Tickets available online are cheaper than at the on-site ticket office. You will also avoid queues and get in faster - simply show your purchased ticket. Plan your visit in advance and take advantage of the better price.

Privacy and Cookie Policy

Privacy and Cookie Policy

Service: zakopanequady.com Effective date: 22 August 2026 Version: 2.0 (replaces version 1.0)


Key points

  • The controller is “AMANDA” Sylwia Boruta, operating zakopanequady.com and selling quad, buggy and snowmobile rides.
  • Online bookings are handled by Droplabs, embedded on the booking page. Booking and payment data pass through that system and are used to provide the ride.
  • A booking does not subscribe you to the newsletter. We answer enquiries and fulfil bookings without marketing consent.
  • Marketing consent is voluntary and may be withdrawn at any time without affecting access to our services.
  • We do not sell personal data. Booking, payment, mailing, analytics and advertising providers may process data on our behalf or, for their own services, as separate controllers.
  • Analytics and marketing cookies run only after consent in the consent panel. Strictly necessary website, booking and payment technology is the exception.
  • We do not record calls or use video surveillance at the rental location.
  • You may access, rectify, erase and port your data, restrict processing, withdraw consent, object and complain to the supervisory authority.

For questions, write to biuro.zakopanequady@gmail.com.


1. Controller, contact and scope

1.1 Controller

  1. The controller is “AMANDA” Sylwia Boruta, ul. Wiślicka 6B, 43-430 Skoczów, Poland, NIP 5481268367 (“Zakopane Quady”, “we”).

  2. Service point and ride location: ul. Zubka 40, Gubałówka, 34-500 Zakopane, Poland.

  3. We are not required to appoint, and have not appointed, a data protection officer. We handle data-protection matters directly.

1.2 Contact

  • email: biuro.zakopanequady@gmail.com
  • phone: 536 274 259
  • post: “AMANDA” Sylwia Boruta, ul. Wiślicka 6B, 43-430 Skoczów, Poland, marked “Personal data”.

1.3 Scope

  1. This Policy covers processing connected with zakopanequady.com, online bookings and rides, payments, correspondence and calls, on-site service, marketing communication and our social-media profiles.

  2. For electronic services, we process data within Article 18 of the Polish Act on Providing Services by Electronic Means: we collect data necessary to establish, shape, change or end a legal relationship, while non-essential data is collected only with consent.

  3. This Policy does not replace the Terms and Conditions, which under Article 8 of that Act govern contracts, participation requirements and complaints. For the service itself, the Terms and Conditions prevail in case of conflict.

  4. It does not describe processing by external-platform operators, including social networks, search engines and payment operators, where they decide purposes and means independently. Their rules are indicated in sections 10–12.

  5. If you book for a group or for other people, this Policy also covers their data where you provide it to us. Section 5 explains those bookings.


2. Data we process and its source

  1. Depending on the relationship, we may process:
  • identification and contact data – name, email, phone and purchaser details for an invoice;
  • booking data – ride type and variant, date and time, participant count, extras, notes and fulfilment status;
  • billing data – amount, payment method and status, order number, accounting documents, refunds and complaints;
  • codes and voucher data – discount code, status, expiry and use;
  • correspondence – email and social-media messages and notes of telephone arrangements needed to handle the matter;
  • technical and usage data – IP address, online and cookie identifiers, device and browser data, approximate location, visit source, pages, clicks, events and visit duration;
  • consent and privacy-preference data – notice content and version, date, channel and source of consent, withdrawal or objection;
  • review data – if you submit a service review.
  1. We receive data mainly from you:
  • through the embedded Droplabs system during online booking (section 4);
  • during direct email or telephone contact; there is no website contact form;
  • through a consent form when you subscribe or give marketing consent;
  • on site before a ride, as described in section 6.
  1. Technical data may arise automatically, within your consent settings. Participant data may come from the person making the booking (section 5).

