Privacy Policy

Last updated:

1. Who processes your data

Data controller: HOBBYKIT SRLS
P.IVA: 02966380640
Registered office: Via Michelangelo Buonarroti, 45 - 83035 Grottaminarda (AV) - Italy
Site: www.ideeinfeltro.com
Privacy email: privacy@ideeinfeltro.com

2. What data we collect

2.1 Account and purchase data

  • Personal and contact data (first name, last name, email, phone).
  • Shipping and billing addresses.
  • Data needed to manage orders, payments, returns and support.

2.2 Login with Facebook / Google (Social Login)

If you choose "Login with Facebook" or "Login with Google" we receive the following platform data from the social providers:

  • App-scoped user ID (Facebook/Google ID internal to the app)
  • First and last name (basic public profile)
  • Email (if available and authorized)

We do not require additional permissions or access to your profile content. We only use this data to authenticate you, create or recognize your customer account, and pre-fill profile fields.

2.3 Technical data and cookies

  • Log data (IP address, user-agent, pages visited, times) for security and operation.
  • Cookies and similar technologies. See our Cookie Policy for details.

3. Why we process data (purpose) and legal basis

PurposesData usedLegal basis (GDPR)Storage
Registration and login (email/password or Social Login)Name, email, app-scoped IDExecution of pre-contractual/contractual measures (Art. 6.1.b)As long as account remains active or until cancellation request
Management of orders, payments, shipments, returnsAccount data, addresses, order dataContract (Art. 6.1.b) and legal/fiscal obligations (Art. 6.1.c)Up to 10 years for civil/tax obligations
Customer supportContact data, contents of requestsContract/legal interest in assistance (Art. 6.1.b/f)Up to 24 months after exchange
Site security and abuse preventionTechnical logs, IPLegitimate interest (art. 6.1.f)Up to 12 months
Statistical analysis and marketing on consentNon-technical online cookies/IDsConsent (art. 6.1.a) via banner cookieAccording to cookie duration or until revoked

4. Nature of provision

Data required for registration, login and purchase are mandatory; without them we cannot provide the service to you. Analytics/marketing cookies are optional and require consent.

5. Recipients and data controllers

We only share data with providers who provide services on our behalf, who are appointed as data controllers (Art. 28 GDPR):

  • Hosting / Server: Netsons (infrastructure in EU) - hosting and maintenance service.
  • Email/SMTP providers: (e.g., Google Workspace/Microsoft 365) - communications management.
  • Payments: (e.g. Stripe/PayPal/other on site) - receive data needed to finalize payment.
  • IT Support/Backups: individuals in charge of technical maintenance and secure backups.

We do not sell your data. Social data (Facebook/Google) are not given to third parties for purposes other than authentication.

6. Transfers outside the EEA

We prefer providers with data centers in the European Economic Area. If a service would process data outside the EEA, the transfer would take place with appropriate safeguards (e.g., EU Standard Contractual Clauses) or other compliant mechanism (Art. 44-49 GDPR).

7. Retention and deletion

  • Account and Social Login: until request for deletion or account closure.
  • Orders and tax documents: for as long as required by law (up to 10 years).
  • Technical logs: up to 12 months.
  • Cookies: according to the duration indicated in the Cookie Policy.

To delete data or disconnect Social Login you can:

8. Rights of the data subject

You can exercise your rights under Articles 15-22 GDPR (access, rectification, deletion, restriction, portability, opposition, withdrawal of consent). To exercise them, write to privacy@ideeinfeltro.com. You have the right to lodge a complaint with the Garante per la protezione dei dati personali(www.garanteprivacy.it).

9. Security

The site uses HTTPS encrypted connections, role-based access controls, strong back-office authentication, periodic backups, and appropriate technical and organizational measures to protect data.

10. Minors

The service is intended for users aged ≥ 13 years. We do not knowingly collect data from minors; if you believe a minor has provided us with data, please contact us for removal.

11. Third-party plugins and policies

When you use Social Login, Facebook and Google treat your data as autonomous owners according to their policies:

12. Cookies

For detailed information about the cookies we use, their purposes, and how to manage your preferences, visit our Cookie Policy. You can change your choices at any time from the Cookie Preference Center on the site.

13. Changes to this policy

We may update this policy for regulatory adjustments or service evolutions. Changes will be posted on this page with the date of the update.

HOBBYKIT SRLS - Via Michelangelo Buonarroti, 45 - 83035 Grottaminarda (AV) - P.IVA 02966380640

Product added to wishlist