Privacy policy

This Privacy Policy explains how personal information may be collected, used, disclosed, stored and otherwise processed when individuals visit, use or make purchases through maxigastro.shop.

We respect the privacy of our customers and website visitors and seek to process personal data transparently, fairly and lawfully.

This Privacy Policy is intended to reflect relevant requirements of the General Data Protection Regulation, Italian data-protection rules and other applicable privacy legislation.

Questions about privacy may be sent to:

Email: info@maxigastro.shop

Scope

This Privacy Policy applies to personal information processed in connection with activities such as:

  • Visiting maxigastro.shop;
  • Browsing products;
  • Creating or using a customer account;
  • Placing an order;
  • Completing checkout;
  • Making payment;
  • Requesting customer support;
  • Requesting a return or refund;
  • Exercising consumer rights;
  • Subscribing to marketing where available;
  • Communicating with us;
  • Interacting with website technologies; or
  • Otherwise using services offered through maxigastro.shop.

Personal Data We May Collect

Depending on how a person interacts with the store, we may process the following categories of information.

Identification Information

This may include:

  • Name;
  • Account details;
  • Customer identification information; and
  • Other information voluntarily supplied to identify an order or request.

Contact Information

This may include:

  • Email address;
  • Telephone number;
  • Billing address;
  • Shipping address; and
  • Other contact information supplied by the customer.

Order and Transaction Information

This may include:

  • Products purchased;
  • Product preferences;
  • Order number;
  • Order status;
  • Transaction amount;
  • Discount information;
  • Shipping method;
  • Delivery details;
  • Returns;
  • Refunds;
  • Communications concerning an order; and
  • Related transaction records.

Payment Information

Payments may be processed by Shopify-supported or other authorized payment providers.

Depending on the payment method, payment processors may process:

  • Payment-card details;
  • Bank or payment-account information;
  • Payment authorization data;
  • Billing details;
  • Fraud-prevention information; and
  • Transaction identifiers.

We may receive limited payment information, such as payment status or transaction reference information, rather than complete payment credentials.

Device and Technical Information

When a visitor accesses maxigastro.shop, certain technical information may be processed automatically, including:

  • IP address;
  • Browser type;
  • Device type;
  • Operating system;
  • Language preferences;
  • Device identifiers;
  • Approximate location derived from IP information;
  • Referring pages;
  • Website interaction information; and
  • Security logs.

Website Usage Information

We may process information relating to:

  • Pages viewed;
  • Products viewed;
  • Searches;
  • Cart activity;
  • Checkout interactions;
  • Time spent on pages;
  • Links selected; and
  • Other interaction information.

The use of non-essential analytics or advertising technologies will be subject to applicable consent requirements.

Customer-Service Communications

When customers contact us, we may process:

  • Email correspondence;
  • Support requests;
  • Complaint information;
  • Return requests;
  • Photographs supplied in support of a claim;
  • Order information; and
  • Other information voluntarily supplied.

Sources of Personal Data

Personal data may be obtained:

  • Directly from customers;
  • Automatically from devices or browsers;
  • Through Shopify;
  • Through payment providers;
  • Through shipping and logistics providers;
  • Through fraud-prevention providers;
  • Through analytics providers, where permitted;
  • Through advertising or marketing providers, where permitted; and
  • From other service providers lawfully supporting store operations.

Purposes of Processing

Personal data may be processed for purposes including:

  • Operating the website;
  • Providing requested ecommerce services;
  • Processing orders;
  • Processing payments;
  • Delivering products;
  • Managing customer accounts;
  • Communicating about orders;
  • Handling returns;
  • Processing refunds;
  • Responding to customer inquiries;
  • Fulfilling legal obligations;
  • Maintaining accounting and transaction records;
  • Preventing fraud;
  • Securing the website;
  • Detecting misuse;
  • Resolving disputes;
  • Improving store functionality;
  • Understanding website performance;
  • Sending marketing communications where lawful;
  • Managing cookie preferences; and
  • Establishing, exercising or defending legal claims.

Legal Bases for Processing

Where GDPR applies, personal data will be processed only where an appropriate legal basis exists.

Performance of a Contract

We may process personal information when necessary to:

  • Process an order;
  • Take payment;
  • Arrange delivery;
  • Provide customer service related to a purchase;
  • Process a return or refund; or
  • Otherwise perform obligations arising from a sales contract.

Steps Before Entering a Contract

We may process information necessary to respond to a request made before a purchase or contract is completed.

Legal Obligations

We may process information where necessary to comply with applicable obligations concerning:

  • Tax;
  • Accounting;
  • Consumer protection;
  • Product safety;
  • Fraud prevention;
  • Regulatory requirements; or
  • Legal proceedings.

Legitimate Interests

Where permitted, we may process personal data on the basis of legitimate interests, such as:

  • Securing our services;
  • Preventing fraud;
  • Protecting customers;
  • Managing business operations;
  • Improving services;
  • Defending legal rights; or
  • Preventing misuse.

Where legitimate interests are relied upon, those interests will be balanced against the rights and freedoms of affected individuals.

Consent

Consent may be relied upon where legally required, including for certain:

  • Marketing communications;
  • Advertising technologies;
  • Profiling cookies;
  • Non-essential tracking technologies; or
  • Other optional processing.

Consent can be withdrawn at any time without affecting the lawfulness of processing undertaken before withdrawal.

Shopify

maxigastro.shop may be hosted and operated using Shopify ecommerce services.

Shopify may process personal information to provide:

  • Store hosting;
  • Checkout services;
  • Transaction infrastructure;
  • Security;
  • Analytics;
  • Fraud-prevention features;
  • Customer-account functionality; and
  • Other ecommerce features.