  2. Do not enter health information or other special-category data in booking fields or messages unless necessary and agreed in advance. If health circumstances affect safe participation, tell on-site staff. We do not record or archive such information; we use it only in the conversation to decide on safe participation.


3. Purposes, legal bases and retention

ProcessPurposeLegal basisRetention
Booking and serviceBooking confirmation, operational contact, preparation and delivery, changes and cancellations.Article 6(1)(b) GDPR and Article 18 of the Polish Act on Providing Services by Electronic Means.Service period, then applicable claim-limitation period.
Online paymentsPayment, transaction confirmation, refunds and payment complaints.Article 6(1)(b) GDPR and Article 6(1)(c) GDPR for payment and anti-money-laundering duties.As required by accounting and payment-services law.
Accounting and tax recordsInvoices and other accounting evidence.Article 6(1)(c) GDPR; tax and accounting obligations.5 years from the end of the year in which the tax-payment deadline expired.
Contact and enquiriesAnswers, availability checks and group/event offers.Article 6(1)(b) GDPR for pre-contractual steps; otherwise Article 6(1)(f) GDPR, ongoing communication with interested persons.While the matter is handled and as needed to prove its course if claims arise.
On-site eligibility checkChecking qualifications and participation requirements.Article 6(1)(b) and (f) GDPR; safety and property protection.Not retained; the document is only viewed (section 6).
Newsletter and email marketingOffers, dates, seasonal promotions, discount codes and news.Article 6(1)(a) GDPR and consent required by Article 398 of the Polish Electronic Communications Law.Until withdrawal, effective objection or end of the newsletter, whichever comes first.
Consent and objection registerProving consent status and preventing further messages after opt-out.Article 6(1)(c) GDPR with Article 7(1), and Article 6(1)(f) GDPR.As needed to prove compliance; limited objection data may be kept longer to respect it.
Review requestInvitation to rate a ride and collect feedback.Article 6(1)(a) GDPR and Article 398 consent for electronic contact; review content – Article 6(1)(f) GDPR.Until withdrawal; review while displayed or used for quality.
Website analyticsTraffic, sources, events, conversions, error diagnosis and improvement.Article 6(1)(a) GDPR and Article 399 of the Polish Electronic Communications Law for non-essential technology; logs – Article 6(1)(f) GDPR.Tool settings and section 8; consent record for the period shown in the panel.
Advertising and campaign measurementCampaign performance, conversions, tailored ads and Google audiences.Article 6(1)(a) GDPR and Article 399 of that Law.Until withdrawal or according to identifier and platform settings.
Website securityProtection, fraud detection, diagnostics, continuity and incident handling.Article 6(1)(f) GDPR; where necessary Article 6(1)(c) GDPR.Operational logs usually up to 12 months; incident data as required for analysis, law or claims.
Complaints, claims and complianceComplaints, claims, data requests and demonstrating compliance.Article 6(1)(c) and (f) GDPR.Until limitation expires or proceedings end finally.

Note. The periods are maximum or typical. We may delete or anonymise data earlier when no longer needed. If data serves several purposes, we retain it for the longest applicable period and then limit processing to what remains justified.


4. Online booking through Droplabs

  1. Bookings are handled by Droplabs, supplied by Droplabs sp. z o.o., ul. Na Zjeździe 11, 30-527 Kraków, Poland, KRS 0000468242, NIP 6772375967. It is embedded as a booking window.

  2. You provide data necessary for the contract, including contact details, ride type and date and participant count. Payment is made within the same system through its integrated payment operator.

  3. We remain controller of booking data and provide the ride. Droplabs processes it on our behalf as a processor under an Article 28 GDPR agreement. The integrated payment operator is a separate controller for transaction data and its payment-institution duties. We do not see or store card or online-banking login data.

  4. The booking window may use technical mechanisms necessary for booking and payment; section 8 lists them.

  5. Booking confirmation, organisational information and the sales document go to the supplied email. These are contract messages, not marketing.


5. Bookings for others and minors

  1. For family, friends, company trips or groups, you provide their data only as needed for the service and safety. Please tell them that their data was provided, why and where this Policy is available. We process it for the contract and our legitimate interest in safe organisation.

