1. Introduction & Overview
Welcome to S&Z Mobile (“we”, “our”, or “us”). We operate the retail consumer electronics store located at Via Vitruvio, 47, 20124 Milano (MI), Italy and our e-commerce platform and digital services accessible via web and mobile interfaces.
This Privacy Policy describes how we collect, process, store, disclose, and protect personal data belonging to customers, website visitors, registered account holders, and storefront visitors (“you” or “Users”). We are committed to maintaining the confidentiality of your personal information in full compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation or GDPR), the Italian Legislative Decree No. 196/2003 (Italian Privacy Code) as amended by Legislative Decree No. 101/2018, and applicable national electronic communications regulations.
2. Data Controller & Contact Details
The Data Controller responsible for the processing of your personal data collected through this website and at our retail store is:
3. Information We Collect
We only collect categories of personal data that are strictly necessary to provide our products, fulfill hardware orders, maintain customer accounts, and provide after-sales warranty service. Based on the actual functionality of our platform, the categories include:
A. Customer Account & Profile Data
When you register for an account (via /register or customer login), we collect your full name, email address, salted password hash (cryptographically hashed using bcryptjs; your plaintext password is never accessible or stored by us), and optional phone number.
B. Order, Billing & Delivery Information
When placing an order (via /checkout and /api/orders), we collect your full name, billing address, shipping/delivery address (street, house number, city, postal code, country), phone number (for delivery courier SMS/coordination), special delivery notes, purchased product items, variant specifications (e.g. storage capacity, color), order amount, and discount vouchers used.
C. Transactional & Payment Identification Data
When paying via PayPal, our servers receive and store transactional identifiers generated by PayPal: paypalOrderId, paypalCaptureId, transaction amount, currency (EUR), and payment authorization status (PAID). We do not collect, process, or store credit or debit card primary account numbers (PAN), CVVs, or card expiration dates on our servers.
D. Marketing Newsletter & Communications Data
When you voluntarily subscribe to the S&Z Mobile Club newsletter, we collect your email address, subscription source (e.g. footer form), and recorded consent timestamp.
E. Shopping Bag & Cart Recovery Snapshots
If an email is entered during checkout and an order is temporarily abandoned, our system creates a temporary CartSnapshot record containing the email, cart item contents, total sum, and expiry date to permit automated abandoned-cart recovery notifications.
F. Technical Session & Device Data
When logging into the website, our server issues an HTTP-only authentication cookie (session_token) linked to a database Session table containing your user ID, session token, and session expiry timestamp. Standard server logs automatically capture IP addresses, browser headers, and access timestamps for diagnostic and security purposes.
4. How We Collect Information
We collect personal data through the following interactions:
- Directly from You: When you complete the customer registration form, place an order at checkout, submit the contact form on our Store Info page, or subscribe to email announcements.
- Automatically: Through essential HTTP-only authentication session cookies and browser client-side storage (for your shopping cart and saved wishlist items).
- From Payment Gateways: When PayPal confirms successful capture of your payment, transmitting order capture tokens and verification statuses back to our order database.
5. Legal Bases & Purposes for Processing (GDPR Art. 6)
In accordance with Article 6 of the General Data Protection Regulation (GDPR), we process your personal data solely under the following lawful bases:
| Processing Purpose | Data Categories | GDPR Legal Basis |
|---|---|---|
| Order fulfillment, dispatch, and in-store collection | Name, email, delivery address, phone, item details | Art. 6(1)(b) — Performance of a Contract |
| Customer account maintenance & authentication | Name, email, password hash, saved addresses | Art. 6(1)(b) — Performance of a Contract |
| Fiscal invoicing & accounting compliance under Italian law | Billing details, tax identifiers (Codice Fiscale/P.IVA where required), totals | Art. 6(1)(c) — Compliance with a Legal Obligation |
| Hardware warranty management (24-Month guarantee) | Order ID, device serials/IMEI, customer contact | Art. 6(1)(b) Contract & Art. 6(1)(c) Legal Warranty |
| Marketing newsletter (S&Z Mobile Club) | Email address, consent date | Art. 6(1)(a) — Explicit Consent (withdrawable anytime) |
| Abandoned cart recovery reminders & fraud prevention | Cart snapshot items, email, IP log | Art. 6(1)(f) — Legitimate Interest |
7. Third-Party Service Providers (Data Processors)
We only disclose your data to vetted third-party service providers who process information on our behalf under strict Data Processing Agreements (DPA) adhering to GDPR Article 28:
- • PayPal (Europe) S.à r.l. et Cie, S.C.A. / PayPal Inc.Service: Payment gateway facilitation. PayPal acts as an independent data controller for raw payment processing and financial fraud screening. Privacy Policy: PayPal Privacy Notice.
