Legal
Privacy Policy
Version 1.0 · Last updated: September 20, 2026
1. Controller
The data controller under Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003 as amended is:
Contact for any privacy matter: quazacards0@gmail.com or the PEC address above.
2. Data we process
- Checkout data, entered on Stripe's page: e-mail address, cardholder name, country, and the payment method. We receive from Stripe the e-mail, name, country, payment status, amount and a session/order reference. We never receive your full card number.
- Delivery data: the signed Access Link generated for your order and the times it is used to download the Product.
- Consent record: the fact that you ticked the checkout consent to immediate delivery, stored with the order reference.
- Technical data: IP address, user agent and request logs kept briefly by our hosting provider for security and error diagnosis.
- Correspondence: whatever you send us by e-mail.
We do not process special categories of data and we do not profile you.
3. Why we process it and on what legal basis
- To conclude and perform the contract (Art. 6(1)(b) GDPR): take payment, deliver the Product, re-issue a lost link, answer support requests.
- To comply with legal obligations (Art. 6(1)(c)): tax and accounting records, responding to authorities, proving consent given at checkout (Art. 51(7) Italian Consumer Code).
- Legitimate interests (Art. 6(1)(f)): security of the Store, preventing fraud and abuse of Access Links, defending claims and chargebacks.
Providing checkout data is necessary to buy; without it the contract cannot be concluded. We send no marketing e-mail.
4. Who we share it with
- Stripe Payments Europe, Ltd. (Ireland) and affiliates: payment processing, receipts, fraud prevention. Stripe acts as an independent controller for payment data under its own privacy policy.
- Vercel Inc. (USA): hosting of the Store and its request logs, as processor.
- Our e-mail provider: for support correspondence.
- Professional advisers and authorities where required by law or to defend a claim.
We do not sell personal data and we do not share it with advertisers.
5. International transfers
Hosting and some Stripe processing take place in the United States. Transfers rely on the EU–US Data Privacy Framework where the recipient is certified and otherwise on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR).
6. How long we keep it
- Order, payment and consent records: 10 years from the end of the financial year of the purchase (Art. 2220 Italian Civil Code and tax law).
- Access Link and download log: for as long as the order record is kept, so the link keeps working.
- Hosting request logs: up to 30 days.
- Support correspondence: up to 24 months after the last message, longer if needed for a claim.
7. Your rights
You may ask for access, rectification, erasure, restriction, portability and object to processing based on legitimate interests (Arts. 15–22 GDPR) by writing to quazacards0@gmail.com. We reply within one month. You may lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority of your country of residence.
8. Cookies
The Store sets no cookies of its own. See the Cookie Policy.
9. Changes
We may update this notice; the date at the top shows the current version.