Privacy Policy
Privacy Policy - Piki Candles
Last updated: February 2026
This Privacy Policy describes how Piki Candles collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and Italian legislation.
1. Data Controller
Piki Candles
Email: pikicandleshop@gmail.com
Headquarters: Italy
2. Personal Data Collected
2.1 Data provided voluntarily
When you place an order or register on our site, we collect:
- First and last name
- Email address
- Phone number
- Shipping and billing address
- Payment data (via certified providers, we do not store cards)
- VAT number and tax data (if required)
2.2 Automatically collected data
- IP address
- Browser and device type
- Pages visited and time spent
- Cookies and similar technologies (see Cookie Policy)
3. Purpose of Processing
Your personal data is processed for the following purposes:
3.1 Contractual purposes (legal basis: contract execution)
- Order processing and management
- Product shipping
- Invoice issuance
- Customer support
- Management of returns and refunds
3.2 Legal purposes (legal basis: legal obligation)
- Tax and accounting compliance
- Document retention for legal terms
3.3 Marketing purposes (legal basis: consent)
- Sending newsletters and promotional communications
- Personalized offers
- Review requests
You can withdraw your consent at any time.
3.4 Analytical purposes (legal basis: legitimate interest)
- User behavior analysis
- Website and service improvement
- Anonymous statistics
4. Legal Basis for Processing
We process your data based on:
- Contract execution: To process orders and provide services
- Legal obligation: For tax and regulatory compliance
- Consent: For marketing activities (revocable)
- Legitimate interest: To improve our services
5. Data Sharing
Your data may be shared with:
5.1 Service providers (Data Processor)
- Shopify: E-commerce platform (USA - Privacy Shield)
- Couriers: BRT, GLS, Poste Italiane for shipments
- Payment providers: Stripe, PayPal for payments
- Email service: For sending communications
5.2 Competent authorities
Upon request from judicial or tax authorities, within legal limits.
5.3 We do not sell your data
We do not sell, rent, or transfer your personal data to third parties for commercial purposes.
6. Data Transfer Outside the EU
Some providers (e.g., Shopify) may transfer data outside the EU. In these cases, we guarantee:
- Standard contractual clauses approved by the EU Commission
- Privacy Shield certifications (where applicable)
- Adequate protection safeguards
7. Data Retention
We retain your data for:
- Contractual data: 10 years (tax obligation)
- Marketing data: Until consent is withdrawn or 24 months of inactivity
- Analytical data: In an anonymous form without time limits
8. Your Rights (GDPR)
You have the right to:
- Access: Obtain a copy of your data
- Rectification: Correct inaccurate data
- Erasure: Request deletion ("right to be forgotten")
- Restriction: Restrict processing
- Portability: Receive data in a structured format
- Objection: Object to processing for marketing
- Withdraw consent: Withdraw consent at any time
- Complaint: Lodge a complaint with the Privacy Guarantor
How to exercise your rights
Send a request to: pikicandleshop@gmail.com
We will respond within 30 days.
9. Data Security
We adopt technical and organizational measures to protect your data:
- 🔒 Encrypted SSL/TLS connection
- 🔐 Limited data access only to authorized personnel
- 🛡️ Regular backups
- ✅ PCI DSS compliance for payments
- 🔒 Encrypted passwords
10. Cookies
The site uses technical and profiling cookies. For more information, please consult our Cookie Policy.
11. Minors
Our services are not intended for minors under 18 years of age. We do not knowingly collect data from minors without parental consent.
12. Changes to the Privacy Policy
We reserve the right to update this Privacy Policy. Changes will be published on this page with the update date.
13. Contacts
For privacy questions or to exercise your rights:
📧 Email: pikicandleshop@gmail.com
📱 WhatsApp: [Insert number]
14. Supervisory Authority
Garante per la Protezione dei Dati Personali (Italian Data Protection Authority)
Website: www.garanteprivacy.it
Email: garante@gpdp.it
Your privacy is important to us. We process your data with the utmost care and transparency. 💚