F FoundIt

Terms of Service

Version: 1.1

Last updated: 12.07.2026

Effective date: 12.07.2026

§ 1. General Provisions

1. These Terms of Service define the rules for the provision of electronic services via the FoundIt service, available in particular at foundit.cc.

2. The Terms of Service define in particular:

  • 1) the types and scope of Services;
  • 2) the conditions for using the Website;
  • 3) technical requirements;
  • 4) rules for creating, maintaining, and deleting an Account;
  • 5) rules for creating, assigning, and using Tags;
  • 6) rules for sending Messages;
  • 7) rights and obligations of Users and Finders;
  • 8) liability rules;
  • 9) rules for reporting unlawful Content and other abuses;
  • 10) the complaint procedure;
  • 11) rules for amending and terminating the Agreement.

3. The Terms of Service are made available free of charge in a way that allows them to be obtained, reproduced, recorded, and stored.

4. Before using the Website, the person using the Services should read the Terms of Service and the Privacy Policy.

5. Using the Website implies the obligation to comply with the Terms of Service to the extent relating to the Service used.

6. Creating an Account requires acceptance of the Terms of Service.

7. Sending a Message via the form on the Tag page requires reading the Terms of Service and accepting the rules regarding this Service.

8. The Terms of Service do not regulate the sale of physical identifiers, products, goods, paid subscriptions, or other paid services, unless explicitly provided otherwise.

9. In the event of introducing paid Services or selling products, the Administrator will provide appropriate conditions, price information, and rights of consumers before concluding a paid agreement.

§ 2. Service Provider

1. The service provider and administrator of the Website is Dawid Kula, a natural person running the FoundIt Website, hereinafter referred to as the "Administrator" or the "Service Provider".

2. Contact with the Administrator is possible at the address: contact@foundit.cc

3. For matters concerning the Website, including statements submitted electronically, contact the Service Provider at: contact@foundit.cc

4. Any additional contact details required by mandatory law will be made available in the Website.

5. The Administrator provides Services using the hosting and mail infrastructure provided by SEOHOST Sp. z o.o.

§ 3. Definitions

The terms used in the Terms of Service mean:

1. Administrator or Service Provider – the person indicated in § 2 of the Terms of Service.

2. Website – the FoundIt internet website along with the User panel, Tag pages, PWA application, forms, and other provided functionalities.

3. Service – a service provided electronically via the Website.

4. User – a person using the Website, in particular a person holding an Account.

5. Registered User – a person holding an active Account.

6. Finder – a person using the Tag page or a form enabling the sending of a Message, without the need to hold an Account.

7. Account – an individual account on the Website, associated with the User's email address.

8. Tag – an electronic identifier created or assigned on the Website, identified by a unique code and intended for binding with an item or another permitted application.

9. Tag Owner – the User to whose Account the Tag is assigned. This term is technical in nature and does not constitute confirmation of ownership of the marked item.

10. Message – content transmitted via the form on the Tag page.

11. User Content – any data and materials entered into the Website by the User or the Finder, including Messages, Tag names, public messages, photos, configurations, URLs, and other information.

12. Unlawful Content – information, material, or activity inconsistent with European Union law, Polish law, or violating the rights of third parties.

13. OTP – a one-time code used for User authentication.

14. Passkey – a cryptographic credential compliant with the WebAuthn standard, enabling login to the Account.

15. Web Push – a function of delivering notifications via the browser or operating system.

16. Agreement – an agreement for the provision of Services electronically concluded between the User and the Administrator.

17. Privacy Policy – a document defining the rules for processing personal data in connection with the Website.

18. Force Majeure – an external, extraordinary event, impossible to foresee or prevent with due diligence.

19. Conversation – a time-limited exchange of encrypted Messages between the Finder and the Tag Owner, relayed by FoundIt.

20. Private Link – a link containing a high-entropy secret that establishes access to one specific Conversation without requiring the Finder to create an Account or log in.

§ 4. Character and Purpose of the Website

1. FoundIt is a technical tool enabling:

  • 1) creating or assigning a Tag to an Account;
  • 2) configuring the Tag page;
  • 3) enabling a person visiting the Tag page to send a Message to the Tag Owner;
  • 4) sending an optional photo;
  • 5) sending an optional link indicating location;
  • 6) receiving Messages in the panel and by email;
  • 7) managing Tags and selected Account settings;
  • 8) using the OTP, Passkey, and Web Push functions;
  • 9) conducting a two-way Conversation relayed by FoundIt without disclosing either party's email address.

2. The Administrator provides only the technical infrastructure supporting contact.

3. The Administrator:

  • 1) is not the owner of the marked items;
  • 2) does not store found items;
  • 3) does not receive or transport items;
  • 4) is not a party to arrangements between the Finder and the Tag Owner;
  • 5) does not mediate in payments between Users;
  • 6) does not guarantee finding, securing, or returning the item;
  • 7) does not resolve disputes regarding ownership, possession, or right to collect the item;
  • 8) does not confirm that the person holding the Account is the owner of the marked item;
  • 9) does not confirm the identity or honesty of the Finder;
  • 10) does not guarantee that the Message is true, complete, or sent in good faith.

4. The Tag code, access to the Account, or assignment of the Tag in the Website do not constitute independent proof of ownership of the item.

