Via Vitruvio, 47 — Milano (20124)
HomePrivacy Policy
EU GDPR & Italian Privacy Code Compliance

Privacy Policy

Transparency regarding how S&Z Mobile processes, safeguards, and stores your personal information when you visit our store in Milan or use our online services.

Effective Date:August 31, 2026

1. Introduction & Overview

Welcome to S&Z Mobile (“we”, “our”, or “us”). We operate the retail consumer electronics store located at Via Vitruvio, 47, 20124 Milano (MI), Italy and our e-commerce platform and digital services accessible via web and mobile interfaces.

This Privacy Policy describes how we collect, process, store, disclose, and protect personal data belonging to customers, website visitors, registered account holders, and storefront visitors (“you” or “Users”). We are committed to maintaining the confidentiality of your personal information in full compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation or GDPR), the Italian Legislative Decree No. 196/2003 (Italian Privacy Code) as amended by Legislative Decree No. 101/2018, and applicable national electronic communications regulations.

Key Document Details:
Effective Date: August 31, 2026
Last Updated: August 31, 2026
Governing Framework: European Union General Data Protection Regulation (GDPR)

2. Data Controller & Contact Details

The Data Controller responsible for the processing of your personal data collected through this website and at our retail store is:

S&Z Mobile
Trade Name / Store: S&Z Mobile (Selling Mobile Phones & Accessories)
Registered Entity Name: [LEGAL COMPANY NAME / P.IVA REQUIRES CONFIRMATION]
Physical Store Address: Via Vitruvio, 47, 20124 Milano (MI), Italy
Telephone / Helpline: +39 389 879 3075
General Email: info@szmobile.it
Data Protection & Privacy Desk: privacy@szmobile.it
Data Protection Officer (DPO): [DATA PROTECTION OFFICER STATUS REQUIRES CONFIRMATION — Not statutory if SME retailer, inquiries handled directly by store management]

3. Information We Collect

We only collect categories of personal data that are strictly necessary to provide our products, fulfill hardware orders, maintain customer accounts, and provide after-sales warranty service. Based on the actual functionality of our platform, the categories include:

A. Customer Account & Profile Data

When you register for an account (via /register or customer login), we collect your full name, email address, salted password hash (cryptographically hashed using bcryptjs; your plaintext password is never accessible or stored by us), and optional phone number.

B. Order, Billing & Delivery Information

When placing an order (via /checkout and /api/orders), we collect your full name, billing address, shipping/delivery address (street, house number, city, postal code, country), phone number (for delivery courier SMS/coordination), special delivery notes, purchased product items, variant specifications (e.g. storage capacity, color), order amount, and discount vouchers used.

C. Transactional & Payment Identification Data

When paying via PayPal, our servers receive and store transactional identifiers generated by PayPal: paypalOrderId, paypalCaptureId, transaction amount, currency (EUR), and payment authorization status (PAID). We do not collect, process, or store credit or debit card primary account numbers (PAN), CVVs, or card expiration dates on our servers.

D. Marketing Newsletter & Communications Data

When you voluntarily subscribe to the S&Z Mobile Club newsletter, we collect your email address, subscription source (e.g. footer form), and recorded consent timestamp.

E. Shopping Bag & Cart Recovery Snapshots

If an email is entered during checkout and an order is temporarily abandoned, our system creates a temporary CartSnapshot record containing the email, cart item contents, total sum, and expiry date to permit automated abandoned-cart recovery notifications.

F. Technical Session & Device Data

When logging into the website, our server issues an HTTP-only authentication cookie (session_token) linked to a database Session table containing your user ID, session token, and session expiry timestamp. Standard server logs automatically capture IP addresses, browser headers, and access timestamps for diagnostic and security purposes.

4. How We Collect Information

We collect personal data through the following interactions:

  • Directly from You: When you complete the customer registration form, place an order at checkout, submit the contact form on our Store Info page, or subscribe to email announcements.
  • Automatically: Through essential HTTP-only authentication session cookies and browser client-side storage (for your shopping cart and saved wishlist items).
  • From Payment Gateways: When PayPal confirms successful capture of your payment, transmitting order capture tokens and verification statuses back to our order database.

