Tickets available online are cheaper than at the on-site ticket office. You will also avoid queues and get in faster - simply show your purchased ticket. Plan your visit in advance and take advantage of the better price.

Service: zakopanequady.com Effective date: 22 August 2026 Version: 2.0 (replaces version 1.0)
For questions, write to biuro.zakopanequady@gmail.com.
The controller is “AMANDA” Sylwia Boruta, ul. Wiślicka 6B, 43-430 Skoczów, Poland, NIP 5481268367 (“Zakopane Quady”, “we”).
Service point and ride location: ul. Zubka 40, Gubałówka, 34-500 Zakopane, Poland.
We are not required to appoint, and have not appointed, a data protection officer. We handle data-protection matters directly.
This Policy covers processing connected with zakopanequady.com, online bookings and rides, payments, correspondence and calls, on-site service, marketing communication and our social-media profiles.
For electronic services, we process data within Article 18 of the Polish Act on Providing Services by Electronic Means: we collect data necessary to establish, shape, change or end a legal relationship, while non-essential data is collected only with consent.
This Policy does not replace the Terms and Conditions, which under Article 8 of that Act govern contracts, participation requirements and complaints. For the service itself, the Terms and Conditions prevail in case of conflict.
It does not describe processing by external-platform operators, including social networks, search engines and payment operators, where they decide purposes and means independently. Their rules are indicated in sections 10–12.
If you book for a group or for other people, this Policy also covers their data where you provide it to us. Section 5 explains those bookings.
Technical data may arise automatically, within your consent settings. Participant data may come from the person making the booking (section 5).
Do not enter health information or other special-category data in booking fields or messages unless necessary and agreed in advance. If health circumstances affect safe participation, tell on-site staff. We do not record or archive such information; we use it only in the conversation to decide on safe participation.
| Process | Purpose | Legal basis | Retention |
|---|---|---|---|
| Booking and service | Booking confirmation, operational contact, preparation and delivery, changes and cancellations. | Article 6(1)(b) GDPR and Article 18 of the Polish Act on Providing Services by Electronic Means. | Service period, then applicable claim-limitation period. |
| Online payments | Payment, transaction confirmation, refunds and payment complaints. | Article 6(1)(b) GDPR and Article 6(1)(c) GDPR for payment and anti-money-laundering duties. | As required by accounting and payment-services law. |
| Accounting and tax records | Invoices and other accounting evidence. | Article 6(1)(c) GDPR; tax and accounting obligations. | 5 years from the end of the year in which the tax-payment deadline expired. |
| Contact and enquiries | Answers, availability checks and group/event offers. | Article 6(1)(b) GDPR for pre-contractual steps; otherwise Article 6(1)(f) GDPR, ongoing communication with interested persons. | While the matter is handled and as needed to prove its course if claims arise. |
| On-site eligibility check | Checking qualifications and participation requirements. | Article 6(1)(b) and (f) GDPR; safety and property protection. | Not retained; the document is only viewed (section 6). |
| Newsletter and email marketing | Offers, dates, seasonal promotions, discount codes and news. | Article 6(1)(a) GDPR and consent required by Article 398 of the Polish Electronic Communications Law. | Until withdrawal, effective objection or end of the newsletter, whichever comes first. |
| Consent and objection register | Proving consent status and preventing further messages after opt-out. | Article 6(1)(c) GDPR with Article 7(1), and Article 6(1)(f) GDPR. | As needed to prove compliance; limited objection data may be kept longer to respect it. |
| Review request | Invitation to rate a ride and collect feedback. | Article 6(1)(a) GDPR and Article 398 consent for electronic contact; review content – Article 6(1)(f) GDPR. | Until withdrawal; review while displayed or used for quality. |
| Website analytics | Traffic, sources, events, conversions, error diagnosis and improvement. | Article 6(1)(a) GDPR and Article 399 of the Polish Electronic Communications Law for non-essential technology; logs – Article 6(1)(f) GDPR. | Tool settings and section 8; consent record for the period shown in the panel. |
| Advertising and campaign measurement | Campaign performance, conversions, tailored ads and Google audiences. | Article 6(1)(a) GDPR and Article 399 of that Law. | Until withdrawal or according to identifier and platform settings. |
| Website security | Protection, fraud detection, diagnostics, continuity and incident handling. | Article 6(1)(f) GDPR; where necessary Article 6(1)(c) GDPR. | Operational logs usually up to 12 months; incident data as required for analysis, law or claims. |
| Complaints, claims and compliance | Complaints, claims, data requests and demonstrating compliance. | Article 6(1)(c) and (f) GDPR. | Until limitation expires or proceedings end finally. |
Note. The periods are maximum or typical. We may delete or anonymise data earlier when no longer needed. If data serves several purposes, we retain it for the longest applicable period and then limit processing to what remains justified.