5. Users should independently and carefully establish a safe way of identification, collection, or return of the item.

§ 5. Types of Services

1. The Administrator may provide in particular the following Services:

  • 1) displaying the public part of the Website;
  • 2) creating and maintaining an Account;
  • 3) login using OTP;
  • 4) login using Passkey;
  • 5) changing email address;
  • 6) creating a free Tag, if such option is currently available;
  • 7) assigning an existing Tag to the Account;
  • 8) managing Tags;
  • 9) setting the name and public message of the Tag;
  • 10) setting URL redirection;
  • 11) enabling or disabling the Message form;
  • 12) personalizing the appearance of selected Tags;
  • 13) counting the number of opens or scans of the Tag;
  • 14) transmitting Messages;
  • 15) temporary storage of Messages in the panel;
  • 16) transmitting photos as an email attachment;
  • 17) creating a link to OpenStreetMap based on voluntarily shared location;
  • 18) Web Push;
  • 19) contact form;
  • 20) changing language settings;
  • 21) deleting the Account;
  • 22) verifying the Finder's optional email address;
  • 23) enabling two-way Conversations relayed by FoundIt;
  • 24) sending notifications about replies and providing a Private Link;
  • 25) closing and deleting Conversations.

2. The scope of available Services may depend on:

  • 1) login status;
  • 2) type of Tag;
  • 3) Tag configuration;
  • 4) activity of a given function;
  • 5) browser and device used;
  • 6) the Administrator's decision regarding the development of the Website.

3. The Administrator may develop, change, replace, or withdraw individual functions, taking into account acquired rights and mandatory provisions of law.

§ 6. Free Nature of Services

1. Services described in the Terms of Service are provided free of charge, unless it is explicitly indicated otherwise for a specific function before starting to use it.

2. The mere use of the Website may involve costs of data transmission, Internet access, email, or device, charged by external operators.

3. The Administrator is not liable for fees charged by the telecommunications operator, Internet provider, device manufacturer, or other external entity.

4. The introduction of paid functions requires prior informing of the User about the price and other conditions. Lack of consent to the paid offer does not automatically create an obligation to pay.

§ 7. Technical Requirements

1. To use the basic functions of the Website, the following are necessary:

  • 1) a device with Internet access;
  • 2) an up-to-date web browser supporting HTML, CSS, JavaScript, session cookies, and encrypted connections;
  • 3) an active email address – in the case of Services requiring an Account;
  • 4) enabled JavaScript;
  • 5) ability to receive email messages;
  • 6) correct date and time setting on the device.

2. To use Passkeys, the following are necessary:

  • 1) a compatible browser;
  • 2) a compatible device or credentials manager;
  • 3) active WebAuthn support.

3. To use Web Push, the following are necessary:

  • 1) a compatible browser or operating system;
  • 2) consent granted in the device or browser;
  • 3) properly functioning infrastructure of the external notification operator.

4. To share the location, permission for the browser to access geolocation is necessary.

5. To take a photo or add a file, it may be necessary to grant the browser appropriate permissions.

6. The Administrator does not guarantee proper functioning of the Website:

  • 1) in outdated browsers;
  • 2) in atypical or modified browsers;
  • 3) on devices without security updates;
  • 4) with JavaScript disabled;
  • 5) after blocking technically necessary cookies;
  • 6) in the event of software interfering with Website communication.

7. The User should use up-to-date software, device security, and legal operating systems.

§ 8. Risks Related to Internet Use

1. Using internet services involves typical threats, including:

  • 1) interception of email access;
  • 2) phishing;
  • 3) malware;
  • 4) impersonating other persons;
  • 5) session hijacking;
  • 6) unauthorized access to the device;
  • 7) leakage of information displayed in notifications;
  • 8) malfunction of external providers;
  • 9) data loss due to failure.

2. The Administrator applies security measures adequate to the type of Services, but cannot guarantee the complete elimination of all threats.

3. The User should in particular:

  • 1) protect access to their email box;
  • 2) not share OTP codes;
  • 3) secure the device;
  • 4) not leave an active session on a public device;
  • 5) remove unused Passkeys;
  • 6) exercise caution regarding messages containing requests for money or credentials;
  • 7) verify the identity of the person to whom the item is to be returned.

§ 9. Conclusion of the Agreement

1. The agreement for maintaining an Account is concluded upon:

  • 1) acceptance of the Terms of Service;
  • 2) correct completion of the registration and authentication process;
  • 3) creation of the Account on the Website.

2. The agreement for a one-time Service not requiring an Account is concluded for the duration of its execution, upon starting to use the function or sending the appropriate form.

3. Sending a Message means ordering the Administrator to perform the technical actions needed to forward it to the Tag Owner.

4. The agreement for maintaining an Account is concluded for an indefinite period.

5. The User may terminate the Agreement at any time by deleting the Account.

6. The User should have the capacity to conclude the Agreement to the extent required by law.

7. A person without full legal capacity may use the Website only to the extent permitted by law and, when required, with the consent of a legal representative.

§ 10. Registration and Account

1. An active email address is required to create an Account.

2. The User is obliged to:

  • 1) provide an email address to which they have the right and actual access;
  • 2) not register an Account using an address belonging to another person without authorization;
  • 3) ensure the security of their email box;
  • 4) not share OTP codes with third parties;
  • 5) not allow unauthorized persons to use the Account;
  • 6) immediately react to suspected Account takeover.