Depending on the particular processing activity, Shopify or other providers may act as processors, sub-processors or, for certain activities, independent controllers subject to their own privacy obligations.

Service Providers

Personal information may be shared with trusted service providers where reasonably necessary for store operations.

Categories may include:

  • Ecommerce-platform providers;
  • Payment processors;
  • Shipping companies;
  • Fulfilment providers;
  • Customer-support providers;
  • Cloud-hosting providers;
  • Security providers;
  • Fraud-prevention services;
  • Accounting providers;
  • Professional advisers;
  • Analytics providers;
  • Marketing providers; and
  • Technology vendors.

Service providers should receive only the information reasonably necessary for their relevant function and process it according to applicable law.

Legal Disclosures

Personal information may be disclosed where reasonably necessary to:

  • Comply with law;
  • Respond to a lawful authority;
  • Enforce contractual rights;
  • Investigate fraud;
  • Protect users;
  • Protect the website;
  • Protect property or safety;
  • Establish or defend legal claims; or
  • Comply with judicial or regulatory requirements.

Business Transactions

If the business operating maxigastro.shop is involved in a reorganization, merger, financing, acquisition, sale or transfer of assets, personal data may be transferred where permitted by applicable law.

Any successor would remain subject to applicable privacy obligations.

International Data Transfers

Some service providers may operate outside Italy or outside the European Economic Area.

Where personal data subject to GDPR is transferred to a country outside the EEA, an appropriate transfer mechanism will be used where required.

Such mechanisms may include:

  • An adequacy decision adopted by the European Commission;
  • Standard Contractual Clauses;
  • Other approved safeguards; or
  • A specific statutory derogation where legally available.

Data Retention

Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected and for applicable legal requirements.

Retention periods may depend on:

  • The duration of the customer relationship;
  • The type of information;
  • Contractual obligations;
  • Tax and accounting obligations;
  • Consumer-protection obligations;
  • Fraud-prevention requirements;
  • Limitation periods;
  • Legal proceedings; and
  • Security considerations.

When data is no longer required, it may be securely deleted or anonymized, subject to applicable law.

Cookies and Similar Technologies

maxigastro.shop may use cookies, pixels, local storage and similar technologies.

These technologies may serve different purposes.

Strictly Necessary or Technical Technologies

Technical technologies may be used to provide functions explicitly requested by users, such as:

  • Shopping-cart functionality;
  • Checkout;
  • Security;
  • Authentication;
  • Session management;
  • Payment processing;
  • Fraud prevention; and
  • Remembering necessary privacy choices.

Where Italian law classifies such technologies as strictly necessary, prior consent may not be required.

Analytics Technologies

Analytics technologies may be used to understand website operation and performance.

Where consent is required under applicable law, such technologies will not be activated until appropriate consent has been obtained.

Advertising and Profiling Technologies

Advertising or profiling technologies may be used to measure campaigns, understand advertising performance or provide more relevant advertisements.

Where required under Italian law, such technologies will be activated only after valid consent.

Cookie Choices

Where a cookie-consent interface is provided, users may be able to:

  • Accept eligible optional technologies;
  • Reject optional technologies;
  • Choose categories;
  • Review preferences; and
  • Withdraw or modify consent.

Rejecting non-essential technologies should not prevent access to core store functions that do not depend upon them.

Marketing Communications

We may send promotional electronic communications only where permitted by applicable law.

Where consent is required, marketing will be sent only after appropriate consent has been obtained.

Recipients may unsubscribe using the method provided in the communication or by contacting:

info@maxigastro.shop

Transactional communications relating to an order or customer-service request are not necessarily marketing communications and may still be sent where necessary.

Automated Processing and Fraud Prevention

Certain payment, security or fraud-prevention providers may use automated systems to identify suspicious activity.

Where a decision producing legal or similarly significant effects is based solely on automated processing, rights available under applicable data-protection law will be respected.

Data Security

We use or rely upon reasonable technical and organizational measures designed to protect personal information against:

  • Unauthorized access;
  • Loss;
  • Misuse;
  • Alteration;
  • Disclosure;
  • Destruction; and
  • Other unlawful processing.

No internet-based system can guarantee absolute security, but reasonable protective measures are maintained according to the nature of the information and relevant risks.

Data Protection Rights

Subject to the requirements and exceptions of applicable law, individuals may have rights including:

  • The right of access;
  • The right to rectification;
  • The right to erasure;
  • The right to restriction of processing;
  • The right to object;
  • The right to data portability;
  • The right to withdraw consent;
  • Rights relating to certain automated decisions; and
  • The right to lodge a complaint with a competent supervisory authority.

Requests may be submitted to:

info@maxigastro.shop

We may request reasonable information to verify identity before fulfilling a request.

Complaints

Individuals who believe their personal data has been processed unlawfully have the right, where applicable, to lodge a complaint with the competent supervisory authority.

For individuals in Italy, the relevant supervisory authority is the Garante per la protezione dei dati personali.

We encourage individuals to contact us first where appropriate so that we can attempt to address the concern.

Children's Privacy

maxigastro.shop is intended as a general ecommerce service and is not designed to knowingly collect personal data from children in violation of applicable law.

Where we become aware that personal data has been collected unlawfully from a child, appropriate steps may be taken to delete or otherwise lawfully handle that information.

Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • Changes to services;
  • Changes in technology;
  • Changes in service providers;
  • Legal developments;
  • Regulatory guidance; or
  • Operational changes.

The updated version will be published on maxigastro.shop with an appropriate revision date.

Contact

Questions, privacy requests or complaints may be sent to:

maxigastro.shop
Email: info@maxigastro.shop