Bookings are handled by Droplabs, supplied by Droplabs sp. z o.o., ul. Na Zjeździe 11, 30-527 Kraków, Poland, KRS 0000468242, NIP 6772375967. It is embedded as a booking window.
You provide data necessary for the contract, including contact details, ride type and date and participant count. Payment is made within the same system through its integrated payment operator.
We remain controller of booking data and provide the ride. Droplabs processes it on our behalf as a processor under an Article 28 GDPR agreement. The integrated payment operator is a separate controller for transaction data and its payment-institution duties. We do not see or store card or online-banking login data.
The booking window may use technical mechanisms necessary for booking and payment; section 8 lists them.
Booking confirmation, organisational information and the sales document go to the supplied email. These are contract messages, not marketing.
For family, friends, company trips or groups, you provide their data only as needed for the service and safety. Please tell them that their data was provided, why and where this Policy is available. We process it for the contract and our legitimate interest in safe organisation.
Provide only necessary data.
Minors may participate under the Terms and Conditions, with a parent’s or legal guardian’s care or consent. The adult making the contract provides the participant’s data and handles organisational matters.
We do not market to minors or collect marketing consent from them. Marketing is for adults only. Contact us if a minor’s data was received without a proper basis or a minor subscribed; we will delete it promptly.
Before the ride, staff may ask the driver to show proof of required qualifications under the Terms and Conditions.
We only view the document. We do not copy, photograph, scan or record its number or other data. It is returned, and we retain only operational approval information.
There is no video surveillance at the rental site and calls are not recorded.
If this changes, we will update this Policy and provide signage before activating the solution.
A booking or enquiry does not subscribe you to the newsletter. Booking confirmations, organisational messages, date or weather information and payment confirmations are sent to perform the contract and need no marketing consent.
Marketing consent is voluntary. Refusal does not affect booking, price, availability or service. We do not condition a service on unrelated consent.
We send marketing only after prior consent required by Article 398 of the Polish Electronic Communications Law. Consent is channel-specific: email consent does not cover phone or SMS. Currently marketing is email-only.
We process your email and, if provided, your name and interest information such as ride type or season.
You may withdraw consent at any time without reason or consequences. This does not affect earlier lawful processing. Each marketing message has an unsubscribe link; you may also write to biuro.zakopanequady@gmail.com.
We stop sending after withdrawal or objection. We keep limited withdrawal/objection information only to prove compliance and prevent re-adding the address. It is not used for other purposes.
After a ride, we may invite a review if we have electronic-contact consent. A review is voluntary.
A review request is separate from benefits. A possible discount code is separate and does not depend on a review or its content.
We use cookies, browser storage, pixels, tags and similar technologies. Necessary technologies support the website, booking, payment, security and privacy choices and run without consent because they are needed for the requested service.
Analytics, functional and marketing technologies run only after consent under Article 399 of the Polish Electronic Communications Law and remain blocked until then.
On first visit, CookieYes provides the consent panel. You may accept non-essential categories, reject them or choose details.
Rejecting is as easy as accepting; the reject button is at the same level. Refusal does not block content or booking, and we do not require non-essential consent.
You can change the choice through the privacy-settings link in the footer. It applies prospectively: it stops further collection but does not erase data lawfully collected earlier.
