Privacy and Cookie Policy

Last updated: 8 August 2026

About this translation: this language version is intended to faithfully reflect the Polish original. If an unintended discrepancy arises from translation, the Polish version is used as the reference; this does not limit mandatory consumer rights or rights under the GDPR.
In short:
  • The Website is informational — we plan activity in travel intermediation. We do not organise cruises. You contract directly with the cruise line or organiser.
  • We do not sell your personal data.
  • We may earn partner commissions and do not add our own markup to the cruise price.
  • We process only data necessary to prepare an offer and operate the Website.
  • The Website does not enable bookings or payments — booking takes place with the cruise line or organiser.
  • You can withdraw consent to optional cookies and marketing at any time.
🔒
Protected dataSSL + Cloudflare WAF
💰
Cruise-line pricesNo markup from us
🤝
TransparencyPartner commissions
⚙️
Your controlChange cookie settings anytime

1. Who we are — controller and business status

The controller of your personal data is the natural person operating the Morze Rejsów Website:

{{PRIVACY_CONTROLLER_NAME}}
Email: {{PRIVACY_CONTROLLER_EMAIL}}
Website: morzerejsow.com
Legal status: The Website is currently operated by the individual identified above while preparing activity related to advice and intermediation in selecting cruises. The absence of registered business activity does not change who acts as data controller. Once business activity begins, the Controller’s identification details will be updated. The Website currently does not allow payments or the conclusion of a cruise participation contract directly with Morze Rejsów.

2. Purposes and legal bases for processing

PurposeLegal basis (GDPR)
Handling enquiries submitted through the Website contact formArticle 6(1)(b) — steps taken at the request of the data subject
Preparing an individual cruise proposalArticle 6(1)(b) — pre-contractual steps
Website analytics and optimisation (GA4)Article 6(1)(a) — your consent to analytics cookies
Remarketing and personalised advertising (Meta Pixel)Article 6(1)(a) — your consent to marketing cookies
Direct marketing, e.g. a future newsletterArticle 6(1)(a) — consent; Article 398 of the Polish PKE
Legal obligations, including tax and accounting obligationsArticle 6(1)(c) — legal obligation
Establishing, pursuing or defending claimsArticle 6(1)(f) — legitimate interests

Providing personal data is voluntary, but necessary data are required to use the contact form and receive a cruise proposal.

3. Data collected and minimisation

We apply the principle of data minimisation under Article 5(1)(c) GDPR and process only information necessary for the relevant purpose. We do not intentionally collect excessive data.

Data provided voluntarily through the Website form

Name, email address, telephone number (optional), message content and cruise preferences. With an enquiry we may store technical information about its source: the subpage of our Website where the form was sent, UTM campaign parameters present in the address and — if the browser provides a referrer — only the origin of the referring page (protocol and domain, without path or query parameters). This is used to handle the enquiry and for basic evaluation of acquisition sources. The data are stored in the application’s SQLite database on the production server and are available only after authentication to the protected CRM panel.

The persistent CRM record does not store the IP address, a pseudonym/hash of the IP address, User-Agent or a full copy of the raw form request. Information needed temporarily for abuse rate-limiting and spam assessment may be used while processing the request, but is not attached to the customer record.

Data collected automatically

Technical server logs may include the IP address, date and time of the request, requested URL, HTTP response code, browser information (User-Agent) and referring page. These logs are used for security, diagnostics and abuse prevention and have a separate retention period described in section 6. Data from analytics and marketing tools are processed only after the relevant consent; the exact scope depends on the provider configuration actually enabled.

4. Recipients and GDPR roles

Your data may be made available only to the extent necessary for the relevant processing purpose:

EntityGDPR roleScope
Production server provider (EU)ProcessorApplication hosting, SQLite database, technical logs and backups
Cloudflare, Inc. (USA)ProcessorCDN, DDoS protection, WAF and traffic protection/routing
Google — GA4 / GTM if enabled after consentService provider; its role and allocation of responsibilities follow the terms of the relevant Google productAnalytics and tag management to the extent actually enabled after consent; data may include online identifiers and activity information
Meta Platforms Ireland Ltd. — if Meta Pixel is enabled after consentJoint controller*Meta Pixel — conversions, remarketing and profiling
Legal, accounting and IT service providersProcessorsOnly to the necessary extent

* To the extent that the Meta Business Tools terms provide for joint controllership of event data collected through Meta Pixel, responsibilities between the Controller and Meta Platforms Ireland Ltd. are allocated under Article 26 GDPR and the Meta Controller Addendum. Data-subject rights remain rights under the GDPR; information on how Meta handles them is available in Meta documentation.