3. One person may hold more than one Account only if it does not serve to bypass security measures, limits, or other provisions of the Terms of Service.

4. It is prohibited to:

  • 1) automatically create Accounts;
  • 2) create dummy Accounts;
  • 3) impersonate another person;
  • 4) use the Account for fraud;
  • 5) resell or rent the Account;
  • 6) bypass restrictions imposed by the Administrator.

5. The User bears responsibility for activities performed using their Account to the extent they result from their action or omission.

6. The Administrator is not liable for obtaining access to the Account as a result of:

  • 1) takeover of the User's email box;
  • 2) transmission of the OTP code to a third party;
  • 3) lack of device security;
  • 4) leaving an active session on a shared device,

unless the damage results from circumstances for which the Administrator is liable under mandatory provisions of law.

§ 11. OTP Codes

1. OTP is a one-time and temporary code.

2. The code may be used only to authenticate the operation for which it was generated.

3. The User must not:

  • 1) share the code with another person;
  • 2) send the code in response to suspicious messages;
  • 3) publish the code;
  • 4) use automated tools to guess codes.

4. The Administrator may apply:

  • 1) OTP expiration time;
  • 2) limit on the number of attempts;
  • 3) sending frequency limit;
  • 4) temporary operation block;
  • 5) other protective measures.

5. The Administrator does not guarantee immediate delivery of the OTP message, as delivery also depends on mail systems and the recipient's mailbox configuration.

§ 12. Passkeys

1. The User may add a Passkey, if the function is available and the device supports it.

2. The User is responsible for:

  • 1) securing the device or credential manager;
  • 2) controlling the list of added Passkeys;
  • 3) removing a Passkey stored on a lost or untrusted device.

3. The Administrator stores the cryptographic credential data necessary to verify the login.

4. The Administrator does not receive fingerprints, facial images, or the PIN code used locally by the device.

5. The availability of Passkey also depends on the device manufacturer, operating system, browser, or external credentials manager.

6. The Administrator is not liable for:

  • 1) loss of the Passkey by the User;
  • 2) failure of the external credential manager;
  • 3) Passkey synchronization by a third party;
  • 4) refusal of the device to operate;

unless liability results from mandatory provisions of law.

§ 13. Tags

1. The User may create or assign Tags, if the function is available.

2. The User may assign a Tag only when:

  • 1) they are authorized to do so;
  • 2) the Tag code was correctly shared with them;
  • 3) the assignment does not violate the rights of another person;
  • 4) the Tag is not already lawfully assigned to another User.

3. The assignment of a Tag to the Account is technical in nature and does not determine ownership of the marked item.

4. The Administrator may require additional verification in the event of a dispute regarding a Tag.

5. The Administrator has no obligation to resolve ownership disputes.

6. In the event of a credible dispute, the Administrator may:

  • 1) temporarily block the Tag;
  • 2) disable the form;
  • 3) halt the possibility of changing configurations;
  • 4) summon the parties to present information;
  • 5) leave the decision to the competent authority or court.

7. The User must not:

  • 1) assign someone else's Tag without authorization;
  • 2) use the Tag to mislead others;
  • 3) place the Tag on someone else's item without consent;
  • 4) use the Tag to track a person without a legal basis;
  • 5) use the Tag for harassment, fraud, or impersonation;
  • 6) obstruct correct use of the Tag by the authorized person.

§ 14. Tag Configuration

1. The Tag Owner may have the possibility to set:

  • 1) Tag name;
  • 2) public message;
  • 3) redirection address;
  • 4) form status;
  • 5) appearance;
  • 6) other parameters.

2. The User is responsible for compliance of the configuration with law and the Terms of Service.

3. The name and public message must not:

  • 1) violate personal rights;
  • 2) contain threats or insults;
  • 3) violate copyrights or trademarks;
  • 4) mislead as to the identity, ownership, or nature of the Website;
  • 5) contain personal data of third parties without an appropriate basis;
  • 6) promote unlawful activities;
  • 7) contain discriminatory, pornographic, or extremely graphic content;
  • 8) serve to extort data or money.

4. The User should limit the scope of publicly presented data to a minimum.

5. The Administrator does not recommend publishing in a public message:

  • 1) home address;
  • 2) document number;
  • 3) PESEL (national identification) number;
  • 4) payment details;
  • 5) passwords;
  • 6) confidential information.

§ 15. URL Redirections

1. The User may set the address of the page to which the Tag should lead, if the function is available.

2. The User may point only to addresses that are:

  • 1) legal;
  • 2) safe;
  • 3) non-infringing on the rights of third parties;
  • 4) free of malware;
  • 5) not serving phishing, fraud, or bypassing security measures.

3. Redirections to pages are prohibited if they:

  • 1) extort data (phishing);
  • 2) distribute malware;
  • 3) violate the law;
  • 4) impersonate FoundIt;
  • 5) offer illegal goods or services;
  • 6) contain clearly unlawful content;
  • 7) violate copyrights or personal rights;
  • 8) serve to bypass blocks imposed in the Website.

4. The Administrator does not constantly monitor the content of all external pages.

5. The Administrator may block a redirection after:

  • 1) obtaining credible information about a violation;
  • 2) detecting a technical threat;
  • 3) receiving a request from an authorized authority;
  • 4) establishing a violation of the Terms of Service.

