PRIVACY POLICY
This Website ( https://shop.fornasaricars.com ) collects some Personal Data of its Users.
This document can be printed using the print command available in the settings of any browser.
DATA CONTROLLERShop Fornasari di Fornasari GiovanniVia Basili 6, Arcugnano 36057 (Vi)Italy
Email address of the Data Controller: Contact@fornasaricars.com
TYPES OF DATA COLLECTED
Among the Personal Data collected by this Website, either independently or through third parties, there are: Tracking Tools; Usage Data; responses to questions; clicks; keypress events; motion sensor events; mouse movements; scroll position relative; touch events; first name; last name; billing address; shipping address; phone number; payment information; device information; email; purchase history; username; password; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); various types of Data; Data communicated during service usage; country; gender; date of birth; geographic location; VAT number; company name; Tax Code; province; ZIP code; city; street address; language; number of Users; session statistics; latitude (of the city); longitude (of the city); browser information; physical address.
Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific informative texts displayed prior to the data collection.
COLLECTION MODE AND PLACE OF DATA PROCESSING
PROCESSING METHODS
The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data. Processing is carried out using computers and/or IT-enabled tools, with organizational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Website (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Data Controller at any time.
LEGAL BASIS OF PROCESSING
The Data Controller processes Personal Data relating to the User if one of the following conditions exists:
The User has given consent for one or more specific purposes; Note: In some jurisdictions, the Data Controller may be allowed to process Personal Data without the User’s consent or another legal basis specified below, until the User objects to such processing (“opt-out”), without having to rely on consent or another legal basis specified below. However, this does not apply whenever the processing of Personal Data is subject to European data protection law;processing is necessary for the performance of a contract with the User and/or for any pre-contractual obligations thereof;processing is necessary for compliance with a legal obligation to which the Data Controller is subject;processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.It is always possible to request the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on the law, provided for by a contract or necessary to conclude a contract.
PLACE
The Data is processed at the Data Controller’s operating offices and in any other places where the parties involved in the processing are located. For further information, please contact the Data Controller. The User’s Personal Data may be transferred to a country other than their own. To find out more about the place of processing, the User can refer to the section containing details about the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization of public international law or consisting of two or more countries, such as the UN, as well as regarding the security measures taken by the Data Controller to protect the Data.
The User can check whether one of the transfers described above takes place by examining the section of this document relating to the details on the processing of Personal Data or request information from the Data Controller by contacting them using the information provided above.
RETENTION PERIOD
The Data is processed and stored for as long as required by the purposes for which it was collected.
Therefore:
Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.Where processing is based on consent, the Data Controller may store Personal Data for a longer period until such consent is revoked. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification, and the right to data portability cannot be enforced anymore upon expiration of the retention period.
PURPOSES OF DATA PROCESSING
User data is collected to allow the Data Controller to provide the Service, fulfill legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of Users or third parties), identify any fraudulent activities, as well as for the following purposes: Statistics, Displaying content from external platforms, Protection from SPAM, Platform and hosting services, Payment management, Tag management, Remarketing and behavioral targeting, Advertising, Registration and authentication, Interaction with live chat platforms, Data collection and online survey management, Interaction with social networks and external platforms, Contacting the User, Contact management and sending messages, Interaction with data collection platforms and other third parties, Location-based interactions, Registration and authentication provided directly by this Website, Data transfer outside the EU, Collection of privacy preferences, Heat mapping and session recording, and Hosting and backend infrastructure.
For detailed information on the purposes of the processing and the Personal Data processed for each purpose, Users can refer to the section “Details on the processing of Personal Data”.
DETAILS ON THE PROCESSING OF PERSONAL DATA
Personal Data is collected for the following purposes and using the following services:
CONTACTING THE USER PHONE CONTACT (THIS WEBSITE)
Users who have provided their phone numbers may be contacted for commercial or promotional purposes related to this Website, as well as to fulfill support requests.
Personal Data processed: phone number.
MAILING LIST OR NEWSLETTER (THIS WEBSITE)
By registering for the mailing list or newsletter, the User’s email address is automatically added to a list of contacts to which email messages containing information, including commercial and promotional information, relating to this Website may be transmitted. The User’s email address may also be added to this list as a result of registering for this Website or after making a purchase.