Telegram — operational notifications. A Telegram bot may send the Controller only a general notification that a new enquiry has appeared in the protected CRM. The message does not contain the customer’s name, email, telephone number, enquiry text, trip parameters or the enquiry number/identifier. Customer data remain in the CRM.

The Controller does not sell personal data to third parties.

5. Transfers to third countries (USA)

Use of Google, Meta or Cloudflare may involve transfers of, or access to, data from outside the European Economic Area, in particular from the United States. The transfer mechanism depends on the relevant provider and its current status: it may be an adequacy decision of the European Commission, including the EU–US Data Privacy Framework where the recipient is covered by it, or Standard Contractual Clauses (SCCs) together with any required supplementary safeguards. Current transfer information is provided in the privacy documentation of the relevant provider.

6. Data retention periods

We apply the storage-limitation principle. The periods below are our retention policy and are technically enforced where we control the relevant system. If legislation requires longer storage or data are needed to establish, pursue or defend claims, the necessary scope may be retained for the period arising from that legal basis.

DataStorage locationPeriod / criterion
Ordinary contact-form enquiries without a completed booking (statuses: new / contact / offer / closed)SQLite / production server (EU)Maximum {{LEAD_RETENTION_DAYS}} days from the last record update; automatic daily cleanup
Enquiries marked as spamSQLite / production server (EU)Maximum {{SPAM_RETENTION_DAYS}} days from the last update; automatic daily cleanup
CRM enquiries marked as resulting in a bookingSQLite / production server (EU)Maximum {{BOOKED_LEAD_RETENTION_DAYS}} days from the last CRM update. Documents that must be retained by law should be stored in the relevant accounting/document system and are subject to the applicable statutory periods
Cookie-choice logSQLite / production serverMaximum {{CONSENT_LOG_RETENTION_DAYS}} days from the consent/refusal/change event; automatic daily cleanup
mr_cookie_consent cookieUser’s deviceMaximum {{COOKIE_CONSENT_MAX_AGE_DAYS}} days or less after a consent-mechanism version change
Google Analytics 4, if enabled after consentGoogle systemsAccording to retention settings and Google rules; standard GA4 properties offer, among other settings, 2 or 14 months for user/event-level data, while aggregated reporting may follow different rules
Meta Pixel, if enabled after consentUser browser + Meta systemsAccording to current Meta rules and retention; Morze Rejsów does not independently set retention for data held by Meta
Dedicated Nginx logsProduction serverMaximum 90 days; daily rotation and automatic removal of older files
Backups of persistent application dataVPS and, if configured, off-site storageMaximum 14 days; local and configured off-site copies are automatically cleaned using the same limit

7. Your rights

Under the GDPR you have:

To exercise these rights, contact {{PRIVACY_CONTROLLER_EMAIL}}. We respond within the periods set by Article 12 GDPR, generally within one month.

You may also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

8. Profiling and automated decisions

If you consent to marketing cookies, your data may be used for advertising profiling.

What does this mean?

Based on your activity on the Website — in particular pages visited, such as particular ports and cruise routes, and offers clicked — tools such as Meta Pixel and Google Ads may be used to tailor advertising shown on Facebook, Instagram and across the Google advertising network.

Legal basis

The basis for this profiling is your consent under Article 6(1)(a) GDPR, expressed by accepting marketing cookies.

Does this affect your rights?

No. Profiling on our Website does not constitute automated decision-making producing legal effects or similarly significantly affecting you within Article 22(1) GDPR. It is used only to improve advertising relevance. The data are not used by us for other solely automated decisions.

You may withdraw consent to marketing cookies at any time (see section 9), which will stop Website-side profiling to the corresponding extent.

9. Cookies and similar technologies

Legal basis

In Poland, storing information on a user’s device or accessing information already stored is governed primarily by Articles 399–400 of the Act of 12 July 2024 — Electronic Communications Law (Prawo komunikacji elektronicznej), and at EU level by Article 5(3) of Directive 2002/58/EC (ePrivacy). Technologies involving personal-data processing are also subject to the GDPR, including its requirements for valid consent and withdrawal.

Consent mechanism — Basic Consent Mode v2

The Website uses its own consent-management panel and Basic Consent Mode v2. On the first visit you may accept all categories, reject all optional categories or choose categories separately. Analytics and marketing are disabled by default. Before your decision, external Google Analytics, Google Ads / Google Tag Manager and Meta Pixel tags are not downloaded and do not send data to those services.

