Privacy Policy — Shop, Customer Account and Contact Form
Slovenská verziaVersion: 1.0 · Effective from: 15 September 2026
This policy explains how we process personal data when you buy a product in our shop at https://zone360.sk, use your customer account, download products or write to us through the contact form at https://zone360.sk/en/contact/. It does not cover third-party websites we link to.
1. Controller
Zone360 s. r. o.
Registered address: Borovicová 1975/16, 059 52 Veľká Lomnica, Slovakia
Company ID (IČO): 57 261 105
Registered in the Commercial Register of the District Court Prešov, Section: Sro, Insert No.: 50828/P
E-mail: info@zone360.sk
Phone: +421 948 954 360
We have not appointed a data protection officer. For any privacy question or request, write to info@zone360.sk.
2. What data we process, why, and on what legal basis
| Situation | Personal data | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Checkout and order | Name, e-mail address, billing address, country, company name and VAT ID (if provided), ordered product, price, taxes, order and payment identifiers, payment status, language, consent given at checkout (text version, date and time) | Concluding and performing the contract, delivering the product, providing the customer account | Art. 6(1)(b) — contract |
| Payment | Payment details are entered on the Stripe Checkout page. We receive only limited information from Stripe, such as the payment method type, card brand, last four digits and country — never the full card number | Taking payment, handling refunds | Art. 6(1)(b) — contract |
| Invoices and accounting | Order, billing and tax data | Keeping accounting and tax records | Art. 6(1)(c) — legal obligation |
| Fraud prevention at payment | Payment, device and transaction data collected by Stripe | Detecting and preventing fraudulent payments (Stripe Radar) | Art. 6(1)(f) — our and Stripe's legitimate interest in preventing fraud |
| Delivery and downloads | Download token (stored only as a hash), number of downloads, download log: customer, product, time, IP address in hashed form, browser user agent | Delivering the product; preventing abuse of download links and unlicensed sharing | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest in protecting our products and systems |
| Customer account and login | E-mail address, one-time login link (stored only as a hash, valid 15 minutes), session identifier, purchase history | Passwordless login, showing purchases, downloads of current versions | Art. 6(1)(b) — contract |
| Security and rate limiting | IP address and e-mail address used for login, checkout and download attempts (short-term counters) | Protecting the shop against abuse and attacks | Art. 6(1)(f) — legitimate interest in security |
| Refunds, withdrawals, complaints, chargebacks | Order data, your messages, payment dispute information from Stripe | Handling your rights and requests, defending legal claims | Art. 6(1)(b) and (c); Art. 6(1)(f) — establishing, exercising or defending legal claims |
| E-mails about your order | E-mail address, order data | Order confirmation, download link, login links, important information about your products (e.g. updates needed to keep them working) | Art. 6(1)(b) — contract |
| Contact form | Name, e-mail address, topic, software (krpano/Pano2VR), language, your message; your IP address in hashed form for spam and flood protection | Answering your enquiry; preparing an offer if you ask for one | Art. 6(1)(b) — steps at your request before a contract; Art. 6(1)(f) — legitimate interest in answering enquiries and preventing spam |
| Web server logs | IP address, date and time, requested page, browser user agent | Operating and securing the website | Art. 6(1)(f) — legitimate interest in security and operation |
We do not send marketing e-mails, and we do not use analytics or advertising cookies in the shop. If this changes, we will ask for your consent where the law requires it.
Is providing data required? The data marked as needed at checkout is necessary to conclude and perform the contract; without it we cannot sell you a product. Contact form fields are needed to answer you.
Automated decisions. We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Stripe's automated fraud screening may decline a payment; if that happens and you think it was a mistake, contact us and we will review it with a person involved.
3. Who receives your data
We share personal data only as needed for the purposes above:
- Websupport s. r. o., Karadžičova 12, 821 08 Bratislava, Slovakia (IČO 36 421 928), and its sub-processors in the EU — web hosting, database, e-mail (including sending order and login e-mails and receiving contact form messages). Acts as our processor.
- Stripe — Stripe Payments Europe, Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland, and its affiliates. Stripe processes payment data as our processor when processing payments on our behalf, and as an independent controller for its own purposes, such as fraud prevention and compliance with anti-money-laundering and other legal obligations. See Stripe's Privacy Policy: https://stripe.com/privacy
- Banks and card networks involved in your payment, as independent controllers.