6. The Administrator is not liable for content, goods, services, or privacy policies of external pages, unless liability results from mandatory provisions of law.

§ 16. Finder's Form and Messages

1. The Finder may send a Message if the form for a given Tag is active.

2. The Finder should transmit only the information needed to contact regarding the given Tag. Information entered in the free-text Message is visible to the Tag Owner.

3. The Finder may voluntarily provide an email address in a separate field. The address is encrypted and is never disclosed, in whole or in part, to the Tag Owner.

4. The first Message is forwarded to the Tag Owner whether or not the Finder provides or confirms an email address.

5. If an email address is provided, FoundIt sends a one-time verification link. Until the address is confirmed, the Tag Owner cannot reply through the Service.

6. Once the address has been confirmed, the Tag Owner may reply from the dashboard. FoundIt sends the latest reply to the Finder and provides a Private Link to the full Conversation.

7. The Finder can use the Private Link to view and reply in the Conversation without rescanning the Tag, re-entering an email address, creating an Account, or logging in.

8. The Private Link is confidential. A person who obtains it may gain access to the Conversation. The Finder must not publish, forward, or otherwise disclose it to unauthorized persons.

9. Sending a Message does not guarantee:

  • 1) its reading;
  • 2) delivery of the email message;
  • 3) reply from the Tag Owner;
  • 4) confirmation of ownership;
  • 5) concluding an agreement;
  • 6) return of the item.

10. Each Message is:

  • 1) stored in encrypted form;
  • 2) assigned a sender type by the Service, not by form data;
  • 3) made available only to the Tag Owner or the Finder authorized for that Conversation;
  • 4) subject to the retention rules in § 26.

11. The parties acknowledge that the latest Message included in an email notification may remain in the recipient's and email providers' systems under their own retention rules.

12. A Conversation may not be continued after it is closed or expires. The Tag Owner may close it after the item has been recovered.

13. Sending Messages is prohibited if they are:

  • 1) false;
  • 2) fraudulent;
  • 3) threatening;
  • 4) persistent (harassment);
  • 5) insulting;
  • 6) discriminatory;
  • 7) promotional without required basis;
  • 8) containing malicious links;
  • 9) requesting OTP codes or passwords;
  • 10) impersonating the Administrator;
  • 11) violating the privacy or rights of a third party;
  • 12) containing Unlawful Content.

14. The Administrator may limit the creation of Conversations, verification attempts, resends, invalid token attempts, and replies by either party to protect against spam, email bombing, and other abuse.

§ 17. Photos

1. The Finder may voluntarily attach a photo, if the function is available.

2. The person sending the photo declares that:

  • 1) they have the right to dispose of it;
  • 2) sending does not violate copyrights;
  • 3) sending does not violate privacy or personal rights;
  • 4) the photo does not contain Unlawful Content;
  • 5) the photo is related to the purpose of the Message.

3. Sending photos is prohibited if they are:

  • 1) pornographic;
  • 2) depicting child sexual abuse;
  • 3) illegal;
  • 4) containing identity documents without justification;
  • 5) containing payment details;
  • 6) containing malicious code;
  • 7) unrelated to the purpose of the Website;
  • 8) violating the rights of third parties.

4. The photo is resized, re-encoded, and stripped of EXIF metadata.

5. The photo is stored on the server only temporarily for processing and transmission by email.

6. After the sending process is completed, the temporary file is deleted.

7. The Administrator does not maintain a photo archive in the panel.

8. The Administrator does not guarantee that:

  • 1) every photo will be processed correctly;
  • 2) the quality of the photo will be preserved;
  • 3) the recipient's mail system will accept the attachment;
  • 4) the recipient will delete the photo after receiving it.

9. After delivering the photo by email, further use of it by the recipient is outside the direct control of the Administrator.

§ 18. Location

1. The Finder may voluntarily share their location to provide information about the place to the Tag Owner.

2. Sharing the location requires consent granted in the browser or device.

3. Based on the coordinates, the Website generates a link to OpenStreetMap.

4. Coordinates are not stored in the Message record in the active database in the current operational model of this function.

5. The link is forwarded to the owner by email.

6. The User acknowledges that:

  • 1) the device location may be inaccurate;
  • 2) the Administrator does not verify the location;
  • 3) the link may be stored in the recipient's email inbox;
  • 4) after clicking the link, the rules of the external service apply;
  • 5) the Administrator is not liable for the accuracy of data provided by the device.

7. It is prohibited to use the location function for unlawful tracking, harassment, or violating privacy.

§ 19. Web Push

1. Web Push is a voluntary function.

2. Enabling requires granting permission in the browser or operating system.

3. Notifications may concern events related to Tags, Messages, and Account operations.

4. The Administrator may limit the content of notifications for privacy and security reasons.

5. The Administrator does not guarantee delivery of every notification.

6. Delivery depends among other things on:

  • 1) the browser;
  • 2) the operating system;
  • 3) the push infrastructure provider;
  • 4) device settings;
  • 5) Internet connection;
  • 6) energy saving;
  • 7) validity of the subscription.