Rejecting optional technologies does not restrict access to the Website. Your choice is remembered for no more than {{COOKIE_CONSENT_MAX_AGE_DAYS}} days, or less if we change the consent-mechanism version earlier. You can change or withdraw consent at any time through the “Cookie settings” button in the footer.

Categories

CategoryExample mechanismsPurposeConsent
Essentialmr_cookie_consent, administrator session, form protectionWebsite operation, security and remembering privacy choicesNo, to the strictly necessary extent
AnalyticsGoogle Analytics 4; typically _ga-family cookiesTraffic measurement, acquisition sources and content effectivenessYes
MarketingGoogle Ads, Meta Pixel; may include _gcl_*, _fbp, _fbcAd measurement, remarketing, audience building and personalisationYes

The exact list of external cookies may change with provider configuration. The current mechanism and consent rules are described in the Cookie Policy.

Consent log

For accountability, the server stores only: a random consent ID, notice version, a cryptographic hash of the immutable notice snapshot, selected categories, method of choice, language and time. The log does not store the IP address, visited page URL, User-Agent, name, email address or CRM enquiry identifier. A snapshot of each notice version is kept separately as a technical document without user data so we can determine the content to which a visitor responded.

10. Analytics and marketing tools

Google Tag Manager and Google Analytics 4

If a Google Tag Manager or Google Analytics 4 identifier is configured in production, the relevant tools are loaded only after the appropriate consent. Where GTM is used, the container receives the Consent Mode v2 state and its tags should have proper consent requirements. If GTM is used for GA4, we do not simultaneously run a second direct GA4 installation, to avoid duplicate measurement.

Google services are provided by Google Ireland Limited and/or the relevant Google group companies. The data scope depends on the specific tag configuration and may include information about pages visited, device, traffic source, events and online identifiers. We do not describe these data as “anonymous” merely because Google limits or processes IP addresses in a particular manner. More information: Google Privacy Policy.

Meta Pixel

If a Meta Pixel ID is configured in production, the script is loaded only after marketing consent. It may be used for conversion measurement, audience building and remarketing on Facebook and Instagram. After withdrawal, the Website revokes the relevant consent state, removes recognised first-party cookies for that category to the extent technically possible and reloads the page; cookies or data in Meta domains/systems remain governed by Meta mechanisms and browser settings. Provider: Meta Platforms Ireland Ltd. More information: Meta Privacy Policy.

11. Partner (affiliate) links

Financial transparency: morzerejsow.com may earn commissions from partners. If you click a partner link and make a purchase, such as booking a cruise, the partner may pay us a commission. We do not add a markup — you buy at the cruise line’s price. The commission is paid by the partner, not by you.

Partner/affiliate links are marked on the Website with [Advertisement] and may affect the order or manner in which offers are presented.

Partners may include, among others, MSC Cruises, Costa Cruises, Royal Caribbean, Norwegian Cruise Line, Princess Cruises, Virgin Voyages, Celebrity Cruises, Dreamlines and GetYourGuide.

Clicking a partner link may result in a cookie being set by the partner site for affiliate attribution. The Controller does not control cookies or privacy policies of external sites; please review their documents before providing personal data.

12. Liability and complaints

Contracts with cruise lines

The Controller is not a party to the travel contract and is not responsible for performance of the contract by the cruise organiser. The Website does not enable bookings or payments — a cruise is booked and paid for directly with the cruise line or organiser, for example MSC Cruises or Costa Cruises. Complaints about the cruise, booking changes, delays or refunds should be addressed to the entity with whom you contracted, in accordance with its terms and applicable law.

Complaints about the Website

Complaints concerning morzerejsow.com, Website content or personal-data processing may be sent to the Controller at the address in section 15. We respond within 14 business days.

13. Data security

We use appropriate technical and organisational measures, including:

14. Changes to this Privacy Policy

The Controller may update this Policy to reflect changes in law or data-processing practices. The last-updated date appears at the top of the page. Material changes will be announced in a visible place on the Website.

15. Contact

For personal-data protection matters:

Controller: {{PRIVACY_CONTROLLER_NAME}}
Email: {{PRIVACY_CONTROLLER_EMAIL}}.

We respond to GDPR-rights requests without undue delay, generally within one month of receipt. In the circumstances provided for by Article 12(3) GDPR, that period may be extended; the data subject will be informed of the extension and reasons.