  2. Provide only necessary data.

  3. Minors may participate under the Terms and Conditions, with a parent’s or legal guardian’s care or consent. The adult making the contract provides the participant’s data and handles organisational matters.

  4. We do not market to minors or collect marketing consent from them. Marketing is for adults only. Contact us if a minor’s data was received without a proper basis or a minor subscribed; we will delete it promptly.


6. On-site service

  1. Before the ride, staff may ask the driver to show proof of required qualifications under the Terms and Conditions.

  2. We only view the document. We do not copy, photograph, scan or record its number or other data. It is returned, and we retain only operational approval information.

  3. There is no video surveillance at the rental site and calls are not recorded.

  4. If this changes, we will update this Policy and provide signage before activating the solution.


7. Contact, marketing and newsletter

7.1 Booking is not marketing

  1. A booking or enquiry does not subscribe you to the newsletter. Booking confirmations, organisational messages, date or weather information and payment confirmations are sent to perform the contract and need no marketing consent.

  2. Marketing consent is voluntary. Refusal does not affect booking, price, availability or service. We do not condition a service on unrelated consent.

7.2 Newsletter and marketing

  1. We send marketing only after prior consent required by Article 398 of the Polish Electronic Communications Law. Consent is channel-specific: email consent does not cover phone or SMS. Currently marketing is email-only.

  2. We process your email and, if provided, your name and interest information such as ride type or season.

  3. You may withdraw consent at any time without reason or consequences. This does not affect earlier lawful processing. Each marketing message has an unsubscribe link; you may also write to biuro.zakopanequady@gmail.com.

  4. We stop sending after withdrawal or objection. We keep limited withdrawal/objection information only to prove compliance and prevent re-adding the address. It is not used for other purposes.

7.3 Reviews

  1. After a ride, we may invite a review if we have electronic-contact consent. A review is voluntary.

  2. A review request is separate from benefits. A possible discount code is separate and does not depend on a review or its content.


8. Cookies and similar technologies

8.1 General rules

  1. We use cookies, browser storage, pixels, tags and similar technologies. Necessary technologies support the website, booking, payment, security and privacy choices and run without consent because they are needed for the requested service.

  2. Analytics, functional and marketing technologies run only after consent under Article 399 of the Polish Electronic Communications Law and remain blocked until then.

8.2 Consent management

  1. On first visit, CookieYes provides the consent panel. You may accept non-essential categories, reject them or choose details.

  2. Rejecting is as easy as accepting; the reject button is at the same level. Refusal does not block content or booking, and we do not require non-essential consent.

  3. You can change the choice through the privacy-settings link in the footer. It applies prospectively: it stops further collection but does not erase data lawfully collected earlier.

  4. We store the choice to avoid asking every visit and to prove what was chosen and when.

8.3 Tools

ToolPurposeCategory
CookieYesConsent panel, choice record and blocking other tools until consent.Necessary
Website session mechanismsSession, security and correct content display.Necessary
Droplabs widgetBooking, payment, cart and order session.Necessary
Google Tag ManagerRuns other tags according to consent.Necessary mechanism
Google Analytics 4Visits, sources, events, conversions and booking-path diagnostics.Analytics
Google AdsCampaign conversions, audience lists and ad tailoring.Marketing
Google MapContact-page access map loaded from Google servers.Functional

This is the tool set on the effective date above. We update this table and the consent configuration when tools change.

8.4 Browser settings

You can block or delete cookies in browser settings or receive storage notices. Blocking necessary cookies may prevent correct operation, especially booking or payment.


9. Segmentation and advertising

  1. The mailing system may segment contacts by ride type, season, booking history, contact source or response to earlier messages, so content can be tailored.

  2. We run Google Search/Display and Meta campaigns. Website behaviour measurement and audience lists are created only in Google and only after marketing-cookie consent. We do not use the Meta pixel or other social pixels.

