Skip to content

Cart

Your cart is empty

Personal data protection

Privacy Policy

This policy describes how we collect, use, store, and protect the personal data of users who visit or make purchases on www.mastrolonardo.net.

Last update: September 27, 2026

Data Controller

SOLE S.R.L.

Registered office
Piazzetta Aniello Falcone, 1 – 80127 Naples – Italy
VAT number
07456781215
Website
www.mastrolonardo.net
Main e-mail
info@mastrolonardo.net
Additional contact
mastrolonardo1938@gmail.com
Phone
081 18779420

Information pursuant to Articles 13 and 14 of Regulation (EU) 2016/679. The processing of personal data is carried out in compliance with the GDPR, Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, and other applicable provisions regarding personal data protection.

01

We only collect necessary data

We use the data necessary to manage the site, orders, payments, deliveries, and support requests.

02

We protect information

We adopt appropriate technical and organizational measures to protect data from unauthorized access or use.

03

We respect your choices

You may exercise the rights provided by the GDPR and revoke any consents given at any time.

01 What personal data we collect

Depending on your use of the site, we may process the following categories of data:

  • identification data, such as first and last name;
  • contact data, such as address, e-mail, and phone number;
  • billing data and tax information, if provided;
  • data relating to orders, purchased products, returns, and refunds;
  • information related to shipping and delivery;
  • customer account data and protected credentials;
  • communications sent to customer service;
  • preferences regarding newsletters and promotional communications;
  • technical and browsing data, such as IP address, browser, device, logs, and online identifiers;
  • information collected through cookies and similar technologies, according to your expressed preferences.

We do not directly collect or store full payment card details.

02 How we collect data

Data may be collected:

  • directly from the user during a purchase or account creation;
  • when a form is filled out or customer service is contacted;
  • during a return, refund, or exchange request;
  • automatically during site navigation;
  • through payment providers, couriers, and parties involved in order fulfillment;
  • through analytical or advertising tools, when permitted and subject to consent if required.
03 Purposes and legal bases for processing

Personal data may be processed to:

  • manage orders, payments, shipments, returns, and refunds: processing is necessary for the performance of the contract or pre-contractual measures requested by the user;
  • create and manage customer accounts: processing is necessary to provide the requested service;
  • respond to support requests: processing is necessary to handle the request and, when applicable, execute the contract;
  • fulfill tax, accounting, and legal obligations: processing is necessary to comply with legal obligations;
  • prevent fraud, abuse, and security issues: processing is based on the controller's legitimate interest in protecting their business and users;
  • manage any disputes and protect rights: processing is based on the legitimate interest of exercising legal defense;
  • send newsletters and promotional communications: processing is based on consent, when required;
  • use non-technical analytical, advertising, or profiling cookies: processing is based on user consent.

Consent may be revoked at any time without affecting the lawfulness of processing based on consent before its withdrawal.

04 Provision of data

Providing the data marked as mandatory at checkout is necessary to conclude and execute the order. Failure to provide such data could prevent purchase, payment, or delivery.

Providing data for newsletters, marketing, and profiling is optional. Refusal does not prevent you from browsing the site or making purchases.

05 Payments and financial data

Electronic payments are handled by the providers selected at checkout through secure links and encrypted protocols.

Full card details, such as number, expiration date, and security code, are transmitted directly to the payment service provider and are not viewed or fully stored by SOLE S.R.L.

Payment providers may process data as independent controllers, according to their own privacy policies and for security, fraud prevention, and regulatory compliance purposes.

06 Recipients and service providers

Within the limits necessary for their respective activities, personal data may be communicated to:

  • authorized personnel of SOLE S.R.L.;
  • Shopify and e-commerce platform providers;
  • hosting, technical support, and cybersecurity providers;
  • management software, warehouse systems, and integration services;
  • payment providers and anti-fraud services;
  • couriers, logistics operators, and collection points;
  • e-mail service, customer support, and communication providers;
  • statistical, advertising, and marketing service providers, subject to consent when required;
  • accountants, consultants, lawyers, and insurance companies;
  • public, administrative, tax, or judicial authorities as required by law.

