Privacy Policy
Last updated: 21 July 2026
This policy describes how BOTTEGA DI SGUARDI S.R.L. collects and processes the personal data of users who visit the website www.bottegadisguardi.com, use its services or make a purchase, in accordance with Regulation (EU) 2016/679 ("GDPR"), Legislative Decree 196/2003, as amended by Legislative Decree 101/2018, and applicable legislation.
1. Data Controller
BOTTEGA DI SGUARDI S.R.L.
Registered office: Via Guglielmo Marconi 19 F/R, 50131 Florence (FI), Italy
VAT number and Tax Code: 06901730488
European VAT number: IT06901730488
REA: FI-664787
Certified email: dentro@pec.it
Email: info@bottegadisguardi.com
The Data Controller can be contacted at the addresses indicated above for any request related to the processing of personal data and the exercise of data subject rights.
2. Categories of personal data processed
Depending on how the site is used, the Data Controller may process the following categories of personal data:
- identification and contact data, such as name, surname, email address, phone number, shipping address, and billing address;
- order data, such as products purchased, amounts, delivery methods, return requests, withdrawal, refunds, assistance, and warranty;
- tax data, such as tax code, VAT number, company name or legal name, recipient code, and certified email address, when necessary for invoicing;
- payment data, such as payment method, outcome, and transaction references. Full payment card data is processed directly by payment service providers and is not stored by Bottega di Sguardi;
- customer account data, such as the email address associated with the profile, order history, and requests sent via self-service functions;
- data voluntarily provided through forms, emails, assistance requests, or other contact channels;
- technical and navigation data, such as IP address, device type, browser, operating system, pages visited, date and time of access, technical logs, and online identifiers;
- data related to preferences and consents, including consents related to cookies, tracking tools, newsletters, and promotional communications;
- data used for security and fraud prevention, to the extent permitted by applicable law.
The Data Controller invites users not to transmit personal data beyond what is necessary for the purpose of the request.
3. Optical prescriptions and health-related data
When the Customer requests the production of glasses with prescription lenses, Bottega di Sguardi may process the data contained in the optical prescription and the visual parameters necessary for the production, control, delivery and adjustment of the requested product.
Such information may fall within the special categories of personal data provided for in Article 9 of the GDPR. Processing takes place only when necessary to provide the requested product or service and in the presence of one of the conditions provided for in Article 9, paragraph 2, of the GDPR, including, when necessary, the explicit consent of the data subject.
Data is accessible exclusively to authorised personnel and to any professionals, laboratories or suppliers involved in the processing, to the strictly necessary extent.
The Customer must transmit only prescriptions and information related to himself/herself or to persons for whom he/she is authorised to act.
4. Purpose of processing, legal bases and retention
4.1 Order and contractual relationship management
Data is processed for:
- managing the shopping cart, order, and payment;
- verifying product availability;
- preparing, shipping, or making the order available for pickup;
- sending communications related to the purchase;
- managing returns, withdrawals, refunds, complaints, assistance, and warranty;
- creating custom products and glasses with prescription lenses.
Legal basis: performance of a contract or pre-contractual measures requested by the data subject. For any special categories of data, the conditions set out in Article 9 of the GDPR also apply.
Retention period: for the time necessary for the performance of the contract and subsequently for the period required by legal obligations or necessary for the protection of the rights of the Data Controller and the data subject.
4.2 Administrative, tax and accounting compliance
Data is processed for invoicing, accounting, tax compliance, and other legal obligations.
Legal basis: fulfillment of legal obligations.
Retention period: for the period required by applicable tax, accounting, and civil law, typically ten years, unless further terms are required by law or necessary in case of dispute.
4.3 Creation and management of customer account
Data is processed to allow access to the profile, order viewing, and use of available functions, including self-service procedures.
Legal basis: performance of a contract or measures requested by the data subject.
Retention period: until the account is deleted, without prejudice to the retention of data necessary for orders already placed, legal obligations, or the protection of rights.
4.4 Assistance and response to requests
Data is processed to respond to questions, information requests, complaints, and communications sent by the user.
