Privacy policy di flyrshop.com

Privacy & Cookie Policy of flyrshop.com

Last update: 25 April 2025

1 Data Controller and Contacts

  
Controller

Flyrshop D.O.O. – Registered office: Begunje pri Cerknici 67-71, 1382 Begunje pri Cerknici, SL  VAT: 064288123745

Privacy e-mailinfo.flyrshop@gmail.com
  
  

2 Personal Data We Process

Data categoryExamplesSource
Identificationfirst and last name, postal address, order IDprovided by user
Contacte-mail, phone, social IDprovided
PaymentIBAN, card token, PayPal transaction IDpayment provider
BrowsingIP address, user-agent, server logs, technical cookiescollected automatically
Profiling / marketingpurchase preferences, viewed productstracking cookies
Supportphotos, videos, chat transcripts, ticketsprovided

Special categories (Art. 9 GDPR): we do not intentionally process sensitive data. If a user submits such data spontaneously (e.g. in order notes) we will delete it.


3 Purposes, Legal Bases and Retention

#PurposeLegal basis (Art. 6 GDPR)Retention*
3.1Execute the sales contract (cart, shipment, after-sales)b) Contract10 years (tax law)
3.2Legal obligations (invoicing, warranty, returns)c) Legal obligation10 years
3.3Customer care (chat, tickets, RMA)b) Contract24 months after last ticket
3.4IT security and fraud preventionf) Legitimate interest24 months; security logs 6 months
3.5Direct marketing e-mail/SMS/newslettera) ConsentUntil withdrawal; max 24 months
3.6Profiling for personalised offersa) ConsentUntil withdrawal; max 12 months
3.7Soft-spam on similar products (Art. 130 §4 Italian Privacy Code)f) Legit. interestUntil opt-out
3.8Anonymous / aggregated statisticsf) Legit. interestAnonymous data only

*Periods may be extended in case of disputes or regulatory requests.


4 Processing Methods and Security

Data are processed on paper and electronically; only authorised staff can access them (“zero-trust” principle). Security measures include TLS 1.3 encryption, encrypted backups, MFA, intrusion-detection logging, automatic retention policies, and data-minimisation by design.


5 Recipients

  • Hosting & cloud providers: [OVH SAS] – servers in EU

  • Carriers / logistics: [UPS, GLS, Poste Italiane]

  • Payment institutions: [Stripe Payments Europe, PayPal Europe]

  • Professional advisors (tax, legal) bound by NDAs

  • Marketing platforms (only with consent): [Klaviyo, Meta, Google]

An up-to-date list of subprocessors is available on request.


6 Transfers outside the EEA

Some suppliers (e.g. Meta Platforms, Google LLC) are located in third countries. Transfers occur under:

  1. An adequacy decision (Art. 45) where available;

  2. Otherwise, Standard Contractual Clauses (Art. 46) plus supplementary safeguards (encryption at rest, pseudonymisation).


7 Data Subject Rights (Arts. 15-22 GDPR)

You may at any time:

  • obtain confirmation of processing and access (Art. 15)

  • request rectification or completion (Art. 16)

  • request erasure (“right to be forgotten”, Art. 17)

  • obtain restriction (Art. 18) or portability (Art. 20)

  • object on legitimate grounds or to marketing (Art. 21)

  • withdraw consent at any time (Art. 7 §3)

Requests: [info.flyrshop@gmail.com].
If you believe your rights have been violated you may lodge a complaint with the Italian Data-Protection Authority (Garante per la Protezione dei Dati Personali) or with your local authority.


8 Minors

Our site and services are not intended for children under 16. We do not knowingly collect their data. If we learn that we have unintentionally obtained personal data from a minor, we will delete it immediately.


9 Cookie Policy

9.1 What cookies are

Cookies are small text files stored by websites on your device. They are classified as:

TypePurposeConsent required?
Technical (first-party)session, language, cartNo
First-party analyticsaggregated stats (e.g. self-hosted Matomo)No, if anonymised
Third-party analyticsGoogle Analytics 4 (IP-anon), HotjarYes, if user-level tracking
Profiling / marketingMeta Pixel, Google Ads, TikTokYes

9.2 Cookies we use

NameProviderExpiryTypePurpose
phpsessidfirst-partysessiontechnicalKeep login/cart state
_gaGoogle LLC13 monthsanalyticsAggregated statistics (GA4)
_fbpMeta90 daysmarketingFacebook/Instagram remarketing
kl_…Klaviyo2 yearsmarketingE-mail & browse tracking

A complete, automatically updated list is generated every 30 days by [Cookiebot].

9.3 Consent management

On first visit a banner compliant with the Italian DPA guidelines (10 June 2021) appears:

  • Accept all, Reject all, Customise

  • Scroll or click outside the banner does not equal consent.

  • Consent is logged server-side (Art. 7 GDPR) and can be withdrawn at any time via the “Cookie settings” widget.

9.4 Disabling cookies via browser

Quick links to guides for Chrome, Firefox, Edge, Safari, Opera.


10 Policy Changes

We may amend this Policy at any time. Previous versions will be archived. For substantial changes (e.g. new marketing purpose) we will notify users by e-mail or banner and, where required, request fresh consent.


(Version 2.0 – fully replaces the previous Privacy & Cookie Policy dated 15 March 2024)