Privacy Policy
Version: privacy-policy@2026-05-20
DRAFT — pending legal review
This document is a placeholder. The final wording will be provided by the data controller after legal review.
This notice explains how we process your personal data when you use this shop, in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (Regulation 2016/679, GDPR).
1. Data controller and contact details
Data controller: [legal name of the business operating this shop]. Registered office: [registered address]. VAT / Tax ID: [VAT number]. Contact email: [privacy contact email]. Telephone: [contact phone].
A data protection officer (DPO) has not been designated, as the conditions under Art. 37(1) GDPR do not apply. The controller can be contacted directly using the details above for any data-protection request.
2. Categories of personal data we process
We process the following categories of personal data: identification data (name, email, phone), authentication data (account credentials managed by Supabase Auth, including verification codes), order data (cart contents, delivery address, scheduled delivery slot, age-verification declaration), payment and transaction data (payment method, transaction reference; full card data is handled by the payment provider and is never stored on our systems), customer-service data (messages and complaints), and technical data (IP address, browser, device data, session identifiers).
We do not knowingly collect personal data from minors under 16. Age-restricted products (e.g. alcoholic beverages) require the customer to confirm that they are at least 18 years old.
3. Purposes of processing and legal bases
Account creation and authentication — to let you sign in and access your order history. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Processing orders and deliveries — to receive, prepare and deliver your orders, including age verification at delivery. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations on the sale of age-restricted goods (Art. 6(1)(c) GDPR).
Customer service — to handle requests, complaints and after-sales communications. Legal basis: performance of a contract or our legitimate interest in responding to you (Art. 6(1)(b) / 6(1)(f) GDPR).
Security, fraud prevention and abuse mitigation — including rate-limiting, audit logs and review of suspicious behaviour. Legal basis: legitimate interest in protecting the service and its users (Art. 6(1)(f) GDPR).
Compliance with tax, accounting and consumer-law obligations — including issuing fiscal receipts and retaining order records. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
Marketing communications and promotions — only with your prior, freely-given consent. Legal basis: consent (Art. 6(1)(a) GDPR); you can withdraw consent at any time.
4. Recipients and processors
We rely on the following data processors (acting on our behalf under written contracts pursuant to Art. 28 GDPR): Supabase (database, authentication and edge-function hosting); Vercel (web application hosting and CDN); Google (sign-in with Google OAuth, optional for users who choose this method); the SMS provider used to deliver phone-verification codes; the payment provider used to process payments (Stripe); the electronic-receipt provider used to issue fiscal receipts.
Specific provider names, locations and the data-processing agreements in place will be listed here once finalised by the controller.
Personal data is not sold to third parties and is not used for automated decision-making that produces legal effects on you.
5. International data transfers
Some of the processors above may process personal data outside the European Economic Area (e.g. Vercel, Google). In those cases, transfers are based on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) and any supplementary measures recommended by the EDPB. You can request a copy of the safeguards in place using the contact details above.
6. Retention periods
Order, invoice and accounting records are retained for the period required by Italian tax and consumer-protection law (typically 10 years).
Account data is retained for as long as your account is active. Inactive accounts are deleted after a defined inactivity period.
Consent records (cookies, marketing, age verification) are retained for as long as required to demonstrate compliance with Art. 7(1) GDPR.
Server logs and security logs are retained for a limited period and then deleted or anonymised.
7. Your rights as a data subject
Under Articles 15–22 GDPR you have the right to: access your personal data; obtain rectification of inaccurate data; obtain erasure (the "right to be forgotten"); restrict processing; receive your data in a structured, machine-readable format and have it transmitted to another controller (portability); object to processing based on legitimate interests; withdraw any consent you have given without affecting the lawfulness of prior processing.
Where processing is necessary to perform a contract or to comply with a legal obligation, erasure and restriction may be limited until the retention obligation expires.
8. How to exercise your rights
You can exercise these rights by contacting the controller at the email above, or — where available — directly from your account settings (data export and account deletion are being implemented under Stories 1.8 and 1.9 of the GDPR compliance epic).
We will respond without undue delay and in any case within one month of receipt of the request, as required by Art. 12(3) GDPR.
9. Right to lodge a complaint
If you believe that processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali — www.garanteprivacy.it) or with the supervisory authority of your habitual residence.
10. Changes to this policy
We may update this policy from time to time. The current version identifier is shown at the top of this page; when material changes are made we will request your renewed consent where required.
