This is an unofficial English translation provided for accessibility. Under Hungarian Act XCVI of 2001, the Hungarian text is the legally binding version. In any inconsistency between the two, the Hungarian wording prevails.

1. Data controller

2. Categories of personal data we process

To process orders and payments we collect:

For users of the mobile app we additionally process:

3. Purpose and legal basis

Guest checkout (ordering without registration). Using the web checkout does not require a user account. In that case we still collect the data above to fulfil the order (name, email, optional billing address). The legal basis remains performance of contract [GDPR Art. 6(1)(b)]; the separate registration-time consent that mobile- app users grant is not collected here — instead, you explicitly accept this Privacy Policy as part of the checkout flow. Records created via guest checkout are subject to the same 8-year accounting retention obligation set out above.

4. Sub-processors

We engage the following sub-processors:

4.1. SimplePay (SimplePay Zrt.)

Online card payments are processed by SimplePay Zrt. (registered seat: 1138 Budapest, Váci út 135–139. B. ép. 5. em.; company number 01-10-143303, Court of Registration of the Budapest-Capital Regional Court) acting as a sub-processor.

Data shared with SimplePay: first and last name, email, billing address (country, postcode, city, street, number). Full card data (card number, CVV) is captured by SimplePay directly from you — it never reaches our systems, neither transiently nor at rest; only the card's last 4 digits and brand appear in the payment-confirmation record (see §2).

SimplePay's privacy notice: https://simplepay.hu/adatkezelesi-tajekoztatok/ .

4.2. Hosting provider

Application data is hosted on the infrastructure of Rackhost Zrt. (registered seat: 6722 Szeged, Tisza Lajos krt. 41.; company number 06-10-000489; email: info@rackhost.hu). Access is granted only to the extent strictly necessary for technical operation.

4.3. Invoicing (KBOSS.hu Kft. / Számlázz.hu)

Invoice issuance and the real-time XML reporting to the Hungarian tax authority (NAV), required by Decree 23/2014 (VI. 30.) NGM, is performed by the Számlázz.hu system, operated by KBOSS.hu Kereskedelmi és Szolgáltató Kft. (registered seat: 1031 Budapest, Záhony utca 7.; company number 01-09-303201; email: info@szamlazz.hu) acting as a sub-processor.

Data shared: first and last name, email, billing address, tax number (if provided), order contents and total. The XML submitted to NAV cannot be revoked by law; if you exercise your right to erasure, the issued invoice and its retained PDF copy remain for the statutory period. We erase direct account and billing fields from the operational database and pseudonymise the related order and payment records. Those retained records may still constitute personal data, for example because the payment provider also holds the transaction identifier.

KBOSS.hu Kft. privacy notice: https://www.szamlazz.hu/adatvedelem/ .

4.4. Push notification delivery (Expo)

Mobile push notifications are delivered by Expo (650 Industries, Inc., 650 Castro Street, Suite 120-219, Mountain View, CA 94041, USA), which in turn forwards messages to Google FCM (Android) and Apple APNs (iOS).

Data shared: the device-bound Expo push token, the message body, and the delivery metadata. The token is stored in our system with AES-256-GCM encryption and a separate SHA-256 hash used for lookup and deduplication. It may also remain in server memory for up to 48 hours while a delivery receipt is pending; account deletion immediately removes that user's outstanding in-memory entries.

Because Expo's servers are located in the USA, the cross-border transfer relies on the EU–US Data Privacy Framework and EU Standard Contractual Clauses (SCC) — see §5. Expo's privacy notice: https://expo.dev/privacy .

4.5. Sign in with Google

Google sign-in is provided by Google Ireland Limited (registered seat: Gordon House, Barrow Street, Dublin 4, Ireland). We only verify the ID token against Google's servers — data shared: the email address, the display name, and the Google user identifier (sub). Your password is never disclosed to us.

Google's privacy notice: https://policies.google.com/privacy .

4.6. Sign in with Apple

Apple sign-in is provided by Apple Distribution International Limited (registered seat: Hollyhill Industrial Estate, Hollyhill, Cork, Ireland) on Apple Inc. (One Apple Park Way, Cupertino, CA 95014, USA) infrastructure. Data shared: the email address (or Apple's private relay address — @privaterelay.appleid.com), the display name (only on first sign-in), and the Apple user identifier (sub).

When you delete your account, we issue a server-side revocation request to Apple (POST /auth/revoke) using the stored SIWA refresh token, as required by App Store Review Guideline 5.1.1(v).

Apple's privacy notice: https://www.apple.com/legal/privacy/ .

4.7. Email delivery (SMTP)

Verification emails, password reset emails, account notifications, and invoice attachments are delivered through SMTP servers operated by us. The SMTP relay provider is part of the hosting configuration; today delivery runs on the same infrastructure as the hosting provider (4.2). Data shared: the recipient email address, the message subject and body.

5. International transfers (third countries)

We transfer personal data outside the EEA only where the contract or the nature of a sub-processor service requires it:

The sub-processors at §4.1 (SimplePay), §4.2 (Rackhost), §4.3 (KBOSS.hu) and §4.7 (SMTP) operate in Hungary or otherwise within the EEA.

We disclose data to public authorities only where required by law.

6. Security measures

7. Your rights

Under the GDPR you have the following rights:

Objection to direct marketing and profiling. You may object at any time, free of charge, to the processing of your personal data for direct-marketing purposes, including the related profiling/segmentation [GDPR Art. 21(2)–(4)]. You can do this in the app's marketing/profiling settings or by emailing plutoszkft@gmail.com; once you object we stop the profiling immediately.

Send requests to plutoszkft@gmail.com. We respond within 30 days of receipt.

You may request account deletion in the app or, without the app installed, at /account/delete.

Deletion can finish only when there is no active order, payment, refund, or unresolved invoicing process. If one remains, resolve it first and request a new single-use confirmation link. We pseudonymise the related order and payment records. An issued invoice and its PDF copy remain with the buyer data required by law for the eight-year accounting period and remain within GDPR scope during that period.

8. Lodging a complaint

If you believe we have breached the GDPR or the Hungarian Information Act (Act CXII of 2011), you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

You may also seek judicial remedy at the regional court (törvényszék) with jurisdiction over your place of residence or stay.

9. Cookies

The site uses only strictly necessary (technical) cookies. A separate cookie notice and banner will be introduced before any optional cookies are added.

10. Children's data (16-year minimum)

We do not knowingly collect personal data from anyone under the age of 16, and we do not create user accounts for them. This is consistent with GDPR Art. 8 and the 16-year default applied in Hungary under the Information Act (Act CXII of 2011).

The optional birthdate provided at registration is validated server-side: a birthdate that would make the user younger than 16 is rejected. The age threshold is configurable in our system, and any administrative change is recorded in the audit log.

If we become aware that we have collected data from a person under 16, we will delete it promptly. A parent or guardian can flag such cases by writing to plutoszkft@gmail.com.

11. Age verification (alcoholic products)

Our offering may include certain alcoholic products, which may only be ordered and sold to persons aged 18 or over (under the Hungarian Trade Act, Act CLXIV of 2005 §5(7), and the Consumer Protection Act, Act CLV of 1997 §16/A). For this purpose:

The legal basis for age-verification processing is compliance with a legal obligation [GDPR Art. 6(1)(c)] — the prohibition on selling alcohol to minors. Date of birth is not special-category data under GDPR Art. 9. In line with data minimisation, we collect no data beyond the above for age verification.

12. Changes to this notice

We may update this notice at any time. Changes take effect upon publication on this site. We will notify registered users separately of any material change.