Privacy notice
Last updated: July 25, 2026
1. Data controller
The data controller is [DA FORNIRE] (registered name), registered office at [DA FORNIRE], VAT no. [DA FORNIRE], certified email [DA FORNIRE].
For anything concerning personal data you can write to ipizzacchierefirenze@gmail.com or call +39 055 246 6332.
Data Protection Officer: [DA FORNIRE]. Appointing a DPO is not mandatory for every business: it must be assessed with a professional, based on the processing actually carried out, including outside this website.
2. What we collect and why
We collect only what is needed to take, prepare, deliver and document an order. We do not collect your date of birth, we do not profile your food preferences, and we do not combine your data with external sources.
| Data | Purpose | Legal basis |
|---|---|---|
| Name, phone, email | Contacting you about your order and sending confirmation and delivery emails | Performance of a contract (Art. 6.1.b GDPR) |
| Delivery address and door entry details | Delivering the order and checking the address is within our area | Performance of a contract (Art. 6.1.b) |
| Order contents and amount | Preparing the order and issuing the tax document | Legal obligation (Art. 6.1.c) |
| Payment data | Taking payment. Card details never pass through nor are stored on our servers: they are handled directly by the payment provider | Performance of a contract (Art. 6.1.b) |
| IP address, user agent, cookie choices | Demonstrating when and how you gave consent, as required by the Italian supervisory authority | Legal obligation (Art. 6.1.c) and consent (Art. 6.1.a) |
| Rider GPS position during delivery | Showing you where your delivery is | Legitimate interest (Art. 6.1.f), limited to the single delivery |
3. Who we share data with
Data is processed on our behalf by the providers listed below, appointed as processors under Art. 28 GDPR. Some are based outside the European Union: those transfers rely on the Standard Contractual Clauses approved by the European Commission.
| Provider | Role | Location | Transfer outside the EU |
|---|---|---|---|
| Supabase | Database, authentication, storage | Ireland (eu-west-1) | No — data stays in the EU |
| Vercel | Application hosting and content delivery | United States, with EU edge nodes | Yes — Standard Contractual Clauses |
| Stripe | Card payments | Ireland and United States | Yes — Standard Contractual Clauses |
| PayPal | PayPal account payments | Luxembourg and United States | Yes — Standard Contractual Clauses |
| Google (Maps Platform) | Address autocomplete, maps and route calculation | United States | Yes — Standard Contractual Clauses |
| Resend | Sending transactional emails | United States | Yes — Standard Contractual Clauses |
| Sentry | Collecting technical application errors | United States | Yes — Standard Contractual Clauses |
4. How long we keep data
Every category of data has a defined retention period, after which it is deleted or anonymised by automated jobs.
| Category | Retention | Reason |
|---|---|---|
| Orders and tax documents | 10 years | Italian civil and tax law (Art. 2220 Civil Code, DPR 633/72) |
| Rider GPS positions | 24-48 hours | Data minimisation: they are only needed during the delivery |
| Consent log | 5 years from collection | Proving consent even after it has been withdrawn |
| Inactive customer accounts | 3 years from last sign-in | Advance notice, then anonymisation |
| Technical and error logs | 12 months | Security and fault diagnosis |
5. Rider geolocation
During a home delivery the rider shares their position, which is shown to you on the tracking map. Sharing is limited to the single delivery: it starts when the order goes out for delivery, ends on delivery, and the data is erased within 48 hours.
The rider can switch sharing off at any time and always has a visible indicator showing whether it is active.
To be reviewed with an employment law professional, not only a privacy one. Employee geolocation falls under Art. 4 of the Italian Workers' Statute (Law 300/1970), which governs remote monitoring: it may require a union agreement or authorisation from the Labour Inspectorate, and in any case a specific written notice to riders, separate from this one.
6. Your rights
You can exercise the rights under Articles 15 to 22 GDPR at any time by writing to the addresses in section 1. We reply within thirty days.
- Access: find out what data we hold and get a copy.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask for your data to be removed, except what we must keep for tax purposes, which is anonymised instead.
- Portability: receive your data in a format another system can read.
- Restriction and objection: ask for processing to be suspended or limited.
- Withdrawal of consent: at any time, without affecting the lawfulness of processing before withdrawal.
- Complaint: contact the Italian Data Protection Authority (www.garanteprivacy.it).
7. Security
Data travels encrypted (HTTPS) and is encrypted at rest by the database provider. Access is governed by policies enforced by the database itself, not only by the application: each customer can read only their own orders, and a rider only the deliveries assigned to them.
Staff operations that change prices, orders or data are written to a log that cannot be modified, not even by an administrator.
8. Changes to this notice
If we change how we process data, we update this page and the date at the top. When the change concerns processing based on consent, the banner will be shown again: consent collected against an earlier text does not apply to a new one.
