Privacy policy
Last updated: 18 August 2026
This is a courtesy translation. In case of discrepancy the Italian text prevails, being the original version.
This page explains what data we collect when you order or book on ipizzacchiere.com, why we collect it and what you can ask us to do with it. It's written to be read, not to be skimmed.
Who processes your data
MICELI DARIO
Via San Miniato 2 — 50125 Firenze (FI)
VAT no. 07465550486
Phone +39 055 2466332
Email ipizzacchierefirenze@gmail.com
For anything to do with your data you can write to us at that address or call us.
What data we collect, and why
| What we collect | When | Why | Legal basis |
|---|---|---|---|
| Name, phone number, delivery address | When you place an order | To prepare the order, deliver it and find you | Performance of the contract — art. 6.1.b GDPR |
| Order or registration | To send you the confirmation and the updates on the order | Performance of the contract | |
| Email and password | If you register | So you can find your orders and your addresses again | Performance of the contract |
| Order notes (allergies, doorbell, floor) | If you write them yourself | To make the order the way you want it | Performance of the contract |
| Amount, method and status of the payment | Every order | To know whether it's been paid, for the invoice and for tax obligations | Legal obligation — art. 6.1.c GDPR |
| Name, phone number, email | If you book the pizza course | To confirm your place and let you know if anything changes | Performance of the contract |
| The messages you exchange with the person bringing your order | If you write in the chat while the delivery is under way | So that they can find you — a broken buzzer, a floor, a front door | Performance of the contract |
| IP address and essential technical data | Every visit | To make the site work and to defend it against abuse | Legitimate interest — art. 6.1.f GDPR |
| Email, date and IP address of your consent | If you subscribe to the news | To send you news from the pizzeria, and to be able to show when and from where you said yes | Consent — art. 6.1.a GDPR |
We don't ask you for anything we don't need. We don't collect your date of birth, we don't profile you, we neither buy nor sell address lists.
We never see your card details
When you pay by card, you don't go through our site: you're taken to the secure page of our payment provider, where you enter your card number.
👉 That number never reaches us, we don't see it and we don't keep it. Of that payment we receive only the amount, the method, the outcome and a code identifying the transaction.
Who else processes your data on our behalf
To make the service work we rely on five providers, each for one thing only. All of them have a contract with us obliging them to process the data only for what we need.
| Who | What they do | Where |
|---|---|---|
| OVH | Hosts the server the site and the database run on | France — European Union |
| MultiSafepay | Handles card payments | Netherlands — European Union |
| Geoapify | Completes the delivery address as you type it | Cyprus, with servers in the European Union |
| Resend | Sends the order confirmation and update emails | United States |
| OpenStreetMap Foundation | Draws the map you follow the rider on, in your order page | United Kingdom — the tiles come through a cache network, and a request leaving from Italy is answered by a node in Italy |
⚠️ About sending the emails: the provider is based in the United States. The transfer takes place on the basis of the standard contractual clauses approved by the European Commission, which are the instrument the GDPR provides for these cases. What goes into the emails is your address, your name and the order details — nothing else.
🗺️ About the map: the tiles are requested by your browser, and it happens only on your order page, while you follow the rider. What their server sees is your IP address — nothing else, and no cookies. The United Kingdom is a country for which the European Commission has recognised equivalent protection to the Union's: this transfer needs nothing further.
Beyond these, nobody else. There are no statistics services, there are no advertising pixels, there are no third-party tools following you as you browse.
Your data can be disclosed to the authorities only if a law requires us to.
Where your data is kept
The site, the database and the photographs are on a server in France, inside the European Union. The database is ours, on our own machine: it isn't a third-party service.
How long we keep it
| What | How long | Why |
|---|---|---|
| Orders and payment data | 10 years | It's the legal obligation for accounting records (art. 2220 of the Italian Civil Code) |
| Your account and your addresses | Until you delete it | It's there for you, to find your things again |
| Course bookings | 10 years if paid for, otherwise 12 months | Tax obligations |
| Consent to commercial communications | Until you withdraw it | The withdrawal takes effect immediately |
| News subscription and proof of consent | Until you leave, then 24 months | After you leave we stop writing. The record stays so we can show the consent existed and that you withdrew it |
| Technical data and security logs | 12 months | They're there to defend the site, not to get to know you |
| The messages with the person bringing your order | 30 days after delivery | Long enough to sort out a mix-up, not long enough to become an archive. They delete themselves |
When you delete your account, we delete your personal data. Only the orders already placed remain, because tax law obliges us to keep them — and they stay linked to the order number, no longer to your profile.
What you can ask us for
The GDPR gives you rights, and they aren't hard to use. You can ask us to:
- see what data we hold about you, and get a copy of it;
- correct what is wrong;
- delete your data, when we have no legal obligation to keep it;
- restrict or object to a processing;
- take away your data in a format another service can read;
- withdraw a consent you had given us — and it takes effect immediately, with no explanations.
👉 How you do it: write to ipizzacchierefirenze@gmail.com. We reply within one month. If the request is complicated we can take two more months, but in that case we tell you within the first.
We don't ask you to justify yourself and we don't charge you anything.
If you think we're getting it wrong
You can turn to the Garante per la protezione dei dati personali:
Piazza Venezia 11 — 00187 Roma
garanteprivacy.it
You can do it at any time, even without having spoken to us about it first. But if you write to us, it usually gets sorted out more quickly.
Automated decisions
We don't take any decision about you automatically. Every order is looked at by a person in the pizzeria, who accepts it or refuses it.
The only automatic thing is a limit on the number of orders that can be placed one after another from the same phone number: it's there to stop pranks, and if it blocks you, you can always call us.
If this page changes
When we change it, we update the date at the top. If something important changes — a new provider, a new piece of data, a different use — we tell you beforehand, not afterwards.
