Privacy policy

PRIVACY POLICY

This Privacy Policy explains how shoprhinestonesandroses.shop collects, uses, stores, shares, and protects personal data when individuals visit https://shoprhinestonesandroses.shop, place an order, purchase or receive a gift card, create an account, contact us, subscribe to marketing, or otherwise use our services.

This policy is intended to provide information required under the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”), applicable Italian data-protection law, and other applicable privacy legislation.

1. Data Controller

For the processing described in this policy, the operator of shoprhinestonesandroses.shop acts as the data controller unless otherwise stated.

Store: shoprhinestonesandroses.shop
Website: https://shoprhinestonesandroses.shop
Email: info@shoprhinestonesandroses.shop
Telephone: +39 3470484135
Business Address: Via Lago Maggiore, 8, Montebello Vicentino (VI), Italy

Privacy questions and requests may be sent to info@shoprhinestonesandroses.shop.

2. Personal Data We Collect

Depending on the individual’s interaction with our store, we may collect:

Identity and contact information

This includes name, email address, telephone number, billing address, delivery address, account information, and preferred language.

Order and transaction information

This includes ordered products, selected sizes and styles, order numbers, transaction values, discounts, payment status, delivery information, cancellations, returns, refunds, complaints, and customer-service history.

Gift card information

Where gift cards are offered, we may process:

  • Purchaser information;

  • Recipient name and email address;

  • Gift message;

  • Gift card identifier;

  • Original and remaining value;

  • Issue date;

  • Redemption history; and

  • Fraud or misuse indicators.

Customers providing a recipient’s information must have lawful authority to do so and should ensure that the recipient is aware of the relevant privacy information.

Payment information

Payments are processed through providers available at checkout. We generally receive transaction status, payment method, limited payment identifiers, billing information, and fraud-screening results rather than complete card information.

Technical and usage information

This may include IP address, browser type, device type, operating system, cookie identifiers, approximate location, time zone, language settings, pages viewed, cart activity, and checkout interaction.

Communications

This includes emails, reviews, return requests, complaints, survey responses, telephone communications, and other correspondence.

Marketing information

This includes subscription status, marketing preferences, consent records, email engagement, and withdrawal of consent.

Security information

This may include transaction patterns, account activity, device signals, delivery information, gift card activity, and risk indicators used to prevent fraud or unauthorized transactions.

3. How We Collect Personal Data

We collect personal data:

  • Directly from customers and visitors;

  • Automatically through cookies and similar technologies;

  • From Shopify;

  • From payment processors;

  • From delivery and fulfilment providers;

  • From fraud-prevention and security providers;

  • From analytics and advertising providers where permitted; and

  • From a person purchasing a product or gift card for another recipient.

4. Purposes and Legal Bases

We process personal data only where a valid legal basis applies.

Performance of a contract

We process information to:

  • Operate the cart and checkout;

  • Accept and fulfil orders;

  • Issue and redeem gift cards;

  • Process payments;

  • Deliver products;

  • Send order and gift communications;

  • Manage customer accounts;

  • Provide customer support;

  • Process returns and refunds; and

  • Handle contractual complaints.

Compliance with legal obligations

We process information to:

  • Maintain tax and accounting records;

  • Comply with consumer-protection requirements;

  • Respond to lawful government requests;

  • Meet product-safety obligations;

  • Comply with privacy and security requirements; and

  • Preserve legally required transaction records.

Legitimate interests

Subject to applicable balancing requirements, we may process information to:

  • Prevent fraud, gift card misuse, and unauthorized transactions;

  • Protect customers, systems, and legal rights;

  • Improve the website and customer service;

  • Measure website performance;

  • Manage inventory;

  • Handle complaints;

  • Establish or defend legal claims; and

  • Send permitted communications to existing customers.

Consent

Where required, we rely on consent for:

  • Promotional emails;

  • Non-essential analytics;

  • Advertising cookies;

  • Personalized advertising; and

  • Other optional processing explained when consent is requested.

Consent may be withdrawn at any time.

5. Shopify

Our store is hosted through Shopify. Shopify provides the e-commerce infrastructure used to display products, operate checkout, support transactions, issue store gift cards where configured, and maintain platform security.

Depending on the processing activity, Shopify may act as our processor, service provider, independent controller, or in another legally recognized role.

Customers should review Shopify’s applicable privacy information regarding its independent processing practices.

6. Sharing Personal Data

We may share necessary personal data with:

  • Shopify and e-commerce technology providers;

  • Payment processors, banks, and card networks;

  • Warehousing and fulfilment providers;

  • Postal services and delivery carriers;

  • Customer-support and communications providers;

  • Cloud hosting and information-technology providers;

  • Security and fraud-prevention providers;

  • Analytics and advertising providers where permitted;

  • Accountants, insurers, auditors, lawyers, and professional advisers;

  • Government authorities, regulators, law-enforcement bodies, or courts where legally required; and

  • A purchaser or successor involved in a lawful business reorganization.

