Data controller
The controller of your personal data is DIGITAL COLLIERS Spółka z ograniczoną odpowiedzialnością, registered in Gliwice, Poland (“Fortuners”, “we”), which operates the fortuners.pl website and the Fortuners service.
- Company
- DIGITAL COLLIERS Spółka z ograniczoną odpowiedzialnością
- Registered address
- ul. Stanisława Konarskiego 18C, 44-100 Gliwice
- Register
- KRS 0000768764, Sąd Rejonowy w Gliwicach, X Wydział Gospodarczy Krajowego Rejestru Sądowego
- Tax ID (NIP)
- 9691635555
- REGON
- 382444548
- Share capital
- 6 000,00 zł
- info@fortuners.pl
For anything related to personal data, write to info@fortuners.pl or send a letter to our registered address marked “Fortuners: personal data”.
What this policy covers
This policy covers the fortuners.pl website in Polish and English: the home page for brands, the page for restaurants, the contact page, the campaign offer pages opened from the QR codes on fortune slips (fortuners.pl/oferta) and the partner panel for brands and venues.
If you work with us as a brand or a venue under a contract, that contract may set out additional rules for processing data.
What data we process and why
Below we describe every situation in which we process personal data: what data, for what purpose, on what legal basis and how long we keep it.
Contact forms and venue sign-ups
- What data
- What you enter in the forms on the home page, the contact page or the page for restaurants: your name, the name of your brand, company or venue, district, cuisine, email address, your message, the topic you chose and the page language. To protect the forms from abuse we also store a hash of your IP address and your browser type.
- Purpose
- Replying to your message, preparing a quote or a partnership proposal, and sending you a confirmation that we received it.
- Legal basis
- Art. 6(1)(b) GDPR (steps taken at your request before entering into a contract) and Art. 6(1)(f) GDPR (our legitimate interest in handling correspondence and protecting the forms from spam).
- How long
- For as long as we are in talks, then up to 12 months after the last contact. If we sign a contract: for its duration and until any claims become time-barred.
QR offer pages and the offer form
- What data
- The QR code on a fortune slip leads to a brand’s offer page. If you want to take up the offer, you leave your name, an email address or phone number (depending on the campaign) and sometimes a preferred date. Together with your request we store the campaign, the venue the cookie came from, the time and the page language.
- Purpose
- Passing your request to the brand that made the offer so it can contact you and deliver it; sending you a confirmation with the discount code if you give an email address; counting redeemed codes for the campaign report and settlement.
- Legal basis
- Art. 6(1)(b) GDPR (steps taken at your request: you want to take up the offer) and Art. 6(1)(f) GDPR (our legitimate interest in reporting on and settling campaigns).
- Recipients
- The brand named on the offer page. Once it receives your request, the brand processes your data as a separate controller under its own privacy policy. The brand panel shows aggregated data only.
- How long
- Until the campaign has ended and been settled, and no longer than 12 months after it ends.
QR code scan measurement
- What data
- Every visit to an offer page counts as a scan. We store the campaign, the venue (from the QR code parameter), the date and time, the browser and device type, the referring page (if your browser sends it), a hash of your IP address and a random identifier from the
fx_vidcookie. Clicks on “Copy” next to a discount code are recorded the same way. We never store the IP address itself, only a one-way hash created with a secret key. - Purpose
- Campaign performance statistics for brands (scans and redeemed codes by venue, day and hour), counting repeat visits by the same person only once, and protection against bots and abuse.
- Legal basis
- Art. 6(1)(f) GDPR: our legitimate interest in measuring and settling campaigns and keeping the site secure.
- How long
- Data on individual scans for up to 12 months after the campaign ends. After that we delete it or keep aggregated statistics only.
We don’t identify the people who scan and we don’t build profiles of them. The random identifier only links a scan to a later use of the code for statistics, for example to measure how long it takes from a scan to a sign-up.
Partner panel
- What data
- Email address, name, role and link to a brand or venue, preferred language, your password stored only as a hash (we never know your password), date of last login, session data (a hash of the session identifier, browser type, a hash of the IP address) and actions taken in the panel, such as ordering a stock top-up or approving a brand.