5. Legal Bases & Purposes for Processing (GDPR Art. 6)

In accordance with Article 6 of the General Data Protection Regulation (GDPR), we process your personal data solely under the following lawful bases:

Processing PurposeData CategoriesGDPR Legal Basis
Order fulfillment, dispatch, and in-store collectionName, email, delivery address, phone, item detailsArt. 6(1)(b) — Performance of a Contract
Customer account maintenance & authenticationName, email, password hash, saved addressesArt. 6(1)(b) — Performance of a Contract
Fiscal invoicing & accounting compliance under Italian lawBilling details, tax identifiers (Codice Fiscale/P.IVA where required), totalsArt. 6(1)(c) — Compliance with a Legal Obligation
Hardware warranty management (24-Month guarantee)Order ID, device serials/IMEI, customer contactArt. 6(1)(b) Contract & Art. 6(1)(c) Legal Warranty
Marketing newsletter (S&Z Mobile Club)Email address, consent dateArt. 6(1)(a) — Explicit Consent (withdrawable anytime)
Abandoned cart recovery reminders & fraud preventionCart snapshot items, email, IP logArt. 6(1)(f) — Legitimate Interest

6. Cookies & Local Storage Technologies

Our website utilizes minimal, technically essential cookies and local storage mechanisms necessary to provide the shopping and authentication functionality requested by you:

1. session_token (Strictly Essential Cookie)HTTP-Only / Secure

Purpose: Authenticates customer and administrative sessions. Flags: HttpOnly, SameSite=Lax, Secure in production environments.

Duration: 24 hours (standard login) or 7 days (new registration).

2. sandz-cart-storage (HTML5 LocalStorage)Client-Side Only

Purpose: Stores the items in your active shopping bag and applied discount codes on your device so your cart does not disappear when navigating between pages.

3. wishlist-storage (HTML5 LocalStorage)Client-Side Only

Purpose: Retains your bookmarked favorite phones and accessories locally in your browser.

No Third-Party Advertising Trackers: S&Z Mobile does not employ third-party advertising pixels (such as Meta Pixel, TikTok Pixel, or retargeting networks) that track your browsing behavior across unrelated third-party websites.

7. Third-Party Service Providers (Data Processors)

We only disclose your data to vetted third-party service providers who process information on our behalf under strict Data Processing Agreements (DPA) adhering to GDPR Article 28:

  • PayPal (Europe) S.à r.l. et Cie, S.C.A. / PayPal Inc.
    Service: Payment gateway facilitation. PayPal acts as an independent data controller for raw payment processing and financial fraud screening. Privacy Policy: PayPal Privacy Notice.
  • Resend Inc.
    Service: Transactional and marketing email delivery infrastructure (dispatching welcome emails, order receipts, and abandoned cart notices).
  • Cloud Infrastructure & Database Hosting Providers
    Service: Secure PostgreSQL database hosting and managed containerized cloud execution (Google Cloud Platform / Cloud Run).
  • Logistics & Express Couriers (e.g. DHL, GLS, Poste Italiane, Bartolini)
    Service: Physical package delivery, generating tracking waybills, and communicating delivery SMS/time windows.

8. Payment Processing & Card Security

All digital transactions on our website are conducted over TLS 1.3/SSL encrypted connections.

Zero Local Storage of Payment Cards:

When you pay using credit cards, debit cards, or PayPal, the card details are transmitted directly to PayPal's PCI-DSS compliant tokenization infrastructure. S&Z Mobile never sees, processes, or stores your 16-digit card number, security CVV, or card expiration date.

9. Artificial Intelligence Disclosures

Where artificial intelligence technologies (such as server-side Gemini API interfaces) are utilized for store management, catalog classification, or search indexing:

  • Your financial information, passwords, and sensitive identity documents are never transmitted to or used for training external AI foundation models.
  • Automated catalog categorization operates strictly on non-personal product titles, variants, and accessory descriptions.

10. Data Retention Schedule

We retain personal data only for as long as necessary to satisfy the purposes for which it was collected, or as required by applicable Italian and European law:

Customer Account Data:Retained until account deletion is requested by the user.
Order & Fiscal Invoicing Records:10 years (statutory requirement under Italian Civil Code Art. 2220 & tax regulations) [CONFIRM TAX RETENTION PERIOD].
Hardware Warranty Logs:24 months from purchase date (duration of statutory store guarantee).
Cart Snapshots (Abandoned Carts):48 hours maximum before automated database cleanup.
Marketing Newsletter List:Retained until you click “Unsubscribe” or withdraw consent.