We store the choice to avoid asking every visit and to prove what was chosen and when.
| Tool | Purpose | Category |
|---|---|---|
| CookieYes | Consent panel, choice record and blocking other tools until consent. | Necessary |
| Website session mechanisms | Session, security and correct content display. | Necessary |
| Droplabs widget | Booking, payment, cart and order session. | Necessary |
| Google Tag Manager | Runs other tags according to consent. | Necessary mechanism |
| Google Analytics 4 | Visits, sources, events, conversions and booking-path diagnostics. | Analytics |
| Google Ads | Campaign conversions, audience lists and ad tailoring. | Marketing |
| Google Map | Contact-page access map loaded from Google servers. | Functional |
This is the tool set on the effective date above. We update this table and the consent configuration when tools change.
You can block or delete cookies in browser settings or receive storage notices. Blocking necessary cookies may prevent correct operation, especially booking or payment.
The mailing system may segment contacts by ride type, season, booking history, contact source or response to earlier messages, so content can be tailored.
We run Google Search/Display and Meta campaigns. Website behaviour measurement and audience lists are created only in Google and only after marketing-cookie consent. We do not use the Meta pixel or other social pixels.
Platforms may tailor ads, create similar audiences and measure conversions under your consents and their rules.
We do not make solely automated decisions with legal or similarly significant effects under Article 22 GDPR. Segmentation and ad tailoring do not affect availability, price or booking terms.
Data may go only to entities needing it for a purpose, including: Droplabs for bookings, orders, codes and vouchers; the payment operator as a separate controller; MailerLite for newsletters and automated messages; Make for rule-based transfers between systems; hosting, email, maintenance, backup and IT providers; analytics, consent and advertising providers, especially CookieYes and Google; confidential accountants, lawyers, auditors and advisers; postal and courier operators when needed; and public authorities or other entities where law or claims require it.
Providers acting for us are bound by Article 28 GDPR data-processing agreements and may process data only as instructed.
We do not sell personal data or share it for third parties’ own marketing.
Providers or subcontractors may process data outside the EEA, especially in the US or UK, mainly for analytics, advertising, consent management and cloud infrastructure.
We use an appropriate mechanism, such as a European Commission adequacy decision, the EU–US Data Privacy Framework for certified recipients, or European Commission standard contractual clauses with a transfer-impact assessment and additional safeguards where needed.
Ask us at the section 1.2 address about safeguards for a specific transfer.
We operate Instagram and TikTok profiles where active. Their operators follow their own policies and may be separate controllers or, for certain statistics and advertising, joint controllers with us. The scope follows platform rules and is outside our control.
Interactions, comments and messages may be visible according to account settings, which we cannot control.
Links may lead to maps, social profiles, review portals or partner sites. Their privacy rules are outside our control. Read the operator’s notice before providing data there.
Send requests to biuro.zakopanequady@gmail.com or the postal address in section 1.2. No form is required.
We may ask for the minimum information needed to verify identity. We do not require excessive data, including an ID scan where another solution is possible.
We normally reply within one month. The period may be extended under Article 12(3) GDPR for complex cases or many requests; we will explain the extension.
Provision is voluntary, but required data is necessary for the particular activity: contact and booking data for booking and organisational contact; billing data for payment and accounting documents; showing required qualifications to drive; and email for the newsletter.
Missing required data prevents that activity but has no other consequences.
Marketing consent is not required for booking, answers or website use.
We use measures appropriate to risk, scope and context: encrypted transmission, least-privilege access, multi-factor authentication where available, updates, backups, logs, confidentiality duties and provider checks.
We limit data and retention to what is needed and periodically review access and tool settings.
No transmission or storage method is absolutely secure. We treat security as an ongoing process and adapt safeguards to risk and tools.
Before launching a form, chat, review system, monitoring, communication channel or advertising pixel, we define roles, legal basis, data scope, retention, transfers outside the EEA and consent settings. Where required, we update this Policy and the consent panel before launch.
We may update this Policy when laws, processes or tools change. The effective date and version are at the beginning.
If a change materially affects processing, we will inform you on the website or another appropriate channel.
A Policy change does not replace consent where the law requires renewed consent. Continued website use is not consent.
This Policy applies to zakopanequady.com and services provided by “AMANDA” Sylwia Boruta. The website Terms and Conditions govern conclusion and performance of contracts.