Providers who process data on behalf of the controller are appointed as data processors pursuant to Article 28 of the GDPR, when necessary. The updated list can be requested from the controller.

07 Transfers outside the European Economic Area

Some technology providers may process or store personal data in countries located outside the European Economic Area.

When necessary, such transfers are carried out based on an adequacy decision of the European Commission, standard contractual clauses, or another mechanism provided by Articles 44 and following of the GDPR.

Information on the applicable safeguards can be requested from the data controller.

08 Retention periods

Data is stored for the time necessary for the purposes for which it was collected and in compliance with legal obligations.

  • data relating to orders, payments, invoices, and accounting documentation are stored for the period required by civil and tax law, generally ten years;
  • account data is stored until a deletion request is made, barring legal obligations or the need to protect rights;
  • support requests are stored for the time necessary for management and any disputes;
  • data used for marketing is processed until consent is withdrawn or opposition is raised, barring periodic checks on its relevance;
  • data relating to disputes is stored until the conclusion of the dispute and the expiration of the related limitation periods.

Once the applicable period has expired, the data is deleted, anonymized, or kept solely when required by law.

09 Cookies and tracking tools

The site uses technical cookies necessary for operation, security, the shopping cart, checkout, and managing user preferences.

The site may also use analytical, advertising, or profiling cookies. When required by law, such tools are activated only after consent expressed through the preference panel.

The user can accept, refuse, or modify their preferences using the cookie management tool present on the site.

Continuing navigation or simply scrolling the page does not constitute consent to the use of non-essential cookies.

10 Newsletters and promotional communications

If the user provides consent, SOLE S.R.L. may use the e-mail address to send newsletters, promotions, product news, and commercial communications.

Consent is optional and can be withdrawn at any time via the unsubscribe link present in the communications or by contacting the controller.

Withdrawal does not affect the ability to make purchases or use other services on the site.

11 Personal data security

SOLE S.R.L. adopts technical and organizational measures appropriate to the risk to protect personal data from loss, destruction, modification, disclosure, or unauthorized access.

Measures may include secure connections, access restrictions, authentication, internal procedures, backups, and the selection of providers that offer adequate guarantees.

However, no computer system can guarantee absolute security. Users are encouraged to protect their credentials and not share them with third parties.

12 Automated processes and anti-fraud services

As a rule, the controller does not adopt decisions based solely on automated processing that produce legal effects or similarly significantly affect the user.

Payment providers and anti-fraud services may use automated systems to evaluate the security of a transaction or authorize a payment, according to their own policies and responsibilities.

13 Data relating to minors

The site and sales services are not intended for the knowing collection of personal data from minors lacking the capacity required to make a purchase.

If the controller becomes aware of data collected unlawfully from a minor, they will take the necessary measures to delete it, barring legal obligations.

14 Changes to the Privacy Policy

The controller may update this policy to adapt it to regulatory, technical, or organizational changes.

The updated version is published on this page with the date of the last modification indicated.

In the event of substantial changes, when necessary, users will be informed via the site or through other available contact methods.

Articles 15–22 of the GDPR

Your rights

In the cases provided for by the GDPR, the data subject may request the controller to exercise the following rights:

Access to personal data
Rectification of inaccurate data
Erasure of data
Restriction of processing
Data portability
Objection to processing
Withdrawal of consent
Complaint to the supervisory authority

Requests can be sent to the addresses indicated in the following section. The controller will provide a response within the time limits established by the GDPR. The data subject may also lodge a complaint with the Data Protection Authority.

Privacy contact

To exercise your rights or request information on the processing of personal data, contact SOLE S.R.L. specifying "Privacy request" in the subject line.