We do not sell personal data in the ordinary meaning of exchanging it directly for money.

7. Cookies and Similar Technologies

Our website may use cookies, pixels, local storage, tags, and similar technologies to:

  • Operate the cart and checkout;

  • Maintain secure sessions;

  • Remember preferences;

  • Prevent fraud;

  • Measure website traffic;

  • Understand website use;

  • Personalize content; and

  • Deliver or measure advertising where consent has been obtained.

Strictly necessary cookies may be used without consent where permitted by law.

Non-essential analytics, personalization, and advertising technologies will be activated only after obtaining any consent required by applicable law.

Visitors may manage available choices through the website’s cookie banner, privacy controls, and browser settings.

8. Marketing Communications

We send electronic marketing only where we have consent or another lawful basis.

Recipients may unsubscribe using the link in a marketing message or by contacting info@shoprhinestonesandroses.shop.

Unsubscribing does not prevent necessary communications concerning orders, gift cards, delivery, returns, refunds, security, or legal notices.

9. International Transfers

Some providers may process personal data outside Italy or the European Economic Area.

Where legally required, transfers will be protected through:

  • A European Commission adequacy decision;

  • Standard Contractual Clauses;

  • Appropriate supplementary safeguards; or

  • Another legally recognized transfer mechanism.

Information about relevant safeguards may be requested from info@shoprhinestonesandroses.shop.

10. Data Retention

We retain personal data only for as long as reasonably necessary for the relevant purpose and legal obligations.

Retention periods depend on:

  • Italian tax and accounting requirements;

  • The duration of the customer relationship;

  • Outstanding gift card balances;

  • Return and legal-guarantee periods;

  • Fraud-prevention and security requirements;

  • Applicable limitation periods; and

  • Existing complaints or disputes.

When data is no longer required, it will be deleted, anonymized, or securely isolated unless continued retention is legally required.

11. Security

We use reasonable technical and organizational safeguards designed to protect personal data against unauthorized access, loss, alteration, misuse, disclosure, or destruction.

These safeguards may include encrypted transmission, access restrictions, authentication controls, monitoring, backups, platform security functions, and confidentiality obligations.

No internet transmission or electronic storage system is completely secure.

12. Children’s Privacy

Our store is not intended for children acting without the authorization of a parent or legal guardian.

We do not knowingly collect personal data directly from children who cannot lawfully consent to the relevant processing. A parent or guardian who believes that a child supplied information without authorization should contact us.

13. Automated Processing

Payment and fraud-prevention providers may use automated systems to evaluate transaction, account, or gift card risks.

Where a solely automated decision produces legal or similarly significant effects and applicable law grants relevant rights, the individual may request human intervention, express a point of view, and contest the decision.

14. Privacy Rights

Subject to applicable conditions and exceptions, individuals may have the right to:

  • Access their personal data;

  • Correct inaccurate information;

  • Request deletion;

  • Restrict processing;

  • Object to legitimate-interest processing;

  • Object to direct marketing at any time;

  • Receive eligible data in a portable format;

  • Withdraw consent;

  • Request information about international-transfer safeguards;

  • Exercise applicable rights concerning automated decisions; and

  • Submit a complaint to a supervisory authority.

15. Exercising Privacy Rights

Requests may be sent to info@shoprhinestonesandroses.shop.

We may request reasonable proof of identity before disclosing, changing, or deleting personal information.

We will respond within the period required by applicable law. Under the GDPR, this is generally one month, subject to lawful extensions for complex or numerous requests.

16. Complaints

Individuals may contact us first so that we can investigate a concern.

They may also submit a complaint to:

Garante per la protezione dei dati personali
Piazza Venezia 11
00187 Rome, Italy
Website: https://www.garanteprivacy.it

An individual may also contact another competent EU or EEA supervisory authority.

17. Third-Party Links

Our website may contain links to payment providers, delivery carriers, social networks, or other independent services.

Those services process information according to their own privacy notices. We are not responsible for independent third-party privacy practices.

18. Changes to This Policy

We may update this Privacy Policy to reflect changes in our services, providers, technology, or legal obligations.

The updated version will be published with a revised effective date. Additional notice or renewed consent will be provided where required.

19. Contact Us

shoprhinestonesandroses.shop
Website: https://shoprhinestonesandroses.shop
Email: info@shoprhinestonesandroses.shop
Telephone: +39 3470484135
Address: Via Lago Maggiore, 8, Montebello Vicentino (VI), Italy