Privacy Policy
Last updated: August 20, 2026.
This is an English translation for convenience. In case of any discrepancy, the Slovak version is the legally binding original governed by Slovak law.
1. Data Controller
The controller of your personal data is Elektrorepas, s. r. o., Turčiansky Peter 84, 038 41 Turčiansky Peter, Slovenská republika, Company ID (IČO): 57 115 893, registered in the Commercial Register of Okresný súd Žilina, Section Sro, Insert No. 88361/L (the "Controller" or "we"). Privacy contact: support@bluefromsky.com.
2. What personal data we process
- Registration and customer account: name (public nickname), e-mail address, password (stored irreversibly hashed), profile picture (optional), unique account identifier.
- Third-party sign-in: if you sign in via Google or Facebook, we receive your name, e-mail address, and a unique account identifier from that provider needed to link the sign-in (the scope depends on your settings with that provider and your consent).
- Order data: the GPS coordinates chosen, dedication text (optional), order history, payment status and method, billing data, IP address, and device data used to prevent fraud and secure the coordinate reservation.
- Public map: by default, coordinates purchased through an Order are not shown on the public Blue From Sky map. You can choose at checkout to have your coordinate (without your name, email, or other identifying data) shown there instead, accessible to anyone.
- Payment data: payment details (e.g., card number) are processed exclusively by our payment partner, Stripe; we only store the transaction/customer identifier from Stripe, never the card number itself.
- Certificate: when generating the Certificate, your name, chosen coordinates, dedication text, and the derived location (country/continent) are embedded directly into the PDF document — your e-mail address is not shown on the Certificate itself, only used to deliver it (see "Order" above).
- Digital original (blockchain record): for every Certificate, we create an independently verifiable digital record on a public blockchain network, containing a cryptographic fingerprint (hash) of the coordinates and the public address of a wallet assigned to your account (its creation and management are handled automatically by us; you do not create or operate it yourself). This record never contains your name, e-mail address, or other directly identifying information.
- Contact form: the name, e-mail, subject, and message text you provide, your communication language, and technical data needed to verify the message was not submitted by an automated bot (Google reCAPTCHA).
- Cookies and similar technologies: see Section 6 below.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Order processing, Certificate delivery, invoicing | performance of a contract (Art. 6(1)(b) GDPR) |
| Managing the customer account | performance of a contract / consent |
| Handling complaints and contact-form requests | performance of a contract / legitimate interest |
| Accounting and tax documents | compliance with a legal obligation (Art. 6(1)(c) GDPR, Slovak Accounting Act, VAT Act) |
| Transactional e-mails (order confirmation, OTP code, password reset) | performance of a contract / legitimate interest |
| Traffic and behavior measurement (Google Analytics, Microsoft Clarity), advertising/remarketing (Facebook Pixel/App) | consent (Art. 6(1)(a) GDPR) — activated only after consent is given via our cookie banner |
| Sign-in via Google/Facebook | consent / performance of a contract |
| Abuse prevention (reCAPTCHA, fraud prevention) | legitimate interest (Art. 6(1)(f) GDPR) |
| Creating an independently verifiable blockchain record for the Certificate | legitimate interest (Art. 6(1)(f) GDPR) |
4. Recipients and processors of personal data
Your personal data may be disclosed to the following recipients/processors, strictly to the extent necessary for the relevant purpose:
- Stripe, Inc. / Stripe Payments Europe, Ltd. — payment processing,
- Google Ireland Limited — Google Maps Platform (coordinate selection, static map in the Certificate), Google Tag Manager, Google Analytics, Google sign-in, Google reCAPTCHA,
- Microsoft Ireland Operations Limited — Microsoft Clarity (analysis of visitor behavior on the website — heatmaps, session recordings),
- Meta Platforms Ireland Limited — Meta Pixel / Meta advertising technologies (marketing and remarketing cookies), Facebook sign-in,
- Google Ireland Limited (Google Workspace) — operation of our e-mail server (sending transactional e-mails),
- Public blockchain network (Base, built on the Ethereum ecosystem): the cryptographic fingerprint (hash) of the coordinates and the assigned wallet address are published on this public, decentralized network, which is not under the Seller's control or that of any single company,
- our hosting/server infrastructure provider,
- public authorities, to the extent required by applicable law.