Personal Data processed: last name; date of birth; email; country; first name; phone number; gender.
CONTACT FORM (THIS WEBSITE)
By filling in the contact form with their Data, the User consents to their use to respond to requests for information, quotes, or any other kind of request as indicated by the form’s header.
Personal Data processed: last name; email; first name; phone number.
CONTACT MANAGEMENT AND MESSAGE SENDING
This type of service enables the management of a database of email contacts, phone contacts, or any other contact information to communicate with the User. These services may also collect data concerning the date and time when the message was viewed by the User, as well as when the User interacted with it, such as by clicking on links included in the message.
MAILCHIMP (INTUIT INC.)
Mailchimp is an email address management and message sending service provided by Intuit Inc.
Personal Data processed: last name; date of birth; email; country; first name; phone number; gender.
Processing location: United States – Privacy Policy.
PAYMENT MANAGEMENT
Unless otherwise specified, this Website processes all payments by credit card, bank transfer, or other means through external payment service providers. In general, and unless otherwise indicated, Users are requested to provide payment details and personal information directly to such payment service providers.This Website is not involved in the collection and processing of such information: instead, it will only receive a notification from the respective payment service provider regarding the successful payment.
GOOGLE PAY (GOOGLE IRELAND LIMITED)
Google Pay is a payment service provided by Google Ireland Limited, which allows the User to make online payments using their Google credentials.
Personal Data processed: last name; purchase history; usage data; email; billing address; shipping address; payment information; first name; phone number; tracking tools; various types of Data as specified in the privacy policy of the service.
Processing location: Ireland – Privacy Policy.
APPLE PAY (APPLE INC.)
Apple Pay is a payment service provided by Apple Inc., which allows the User to make payments using their mobile phone.
Personal Data processed: last name; purchase history; usage data; email; billing address; shipping address; payment information; first name; phone number; tracking tools; various types of Data as specified in the privacy policy of the service.
Processing location: United States – Privacy Policy.
PAYPAL (PAYPAL)
PayPal is a payment service provided by PayPal Inc., which allows the User to make online payments.
Personal Data processed: last name; purchase history; usage data; email; billing address; payment information; information about the device; first name; phone number; password; tracking tools; username; various types of Data as specified in the privacy policy of the service.
Processing location: See Paypal’s privacy policy – Privacy Policy.
STRIPE (STRIPE TECHNOLOGY EUROPE LTD)
Stripe is a payment service provided by Stripe Technology Europe Ltd.
Personal Data processed: last name; purchase history; usage data; email; billing address; payment information; first name; tracking tools; various types of Data as specified in the privacy policy of the service.
Processing location: Ireland – Privacy Policy.
BANK TRANSFER PAYMENT (THIS WEBSITE)
In case the chosen payment method is a direct bank transfer to the bank account indicated by this Website, the Owner will collect the payment data of the User, namely the account number of the sender, the SWIFT code, the Bank, and the name of the sender. Such data will be collected and processed exclusively for the transaction and for billing purposes.
Personal Data processed: last name; physical address; payment information; first name; company name.
TAG MANAGEMENT
This type of service is functional for the centralized management of tags or scripts used on this Website. The use of such services involves the flow of User Data through them and, if necessary, their retention.
GOOGLE TAG MANAGER (GOOGLE IRELAND LIMITED)
Google Tag Manager is a tag management service provided by Google Ireland Limited.
Personal Data processed: Usage Data; Tracking Tools.
Processing location: Ireland – Privacy Policy.
DATA COLLECTION AND ONLINE SURVEY MANAGEMENT
This type of service allows this Website to manage the creation, implementation, administration, distribution, and analysis of online forms and surveys in order to collect, store, and reuse User Data who respond. The Personal Data collected depends on the information requested and provided by Users in the corresponding online form.
These services may be integrated with a wide range of third-party services to allow the Owner to take subsequent actions with the processed Data – for example, contact management, message sending, statistics, advertising, and payment processing.
