← Sponic Gardens
Legal
Privacy Policy
Effective date: May 3, 2026 · Last updated: July 20, 2026
This Privacy Policy explains what personal data Sponic Gardens collects, why we collect it, how we use it, and what rights you have. We believe in transparent data practices — our AI systems are designed to serve your interests, not surveil you.
1. Who We Are (Data Controller)
Sponic Gardens is operated by Sponic Gardens sp. z o.o., a company registered in Poland — registered office al. „Solidarności" 68/121, 00-240 Warsaw, KRS 0001248017, NIP 5253094235, REGON 545044515. We are the data controller for the personal data described in this policy.
We run the Sponic Gardens pilot (including the "sponigotchi" microgreens programme) and related digital services ("Services"). Questions about this policy, or to exercise your rights, can be sent to [email protected].
2. Data We Collect
Information you provide directly
- Account data: name, email address, password, profile photo, and preferences you set during onboarding.
- Membership data: billing address, payment method (processed by our payment provider — we do not store full card numbers), and membership plan selections.
- Communications: messages you send to us, feedback, support requests, and responses to surveys.
- Application data: information you submit when applying for membership or partnership programs.
Data collected through your use of our spaces and platform
- Behavioral signals: areas of the space you visit, duration of visits, activities you participate in, and anonymized movement patterns used for space optimization.
- AI interaction data: queries, commands, and feedback you give to AI features within our platform or spaces.
- Device and log data: IP address, browser type, operating system, referrer URL, and timestamps when you access our website or apps.
- Environmental preference data: implicit signals (lingering in a zone, adjusting a setting) and explicit preferences (requesting a temperature change) used to personalize your experience.
- Access logs: entry and exit times recorded by access systems at physical locations.
Data from third parties
- If you sign in via a third-party identity provider (e.g., Google), we receive your name, email, and profile photo from that provider.
- Our payment processor provides transaction confirmation and limited billing details.
- If another member chooses to find friends using their phone's contacts, and your email address is in their contact list, we receive a one-way scrambled (hashed) version of your email — never the address itself — to check whether it matches an existing Spotka account. See "Finding friends via your contacts" below.
Spotka members can optionally use their phone's contacts to find friends who are already members, or to invite the ones who aren't. This is always something the member chooses to do — we never read anyone's contacts automatically.
- What we receive: a scrambled (SHA-256 hashed) version of each contact's email address — never the raw email, never a name, and never a phone number. Phone numbers are never sent to us for this feature.
- What we do with it: we check whether the scrambled email matches an existing member, then immediately forget the request. We do not store the scrambled codes, log them, or keep any record of who was checked against whom.
- What you control: a "let people who have your email find you" setting in your profile lets you opt out of being matchable this way at any time, independent of whether you use the feature yourself.
3. How We Use Your Data
| Purpose | Data used | Legal basis |
| Providing and operating the Services | Account, membership, access logs | Contract |
| AI personalization of your space experience | Behavioral, preference, AI interaction | Legitimate interest / Consent |
| Processing payments | Billing data (via payment processor) | Contract |
| Sending service communications | Email, name | Contract |
| Sending marketing updates | Email, name | Consent (opt-in) |
| Helping members find friends who are already members | Scrambled (hashed) contact email addresses, discarded immediately after each check | Legitimate interest |
| Safety and security | Access logs, device data | Legitimate interest |
| Improving our AI models and services | Behavioral, AI interaction (anonymized) | Legitimate interest |
| Legal compliance | As required | Legal obligation |
We do not sell your personal data. We do not use your data to train third-party AI models without your explicit consent.
4. AI and Automated Decision-Making
Our spaces use AI to make automated decisions about your experience — including environment settings, program recommendations, and content surfaced in the app. These decisions are designed to benefit you and are informed by your preferences and feedback.
Where automated decisions could have a significant effect on you (for example, a membership eligibility determination), you have the right to request human review. Contact us at [email protected] to exercise this right.