- Our external accountant — bookkeeping and tax compliance.
- Public authorities, courts and legal advisers, where required by law or needed to establish, exercise or defend legal claims.
We do not sell personal data.
4. Transfers outside the EU/EEA
Our hosting and e-mail provider, Websupport s. r. o., and its sub-processors store data in the EU.
Stripe may transfer personal data to the United States and other countries. For transfers to the United States, Stripe relies on its certification under the EU-U.S. Data Privacy Framework (European Commission adequacy decision (EU) 2023/1795) and, as a fallback, on the European Commission's Standard Contractual Clauses. More information: https://stripe.com/legal/privacy-center
5. How long we keep data
| Data | Retention |
|---|---|
| Accounting documents (e.g. invoices) | 10 years after the end of the year they relate to, as required by Slovak accounting and VAT law |
| Customer account, orders and licence records (what you bought, when, license, refunds, withdrawal requests, complaints), including the record of the consent given at checkout | 10 years after the end of the year they relate to, kept as accounting records. If you close your account, you can no longer log in or download, but these records are kept for this period |
| Stored payment events from Stripe (webhooks) | 10 years after the end of the year they relate to, together with the related order |
| Download links (hashed tokens) | Valid for 7 days; deleted within 24 hours after expiry |
| Login links (hashed tokens) and login requests | Valid for 15 minutes; deleted within 24 hours after expiry |
| Download log (hashed IP, user agent, time) | 24 months |
| Session cookie | Up to 30 days, or until you log out |
| Security and rate-limit counters | Deleted within 24 hours |
| Contact form messages and our replies | 3 years after the last message; if the enquiry leads to a contract, kept with the order records |
| Web server logs | Kept by the hosting provider for a short period |
| Data held by Stripe as an independent controller | According to Stripe's Privacy Policy |
When the retention period ends, we delete or anonymise the data.
6. Cookies
The shop and the customer account use only strictly necessary cookies:
| Cookie | Purpose | Duration |
|---|---|---|
zone360_shop_session | Keeps you logged in to your customer account (HttpOnly, Secure, SameSite=Lax) | Up to 30 days, or until you log out |
XSRF-TOKEN | Protects login, logout and withdrawal forms against cross-site request forgery (Secure, SameSite=Lax) | Up to 30 days |
These cookies are necessary to provide the account you requested, so no consent is needed for them. We do not use analytics, advertising or social media cookies in the shop.
The payment page is operated by Stripe on Stripe's own domain. Stripe uses its own cookies and similar technologies there, for example for fraud prevention. See Stripe's Cookie Policy: https://stripe.com/cookie-settings
7. Your rights
You have the right to:
- access your personal data and receive a copy (Art. 15 GDPR),
- rectify inaccurate data (Art. 16),
- erase your data, where the law allows (Art. 17) — for example, we must keep accounting records for the statutory period,
- restrict processing (Art. 18),
- data portability for data you provided to us under a contract (Art. 20),
- object to processing based on our legitimate interests (Art. 21),
- lodge a complaint with a supervisory authority (Art. 77).
To exercise your rights, write to info@zone360.sk. We may need to verify your identity, for example by replying to the e-mail address linked to your account. We respond within one month; this can be extended by two further months for complex requests, in which case we tell you why.
Supervisory authority in Slovakia:
Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic), Hraničná 12, 820 07 Bratislava 27, Slovakia — https://dataprotection.gov.sk — statny.dozor@pdp.gov.sk.
You may also complain to the authority in the EU country where you live or work.
8. Security
We protect your data with appropriate technical and organisational measures, including encrypted connections (HTTPS), passwordless one-time login links, storing download and login tokens only as hashes, short-lived signed download URLs, rate limiting, and keeping product files and customer data outside the public web root.
9. Children
Our products are intended for professionals and adults. The shop is not directed at children under 16, and we do not knowingly collect their data.
10. Changes
We may update this policy when our services or the law change. The current version is always published at https://zone360.sk/en/privacy/ with its effective date. We inform customers by e-mail about material changes.