- Purpose
- Providing the panel and carrying out our partnership (campaign reports, deliveries, brand approvals), sign-in, password resets and invitations, account security.
- Legal basis
- Art. 6(1)(f) GDPR: our legitimate interest in performing the contract with the brand or venue you represent and in keeping accounts secure. If you are a party to the contract yourself: Art. 6(1)(b) GDPR.
- How long
- For as long as we work together and you have an account, then until any claims become time-barred. Sessions expire after 30 days (demo sessions after 2 days), password links after 60 minutes, invitations after 7 days.
The demo accounts in the panel are public and contain sample data only.
Email correspondence
- What data
- If you write directly to info@fortuners.pl: your email address, the details in your signature and the content of your message.
- Purpose
- Replying and continuing the conversation.
- Legal basis
- Art. 6(1)(f) GDPR: our legitimate interest in handling correspondence.
- How long
- For as long as the conversation lasts and up to 12 months after it ends, unless the messages are needed longer to perform a contract or defend against claims.
Server logs
- What data
- Whenever you visit the site, the server automatically records basic technical information: IP address, date and time, the requested page, the response code and browser type.
- Purpose
- Running and securing the site, diagnosing errors, protection against attacks and excessive requests.
- Legal basis
- Art. 6(1)(f) GDPR: our legitimate interest in the security and continuity of the site.
- How long
- Briefly, according to the hosting provider’s settings, generally no longer than 30 days.
Analytics
We currently don’t use any analytics or advertising tools that track your behaviour on the site. If that changes, we will ask for your consent first and update this policy.
Who we share data with
We don’t sell personal data. It is accessed by authorised members of our team and by providers who process it on our behalf under data processing agreements:
- Railway Corporation (USA): hosting for the site and the database
- Resend, Inc. (USA): sending emails from the site (confirmations, notifications, password changes, invitations)
- Google Ireland Limited: the Google Workspace mailbox where we receive messages and sign-ups
We pass the details from an offer form to the brand the offer belongs to (see “QR offer pages and the offer form”).
The maps on the home page are loaded directly from OpenStreetMap Foundation servers (United Kingdom), which receive your IP address and browser details and process them as a separate controller under their own privacy policy. We serve our fonts from our own server, without connecting to Google Fonts.
We may also disclose data to public authorities where the law requires it.
Transfers outside the EEA
Some of our providers are based in the United States or may process data outside the European Economic Area. In that case the transfer relies on a European Commission adequacy decision (including the EU-US Data Privacy Framework, where the recipient is certified) or on standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR). The United Kingdom is covered by a Commission adequacy decision.
To find out which safeguards apply and get a copy, write to info@fortuners.pl.
Your rights
In connection with the processing of your data, you have the right to:
- access your data and get a copy of it (Art. 15 GDPR),
- have your data corrected (Art. 16 GDPR),
- have your data erased (Art. 17 GDPR),
- restrict processing (Art. 18 GDPR),
- data portability for data processed under a contract or consent (Art. 20 GDPR),
- object to processing based on our legitimate interest (Art. 21 GDPR),
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal (Art. 7(3) GDPR).
To exercise these rights, write to info@fortuners.pl. We will reply without undue delay and within one month at the latest. We may ask for information needed to confirm that the request comes from the person the data relates to.
If you believe we process your data unlawfully, you can lodge a complaint with the President of the Polish Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl).
Do you have to provide data
Providing data is voluntary. In the forms only the required fields are needed (for example your email address and name or venue name): without them we can’t reply to your message, accept your sign-up or pass it on to the brand.
We don’t make decisions about you based solely on automated processing, including profiling.
How we protect data
Connections to the site are encrypted (HTTPS). We store passwords only as hashes (bcrypt), session tokens and one-time links as SHA-256 hashes, and IP addresses as keyed hashes. Only authorised people have access to the data. The forms are protected against spam and excessive submissions.
Changes to this policy
We may update this policy, for example when the site’s features, our providers or the law change. The current version is always available on this page, and we will announce significant changes on the site.
Version of 11 September 2026