Behavioral data used for AI personalization is processed on a rolling basis. We do not build persistent psychological profiles intended for manipulation. Our AI systems optimize for member wellbeing, as defined in our Charter.
5. How We Share Your Data
We share personal data only in the following circumstances:
- Service providers (sub-processors): We share data with trusted providers who help us operate the Services, under data-processing agreements that bind them to use the data only on our instructions. These include Supabase (database hosting), Resend (email delivery), Cloudflare (website hosting, DNS and email routing), PostHog (EU-hosted, privacy-respecting product analytics), Meta (advertising measurement, only where you have consented), and Przelewy24 (payment processing). We keep an up-to-date list and can provide it on request.
- Other members: Your name and profile are visible to other members as part of the community experience. Behavioral and preference data are not shared with other members individually.
- Business transfers: If Sponic Gardens is acquired or merged, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
- Legal requirements: We may disclose data when required by law, court order, or to protect the safety of our members or the public.
- With your consent: For any other purpose, with your prior consent.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Services. After account closure:
- Account and membership data: retained for 3 years to comply with financial and legal obligations, then deleted.
- Behavioral and preference data: anonymized within 90 days of account closure and used only in aggregate for service improvement.
- AI interaction logs: retained for 12 months then deleted, unless retained longer by legal requirement.
- Billing records: retained for 7 years per accounting regulations.
- Contact-matching data: the scrambled email codes used to find friends via contacts are never stored — each check is discarded immediately after it completes.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to our retention obligations.
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Restriction: Request that we restrict processing in certain circumstances.
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Human review: Request human review of significant automated decisions.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
8. Cookies and Tracking
Our website uses cookies and similar technologies for:
- Essential operation: session management, authentication, security. These cannot be disabled.
- Analytics: understanding how visitors use our site so we can improve it. We use privacy-respecting analytics that do not fingerprint individuals.
- Advertising measurement: understanding whether our ads actually work. This only happens if you choose Accept on our cookie banner.
- Preferences: remembering your settings and preferences across visits.
Advertising measurement and Meta (Facebook)
If — and only if — you accept advertising cookies on our banner, we measure how our Meta (Facebook and Instagram) ads perform, in two ways:
- The Meta Pixel loads in your browser and reports page views and sign-ups.
- The Meta Conversions API. When you sign up, our server sends the sign-up event directly to Meta. This includes your email address in hashed form (an irreversible fingerprint, never the plain address), so Meta can tell whether the person who signed up came from one of our ads.
If you decline advertising cookies, neither of these happens: the Pixel does not load, and we do not send your sign-up to Meta. Declining does not stop you signing up, and it does not affect the emails you asked for.
These two consents are separate and independent. Ticking the newsletter box on a sign-up form only means we may email you — it never authorises sharing anything with Meta. Withdrawing consent for advertising measurement is as easy as giving it: clear this site's cookies and choose Decline, or email us (see section 13) and we will action it. Meta acts as an independent controller for the data it receives; see Meta's own privacy policy for how it uses it.
You can control cookies through your browser settings. Disabling non-essential cookies will not affect your core use of the Services.
9. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No system is perfectly secure — if you believe your account has been compromised, contact us immediately.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant authorities as required by law.
10. International Transfers
Sponic Gardens sp. z o.o. is established in Poland (EU). Some of our service providers process data outside the EEA — in particular in the United States (for example, our email delivery and part of our database and hosting infrastructure). Where personal data is transferred outside the EEA, we rely on appropriate safeguards: the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. We are working to host EU personal data within the EU. You can ask us for more detail about these safeguards at any time.
11. Children's Privacy
Our Services are not directed to children under 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a child, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by a prominent notice in the app at least 14 days before the changes take effect. The "last updated" date at the top of this page reflects the most recent revision.
13. Contact and Complaints
For privacy questions or to exercise your rights:
Sponic Gardens sp. z o.o.
al. „Solidarności" 68/121, 00-240 Warsaw, Poland
[email protected] · sponicgardens.com
If you are not satisfied with our response, you have the right to lodge a complaint with the Polish supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), uodo.gov.pl.