- • Resend Inc.Service: Transactional and marketing email delivery infrastructure (dispatching welcome emails, order receipts, and abandoned cart notices).
- • Cloud Infrastructure & Database Hosting ProvidersService: Secure PostgreSQL database hosting and managed containerized cloud execution (Google Cloud Platform / Cloud Run).
- • Logistics & Express Couriers (e.g. DHL, GLS, Poste Italiane, Bartolini)Service: Physical package delivery, generating tracking waybills, and communicating delivery SMS/time windows.
8. Payment Processing & Card Security
All digital transactions on our website are conducted over TLS 1.3/SSL encrypted connections.
Zero Local Storage of Payment Cards:
When you pay using credit cards, debit cards, or PayPal, the card details are transmitted directly to PayPal's PCI-DSS compliant tokenization infrastructure. S&Z Mobile never sees, processes, or stores your 16-digit card number, security CVV, or card expiration date.
9. Artificial Intelligence Disclosures
Where artificial intelligence technologies (such as server-side Gemini API interfaces) are utilized for store management, catalog classification, or search indexing:
- Your financial information, passwords, and sensitive identity documents are never transmitted to or used for training external AI foundation models.
- Automated catalog categorization operates strictly on non-personal product titles, variants, and accessory descriptions.
10. Data Retention Schedule
We retain personal data only for as long as necessary to satisfy the purposes for which it was collected, or as required by applicable Italian and European law:
11. Technical & Organizational Security
We implement robust technical and operational measures designed to protect your personal data against unauthorized access, loss, destruction, alteration, or disclosure:
- Encryption in Transit: 256-bit TLS/SSL encryption across all public web and API endpoints.
- Password Hashing: State-of-the-art
bcryptone-way adaptive hashing with random salting. - Database Isolation: Parameterized queries via Prisma ORM preventing SQL injection attacks.
- Role-Based Access Control: Strict administrative role enforcement (SUPER_ADMIN, CONTENT_MANAGER, ORDER_MANAGER) restricting access to order details exclusively to authorized personnel.
12. International Data Transfers
Your personal data is predominantly stored and processed on servers located within the European Economic Area (EEA). If third-party processors (such as email delivery or payment APIs) transfer data outside the EEA, such transfers are governed by standard contractual clauses (SCCs) approved by the European Commission or European Adequacy Decisions, ensuring an equivalent level of data protection.
13. Your Rights Under the GDPR
Under Articles 15 through 22 of the GDPR, European Union residents possess specific statutory rights regarding their personal data:
To exercise any of these rights, email us at privacy@szmobile.it or visit our store in Milan. We will respond within thirty (30) days as prescribed by law without charging a fee.
14. United States & International Users
While our primary establishment is in Milan, Italy, we respect the privacy rights of international visitors. For residents of California (under the CCPA/CPRA) and other jurisdictions with applicable privacy statutes:
- No Sale or Sharing of Personal Data: We do not sell your personal data or share your personal information for cross-context behavioral advertising.
- Non-Discrimination: We will never discriminate against you (by denying goods or charging different rates) for exercising your statutory privacy rights.
15. Children's Privacy
Our services, online store, and account registration are directed at adults aged eighteen (18) and older. We do not knowingly collect personal data from minors under 16 years of age without verifiable parental consent. If we become aware that a minor has provided us with personal data, we will promptly delete the corresponding account records.
16. Account Deletion & Right to Erasure
You have the right to request the permanent deletion of your customer account at any time. To initiate account deletion:
17. Security Incidents & Notifications
In the unlikely event of a security incident or personal data breach resulting in a risk to your fundamental rights and freedoms, we will notify the competent supervisory authority (Garante Privacy) within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33, and inform affected data subjects without undue delay where required by Article 34.
18. Updates to this Privacy Policy
We may periodically update this Privacy Policy to reflect changes in our retail operations, technical features, or relevant privacy laws. When updates are published, we will revise the “Last Updated” timestamp at the top of this page. Substantial revisions will be communicated via banner notices on the website or via direct email to registered users.
19. Contact Details & Supervisory Authority
If you have questions, concerns, or complaints regarding this Privacy Policy or our data processing activities, please reach out to us:
You also have the right to lodge a formal complaint with your national data protection supervisory authority. In Italy, this is the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Roma, www.garanteprivacy.it).