Article 6(1)(a). Such tools must not be activated before consent where consent is required.

Providing your name, email address, and the data needed to complete payment is necessary to enter into and perform the purchase contract. If you do not provide it, the order cannot be processed or the digital product delivered. Newsletter subscription and non-essential cookie consent are voluntary and are not a condition of purchase.

4. Payments through Stripe

Payments are processed using Stripe. Stripe may collect payment details, billing information requested for the selected payment method, IP address, device and browser information, and fraud-prevention signals. Stripe may also offer payment wallets or its Link service. Stripe processes some data to provide payment services to us and may process other data for its own legal, security, fraud-prevention, and service-improvement purposes.

We do not receive or store your full payment-card number or card security code. Please see Stripe’s Privacy Policy for further information.

5. Newsletter and MailerLite

The newsletter checkbox at checkout is optional and should not be pre-selected. If you actively subscribe, your email address, name where available, consent record, and relevant e-commerce information may be transferred to MailerLite so that we can manage the subscriber list, send campaigns and automations, and measure campaign performance.

MailerLite may use tracking technologies in emails, such as web beacons, to report whether a message was delivered, opened, or clicked, where this is enabled and legally permitted. You may unsubscribe at any time using the link in every marketing email or by contacting store@voidofcoursemoon.com. Withdrawing consent does not affect processing carried out before withdrawal. We may retain a minimal suppression record so that we can respect your unsubscribe request.

For more information, see MailerLite’s Privacy Policy.

6. Cookies and similar technologies

Cookies are small text files or similar identifiers stored on, or accessed from, your device. Polish electronic-communications law requires clear information and consent before non-essential cookies or similar technologies are used. Consent is not required for technologies that are strictly necessary to transmit a communication or provide a service you explicitly request.

Strictly necessary technologies

These technologies support the shopping cart, checkout, secure payments, fraud prevention, session management, and security. The store cannot function correctly without them.

Provider / examplesPurposeTypical duration
WooCommerce: woocommerce_cart_hash, woocommerce_items_in_cartRecognises changes to the shopping cart and keeps cart information available during the visit.Session
WooCommerce: wp_woocommerce_session_*Links the browser to the customer’s cart and checkout session stored by the website.Typically 2 days
WooCommerce: woocommerce_recently_viewed, if usedSupports the recently viewed products feature.Session
Stripe: examples may include __stripe_mid, __stripe_sid, m, and storage used by Stripe’s secure framesProcesses secure payments, assesses transaction risk, prevents fraud, and supports payment methods such as Link or digital wallets.Varies by technology; for example, Stripe describes __stripe_sid as approximately 30 minutes and __stripe_mid as up to 1 year.

Order-attribution technologies

WooCommerce order attribution is currently present in the checkout. It may store first-party sbjs_* cookies containing the referring source, UTM parameters, device information, entry page, and session page-view information. Examples include sbjs_session, sbjs_udata, sbjs_first, sbjs_current, sbjs_first_add, sbjs_current_add, and sbjs_migrations. These normally expire at the end of the session, while sbjs_session typically expires after about 30 minutes. If an order is placed, attribution data may be saved with the order.

Because order attribution is not required to deliver the product, it should be activated only after valid consent where required by applicable law. You must be able to reject non-essential cookies as easily as you accept them and change your choice later.

Managing cookies

You can use the store’s cookie settings, where available, to accept, reject, or withdraw consent for non-essential technologies. You can also delete or block cookies in your browser. Blocking strictly necessary cookies may prevent the cart, checkout, payment, or download functions from working correctly.

Cookie names, providers, and durations can change when WordPress, WooCommerce, Stripe, MailerLite, or other store components are updated. This section should therefore be reviewed after material technical changes.

