Privacy policy
This notice explains which personal data we collect when you visit www.basedodici.com, buy our products or contact us, why we process it, who we share it with and what your rights are. It is provided under articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 ("Privacy Code").
1. Data controller
BASEDODICI SRLS
Via dell'Abbazia 1/a, 61032 Fano (PU), Italy
VAT IT02796290415 · REA PS-288305
Email: onlineshop@basedodici.com
For any request about your data you can write to this address.
2. Which data we process
- Contact and identity data: name, surname, email, phone number, shipping and billing address, tax code or VAT number if you request an invoice.
- Order data: products purchased, amounts, order history, returns, discount codes and gift cards used.
- Payment data: processed directly by the payment providers (see §5). We do not store full card numbers.
- Account data: credentials, wishlist, loyalty points, preferences, if you create an account or sign up through social login.
- Browsing data: IP address, device and browser type, pages visited, referrer, interactions with the site, collected through cookies and similar technologies (see §9).
- Communications: the content of messages you send us by email, site forms or WhatsApp.
3. Why we process it and on which legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Managing your order: payment, shipping, invoicing, returns and support | contact, order, payment | Performance of the contract (art. 6.1.b GDPR) |
| Complying with tax and accounting obligations | contact, order, invoicing | Legal obligation (art. 6.1.c) |
| Managing your account, wishlist and loyalty programme | account, order | Performance of the contract (art. 6.1.b) |
| Answering your requests (email, forms, WhatsApp) | contact, communications | Pre-contractual measures and legitimate interest (art. 6.1.b and 6.1.f) |
| Sending you newsletters, promotions and SMS | email, phone, order history | Consent (art. 6.1.a), revocable at any time |
| Sending you offers on products similar to those you already bought (soft spam) | email, order history | Legitimate interest (art. 6.1.f and art. 130.4 Privacy Code), with the right to object at any time |
| Reminding you of an abandoned cart | email or phone, cart content | Consent (art. 6.1.a) |
| Measuring visits and understanding how the site is used | browsing | Consent through the cookie banner (art. 6.1.a) |
| Showing you personalised ads on Meta, Google, TikTok, Pinterest and measuring their effectiveness | browsing, order, hashed email and phone | Consent through the cookie banner (art. 6.1.a) |
| Preventing fraud and abuse, protecting our rights | browsing, order, payment | Legitimate interest (art. 6.1.f) |
Providing the data needed for the order is essential: without it we cannot sell you the product. Consent to marketing and to non-essential cookies is optional and does not affect your purchase.
4. How long we keep the data
- Order and invoicing data: 10 years from the order, as required by law (art. 2220 Italian Civil Code).
- Account data: as long as the account is active; you can ask for deletion at any time.
- Marketing data: until you withdraw consent or object, with periodic checks of your interest.
- Browsing data and cookies: for the durations indicated in the cookie section (§9).
- Support communications: as long as needed to handle the request and no longer than 2 years, except for disputes.
5. Who we share the data with
We do not sell your data. We share it only with providers we need to run the shop, each for its own function. Providers processing data on our behalf are appointed as data processors (art. 28 GDPR).
E-commerce platform
- Shopify (Shopify International Ltd, Ireland; Shopify Inc., Canada): hosts the site and manages orders, accounts and checkout. Canada and the United States are covered by adequacy decisions or standard contractual clauses.
Payments (they process payment data independently, as controllers)
- Shopify Payments (credit and debit cards, Apple Pay, Google Pay, Shop Pay)
- PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg)
- Scalapay (Scalapay S.r.l., Italy), instalment payments
- Cash on delivery, where available: the carrier collects the payment
Shipping
- GLS Italy for Italy · DHL Express for other countries: they receive name, address, phone and email for delivery and notifications.
Email, SMS and messaging
- Omnisend (Omnisend Ltd, UK and EU): newsletters, SMS, cart reminders.
- WhatsApp services integrated in the site (chat, order notifications and marketing via WhatsApp, through third-party providers and Meta's WhatsApp Business platform): used only if you write to us on WhatsApp or have agreed to receive messages.
- Shopify Forms and site forms: collect the data you enter in the forms.
Statistics and site improvement (only with your consent to cookies)
- Google Analytics 4 (Google Ireland Ltd): visit statistics.
- Microsoft Clarity (Microsoft Ireland Operations Ltd): heatmaps and anonymised session recordings.
- Triple Whale (Triple Whale Inc., USA): attribution of sales to advertising campaigns.
Advertising (only with your consent to cookies)
- Meta (Meta Platforms Ireland Ltd): Meta Pixel and Conversions API for Facebook and Instagram.
