Privacy Policy
Last updated: 5 September 2026 · version 2026-09-05.1
Information translation. This is a complete information translation. If there is a discrepancy, the Polish version is legally binding.
1. Controller and contact
KrolTech Łukasz Król (sole proprietorship registered in Poland)Registered office and service address: ul. Korabnicka 66A, 32-050 Skawina
Electronic address: kontakt@infogrunt.pl
NIP: 9442232002
Use the electronic address above for data requests, objections, consent withdrawal and error reports.
2. Ordinary visit and necessary mechanisms
The map and content work without an account. Delivering an HTTP response temporarily requires the server and hosting provider to process the IP address and connection headers. The application does not record the full User-Agent or viewport in its pageview log. The User-Agent is inspected in process memory only to filter bots.
| Data / identifier | Purpose and legal basis | Application retention |
|---|---|---|
| Full IP in a request-limit key | Endpoint security and protection of costly functions; legitimate interests, Article 6(1)(f) GDPR. | Up to 24 hours; cleanup reason code RET_RATE_LIMIT_1D. |
pw_fp — random 128-bit HttpOnly cookie | Binds a CSRF token for a browser without a signed-in account and a short queue/report-protection window to the browser that requested that function. It is not calculated from device characteristics and is not used for analytics. | 30 days in the browser; report-view records without a signed-in account up to 30 days, queue up to 1 hour, CSRF token 24 hours. Remove it in browser settings. |
| Truncated IP and UA hash for an account session | Sign-in security and abuse detection. | Until session expiry, no more than 30 days. |
pw_qa | Technical QA marker set only after an explicit ?qa=1 visit so tests are kept out of user traffic. | 180 days or until ?qa=0/cookie deletion. |
infogrunt_fp and dzialkaRadarSessionId are retired. The code removes old values and no longer sends X-Fingerprint or X-Dzialka-Session.
3. Analytics — consent only
Before a choice, after “Necessary only”, and after consent withdrawal, we do not create, read or transmit ig_browser_nonce_v1. No identified pageview or campaign event is sent. DNT blocks this category regardless of the stored choice.
After analytics consent, the script may create ig_browser_nonce_v1 in localStorage: a random ID, creation time and expiry. JavaScript reads and sends the ID to /api/pageview.php with a path category, language, random event ID and QA marker. It does not send viewport, referrer or a custom User-Agent field. The server rejects an older payload that lacks the current consent-schema marker.
The server records daily and 30-day-window HMACs, path category, language, country from an infrastructure header when available, event ID and QA. Raw entries live for 30 complete days. They are deleted only after a dry run, a private seven-day recovery backup and a verified aggregate containing no user/session identifier, full URL, IP address or click-ID value. Daily aggregates may be retained for longer.
“People” is a limited-coverage estimate: it includes only browsers that consented to analytics and do not enable DNT. It is not an exact count of humans and is not directly comparable with pageviews derived from minimised server logs.
3.1. Campaigns and Google providers
Only after analytics consent, ig_campaign_attribution_v1 in sessionStorage keeps allowlisted UTM source/medium/campaign/content values and presence flags for click IDs until the tab session ends. It never stores the gclid, fbclid or similar values. Events sent to /api/track/ping are limited to the event name and ID, language, path category, QA, allowlisted UTM/flags and, for a report failure, a reason code. Raw retention is 30 days.
Google Analytics 4 is fetched only after analytics consent and only if production has a valid active ID. AdSense is fetched only after advertising consent and an active configuration. This document does not state that Google Analytics or AdSense is currently active. Before a choice, after “Necessary only”, after rejection, or after consent withdrawal, the browser does not fetch Google Analytics, Google Tag Manager, AdSense, DoubleClick or other Google advertising/analytics scripts.
Change consent through “Cookie settings” in the footer. Withdrawal blocks future transmissions, aborts an in-flight first-party request, and removes available first-party identifiers and Google cookies accessible from this domain. We cannot undo a request completed before withdrawal or remove a cookie controlled exclusively by an external domain. Re-enabling requires a new explicit choice.
Ads also wait for an actual result from the certified Google CMP (TCF). The local category choice is not consent to every partner purpose. Ads stay paused without a valid result. The advertising tag is not loaded on the map, parcel report or account screens. When Google CMP is available, cookie settings include a separate button for partner choices. Switching off local advertising consent stops ads, removes the accessible local Google consent record and reloads the page to unload scripts that were already running.
Report-attempt measurement uses a random identifier held only in the open page memory. It links the start with a complete, partial or failed result and the first use of a card, print or share action. It contains no parcel number, coordinates, address or browser ID; raw events in the existing campaign counter are kept for 30 full days. Analytics consent is required. A browser marked with ?qa=1 is separated in the first-party counter and does not load GA4.