Legal basis: performance of pre-contractual measures, performance of a contract, or the legitimate interest of the Data Controller in managing received requests.
Retention period: for the time necessary to manage the request and, subsequently, for the period necessary to protect the rights of the parties.
4.5 Security, fraud prevention and protection of rights
Data may be processed to ensure the security of the site and transactions, prevent illicit or fraudulent use, ascertain liability, and protect the rights of the Data Controller, users, or third parties.
Legal basis: legitimate interest of the Data Controller and, where applicable, fulfillment of legal obligations.
Retention period: for the time necessary for verification, complaint management, or any legal proceedings.
4.6 Newsletter and promotional communications
With prior consent, contact data may be used to send newsletters, news, invitations, content, and promotional communications related to Bottega di Sguardi.
Legal basis: consent of the data subject.
Retention period: until consent is withdrawn or a cancellation request is made, without prejudice to the retention of information necessary to demonstrate previously given consent.
The data subject can withdraw consent at any time using the link in the communications or by writing to info@bottegadisguardi.com.
4.7 Statistics, personalisation and advertising
With prior consent, the site may use cookies and other tracking tools to analyse site usage, measure performance, personalise content, measure advertising campaigns, and propose relevant communications or advertisements.
Legal basis: consent of the data subject, except for processing strictly necessary for the operation and security of the site.
Retention period: according to the duration of individual tools indicated in the preferences panel and in the Cookie Policy managed via Consentmo GDPR Compliance.
5. Nature of data provision
The provision of data indicated as necessary is essential to place an order, receive products, obtain assistance, or use the requested service.
Failure to provide it may make it impossible to conclude or execute the contract.
The provision of data for newsletters, marketing, non-essential analyses, personalisation, and advertising is optional. Refusal or withdrawal of consent does not prevent access to essential site functions or the ability to make purchases.
6. Processing methods and security measures
Processing is carried out using computer, electronic, and, when necessary, paper tools, according to principles of lawfulness, fairness, transparency, minimisation, and storage limitation.
The Data Controller adopts appropriate technical and organisational measures to protect personal data from loss, unauthorised access, disclosure, alteration, or destruction.
However, no IT system can guarantee absolute security. The user is invited to use secure devices and to protect their credentials and access codes.
7. Data Recipients
Data may be communicated or made accessible, to the necessary extent, to the following categories of recipients:
- authorised personnel and collaborators of the Data Controller;
- Shopify, as provider of the e-commerce platform, hosting, checkout, customer accounts, and related technological functions;
- Consentmo, provided by iSenseLabs, for managing the cookie banner, preferences, consents, and privacy requests;
- payment service providers;
- couriers, logistics operators, and pickup points;
- laboratories, opticians, technicians, and suppliers involved in the creation or customisation of products;
- providers of IT services, maintenance, security, email, and support;
- newsletter, marketing, analysis, and advertising providers, when such services are active and in compliance with user preferences;
- accountants, consultants, lawyers, banking institutions, and insurance companies;
- public authorities, law enforcement, and other entities to whom communication is mandatory by law.
Providers who process personal data on behalf of the Data Controller are appointed as data processors when required by Article 28 of the GDPR.
An updated list of data processors can be requested from the Data Controller.
8. Shopify
The website and online store are built using the Shopify platform.
Shopify processes personal data necessary for the provision of e-commerce technological services, including hosting, infrastructure, checkout, order management, customer accounts, security, and fraud prevention.
In relation to different activities, Shopify may act as a data processor on behalf of the Seller or, in cases indicated in its documentation, as an independent data controller.
For more information on processing carried out by Shopify, please consult its privacy policy at Shopify Privacy Policy.
9. Consentmo GDPR Compliance
The website uses the Shopify app Consentmo GDPR Compliance, provided by iSenseLabs, to:
- display the cookie banner and preferences panel;
- collect, record, and manage user choices;
- allow acceptance, rejection, or selection of non-essential cookie categories;
- block or activate tracking tools based on expressed preferences, within the limits of the site's technical configuration;
- manage privacy functions and requests configured by the Data Controller.
