Last updated: May 18, 2026
Privacy Policy
Draft. This English version is a translation of the Italian original, provided for the convenience of international visitors. In case of any conflict between the two versions, the Italian version prevails. This text is a working draft not yet reviewed by counsel and may change before public launch.
This policy describes how Chipcolate S.r.l. processes the personal data of users of makolate.store (the “Site”) under Regulation (EU) 2016/679 (“GDPR”) and Legislative Decree 196/2003 (the “Italian Privacy Code”), as amended by Legislative Decree 101/2018.
1. Data controller
The data controller is Chipcolate S.r.l., with registered office at Piazza della Repubblica 19, 20124 Milan (MI), Italy. VAT ID 12207370961. For any request regarding your personal data, write to [email protected] or to our certified email [email protected].
No Data Protection Officer has been appointed, as our processing does not fall within the cases of mandatory appointment under art. 37 GDPR.
2. Categories of data processed
Depending on how you interact with the Site, we process the following categories of data:
- Account data: email, password (hashed), name (if provided).
- Order and billing data: shipping address, billing address, phone number (if provided), tax ID or VAT number (if provided for invoicing).
- Payment data: processed directly by our provider Stripe Payments Europe Limited. Chipcolate never receives or stores card data — only transaction results and identifiers.
- Configurator content: text, images and files you upload for product personalisation, plus the technical configuration of the 3D model.
- Browsing data: IP address, timestamp, pages visited, user-agent — logged in application logs for security purposes.
- Technical cookies: language and currency preferences, session identifier. The Site does not use profiling cookies or third-party analytics.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Account creation and management | Performance of a contract or pre-contractual measures — art. 6(1)(b) GDPR |
| Order processing, production and shipping | Performance of contract — art. 6(1)(b) GDPR |
| Invoicing and fulfilment of tax and accounting obligations | Legal obligation — art. 6(1)(c) GDPR |
| Fraud prevention and Site security | Legitimate interest — art. 6(1)(f) GDPR |
| Transactional emails (order confirmation, shipping) | Performance of contract — art. 6(1)(b) GDPR |
| Newsletter or cart-reminder emails | Consent — art. 6(1)(a) GDPR |
Marketing consent is optional and may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Retention
- Account data: for the lifetime of the account; on deletion, up to 30 days following the request, subject to encrypted technical backups retained for up to 90 days.
- Order and billing data: 10 years from issuance, to comply with civil and tax obligations (arts. 2214 et seq. of the Italian Civil Code and Presidential Decree 600/1973).
- Marketing consent: until withdrawn.
- Security logs: 12 months.
- Configurator uploads: for the lifetime of the account; for completed orders, up to 24 months after delivery to support warranty handling.
5. Recipients and third parties
For the purposes above, your data may be shared with:
- Stripe Payments Europe Limited (Ireland) — payment processing.
- ActiveCampaign LLC / Postmark (United States) — transactional email delivery. The non-EU transfer relies on the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914).
- Selected carrier for delivery — only the shipping data needed for delivery.
- Hetzner Online GmbH (Germany) — infrastructure hosting provider.
- Consultants, accountants and lawyers — to the extent necessary for performance of contractual or tax obligations, or for legal defence.
These parties act as data processors under art. 28 GDPR, bound by agreements that govern their security and confidentiality obligations. We do not share your data with other parties except where required by law.
6. Transfers outside the EU
Some providers (in particular for email delivery) may involve transfers of data outside the European Economic Area. In such cases, the transfer relies on European Commission adequacy decisions or on the Standard Contractual Clauses under art. 46(2)(c) GDPR, supplemented by additional technical and organisational measures where necessary.
7. Your rights
Under arts. 15 to 22 GDPR you have the right to:
- obtain confirmation that we are processing your data and access that data (art. 15);
- have inaccurate data corrected (art. 16);
- have your data erased where the conditions are met (art. 17);
- restrict processing (art. 18);
- receive your data in a structured, readable format and transmit it to another controller (portability, art. 20);
- object to processing based on legitimate interest (art. 21);
- withdraw any marketing consent at any time (art. 7);
- lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
To exercise these rights, write to [email protected]. We respond without undue delay and in any event within 30 days.
8. Cookies
The Site uses only technical and preference cookies strictly necessary for it to work (session, selected language, displayed currency). No profiling, analytics or third-party advertising cookies are installed. If the Site introduces tools that require consent in the future, a banner compliant with the Italian DPA’s Guidelines of 8 July 2021 will be shown.
9. Minors
The Site is not intended for users under 14 years of age (art. 2-quinquies of the Italian Privacy Code). We do not knowingly collect data from minors. If we become aware of processing of a minor’s data without parental consent, we will delete it.
10. Changes to this policy
We may update this policy at any time. The “Last updated” date is shown at the top of the document. Changes take effect from the date of publication; for substantial changes we will notify you by email or via a notice on the Site.
11. Contact
For any privacy request: [email protected] — Chipcolate S.r.l., Piazza della Repubblica 19, 20124 Milan (MI), Italy.