We have data processing agreements in place with the above processors under Art. 28 GDPR, or their processing is governed by their own privacy policies as independent controllers (in particular for third-party sign-in and cookies).
5. International data transfers
Some of the recipients above (in particular Google, Microsoft, Meta, and Stripe group companies) may process data outside the European Economic Area (e.g., in the US). In such cases, the transfer is safeguarded by appropriate measures — in particular Standard Contractual Clauses approved by the European Commission and/or the relevant company's participation in the EU–US Data Privacy Framework.
6. Cookies
Our website uses:
- necessary (functional) cookies — enable sign-in, the purchase process, and site security; these cannot be disabled, as the site cannot function correctly without them,
- analytics and marketing cookies (Google Analytics, Microsoft Clarity, Facebook Pixel/App) — loaded only after you give consent via our cookie banner; you can change or withdraw consent at any time in the cookie settings in the site footer.
7. Retention periods
- customer account data: for the duration of the account, or until a deletion request is made and processed (Section 9),
- orders and billing data: 10 years from the end of the tax period in which the invoice was issued, in accordance with the Slovak Accounting Act (No. 431/2002 Coll.) and the VAT Act (No. 222/2004 Coll.),
- records of sent e-mails: max. 12–24 months,
- contact form data: for as long as necessary to handle the request, plus a reasonable period to demonstrate it was handled,
- cookies: per the validity period shown in the cookie banner settings (typically 6–24 months).
8. Your rights
Under the GDPR, you have the right to:
- access your personal data,
- rectify inaccurate data,
- erasure ("right to be forgotten") — you can request this directly in your account settings ("Delete account" section); the request can be cancelled within 24 hours,
- restriction of processing,
- data portability,
- object to processing based on legitimate interest,
- withdraw consent at any time (e.g., cookie consent) without affecting the lawfulness of processing before withdrawal,
- lodge a complaint with the Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava 27, www.dataprotection.gov.sk, or with your own local supervisory authority if you reside elsewhere in the EU.
Note: the right to erasure is not absolute — personal data appearing on tax documents (invoices) must be retained even after account deletion for the period required by applicable law (Section 7), as this constitutes compliance with a legal obligation under Art. 17(3)(b) GDPR.
9. Account deletion
A request to delete an account can only be made by a signed-in Buyer through their customer account, after re-verifying identity (entering their password) and passing an anti-abuse check (reCAPTCHA). Once submitted, you have 24 hours to cancel the request directly in your account; after this period, your personal data (name, e-mail, password, profile picture, third-party account links) will be permanently anonymized and access to the account will end. Data on already-issued invoices remains retained to the extent and for the duration required by accounting and tax law (Section 7). Due to the technical nature of blockchain technology, the digital blockchain record described in Section 2 (the cryptographic (hash) coordinate fingerprint and wallet address) cannot be removed or altered once created, even as part of an account deletion; this record does not, on its own, contain directly identifying personal data.
10. Contact form
If you contact us via the form on the Contact page, we process the name, e-mail, subject, and message text you provide in order to handle your request. The form is protected by Google reCAPTCHA, which verifies the message was not submitted by automated software; this involves transferring technical data (e.g., IP address, browser behavior) to Google Ireland Limited in accordance with its own privacy policy.
11. Reviews
If you submit a customer review through the website (name or nickname, star rating, review title and text, and whether you choose to publish anonymously), we process this data to display it publicly as a testimonial once approved. Reviews are moderated before publication and are never shown automatically. If you submitted a review while logged in, it is linked to your account; if you submitted it as a guest, only the nickname you provided is stored, with no link to any account. If your review was submitted through the unique link sent after a purchase, we also record its association with that order and the fact that it comes from a verified purchase — the order's own details are never shown publicly on the review. You can request removal of a review you submitted at any time by contacting us (Art. 8).
12. Data security
We store personal data on secure servers, accessible only to authorized personnel; passwords are stored irreversibly hashed; payment data never passes through our systems (processed exclusively by Stripe); and sensitive files (Certificates) are stored on non-public storage accessible only via a unique, hard-to-guess link.
13. Children
In line with our Terms & Conditions, our services are intended exclusively for individuals 18 years of age or older. If we become aware that we have inadvertently processed personal data of a person under 18, we will delete such data without undue delay.
14. Changes to this policy
We may update this policy from time to time, in particular in connection with changes to applicable law or the scope of data processed. The current version is always available on this website.