Privacy policy
Privacy Policy
1) Purpose of the information
This Policy describes how Lumiavera Srl (“ Lumiavera ,” “we,” or “us”) collects, uses, discloses, and protects personal information when you visit lumiavera.com , use our services, or make purchases (the “ Services ”). By using the Services, you accept the practices described in this Policy. If you do not accept them, please do not use the Services.
2) Data controller and contact details
- Owner: Lumiavera Srl, Viale Sondrio 3, 20124 Milan, Italy – VAT number 13769230965
- Email: info@lumiavera.com
- PEC: lumiavera@pec.it
3) Changes to this policy
We may update this Policy for operational, legal, or regulatory reasons. We will post the updated version on this page and adjust the "Last Updated" date.
4) What data we collect
4.1 Data provided directly by you
- Personal and contact information (name, surname, address, email, telephone number).
- Order and delivery information (billing/shipping address, order contents, notes).
- Account data (if you create an account): username, preferences.
- Support communications (content you choose to send us).
4.2 Data collected automatically (cookies and similar technologies)
We collect technical and usage information (e.g., IP address, device, browser, page views, events) through cookies, pixels, and similar technologies (" Cookies "). See the "Cookies and Tracking" section.
4.3 Data from third parties
We may receive data from vendors who provide parts of the Services (e.g., payments, shipping, reviews, analytics, anti-fraud).
5) Purposes and legal bases of the processing
- Contract performance : order management, payments, delivery, returns, warranties; account management. (Article 6(1)(b) GDPR)
- Legal obligation : tax/accounting compliance and legal obligations. (Article 6(1)(c) GDPR)
- Legitimate interests : IT security, fraud prevention (including fraud controls), improved customer care, basic analytics, protection of rights. (Article 6(1)(f) GDPR)
- Consent : sending promotional communications via email, non-technical cookies, profiling / retargeting activities. (Article 6(1)(a) GDPR)
- Soft opt-in (Italy): We may send marketing emails to existing customers regarding similar products/services, with the option to opt-out in each message . (Article 130, paragraph 4, Privacy Code)
6) Profiling and personalization
To improve your experience and make communications more relevant, we may use data (e.g., purchase history, email interactions, cart history) to create segments (e.g., new customers, returning customers, abandoned carts) and display personalized offers, subject to your consent where required. You can withdraw/object to this at any time (see "Rights").
7) Cookies and tracking
We use technical cookies to operate the site and, with your consent, measurement and marketing cookies (e.g., Google Analytics 4, Microsoft Clarity, standard Meta Pixel). In the absence of a dedicated Cookie Policy page, we point you to Shopify's resources on cookies: shopify.com/legal/cookies .
You can manage your preferences from your browser (blocking/removing cookies). Blocking some cookies may limit the functionality of the site. If a global signal (e.g., GPC) is sent, we may not currently recognize it, in addition to the choices expressed via your browser/available tools.
8) Data suppliers and recipients
We share data only with parties who support us in providing the Services or for legal obligations, as data processors or independent controllers when applicable:
- E-commerce platform: Shopify.
- Payments: Shopify Payments, PayPal, Klarna, Apple Pay, Google Pay (card details processed by the respective PSPs).
- Shipping and logistics: e-courier and GSped platforms; main carrier TNT.
- Reviews: Loox, Trustpilot.
- Anti-fraud: Shopify Fraud Protect.
- Analytics/tracking: Google Analytics 4, Microsoft Clarity; Standard Meta Pixels.
- Email marketing: Mailchimp, Shopify Email.
- Consultants/Authorities: Legal/IT consultants, authorities, and public bodies when required by law.
Upon request, we can provide an updated list of data controllers.
9) Storage times
- Order and billing data: up to 10 years (civil/tax obligations).
- Inactive customer accounts: Deletion/anonymization after 24–36 months of inactivity (criterion: 30 months unless otherwise requested).
- Customer support (ticket/email): 24 months .
- Email marketing: until consent is revoked or 24 months of inactivity.
- Analytics (GA4): Event retention typically 14 months (or configured GA4 default value).
- Abandoned cart: 60 days .
- Technical/security logs: approximately 12 months .
10) Data transfers outside the EEA
Some providers may also process data outside the European Economic Area (e.g., Canada/USA). In such cases, we adopt appropriate safeguards such as the Standard Contractual Clauses (SCCs) and, where applicable, rely on adequacy decisions or the Data Privacy Framework . Detailed information is available in the privacy policies of individual providers.
11) Your rights
Under the GDPR, you can exercise your rights to access , rectification , erasure , restriction , objection (including profiling and direct marketing), and data portability , as well as withdraw your consent. You will not be discriminated against for exercising your rights.
How to exercise them: write to info@lumiavera.com or lumiavera@pec.it . We may request information to verify your identity before processing your request.
Supervisory Authority: you can lodge a complaint with the Italian Data Protection Authority .
12) Communications and marketing
- Marketing: Email only (Mailchimp, Shopify Email), with prior consent or soft opt-in for existing customers; opt-out always available.
- Support: Email and WhatsApp (support only, no marketing).
13) Data security
We take appropriate technical and organizational measures to protect personal data (e.g., encryption in transit, access controls, the principle of least privilege, monitoring, and backups). No measure is perfect: please avoid sending us sensitive information over unsecured channels.
14) Minors
The Services are not intended for children under 16. We do not knowingly collect data from minors; if you believe a minor has provided us with data, please contact us to have it removed.
15) Data breaches
In the event of a breach that poses a risk to the rights and freedoms of individuals, we will conduct a risk assessment and, if requested, notify the competent authority and the data subjects in accordance with Articles 33–34 of the GDPR.
16) Third-party sites and links
The Site may contain links to third-party sites not controlled by us. Always review their privacy policies. We are not responsible for the privacy, security, accuracy, or practices of such sites.
Contacts
- Lumiavera Srl — Viale Sondrio 3, 20124 Milan, Italy
- Privacy and rights email: info@lumiavera.com
- PEC: lumiavera@pec.it
- Telephone: +39 340 4723593