Consentmo may process technical data necessary to record and demonstrate expressed preferences, such as access date and time, browser and device information, anonymised IP address, and recording of acceptance or rejection choices.
The service is provided by:
iSenseLabs, operating as Consentmo
4 Prof. Georgi Bradistilov Street
1700 Sofia, Bulgaria
EU registration number: 112660079
Email: support@consentmo.com
For more information, please consult the Consentmo Privacy Policy.
Users can change or withdraw their preferences at any time through the "Cookie Preferences" button or link available on the site.
10. Cookies and other tracking tools
The site uses cookies and similar technologies. Some are strictly necessary for the operation of the store, security, shopping cart, checkout, accounts, and storage of privacy preferences and do not require consent in cases provided for by law.
Cookies and tools intended for non-essential statistics, personalisation, or advertising are used only after consent has been given, when required.
The updated list of cookies and tools actually detected, broken down by category, provider, purpose, and duration, is available in the Cookie Policy and in the preferences panel managed via Consentmo.
Categories may include:
- necessary cookies, essential for the operation of the site and the store;
- preference cookies, used to remember settings and choices;
- statistical or analytical cookies, used to understand how the site is used;
- marketing cookies, used to measure campaigns, personalise ads, and recognise users on different sites or platforms.
Simply continuing to browse does not constitute consent to the use of non-essential cookies.
Users can refuse non-essential cookies without losing access to the essential functions of the site.
11. Transfers of data outside the European Economic Area
Some providers, including Shopify and other technological services that may be used, may process personal data in countries located outside the European Economic Area.
When necessary, transfers take place on the basis of an adequacy decision by the European Commission, standard contractual clauses approved by the European Commission, or another mechanism provided for by Articles 44 et seq. of the GDPR.
The data subject can request more information on the applied safeguards by contacting the Data Controller.
12. Data Subject Rights
In cases provided for by the GDPR, the data subject can:
- obtain confirmation as to whether or not their data is being processed;
- access personal data and receive a copy of it;
- request the rectification or updating of inaccurate or incomplete data;
- request the erasure of data;
- request restriction of processing;
- object to processing based on legitimate interest;
- object to direct marketing at any time;
- receive data in a structured, commonly used, and machine-readable format and, where applicable, obtain its transmission to another controller;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal;
- not be subject to a decision based solely on automated processing which produces legal effects or significantly affects them, in cases provided for by law;
- lodge a complaint with the competent supervisory authority.
13. Exercise of rights
Requests can be sent to:
Email: info@bottegadisguardi.com
Certified email: dentro@pec.it
The Data Controller may request the information necessary to verify the identity of the applicant and responds within the terms provided by applicable legislation.
Requests are free, except in cases of manifestly unfounded or excessive requests provided for by the GDPR.
14. Complaint to the Garante
A data subject who believes that the processing of their personal data violates applicable legislation may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or appeal to the competent judicial authority.
Information on how to lodge a complaint is available on the institutional website www.garanteprivacy.it.
15. Data of Minors
The site and online sales services are not intended for individuals under 18 years of age.
The Data Controller does not knowingly collect personal data of minors to allow them to make purchases on the site independently.
If a parent or guardian believes that a minor has submitted personal data without authorisation, they can contact the Data Controller to request verification and, where applicable, deletion.
16. Third-party links and services
The website may contain links, content or functionalities provided by third parties.
When the user interacts with such services, third parties may process personal data in accordance with their own policies and as independent data controllers.
Users are invited to consult the privacy policies of third parties before using their services.
17. System logs and maintenance
For operational, maintenance and security purposes, the website and technical providers may collect system logs containing data such as IP address, date and time of access, requests made, errors and device or browser information.
This data is processed to ensure the proper functioning of the services, prevent abuse, diagnose problems and protect security.
18. Changes to the Privacy Policy
The Controller may modify or update this Privacy Policy to adapt it to regulatory, technical or organisational changes.
The updated version will be published on this page with an indication of the last update date.
When required by law, the Controller will inform data subjects through additional means or will re-collect consent.
