Privacy Policy
Last updated: 26 July 2026
Who we are
The data controller is WB Soft, ul. Braniborska 50/2, 53-680 Wrocław, NIP: 8943126279. For any privacy request, contact virya.crew@gmail.com.
What we collect & why
When you contact us or subscribe, we process your email (and name, if given) to reply and to send updates you asked for. When you order merch, we process your name, email, delivery point and billing details to fulfil and invoice the order. Legal bases: performance of a contract, your consent (newsletter), and our legitimate interest in responding to enquiries.
In VIRYA Area, finding the nearest city happens only on your device. When you start signal lock, the server temporarily processes several latitude, longitude, accuracy and timestamp readings to verify presence in the zone, then discards the raw samples. We store the signed-in account identifier, claimed drop, rounded verification distance, reward balance and issued-code history to operate the pilot and prevent duplicate claims. There is no background location tracking.
Who processes your data
We share data only with processors needed to run the service:
- Stripe — payment processing
- InPost — parcel delivery
- Netlify — site hosting, form storage and VIRYA Area wallet storage
- Google (Gmail) — sending and receiving email
Retention
We keep order and invoicing data for as long as required by tax and accounting law, and newsletter data until you unsubscribe. Enquiry messages are kept only as long as needed to handle them. VIRYA Area claim and reward records are retained for the pilot and the validity of issued codes, then deleted or anonymised unless a longer period is needed to establish or defend legal claims.
Your rights
Under the GDPR you may access, rectify, erase, restrict or port your data, object to processing, and withdraw consent at any time. You also have the right to lodge a complaint with the Polish supervisory authority (UODO).
Cookies
The site uses only what is needed to function and to remember your cart. VIRYA Area uses strictly necessary HttpOnly session and legacy wallet cookies so the server can return the signed-in collection, support migration and prevent duplicate claims. Embedded players (e.g. Spotify, YouTube) may set their own cookies when loaded.
Site designed & built by Wojciech Bator