11. Technical & Organizational Security

We implement robust technical and operational measures designed to protect your personal data against unauthorized access, loss, destruction, alteration, or disclosure:

  • Encryption in Transit: 256-bit TLS/SSL encryption across all public web and API endpoints.
  • Password Hashing: State-of-the-art bcrypt one-way adaptive hashing with random salting.
  • Database Isolation: Parameterized queries via Prisma ORM preventing SQL injection attacks.
  • Role-Based Access Control: Strict administrative role enforcement (SUPER_ADMIN, CONTENT_MANAGER, ORDER_MANAGER) restricting access to order details exclusively to authorized personnel.

12. International Data Transfers

Your personal data is predominantly stored and processed on servers located within the European Economic Area (EEA). If third-party processors (such as email delivery or payment APIs) transfer data outside the EEA, such transfers are governed by standard contractual clauses (SCCs) approved by the European Commission or European Adequacy Decisions, ensuring an equivalent level of data protection.

13. Your Rights Under the GDPR

Under Articles 15 through 22 of the GDPR, European Union residents possess specific statutory rights regarding their personal data:

• Right of Access (Art. 15)Request confirmation of whether your data is being processed and obtain a copy.
• Right to Rectification (Art. 16)Request correction of inaccurate or incomplete personal information.
• Right to Erasure / “Be Forgotten” (Art. 17)Request the deletion of your account and personal data, subject to legal fiscal retention.
• Right to Restriction (Art. 18)Request temporary limitation of data processing under specific statutory circumstances.
• Right to Data Portability (Art. 20)Receive your data in a structured, commonly used, machine-readable format.
• Right to Object & Withdraw Consent (Art. 21)Object to processing based on legitimate interests or withdraw newsletter consent at any time.

To exercise any of these rights, email us at privacy@szmobile.it or visit our store in Milan. We will respond within thirty (30) days as prescribed by law without charging a fee.

14. United States & International Users

While our primary establishment is in Milan, Italy, we respect the privacy rights of international visitors. For residents of California (under the CCPA/CPRA) and other jurisdictions with applicable privacy statutes:

  • No Sale or Sharing of Personal Data: We do not sell your personal data or share your personal information for cross-context behavioral advertising.
  • Non-Discrimination: We will never discriminate against you (by denying goods or charging different rates) for exercising your statutory privacy rights.

15. Children's Privacy

Our services, online store, and account registration are directed at adults aged eighteen (18) and older. We do not knowingly collect personal data from minors under 16 years of age without verifiable parental consent. If we become aware that a minor has provided us with personal data, we will promptly delete the corresponding account records.

16. Account Deletion & Right to Erasure

You have the right to request the permanent deletion of your customer account at any time. To initiate account deletion:

1. Log into your account and navigate to Customer Profile, or
2. Send an email from your registered email address to privacy@szmobile.it with the subject line “Account Erasure Request”.
3. Upon verification, we will permanently purge your authentication credentials, session tokens, and default delivery addresses within 30 days. Note that completed transaction invoices will remain archived solely for mandatory Italian tax audit compliance.

17. Security Incidents & Notifications

In the unlikely event of a security incident or personal data breach resulting in a risk to your fundamental rights and freedoms, we will notify the competent supervisory authority (Garante Privacy) within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33, and inform affected data subjects without undue delay where required by Article 34.

18. Updates to this Privacy Policy

We may periodically update this Privacy Policy to reflect changes in our retail operations, technical features, or relevant privacy laws. When updates are published, we will revise the “Last Updated” timestamp at the top of this page. Substantial revisions will be communicated via banner notices on the website or via direct email to registered users.

19. Contact Details & Supervisory Authority

If you have questions, concerns, or complaints regarding this Privacy Policy or our data processing activities, please reach out to us:

S&Z Mobile Privacy Helpdesk
In-Person: Via Vitruvio, 47, 20124 Milano (MI), Italy
Right to Lodge a Complaint with the Supervisory Authority:

You also have the right to lodge a formal complaint with your national data protection supervisory authority. In Italy, this is the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Roma, www.garanteprivacy.it).