FACEBOOK LEAD ADS (META PLATFORMS IRELAND LIMITED)
Facebook Lead Ads is an advertising and data collection service provided by Meta Platforms Ireland Limited that allows Users to be shown advertising messages in the form of pre-populated forms with Personal Data from their Facebook profiles, such as names and email addresses. Depending on the type of ad, Users may be asked to provide additional information.
Submitting the form involves the collection and processing of this Data by the Owner in accordance with this privacy policy and only for the specific purpose indicated in the form and/or within this privacy policy, where provided.
Personal Data processed: last name; email; first name; phone number.
Processing location: Ireland – Privacy Policy – Opt out.
HOSTING AND BACKEND INFRASTRUCTURE
This type of service is used to host Data and files that allow this Website to function, enable their distribution, and provide a ready-to-use infrastructure to deliver specific functionalities of this Website. Some of the services listed below, if any, may operate on geographically distributed servers, making it difficult to determine the actual location where Personal Data is stored.
INTERACTION WITH LIVE CHAT PLATFORMS
This type of service allows interaction with live chat platforms operated by third parties directly from the pages of this Website, in order to contact and be contacted by the support service of this Website. If a live chat platform interaction service is installed, it is possible that, even if Users do not use the service, the same may collect Usage Data relating to the pages where it is installed. Additionally, live chat conversations may be recorded.
FACEBOOK MESSENGER CUSTOMER CHAT (META PLATFORMS IRELAND LIMITED)
Facebook Messenger Customer Chat is an interaction service with the Facebook Messenger live chat platform, provided by Meta Platforms Ireland Limited.
Personal Data processed: Data communicated during the use of the service; Usage Data; Tracking Tools.
Processing location: Ireland – Privacy Policy.
INTERACTION WITH DATA COLLECTION PLATFORMS AND OTHER THIRD PARTIES
This type of service allows Users to interact with data collection platforms or other services directly from the pages of this Website for the purpose of saving and reusing data. If one of these services is installed, it is possible that, even if Users do not use the service, the same may collect Usage Data relating to the pages where it is installed.
MAILCHIMP WIDGET (INTUIT INC.)
The Mailchimp widget allows interaction with the Mailchimp email management and messaging service provided by Intuit Inc.
Personal Data processed: email.
Processing location: United States – Privacy Policy.
INTERACTION WITH SOCIAL NETWORKS AND EXTERNAL PLATFORMS
This type of service allows interaction with social networks or other external platforms directly from the pages of this Website. Interactions and the information acquired by this Website are in any case subject to the User’s privacy settings for each social network. This type of service may still collect traffic data for the pages where the service is installed, even when Users do not use it. It is recommended to log out of the respective services to ensure that the data processed on this Website is not linked to the User’s profile.
PAYPAL BUTTONS AND WIDGETS (PAYPAL)
PayPal buttons and widgets are interaction services with the PayPal platform, provided by PayPal Inc.
Personal Data processed: Usage Data; Tracking Tools.
Processing location: Consult PayPal’s privacy policy – Privacy Policy.
LOCATION-BASED INTERACTIONSNON-CONTINUOUS GEOLOCATION (THIS WEBSITE)
This Website may collect, use, and share Data related to the User’s geographical location in order to provide location-based services. Most browsers and devices provide default tools to deny geolocation tracking. If the User has expressly authorized this possibility, this Website may receive information about their actual geographical location. The geographical location of the User occurs in a non-continuous manner, upon specific request of the User or when the User does not indicate their location in the appropriate field and allows the application to automatically detect the location.
Personal Data processed: geographical location.
SPAM PROTECTION
This type of service analyzes the traffic of this Website, potentially containing Personal Data of Users, in order to filter it from parts of traffic, messages, and content recognized as SPAM.
GOOGLE RECAPTCHA (GOOGLE IRELAND LIMITED)
Google reCAPTCHA is a SPAM protection service provided by Google Ireland Limited. The use of the reCAPTCHA system is subject to Google’s privacy policy and terms of use.
Personal Data processed: clicks; Usage Data; keypress events; motion sensor events; touch events; mouse movements; scrolling position relative to the page; answers to questions; Tracking Tools.