7. The User may disable notifications in the settings of the Website, browser, or device.

8. The Administrator may automatically remove an expired subscription.

9. The User should not enable notifications on a device to which unauthorized persons have access.

§ 20. Scan Counter

1. The Website may record the aggregated number of views or scans of a Tag.

2. The counter is indicative in nature.

3. The Administrator does not guarantee the full accuracy of the counter, in particular due to:

  • 1) automated traffic;
  • 2) page refreshes;
  • 3) network errors;
  • 4) cache mechanisms;
  • 5) abuse attempts;
  • 6) technical work.

4. The counter does not constitute proof that a specific person scanned the Tag or that the item was found.

§ 21. Permitted Use of the Website

1. The Website should be used:

  • 1) in accordance with the law;
  • 2) in accordance with the Terms of Service;
  • 3) in accordance with good practices;
  • 4) respecting the rights of other persons;
  • 5) in a way that does not interfere with the functioning of the Website.

2. The User may use the Website only to the extent resulting from its functions.

3. The User does not acquire rights to the source code, infrastructure, marks, or elements of the Website other than the right to use the Services in accordance with the Terms of Service.

§ 22. Prohibited Activities

It is prohibited in particular to:

1. provide Unlawful Content;

2. violate copyrights, trademarks, and personal rights;

3. impersonate another person, the Administrator, or an institution;

4. commit or attempt fraud;

5. extort data;

6. demand OTP codes, passwords, or payment details;

7. harass, threaten, or persistently send messages;

8. publish personal data of third parties without a legal basis;

9. use the Website to track people;

10. use automated tools for mass use of forms;

11. bypass limits, blocks, or security measures;

12. test vulnerability without prior authorization;

13. scan infrastructure;

14. attempt to access other people's Accounts;

15. interfere with the operation of the Website;

16. overload servers;

17. introduce malware;

18. modify headers or request data for fraud;

19. extract data from the Website by automated methods without consent;

20. copy or reproduce the Website code to the extent not permitted by law;

21. use a found item, Tag, or form to extort payment;

22. demand benefits from the owner of the item in violation of the law;

23. publish false information about finding the item;

24. use redirections for phishing;

25. use the Website in a manner inconsistent with its purpose.

§ 23. User Content

1. User Content remains under the responsibility of the person who entered it.

2. The User declares that they possess the rights and grounds needed to use the transmitted Content.

3. The User grants the Administrator a non-exclusive, free, and limited authorization to technically:

  • 1) store;
  • 2) reproduce;
  • 3) process;
  • 4) encrypt;
  • 5) display;
  • 6) send;
  • 7) adapt the format of

the User Content solely to the extent necessary to perform the Service.

4. The authorization specified in paragraph 3:

  • 1) does not transfer intellectual property rights to the Administrator;
  • 2) does not authorize the Administrator to use photos or Messages for marketing;
  • 3) expires after the processing is completed, subject to backups and legal obligations.

5. The Administrator has no general obligation to monitor all User Content in advance.

6. The Administrator may, however, take action in the event of detecting or receiving a report of a violation.

§ 24. Reporting Unlawful Content and Abuses

1. Unlawful Content, violation of rights, or other abuse can be reported to the address: contact@foundit.cc

2. The report should, as far as possible, contain:

  • 1) precise indication of the Tag, page, URL, or Content;
  • 2) description of the violation;
  • 3) justification why the Content is illegal or violates rights;
  • 4) contact details of the reporter, except for cases in which their provision is not required or justified;
  • 5) a declaration of good faith;
  • 6) documents or materials supporting the report, if available.

3. The Administrator may request the report to be completed if without additional information the Content cannot be identified or the case evaluated.

4. The Administrator processes reports with due diligence, without arbitrariness, and taking into account the rights of the persons concerned.

5. As a result of the report, the Administrator may:

  • 1) take no action if the report is insufficient or groundless;
  • 2) limit the visibility of the Content;
  • 3) remove the Content;
  • 4) disable the redirection;
  • 5) block the form;
  • 6) temporarily suspend the Tag;
  • 7) suspend or delete the Account;
  • 8) secure information to the extent required by law;
  • 9) forward the matter to the competent authority.

6. The Administrator may inform the person responsible for the Content about the decision and its basic reasons, unless:

  • 1) the law prohibits it;
  • 2) it could obstruct the proceedings;
  • 3) the report concerns cyber security;
  • 4) disclosure would increase the risk of damage.

7. Conscious filing of false or misleading reports may constitute a violation of the Terms of Service.

§ 25. Moderation and Protective Measures

1. The Administrator may take proportionate measures to:

  • 1) ensure security;
  • 2) protect Users;
  • 3) perform a legal obligation;
  • 4) protect the rights of third parties;
  • 5) prevent abuse;
  • 6) protect infrastructure.

2. The measures may include:

  • 1) warning;
  • 2) limiting a specific function;
  • 3) removing Content;
  • 4) changing Tag status;
  • 5) disabling the form;
  • 6) blocking redirection;
  • 7) invalidating the session;
  • 8) removing the Push subscription;
  • 9) temporary suspension of the Account;
  • 10) permanent deletion of the Account;
  • 11) blocking re-registration to the extent consistent with the law.

3. When choosing a measure, the Administrator may take into account:

  • 1) nature of the violation;
  • 2) its effects;
  • 3) repeatability;
  • 4) User's intention;
  • 5) threat to other persons;
  • 6) previous violations;
  • 7) possibility of applying a milder measure.

