Privacy · GDPR
Privacy Notice
Effective and last updated: 31 August 2026
This notice explains how KOLLEGI sp. z o.o., as data controller, processes personal data in the STAGE mobile and web application and on stageco.pl, and describes your rights under the General Data Protection Regulation (GDPR).
Creating an account means accepting the Terms of Use and confirming that you have read this notice. It is not blanket consent to data processing. Where consent is legally required, STAGE will ask for it separately.
1. Controller and contact
KOLLEGI sp. z o.o. Aleja Bohaterów Września 10/106, 00-973 Warsaw, Poland KRS 0001239606 · NIP 7011312511 · REGON 544656446 Privacy requests: info@stageco.pl We have not appointed a Data Protection Officer. You may contact us directly.
2. Account, identity and security data
We process your email address, member number, email-verification status, account dates and a protected password hash. Verification and password-reset codes and session tokens are protected or hashed. If you choose Google Sign-In or Sign in with Apple, we receive the provider account identifier, a verified email address (which may be an Apple private relay address) and, when available, first and last name. We keep the version and time of the Terms accepted and Privacy Notice shown. Access and refresh tokens are stored in SecureStore on supported mobile devices and in localStorage in the web app.
3. Profile, community and location data
Depending on the features you use, we process your name, username, avatar, language, privacy and notification preferences; car details, registration plate, descriptions and photos; car-spot photos and a location you submit; event details, venue address and coordinates; registrations and check-ins; moderation decisions; viewed-car history; and Instagram or TikTok usernames submitted for quest verification. Public content may be visible to other users after moderation. STAGE does not continuously track device location. A photo or location is uploaded only when you choose and submit it. Camera or photo-library access is requested only when you choose an image feature. The QR scanner processes the camera view on the device to read a member code; STAGE does not retain or upload the camera feed.
4. Orders, loyalty and communications
We process Cafe, Menu and Shop order history, products, quantities, prices, selected payment method, fulfilment status and, for Shop orders, a contact phone number. The app does not collect payment-card numbers or other payment secrets. We also process Stage Coin balances and ledger entries, quest visits and claims, favourites, notification-read state, support requests and messages. Transactional email is used for verification and password recovery.
5. In-app analytics, technical diagnostics and website storage
For signed-in, verified members, STAGE records route templates visited, timestamps, their order in a session and the account identifier. To protect and repair the service, STAGE also records technical error diagnostics: time, app or API route template, feature and operation, error type and sanitised message or stack, platform, release/build, generated diagnostic identifiers and a bounded history of navigation and API operations. When you are signed in, the backend may associate a diagnostic occurrence with your account and session. These records exclude form values, message contents, email, phone, registration plates, precise coordinates, request or response bodies, cookies and authentication tokens. If native Sentry crash reporting is enabled for a released build, Sentry may additionally process device model, operating-system version and native crash data. Navigation and diagnostic records do not contain screen contents, keystrokes, advertising identifiers or a device fingerprint. The public stageco.pl landing page stores only the selected language in localStorage and currently uses no advertising or analytics cookies.
6. Purposes and legal bases
GDPR Article 6(1)(b): account operation, requested features, orders, loyalty, registrations, events, quests and support. Article 6(1)(c): accounting, tax, consumer-protection and other legal duties. Article 6(1)(f): service security, fraud prevention, moderation, aggregate business reporting and limited navigation analytics. Our legitimate interests are protecting STAGE and its users and improving the service. Where a future optional feature requires consent, Article 6(1)(a) will apply and consent can be withdrawn at any time.
7. Required and optional data
Email and account-security data are required to create an email account. Data marked required in an order or feature is needed to fulfil that request. Profile photos, cars, public content, social usernames and optional device permissions are voluntary.
8. Recipients
We do not sell personal data and do not share it for cross-app advertising. Access is limited to authorised KOLLEGI personnel and providers needed to run STAGE, such as infrastructure and database hosting, transactional email, technical support, optional Google or Apple authentication and, only when enabled, Sentry crash reporting. An order or event partner may receive the minimum data needed to fulfil your request. We may disclose data to advisers, courts or public authorities where authorised or required by law. We require processors and other recipients acting for us to apply appropriate confidentiality, security and data-protection safeguards.
9. International transfers
We aim to host the core database in the European Economic Area. Some providers, including Google, Apple, Sentry when enabled, or transactional-email infrastructure, may process data outside the EEA. Where required, we use an adequacy decision, European Commission Standard Contractual Clauses or another lawful safeguard. You may request information about the applicable safeguard.
10. Retention and deletion
Account, profile, content, support, loyalty and navigation data are kept while your account is active and as needed to provide STAGE. Security records are kept as needed to operate sessions, prevent replay and investigate abuse. Technical error occurrences are kept for 7 days in development, 30 days in preview and 90 days in production. Delete Account removes the account and associated profile, sessions, media, community submissions, support, loyalty, orders, blocks and navigation records from the current STAGE database and signs you out. Technical occurrences remain only until their normal expiry after their account and session identifiers are removed. You can also start an account-deletion request without the app at stageco.pl/account-deletion. Data that must be kept separately for a legal duty or legal claims may be retained only for the applicable statutory period, then deleted or anonymised.
11. Your rights
Depending on the legal conditions, you may request access, a copy, correction, deletion, restriction or portability; object to processing based on legitimate interests; and withdraw any consent without affecting earlier lawful processing. The app Settings provide Export My Data and Delete Account. You may also email info@stageco.pl. We normally respond within one month.
12. Complaints and automated decisions
You may complain to the President of the Personal Data Protection Office (Prezes UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland, or to your local supervisory authority. STAGE does not make decisions producing legal or similarly significant effects based solely on automated processing and does not use personal data for advertising profiling.
13. Children, security and changes
STAGE is not directed to children under 16. If you believe a child provided data without required authorisation, contact us. We use access controls, protected credentials, encrypted transport and proportionate safeguards, but no service guarantees absolute security. Material changes will be published in the app and on stageco.pl; if another legal basis or consent is required, we will ask before new processing begins.