7. Who receives personal data?

Personal data may be disclosed, only to the extent necessary, to:

  • website-hosting, server, content-delivery, backup, security, and technical-support providers;
  • providers supporting the WordPress and WooCommerce store, including contractors who maintain the website;
  • Stripe and the financial institutions or payment networks involved in the selected payment method;
  • MailerLite, but for marketing communications only when you have subscribed or where another valid legal basis applies;
  • email and customer-support service providers;
  • accountants, tax advisers, legal advisers, insurers, and professional consultants where necessary;
  • public authorities, courts, regulators, or law-enforcement bodies where disclosure is required by law or necessary to protect legal rights.

We do not sell personal data for money and do not use customer data for cross-context behavioural advertising.

8. International data transfers

The controller is established in Poland. Some service providers or their subprocessors may process data outside Poland or the European Economic Area. Where the GDPR requires transfer safeguards, transfers are made on the basis of an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful mechanism, with additional safeguards where required.

You may contact us for information about the safeguards relevant to a particular transfer. The independent privacy notices of Stripe and MailerLite also explain their international data-processing arrangements.

9. How long do we keep personal data?

We keep personal data only for as long as necessary for the relevant purpose:

  • Orders, transactions, tax and accounting records: for the period required by Polish tax and accounting law. As a general rule for tax records, this is 5 years counted from the end of the calendar year in which the tax payment deadline expired, subject to suspension, interruption, or extension under applicable law.
  • Contract-performance and download records: for the time needed to fulfil the order and provide support, and afterwards until relevant claims are time-barred or the records are no longer necessary to defend legal rights.
  • Support correspondence: until the matter is resolved and then for the period reasonably necessary to document the response and protect against claims.
  • Newsletter data: until you withdraw consent or unsubscribe. A limited suppression record may be kept afterwards to ensure that marketing is not sent again and to demonstrate compliance.
  • Consent and compliance records: for as long as needed to demonstrate that consent or another legal requirement was satisfied, including until related claims or regulatory matters can no longer arise.
  • Security and technical logs: for periods set according to security needs, log-rotation schedules, and incident-investigation requirements; longer only where necessary to investigate abuse, a security event, or a legal claim.
  • Cookie data: for the duration shown in the cookie section or until you delete it, withdraw consent, or the relevant storage expires.

When data is no longer needed, it is deleted or irreversibly anonymised unless the law requires continued storage.

10. Your data-protection rights

Subject to the conditions in applicable law, you have the right to:

  • request access to your personal data and obtain a copy;
  • request correction of inaccurate or incomplete data;
  • request erasure of personal data;
  • request restriction of processing;
  • receive data you provided in a structured, commonly used and machine-readable format and transmit it to another controller, where the right to portability applies;
  • object, on grounds relating to your situation, to processing based on legitimate interests;
  • object at any time to direct marketing;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
  • lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) or another competent supervisory authority.

Information about complaints is available at uodo.gov.pl. To exercise your rights, contact store@voidofcoursemoon.com. We may request information necessary to verify your identity, but we will not ask for more data than is reasonably needed.

11. Automated decision-making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. Stripe and payment partners may carry out automated fraud, risk, authentication, or security checks under their own terms and privacy notices, which may affect whether a payment can be completed.

12. Security

We use reasonable technical and organisational measures appropriate to the nature of the data and the risks involved. These measures include limiting access, using encrypted HTTPS connections, relying on secure Stripe payment elements, maintaining software, and using backups and security controls. No method of internet transmission or electronic storage is completely secure, so absolute security cannot be guaranteed.

13. Children

The store and digital calendars are not directed to children, and we do not knowingly collect personal data from children who cannot validly provide the data or enter into a purchase under applicable law. If you believe that a child has provided personal data without appropriate authorisation, contact us so that we can review and, where required, delete it.

14. External links

The website may contain links to third-party websites. Their operators are responsible for their own privacy practices. We encourage you to review the privacy notice of any external service you use.

15. Changes to this Policy

We may update this Policy when the store, service providers, legal requirements, or data-processing activities change. The effective date at the top identifies the current version. Material changes will be communicated in an appropriate manner.

16. Contact

For questions about this Policy or the use of your personal data, contact:

Void of Course Moon
Email: store@voidofcoursemoon.com