4. The Administrator may apply an immediate measure without prior warning when:

  • 1) a safety threat occurs;
  • 2) Content is obviously unlawful;
  • 3) the Account is used for fraud;
  • 4) there is a risk of damage to other persons;
  • 5) it is required by a public authority;
  • 6) prior warning could prevent effective action.

5. As far as possible, the User may report objections to the decision by contacting the Administrator.

§ 26. Conversation Deletion and Retention

1. A Conversation expires after 30 days without activity and in every case no later than 60 days after it was created.

2. Each new Message may move the inactivity deadline, but it never extends the 60-day absolute deadline.

3. The Tag Owner may close a Conversation after the item has been recovered. A closed Conversation is deleted from the active database after 7 days.

4. The Tag Owner may delete a Conversation earlier if the Website provides such an option.

5. Deleting a Conversation removes all related Messages, the Finder's encrypted email address, token HMAC values, and related metadata from the active database.

6. After deletion or expiry, the Conversation is not available to either party and cannot be recovered through the Website.

7. Limited copies may temporarily remain in rotating backups and are not used in current operations.

8. The User should independently secure information they are entitled to keep, taking into account the rights of others and data protection rules.

§ 27. Account Deletion

1. The User may delete the Account using the appropriate function of the Website.

2. Account deletion means termination of the Agreement with immediate effect, subject to the time needed for the technical execution of the operation.

3. Account deletion may cause:

  • 1) loss of access to the panel;
  • 2) loss of Tags assigned to the Account;
  • 3) deletion of settings;
  • 4) deletion of Messages;
  • 5) deletion of Passkeys;
  • 6) deletion of Push subscriptions;
  • 7) permanent loss of configuration.

4. The operation may be irreversible.

5. The Administrator may retain a limited scope of data if:

  • 1) required by law;
  • 2) necessary for defense against claims;
  • 3) data is temporarily in backups;
  • 4) necessary to document a violation or perform a legal obligation.

6. Before deleting the Account, the User should read the information about the effects of the operation.

§ 28. Termination of the Agreement by the Administrator

1. The Administrator may terminate the Agreement or suspend the Account if the User:

  • 1) grossly violates the Terms of Service;
  • 2) repeats violations despite warning;
  • 3) uses the Website for fraud;
  • 4) provides Unlawful Content;
  • 5) threatens security;
  • 6) violates the rights of other persons;
  • 7) attempts to hijack someone else's Account or Tags;
  • 8) bypasses imposed restrictions;
  • 9) uses the Website in a manner inconsistent with its purpose.

2. The Administrator may also terminate the provision of Services if:

  • 1) the Website is closed;
  • 2) further provision is technically impossible;
  • 3) required by law;
  • 4) maintaining the function has become disproportionately difficult;
  • 5) a significant change in the Website's model occurs.

3. In the event of a planned termination of the Website, the Administrator will, as far as possible, inform Users with appropriate advance notice.

4. The Administrator may terminate the Service immediately when further provision:

  • 1) would violate the law;
  • 2) would pose an immediate threat;
  • 3) could cause serious damage.

5. The provisions of this paragraph do not exclude the rights of the User resulting from mandatory provisions of law.

§ 29. Website Availability

1. The Administrator strives to ensure the availability of the Website, but does not guarantee uninterrupted or error-free operation.

2. The Website may be temporarily unavailable due to:

  • 1) maintenance;
  • 2) updates;
  • 3) repair;
  • 4) implementation of security measures;
  • 5) hosting failure;
  • 6) mail failure;
  • 7) network failure;
  • 8) software errors;
  • 9) third-party activities;
  • 10) cyber attack;
  • 11) Force Majeure;
  • 12) performance of a legal obligation.

3. The Administrator may carry out work without prior notice if it is urgent or related to security.

4. The Administrator does not guarantee compatibility of the Website with every device, system, and software.

5. User should take into account that the Website is not a life-saving, alarm, or intended system for applications where an interruption could pose a threat to life or health.

§ 30. External Services

1. The operation of the Website may depend on external services, including:

  • 1) hosting;
  • 2) email;
  • 3) Cloudflare Turnstile;
  • 4) OpenStreetMap;
  • 5) Web Push operators;
  • 6) browser and operating system manufacturers.

2. The Administrator does not have full control over external services.

3. The Administrator is not liable for their failures, changes, limitations, or termination of operation, unless liability results from mandatory provisions of law or from the culpable action of the Administrator.

4. Using an external website may be subject to its own terms of service and privacy policy.

§ 31. User Liability

1. The User is responsible for:

  • 1) their actions and omissions;
  • 2) User Content;
  • 3) compliance of the Content with the law;
  • 4) possessing rights to photos and other materials;
  • 5) correctness of data transmitted in the Website;
  • 6) safe use of the Account;
  • 7) proper security of mail and device;
  • 8) using the Tag in accordance with the law;
  • 9) consequences of redirections set;
  • 10) arrangements made with other persons.

2. The User bears liability to third parties for violations resulting from their Content or use of the Website.

3. If the Administrator suffers damage in connection with the User's unlawful activity, the Administrator may seek compensation on general terms, taking into account applicable law.

§ 32. Administrator Liability

1. The Administrator is liable for non-performance or improper performance of the Agreement on terms resulting from applicable regulations, taking into account the following provisions.

