Privacy policy
What data we process, why, for how long, and your rights.
Last updated:
This notice is given under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and explains how we process the personal data of people who visit the site and people who buy from it.
1. Controller
The controller is the Seller, whose details and contacts are shown at the top of this page. For any privacy request, write to the email address shown there.
2. What data we process
Browsing data. When you visit the site, the hosting provider automatically records technical data such as IP address, browser type, requested page and time. This is needed to serve the pages and protect the site from abuse.
Cart. Your cart and chosen shipping zone are stored only in your browser (localStorage) and are not sent to us until you go to checkout. See the Cookie policy.
Order data. When you buy, we collect through Stripe’s payment page: first and last name, email, phone, shipping and billing address, items bought and amounts. Card and other payment details are collected directly by Stripe: we never see or store them.
Messages. If you write to us by email or WhatsApp, we process the data you give us in order to reply.
We don’t collect special categories of data and don’t ask for data we don’t need.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Handling your order: payment, production, shipping, support, returns and guarantee | Performance of a contract (Art. 6(1)(b) GDPR) |
| Answering questions before you buy | Pre-contractual steps (Art. 6(1)(b)) |
| Meeting accounting and tax obligations | Legal obligation (Art. 6(1)(c)) |
| Keeping the site secure and preventing fraud | Legitimate interest (Art. 6(1)(f)) |
| Establishing, exercising or defending legal claims | Legitimate interest (Art. 6(1)(f)) |
We don’t use your data for marketing or profiling. If we ever want to send you promotional messages, we’ll ask first and only do so with your consent.
Order data is needed to form the contract: without it we can’t fulfil your order.
4. Who we share data with
Data is processed by the Seller and shared only with those needed for the purposes above:
- Stripe Payments Europe Ltd. (Ireland), for payment processing and fraud prevention. Stripe acts as an independent controller for payment data: see Stripe’s privacy policy;
- Cloudflare, Inc., the site’s hosting and security provider, as processor;
- carriers, for delivery;
- suppliers of preorder items, who receive your delivery name, address and phone so they can ship directly to you;
- partner workshops, for services carried out on the vehicle, limited to the data needed for the appointment;
- accounting and tax advisers, bound by confidentiality;
- our email provider and, if you contact us on WhatsApp, WhatsApp Ireland Ltd.;
- public authorities, where required by law.
Data is not published or sold to anyone.
5. Transfers outside the European Economic Area
Some providers (in particular Cloudflare and Stripe) may process data in the United States. Such transfers rely on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework and/or on the Standard Contractual Clauses approved by the Commission.
If a preorder item ships from a supplier outside the EEA, passing on your delivery details is necessary to perform the contract you asked for (Art. 49(1)(b) GDPR).
6. How long we keep data
- Order data and accounting records: 10 years from the order date, as required by Article 2220 of the Italian Civil Code;
- support messages: as long as needed to handle the request and no longer than 24 months after the last contact, unless needed for a dispute;
- browsing data: for the limited period set by the hosting provider for security purposes;
- cart: stays in your browser until you complete the order or clear the site’s data.
7. Your rights
At any time you can ask for access to your data, rectification, erasure, restriction of processing and data portability, and you can object to processing based on legitimate interest (Articles 15–21 GDPR). Write to the email address at the top of this page: we reply within one month.
Some data can’t be erased before legal retention periods end, for example accounting records.
If you believe the processing breaches the GDPR, you can lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority of the country where you live.
8. Automated decisions
We don’t make decisions based solely on automated processing. Stripe may run automated fraud checks on payments, as described in its own policy.
9. Minors
The site and its services are intended for adults. We don’t knowingly collect data from minors.
10. Changes
We may update this notice. The date of the last update is shown at the top of the page; significant changes will be flagged on the site.