  3. Platforms may tailor ads, create similar audiences and measure conversions under your consents and their rules.

  4. We do not make solely automated decisions with legal or similarly significant effects under Article 22 GDPR. Segmentation and ad tailoring do not affect availability, price or booking terms.


10. Recipients

  1. Data may go only to entities needing it for a purpose, including: Droplabs for bookings, orders, codes and vouchers; the payment operator as a separate controller; MailerLite for newsletters and automated messages; Make for rule-based transfers between systems; hosting, email, maintenance, backup and IT providers; analytics, consent and advertising providers, especially CookieYes and Google; confidential accountants, lawyers, auditors and advisers; postal and courier operators when needed; and public authorities or other entities where law or claims require it.

  2. Providers acting for us are bound by Article 28 GDPR data-processing agreements and may process data only as instructed.

  3. We do not sell personal data or share it for third parties’ own marketing.


11. Transfers outside the EEA

  1. Providers or subcontractors may process data outside the EEA, especially in the US or UK, mainly for analytics, advertising, consent management and cloud infrastructure.

  2. We use an appropriate mechanism, such as a European Commission adequacy decision, the EU–US Data Privacy Framework for certified recipients, or European Commission standard contractual clauses with a transfer-impact assessment and additional safeguards where needed.

  3. Ask us at the section 1.2 address about safeguards for a specific transfer.


12. Social media and external sites

  1. We operate Instagram and TikTok profiles where active. Their operators follow their own policies and may be separate controllers or, for certain statistics and advertising, joint controllers with us. The scope follows platform rules and is outside our control.

  2. Interactions, comments and messages may be visible according to account settings, which we cannot control.

  3. Links may lead to maps, social profiles, review portals or partner sites. Their privacy rules are outside our control. Read the operator’s notice before providing data there.


13. Your rights

  1. Depending on the basis and circumstances, you may:
  • access data and obtain a copy;
  • rectify inaccurate or incomplete data;
  • erase data where no basis for continued processing exists;
  • restrict processing under Article 18 GDPR;
  • port data processed automatically on consent or contract;
  • withdraw consent without affecting earlier lawful processing;
  • object to legitimate-interest processing for reasons related to your situation;
  • object at any time to direct marketing, including related profiling; and
  • complain to the President of the Polish Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland, uodo.gov.pl.
  1. Send requests to biuro.zakopanequady@gmail.com or the postal address in section 1.2. No form is required.

  2. We may ask for the minimum information needed to verify identity. We do not require excessive data, including an ID scan where another solution is possible.

  3. We normally reply within one month. The period may be extended under Article 12(3) GDPR for complex cases or many requests; we will explain the extension.


14. Voluntary data provision

  1. Provision is voluntary, but required data is necessary for the particular activity: contact and booking data for booking and organisational contact; billing data for payment and accounting documents; showing required qualifications to drive; and email for the newsletter.

  2. Missing required data prevents that activity but has no other consequences.

  3. Marketing consent is not required for booking, answers or website use.


15. Data security

  1. We use measures appropriate to risk, scope and context: encrypted transmission, least-privilege access, multi-factor authentication where available, updates, backups, logs, confidentiality duties and provider checks.

  2. We limit data and retention to what is needed and periodically review access and tool settings.

  3. No transmission or storage method is absolutely secure. We treat security as an ongoing process and adapt safeguards to risk and tools.


16. New tools

Before launching a form, chat, review system, monitoring, communication channel or advertising pixel, we define roles, legal basis, data scope, retention, transfers outside the EEA and consent settings. Where required, we update this Policy and the consent panel before launch.


17. Changes

  1. We may update this Policy when laws, processes or tools change. The effective date and version are at the beginning.

  2. If a change materially affects processing, we will inform you on the website or another appropriate channel.

  3. A Policy change does not replace consent where the law requires renewed consent. Continued website use is not consent.


This Policy applies to zakopanequady.com and services provided by “AMANDA” Sylwia Boruta. The website Terms and Conditions govern conclusion and performance of contracts.