Pirate AC

Pirate AC

Privacy Policy

1. Controller and contact

The data controller (“PirateAC”, the “Controller”) is:

Company and controller details

  • Company name: Pirate Marcin Rakowiecki
  • EU VAT number: PL7272691051
  • Street: Wieniawskiego 19
  • Postal code: 95-100
  • City: Zgierz
  • Province/region: Łódź
  • Country: Poland
  • Privacy email: wwwpirateac@gmail.com

This Policy covers pirate.ac, WordPress accounts, digital checkout, Support, comments, protected downloads and Patreon linking. External providers such as Patreon, YouTube or a payment provider also process data under their own policies.

2. Data we process

Depending on the feature used, data may include:

  • technical and security data: IP address, request time, URL, browser or device type, errors and logs;
  • account data: username, email, profile, login history and settings;
  • digital purchase data: identity and billing data, order contents, payment status and reference, and accepted Terms and consent versions;
  • Support data: name, email, topic, message and an optional JPG, PNG, PDF or ZIP attachment up to 20 MB;
  • comment data: name, email, content, IP address and moderation data;
  • Patreon and download data: account, membership, campaign and tier identifiers, local entitlement, access grant and file-delivery history;
  • consent data for cookies, a newsletter or another optional feature.

We do not ask for passwords, full card details, private keys or unnecessary sensitive data. Users should not include them in messages or attachments.

We use data to:

  • display the Service, maintain sessions, protect accounts and diagnose errors;
  • create an account, enter into and perform a contract, confirm payment and supply Digital Content;
  • determine Patreon entitlement and secure private downloads;
  • answer Support requests and handle complaints or withdrawal;
  • keep required accounting and evidence records;
  • moderate comments, prevent abuse and establish, exercise or defend legal claims;
  • activate analytics, marketing or consent-based embeds only after consent where required.

The legal basis is contract performance or steps requested before a contract (Article 6(1)(b) GDPR), legal obligation (point (c)), legitimate interests in security, correspondence and claims (point (f)), or consent for optional features (point (a)). Consent may be withdrawn without affecting processing already carried out lawfully.

4. Support, Patreon and protected downloads

The local Support attachment copy on the WordPress server is deleted after the email-send attempt. The message or attachment may remain in email systems and backups while needed for the request and legal claims. A one-minute spam limit may use a short-lived email hash.

Patreon linking is initiated by a logged-in user. PirateAC uses the minimum identifiers needed to check entitlement and should not retain the patron access token permanently. Grant and download history may be retained as evidence of access, accounting and file protection.

For immediate supply of paid Digital Content, we record minimal evidence of the contract, statement, product and file versions and the acceptance and supply times. The Legal Center acceptance register does not store an IP address or user-agent as acceptance evidence.

5. Recipients and international transfers

Data may be received only by providers needed for the service: hosting, email, backups, security, payments, accounting, technical or legal support, consent management and analytics and, where the user selects a feature, Patreon, YouTube or another external platform. Data may be disclosed to a public authority where required by law. PirateAC does not sell personal data.

Some providers may process data outside the EEA. A transfer takes place only under a lawful mechanism, such as an adequacy decision or standard contractual clauses. The final provider and transfer list must match the live implementation.

6. Retention

We retain data only as long as needed:

  • account data — while the account operates and then for accounting, claims and security;
  • purchase, payment and accounting data — for statutory tax periods and applicable limitation periods;
  • Support — until the matter is closed and for a justified claims period;
  • security logs — for the period confirmed in the hosting configuration;
  • consent and withdrawal records — while needed to demonstrate compliance;
  • entitlements and downloads — during the relationship and then for complaints, accounting and abuse prevention.

Exact periods for technical logs and backups follow the configuration of the relevant server or provider and are reviewed periodically. Backups may retain data until the end of their normal rotation cycle.

7. User rights

Depending on the legal basis, users may request access, a copy, correction, erasure, restriction or portability, object to legitimate-interest processing, object unconditionally to direct marketing and withdraw consent.

Requests can be sent to wwwpirateac@gmail.com. We may request information needed to verify identity. Some records cannot be erased immediately where retention is required for law, contract, security or claims. A complaint may be made to the Polish President of the Personal Data Protection Office (uodo.gov.pl) or the competent authority in the user's country.

8. Cookies, security and changes

Necessary cookies may support sessions, login, digital checkout, security and privacy choices. Analytics, marketing and tracking embeds require consent where the law requires it. Details are in the Cookie Policy.

We use measures appropriate to risk, including data minimisation, access controls, updates, form validation and backups. The Service is not directed to children who cannot give valid consent for the relevant online service on their own.

A new Policy version will show its number and date. Where a change requires new consent, it will be obtained before processing continues for the new purpose.