Processing location: Ireland – Privacy Policy.
ADVERTISING
This type of service allows the use of User Data for commercial communication purposes. These communications are displayed on this Website in the form of banners and other advertising formats, also in relation to the User’s interests. However, this does not mean that all Personal Data is used for this purpose. Data and usage conditions are indicated below. Some of the services listed below may use Tracking Tools to identify the User or employ behavioral retargeting techniques, meaning they display personalized advertising based on the User’s interests and behavior, even outside of this Website. For more information, we suggest checking the privacy policies of the respective services. Generally, services of this kind offer the possibility to opt-out of such tracking. In addition to any opt-out feature provided by any of the services listed in this document, Users can learn more about how to disable interest-based advertising in the dedicated “How to Disable Interest-Based Advertising” section in this document.
GOOGLE ADS SIMILAR AUDIENCES (GOOGLE IRELAND LIMITED)
Google Ads Similar Audiences is an advertising and behavioral targeting service provided by Google Ireland Limited that uses Google Ads Remarketing Data to display advertising to Users with behaviors similar to those of other Users who are already in the remarketing list due to their previous use of this Website. Based on this Data, personalized ads will be shown to Users suggested by Google Ads Similar Audiences.
Users who do not wish to be included in similar audience segments can choose not to participate and disable the use of advertising Tracking Tools by visiting Google’s Ad Settings.
For an understanding of Google’s use of Data, please refer to Google’s Partner Policies.
Personal Data processed: Usage Data; Tracking Tools.
Processing location: Ireland – Privacy Policy – Opt Out.
META AUDIENCE NETWORK (META PLATFORMS IRELAND LIMITED)
Meta Audience Network is an advertising service provided by Meta Platforms Ireland Limited. For an understanding of Facebook’s data usage, please refer to Facebook’s data policies.
To allow the operation of the Meta Audience Network, this Website may use some identifiers for mobile devices (including Android Advertising ID or Advertising Identifier for OS) or technologies similar to cookies. Among the methods through which the Audience Network offers advertising messages to the User, there is also the use of the User’s advertising preferences. Users can control the sharing of their advertising preferences within Facebook’s Ad settings.
Users can opt out of some Audience Network targeting functions through their device settings. For example, they can change advertising settings available for mobile devices, or follow applicable Audience Network instructions if available within this privacy policy.
Personal Data processed: Usage Data; unique identifiers for advertising devices (Google Advertiser ID or IDFA identifier, for example); Tracking Tools.
Processing location: Ireland – Privacy Policy – Opt Out.
FACEBOOK SIMILAR AUDIENCE (META PLATFORMS IRELAND LIMITED)
Facebook Similar Audience is an advertising and behavioral targeting service provided by Meta Platforms Ireland Limited that uses data collected through Facebook’s Custom Audience service to display advertising to Users with behaviors similar to Users who are already in a Custom Audience list based on their previous use of this Website or their interaction with relevant content through Facebook’s applications and services. Based on this Data, personalized ads will be shown to Users suggested by Facebook Similar Audience.
Users can choose not to use Facebook’s Tracking Tools for ad personalization by visiting this opt-out page.
Personal Data processed: Usage Data; Tracking Tools.
Processing location: Ireland – Privacy Policy – Opt Out.
Collection of Privacy Preferences
This type of service allows this Website to collect and store User preferences regarding the collection, use, and processing of their personal information, as required by applicable privacy legislation.
Complianz
Complianz allows the Data Controller to collect and store User preferences regarding the processing of personal data, particularly the use of Cookies and other Tracking Tools on this Website.
Personal Data processed: Tracking Tools.
Processing location: Italy – Privacy Policy.
Complianz allows the storage and retrieval of User consent records for the processing of Personal Data, as well as the information and preferences expressed in relation to the provided consent. For this purpose, it uses a Tracking Tool that temporarily stores pending information on the User’s device until processed by the API. The Tracking Tool (a browser feature called localStorage) is then deleted.
Personal Data processed: Data communicated during the use of the service; Tracking Tools.
Processing location: Italy – Privacy Policy.