2. The Administrator is not liable for:

  • 1) the fact of losing an item;
  • 2) lack of finding the item;
  • 3) Finder's behavior;
  • 4) Tag Owner's behavior;
  • 5) refusal to return the item;
  • 6) handing over the item to an unauthorized person;
  • 7) incorrect identification of the owner;
  • 8) dispute over ownership or possession;
  • 9) truthfulness of User Content;
  • 10) loss or damage to the item;
  • 11) financial claims directed between Users;
  • 12) meetings and arrangements organized outside the Website;
  • 13) actions on external websites;
  • 14) loss of email access;
  • 15) sharing the OTP code by the User;
  • 16) incorrect location provided by the device;
  • 17) non-delivery of Web Push;
  • 18) message rejected by the mail system;
  • 19) non-reading of the message by the recipient;
  • 20) deletion of Messages after the expiration of retention.

3. The Administrator is not liable for User Content of which they are not the author, to the extent permitted by provisions regulating the liability of intermediary service providers.

4. The Administrator may bear liability after obtaining credible knowledge about the illegality and failing to take the required action, to the extent resulting from the law.

5. The Administrator does not guarantee:

  • 1) recovery of the item;
  • 2) effectiveness of the Tag in every case;
  • 3) uninterrupted availability;
  • 4) lack of errors;
  • 5) retention of every configuration indefinitely;
  • 6) compatibility with every device;
  • 7) delivery of every email or Push notification.

6. Towards a User who is not a consumer nor a natural person using consumer protection, the liability of the Administrator for lost profits is excluded to the widest extent permitted by law.

7. Towards the entities indicated in paragraph 6, the total liability of the Administrator related to free Services is limited to the actual damage suffered as a result of the Administrator's intentional action or gross negligence, provided that the law allows such limitation.

8. Liability limitations do not apply:

  • 1) to damage caused intentionally;
  • 2) to liability that cannot be excluded or limited;
  • 3) to consumer rights resulting from mandatory provisions;
  • 4) to personal injury to the extent that limitation would be unacceptable.

9. No provision of the Terms of Service excludes rights that a consumer cannot effectively waive.

§ 33. Safety of Meetings and Handover of Items

1. The Administrator does not organize meetings between Users.

2. Persons arranging the return of an item should exercise caution.

3. It is recommended to:

  • 1) choose a public and safe place;
  • 2) avoid transferring unnecessary data;
  • 3) confirm the characteristics of the item that have not been publicly disclosed;
  • 4) not share OTP codes;
  • 5) exercise caution regarding demands of payment;
  • 6) not click suspicious links;
  • 7) report fraud attempts to appropriate authorities.

4. FoundIt is not a service that ensures physical safety of meetings.

5. The Administrator is not liable for events during the meeting, unless this liability results from their own culpable action and cannot be excluded.

§ 34. Intellectual Property

1. Rights to the Website, in particular to:

  • 1) code;
  • 2) layout;
  • 3) graphic elements;
  • 4) logo;
  • 5) name FoundIt;
  • 6) databases;
  • 7) documentation;
  • 8) templates and designs

belong to the Administrator or appropriate licensors.

2. Using the Website does not result in the transfer of intellectual property rights.

3. The User receives a non-exclusive, non-transferable, and revocable right to use the functions of the Website within the scope of the Terms of Service.

4. Without the consent of the Administrator, it is prohibited to:

  • 1) copy an essential part of the Website;
  • 2) distribute the code;
  • 3) use marks in a way suggesting a commercial relationship;
  • 4) create services impersonating FoundIt;
  • 5) remove legal notices;
  • 6) use elements of the Website commercially outside the scope of the license.

5. Open source components are subject to the terms of their respective licenses.

§ 35. Data Protection

1. The rules of data processing are defined in the Privacy Policy.

2. The Terms of Service and the Privacy Policy constitute separate documents.

3. Acceptance of the Terms of Service does not mean automatic consent to all data processing.

4. The Administrator processes data on grounds appropriate for a specific process.

5. The User must not use the Website to unlawfully obtain or distribute data of other persons.

§ 36. Complaints

1. Complaints regarding the operation of Services may be submitted:

  • 1) by email to contact@foundit.cc;
  • 2) in writing to the address indicated in accordance with § 2, if provided.

2. The complaint should contain, as far as possible:

  • 1) details allowing contact with the complainant;
  • 2) description of the problem;
  • 3) date of occurrence of the problem;
  • 4) indication of the Tag or Account, if needed;
  • 5) expected way of resolution;
  • 6) screenshot or other materials, if they can help.

3. The User should not send in the complaint:

  • 1) mail password;
  • 2) active OTP code;
  • 3) payment details;
  • 4) unnecessary personal data.

4. The Administrator may request completion of information if it is needed to process the complaint.

5. The complaint will be processed without undue delay, no later than within 14 days of its receipt, unless:

  • 1) special regulations provide for a different deadline;
  • 2) the case requires completion by the complainant;
  • 3) extraordinary circumstances occur, of which the Administrator will inform the complainant.

6. The reply will be sent to the email address used for the report, unless another method has been agreed.

7. The complaint procedure does not limit rights arising under the law.

§ 37. Consumers

1. The provisions of the Terms of Service do not violate consumer rights resulting from mandatory provisions.

2. In the event of a conflict between the Terms of Service and a mandatory provision protecting the consumer, the provision of law shall apply.