- Google Ads (Google Ireland Ltd): conversion measurement and remarketing.
- TikTok (TikTok Technology Ltd, Ireland): pixel and events.
- Pinterest (Pinterest Europe Ltd, Ireland): conversion tag.
Other services
- Growave: loyalty programme and wishlist.
- Social login (Google, Facebook): if you choose to sign up this way, we receive your name and email from the provider.
- Technical providers and automations (e.g. Zapier, support and shipping-management tools): they process data only for the necessary operations.
- Advisors and authorities: accountants, lawyers, public authorities when required by law.
6. Transfers outside the European Union
Some providers (Google, Meta, Microsoft, Shopify, Triple Whale, TikTok, Pinterest) may process data in the United States or other non-EU countries. In these cases the transfer is based on an adequacy decision of the European Commission (including the EU-US Data Privacy Framework for certified companies) or on the standard contractual clauses approved by the Commission, with any additional safeguards needed. You can ask us for a copy of the safeguards applied.
7. Your rights
At any time you can:
- access your data and obtain a copy;
- rectify it if inaccurate or incomplete;
- erase it ("right to be forgotten"), within the limits of legal obligations;
- restrict processing;
- object to processing based on legitimate interest, including direct marketing;
- withdraw consent, without affecting processing already carried out;
- obtain the portability of your data in a structured format;
- lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with the authority of the country where you live.
To exercise your rights write to onlineshop@basedodici.com. We reply within one month, extendable by two in complex cases. To unsubscribe from the newsletter you can also use the link at the bottom of every email; for SMS, follow the instructions in the message.
8. Minors
The site is intended for people aged 14 or over. We do not knowingly collect data from children under 14: if you believe this has happened, write to us and we will delete it.
9. Cookies and similar technologies
The site uses cookies and similar technologies (pixels, local storage, session identifiers). When you reach the site from the European Union, the United Kingdom or Switzerland, a banner asks you whether to accept non-essential cookies. You can accept all, reject all or choose by category, and change your mind at any time from the "Cookie preferences" link at the bottom of the site.
9.1 Essential cookies (always active)
They make the site work: cart, checkout, login, language and currency, security, memory of your cookie choice. They do not require consent.
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
cart, cart_currency, cart_ver, cart_sig
|
Shopify | cart content and state | 14 days |
_shopify_s, _shopify_y
|
Shopify | session and Shopify internal analytics | 30 min · 1 year |
_tracking_consent, _cmp_a
|
Shopify | stores your cookie choice | 1 year |
localization |
Shopify | language, country and currency | 14 days |
secure_customer_sig, customer_auth_*, keep_alive
|
Shopify | account login and session | up to 1 year |
checkout_*, _secure_session_id, shopify_pay, _pay_session
|
Shopify | checkout and payment | session, up to 1 year |
_orig_referrer, _landing_page
|
Shopify | landing page and referrer | 14 days |
9.2 Functional cookies
They remember your preferences and enable features such as wishlist, loyalty programme, WhatsApp chat, instalment-payment widget and social login. Set by Growave, Scalapay, Oxi Social Login and the messaging services.
9.3 Analytics cookies (with consent)
| Service | Main cookies | Duration |
|---|---|---|
| Google Analytics 4 |
_ga, _ga_*, _gid
|
up to 2 years |
| Microsoft Clarity |
_clck, _clsk, CLID, MUID
|
up to 1 year |
| Triple Whale | session and attribution identifier | up to 1 year |
9.4 Marketing cookies (with consent)
| Service | Main cookies | Duration |
|---|---|---|
| Meta (Facebook and Instagram) |
_fbp, _fbc
|
3 months |
| Google Ads |
_gcl_au, _gcl_aw
|
3 months |
| TikTok |
_ttp, _tt_enable_cookie
|
13 months |
_pin_unauth, _pinterest_ct_ua
|
1 year | |
| Omnisend | session and contact identifiers | up to 1 year |
Names and durations are set by the respective providers and may change. For details and opt-out options see their policies: Google, Meta, Microsoft, TikTok, Pinterest, Omnisend, Triple Whale, Shopify.
9.5 How to manage cookies
- From the banner on your first visit, or later from the "Cookie preferences" link in the site footer.
- From your browser settings, which let you block or delete cookies (with possible limits on how the site works).
- For interest-based advertising, also through YourOnlineChoices.
10. Security
The site uses encrypted connections (HTTPS). Shopify and the payment providers are PCI-DSS certified. We adopt appropriate technical and organisational measures to protect data from unauthorised access, loss or misuse.
11. Changes to this notice
We may update this notice, for example when the services we use change. The version in force is always the one published on this page. In case of significant changes we will let you know, if we have your contact details.