Privacy policy
Last updated: 2026-08-16
§ 1. Definitions
- Controller (We) - DjWeb Damian Jóźwiak, ul. Bolesława Limanowskiego 107/21, 91-334 Łódź, Poland, Tax ID (NIP): 7262640201, REGON: 368000615.
- Personal data - all information about a natural person identified or identifiable by one or more specific factors determining physical, physiological, genetic, mental, economic, cultural or social identity, including the device IP address, online identifier and information collected via cookies or other similar technology.
- Policy - this Privacy Policy.
- GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
- Website - the website operated by us at meetinplane.com.
- User (You) - any natural person visiting the Website or using one or more of the services or functionalities described in the Policy.
§ 2. What data we process
- In connection with your use of the Website, we collect data only to the extent necessary to provide the offered services. We process:
- account data - e-mail address, password as an irreversible hash, chosen language and time zone, the date the address was confirmed, the date the terms were accepted and adulthood confirmed, and - if you choose to give it - a phone number together with the date it was confirmed;
- profile data - display name, description, languages, interests, travel style, year of birth, photo and visibility settings; you choose the scope and visibility of this data yourself;
- trip data - destination and dates, optionally a flight number with airports and times, a place of stay at the precision you choose (city, neighbourhood or hotel) and travel intents. The hotel name is stored encrypted and stays are compared using an irreversible digest of it; seat numbers and booking details are not collected;
- contact data with other Users - invitations sent and received with their status, message content, blocks and reports;
- billing data - the purchase (product, amount, currency, date), the payment identifier at the operator, and the details needed to issue an invoice that you supply at purchase. We neither collect nor store card details;
- route interest declarations - the route entered together with language and date and - if you request a notification - an e-mail address;
- server logs - IP address, date and time of the request, URL - to the extent standardly recorded by a web server;
- visit analytics data (first-party analytics) - a random visitor and session identifier (stored in cookies), the subpages visited together with time spent and scroll depth, the IP address and the approximate location derived from it (country, region, city, time zone), device type, browser and operating system, language, entry source (referrer, UTM parameters) and page performance metrics. This data serves only the statistics of our Website, is not linked to your account and is not shared with third parties.
- We do not collect data from social networks or address books, nor data about your activity on other websites.
§ 3. Purposes and legal bases of processing
- We process account, profile, trip and contact data in order to provide the service - keeping the account, matching travellers and enabling them to make contact - the legal basis being performance of a contract (Art. 6(1)(b) GDPR).
- We process billing data in order to complete the purchase and to issue and keep accounting documents - the legal basis being performance of a contract (Art. 6(1)(b) GDPR) and our legal obligation (Art. 6(1)(c) GDPR) under tax and accounting law, including the obligation to submit invoices to the Polish National e-Invoicing System (KSeF).
- We process reports, blocks and moderation actions in order to keep Users safe and to meet the obligations following from the Digital Services Act - the legal basis being our legal obligation (Art. 6(1)(c) GDPR) and our legitimate interest (Art. 6(1)(f) GDPR).
- An e-mail address left with a route notification request is processed solely in order to send that notification - the legal basis being your consent (Art. 6(1)(a) GDPR).
- We process server logs for technical and administrative purposes, to ensure the security of the IT system and to manage it - the legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
- We process visit analytics data and route interest declarations for analytical and statistical purposes, to assess interest in the service, measure the effectiveness of promotional activities and plan the development of the Website - the legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
- Data collected by the third-party analytics and marketing tools described in § 7 is processed to keep visit statistics and to measure and target advertising - the legal basis is solely your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
- We may also process data to establish, pursue or defend against claims - the legal basis is our legitimate interest (Art. 6(1)(f) GDPR) consisting in the protection of our rights.
§ 4. Data retention
- We keep account and profile data for as long as the account exists. You can delete the account at any time in the application settings - the data is then permanently removed.
- For every trip you choose yourself how long its data is kept: deletion right after the trip ends, after 24 hours, after 7 days, after 30 days, or kept indefinitely. The chosen deadline is applied automatically.
- We keep conversation content until either participant deletes their account, and reports and moderation decisions for one year after they were dealt with.
- We keep accounting documents for the period required by law, that is 5 years counted from the end of the calendar year in which the tax payment deadline fell. Deleting an account does not shorten that period.
- An e-mail address left with a route notification request is kept until the notification is sent or until you withdraw your consent - whichever comes first. You can withdraw consent at any time: every e-mail from us contains a link enabling immediate and permanent deletion of your data with one click.
- We keep server logs for a maximum of 90 days, and visit analytics data for a maximum of 12 months, after which it is deleted automatically (older data remains solely in the form of aggregated, anonymous daily statistics).