3. Provisions regarding the exclusion or limitation of liability apply to the consumer only to the extent legally permissible.

4. If in the future the Website offers paid digital services, before concluding the appropriate agreement, the required information will be made available, concerning in particular:

  • 1) price;
  • 2) duration;
  • 3) right of withdrawal;
  • 4) compliance of the digital service with the agreement;
  • 5) functionality and compatibility;
  • 6) complaint procedure.

5. These Terms of Service do not constitute regulations for the sale of physical Tags.

§ 38. Out-of-Court Dispute Resolution

1. The consumer may use out-of-court methods of processing complaints and seeking claims, if they are available under applicable regulations.

2. Information on the possibilities of out-of-court consumer dispute resolution can be obtained from:

  • 1) municipal and county consumer ombudsmen;
  • 2) consumer organizations;
  • 3) competent entities authorized to resolve disputes out of court;
  • 4) the President of the Office of Competition and Consumer Protection.

3. The Administrator does not undertake to participate in specific out-of-court proceedings unless such obligation results from the law or the Administrator consents to it.

§ 39. Amendments to the Terms of Service

1. The Administrator may amend the Terms of Service for an important reason, in particular in the case of:

  • 1) change in law;
  • 2) decision of authority;
  • 3) change of Website functions;
  • 4) introduction of a new Service;
  • 5) removal of a function;
  • 6) change of technology;
  • 7) change of security requirements;
  • 8) need to counteract abuse;
  • 9) change of Administrator's details;
  • 10) need to remove ambiguities or errors.

2. An amendment cannot deprive the User of acquired rights if it would run counter to the law.

3. Users holding an Account will be informed of a significant amendment by:

  • 1) email message;
  • 2) message on the Website;
  • 3) another appropriate method.

4. The information should indicate:

  • 1) content or scope of changes;
  • 2) date of entry into force;
  • 3) possibility to terminate the Agreement if the User does not accept the change.

5. The Administrator may require re-acceptance of the Terms of Service before further use of functions changing the state of the Account or data.

6. Until the required acceptance, the Administrator may limit the possibility of performing operations, leaving access to information needed to read the amendment and delete the Account.

7. Purely editorial changes that do not affect rights and obligations may enter into force without advance notice.

8. If an immediate change is necessary due to law or security, it may enter into force earlier, with appropriate information for Users.

§ 40. Termination of the Website Operation

1. The Administrator may terminate the Website.

2. Users will be informed of the planned termination with appropriate advance notice, as far as possible and consistent with security.

3. After the termination of the Website:

  • 1) Accounts may be deleted;
  • 2) Tags may stop working;
  • 3) redirections may be disabled;
  • 4) Messages may be deleted;
  • 5) notifications will stop being sent.

4. The User acknowledges that the free Service is not guaranteed indefinitely.

5. The Administrator is not liable for the need to replace the Tag with another solution after the termination of the Website, subject to rights that cannot be excluded.

§ 41. Force Majeure

1. The Administrator is not liable for non-performance or delay in performance of Services caused by Force Majeure to the extent permitted by law.

2. Events of Force Majeure may be considered in particular:

  • 1) natural disasters;
  • 2) war;
  • 3) riots;
  • 4) long-term power failure;
  • 5) wide-range telecommunications infrastructure failure;
  • 6) actions of public authorities;
  • 7) serious cyber attacks;
  • 8) other events remaining outside the reasonable control of the Administrator.

3. The Administrator will take reasonable actions to limit the effects of the event and restore the Services, if possible.

§ 42. Governing Law and Disputes

1. Polish law applies to the Terms of Service and Agreements, subject to regulations that provide the consumer with protection under the law of the state of their habitual residence and which cannot be excluded by agreement.

2. Disputes will be resolved by the competent court in accordance with applicable regulations.

3. The provision of paragraph 2 does not impose on the consumer a court other than competent under the provisions of law.

4. In relations with an entity that is not a consumer nor a natural person using consumer protection, the competent court may be the court competent for the Administrator's place of residence, if the law permits such agreement.

§ 43. Severability

1. If any provision of the Terms of Service turns out to be invalid, ineffective, or unenforceable, it does not affect the validity of the remaining provisions.

2. In place of the invalid provision, the appropriate provision of law shall apply.

3. The Administrator may replace the defective provision with a new provision that as fully as possible realizes the lawful purpose of the original entry.

§ 44. Priority of Provisions of Law

1. The Terms of Service do not exclude or limit rights which under applicable regulations cannot be excluded or limited by agreement.

2. If a provision of the Terms of Service is inconsistent with a mandatory provision, that provision applies in its place.

3. Liability limitations provided for in the Terms of Service should be interpreted only to the widest extent permitted by law.

§ 45. Final Provisions

1. The Terms of Service apply from the day indicated in their header.

2. The current version of the Terms of Service is available free of charge on the Website.

3. The Terms of Service may be saved and reproduced using ordinary functions of the device or browser.

4. The Privacy Policy is an integral information document regarding privacy, which, however, does not constitute a basis for extending the Administrator's liability beyond the scope resulting from the law and the Terms of Service.

5. In matters related to the Terms of Service, you can contact the Administrator at: contact@foundit.cc

6. In matters not regulated, the relevant provisions of Polish law and European Union law shall apply.