Page performance: after analytics consent, a locally hosted Web Vitals library measures LCP, INP and CLS. The map also records completion time or failure of the visible base tiles; this does not measure cadastral data coverage. At the first page hide we send at most one batch containing available metric values, page category, language and screen-width class (mobile/tablet/desktop). This measurement stores no user ID, IP, User-Agent, full URL or coordinates. The server retains daily histograms for 30 days and removes expired files on the next write. The p75 is a bucket-based estimate; a missing sample is not zero. QA traffic and DNT are excluded.
4. Account, forms and listings
- Account: email, optional bcrypt password hash, optional Google ID, favourites and listing data — until account or item deletion.
pw_sessand the session row live for 30 days. - Sign-in/deletion codes: hashed code, email, truncated IP and attempt count; valid for 10 minutes and deleted no later than 24 hours after expiry, use or revocation.
- Google OAuth:
pw_goauth_stateis a one-use HttpOnly cookie valid for 10 minutes and created only after Google sign-in is selected. - Recent searches:
dzialkaRecentholds up to five queries, label, coordinates and a timestamp for 30 days. The list itself is not transmitted; selecting an entry may trigger an ordinary geocoding/report request. - Listings: content, photos and optional phone number are public until the listing ends (normally up to 60 days, with renewal). Email is not published and photo EXIF is removed.
Article 6(1)(b) GDPR applies to account data and explicitly requested functions; Article 6(1)(f) to security; Article 6(1)(a) and the relevant terminal-device consent to analytics and ads. Withdrawal does not affect processing completed before withdrawal.
5. RCN data and Article 14 GDPR information
The source is the Polish Register of Real Estate Prices (RCN), maintained by county authorities and integrated and provided by GUGiK. InfoGrunt obtains source data, validates and minimises it automatically, and creates market statistics. Public output may include transaction observations and derived data such as sample size, median, quartiles, confidence interval, time window, quality tier and municipal ranking. InfoGrunt does not publish names of instrument parties or their contact details.
The purpose is market information, comparable statistics and ranking, not identifying transaction parties. The current method is v5-full-right-free-market-scoped-price-12m and the snapshot is rcn-clean-20260904-2bb45b1a. The RCN snapshot and derived data are versioned; the code currently has no separate automatic TTL for the source snapshot. Source data is not used to profile visitors.
If you believe information concerns you, use the rights below and identify the transaction or report page. The final qualification of Article 14 duties, exceptions and legal bases for RCN requires confirmation by a lawyer/DPO. We do not assume that an exception automatically applies.
6. Recipients and transfers
- SeoHost.pl — hosting and database in Poland/EEA.
- Google — only for Google sign-in selected by you or, with the relevant consent, an active Analytics/AdSense configuration. Google services may involve processing outside the EEA under mechanisms identified by Google, including an adequacy decision or standard contractual clauses.
- buycoffee.to — only after the external support link is selected; InfoGrunt does not receive card details.
- Relevant public mapping/geocoding APIs receive a technical request when their feature is used. Domains are listed in the Cookie Policy.
We do not sell personal data.
7. Rights under the GDPR
As applicable, you have rights of access, rectification, erasure, restriction, portability, consent withdrawal and objection to processing based on legitimate interests (Article 21 GDPR), and the right to complain to the President of the Polish UODO. The account provides JSON export and code-confirmed deletion; otherwise contact the controller.
Notices and appeals
We process the exact listing URL, explanation, name and email (optional for notices concerning child sexual abuse or exploitation), good-faith declaration and correspondence to handle notices under Article 16 DSA and GDPR Article 6(1)(c). Access is limited to the operator and hosting/email providers. The private receipt link grants access to the decision and your appeal. Do not share it. Decisions are reviewed by a person; the system stores and sends notifications. Appeals are accepted for at least six months from notification. Records stay while the case or visibility restriction remains active; resolved cases are deleted 30 days after the appeal window ends, provided delivery is complete. Active restrictions receive periodic review. Applicable access, rectification, restriction and erasure rights and the right to complain to UODO remain available through kontakt@infogrunt.pl.
8. Retention, safeguards and changes
Cleanup uses unambiguous cut-offs and reason codes. It counts the exact scope before mutation and, in apply mode, creates a private scope backup with SHA-256; that recovery backup is deleted after seven days. A campaign aggregate contains no person/session identifier, full URL, IP or click-ID value. HTTPS, CSP, HSTS, HttpOnly, Secure, SameSite, token hashing and request limits provide layered safeguards.
A material category or consent-schema change invalidates the old record and shows the choice again. The current consent record expires automatically after 180 days.