- Cookies set by third-party tools expire as stated in § 7; retention on the providers' side is governed by the privacy policies of Google and Meta. Withdrawing consent stops those tools from running on subsequent visits.
§ 5. Data recipients
- We do not sell your personal data. We do not share it with third parties for marketing purposes beyond the tools described in § 7, which we load only after you consent.
- Data may be entrusted solely to entities providing technical services for us, on the basis of data processing agreements. These are: the hosting provider, the outgoing mail provider, the payment operator Stripe Payments Europe, Ltd. (Ireland) and the accounting service iFirma S.A. (Poland), through which we issue invoices.
- Invoices issued in Poland are submitted to the National e-Invoicing System (KSeF) operated by the Head of the Polish National Revenue Administration. The basis for this is our legal obligation; it is not entrustment of processing but disclosure to a public authority.
- The Website uses a script from our affiliate partner Travelpayouts, which appends our partner identifier to links leading to booking services. The script runs in your browser and may access the address of the page you are viewing and information about your device.
- If you consent to analytics cookies, the recipient of the data described in § 7(4) is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), which may transfer it to Google LLC in the United States.
- If you consent to marketing cookies, the recipient of the data described in § 7(5) is Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland), which may transfer it to Meta Platforms, Inc. in the United States. For pixel data we and Meta act as joint controllers within the meaning of Art. 26 GDPR.
- If you have given the consent described above, we also report a completed purchase (product, amount, currency) to Meta directly from our server. It is accompanied by the data Meta needs to attribute the purchase to an ad it showed you: your e-mail address, phone number, first and last name, city, postal code and country - solely as an irreversible cryptographic hash (SHA-256) - together with your IP address, browser information and the identifiers held in the
_fbpand_fbccookies. The server-side and browser-side reports carry the same event identifier, so Meta treats them as one event rather than two. Without your consent none of this is sent. - Website data is stored on servers located within the European Union. Any transfer outside the European Economic Area happens solely in connection with the tools listed above and relies on the European Commission adequacy decision (EU-US Data Privacy Framework) and on standard contractual clauses.
- Your data may be disclosed to entities authorised under the law, in particular judicial authorities - solely upon their justified request.
§ 6. Your rights
- You have the right to access your data and to request its rectification, erasure or restriction of processing, the right to data portability and the right to object to the processing.
- To the extent data is processed on the basis of consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- You also have the right to lodge a complaint with a supervisory authority responsible for personal data protection - in Poland this is the President of the Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw).
- Requests concerning your rights can be submitted to the e-mail address indicated in § 8. We respond without undue delay, no later than within one month of receiving the request.
§ 7. Cookies
- The Website uses strictly necessary cookies: a session cookie and a cookie protecting forms against CSRF attacks. These are technical files without which the Website cannot function properly and they do not require consent.
- The Website additionally uses a first-party analytics cookie containing a random visitor identifier, valid for 12 months. It serves solely to keep visit statistics of our Website (§ 2(1)(4)) - it does not track your activity on other websites and is not used for advertising purposes.
- Google Analytics 4 - once you consent, we load Google's analytics tool, which stores the cookies
_gaand_ga_<identifier>(valid 2 years). It collects a random browser identifier, the pages you visit, the traffic source, an approximate location derived from your IP address and information about your device. This serves statistics and measuring the effectiveness of our marketing. The IP address is truncated before storage. - Meta (Facebook) Pixel - once you consent, we load Meta's tool, which stores the
_fbpcookie (valid 3 months) and reads thefrcookie if you have a Facebook account. It measures the effectiveness of our ads and lets us target people with similar interests; this involves profiling for advertising purposes and sending information about your visit to Meta. - The tools above are loaded solely on the basis of your consent (Art. 6(1)(a) GDPR). Your choice is stored in the
analytics_consentcookie (valid 12 months); until you make it, none of those files are written. You can change or withdraw consent at any time using the "Cookie settings" button in the footer, with effect for the future. - The affiliate script referred to in § 5(3) may use cookies to attribute a commission for a booking made after leaving our Website.
- We do not sell cookie data and we do not combine data from third-party tools with the content of your account, trips or conversations in the app.
- You can delete or block cookies at any time in your browser settings; blocking the necessary cookies may prevent the use of forms on the Website.
§ 8. Contact and changes to the Policy
- In all matters related to the processing of personal data you can contact us at: kontakt@meetinplane.com or in writing at: DjWeb Damian Jóźwiak, ul. Bolesława Limanowskiego 107/21, 91-334 Łódź, Poland.
- The Policy is reviewed on an ongoing basis and updated when necessary. The current version of the Policy, together with the date of its last update, is always available on the Website.