Skip to content

Country

Language

Cart

Your cart is empty

Privacy Policy

Privacy Policy

Information notice on the processing of personal data pursuant to Article 13 and, where applicable, Article 14 of Regulation (EU) 2016/679 (“GDPR”)

Last updated: 31/08/2026

This notice describes how SIAP S.r.l., acting as Data Controller, processes the personal data of users who visit the website https://www.finamore.it (the “Site”), who make purchases through the Site, or who use the services and functionalities made available through it.

This notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (the “Regulation” or “GDPR”) and the applicable national legislation on the protection of personal data, including Italian Legislative Decree No. 196 of 30 June 2003 (the “Privacy Code”), as amended by Legislative Decree No. 101 of 10 August 2018.

The notice is addressed to users of the Site and to data subjects whose personal data are processed in connection with the services offered by the Controller.

Personal data are processed in compliance with the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, as well as with the other principles set out in the applicable data protection legislation.

This notice relates exclusively to the Site and does not apply to third-party websites, platforms or services that may be reached through links available on the Site; users are invited to consult the relevant privacy notices of those third parties.

For specific information on the cookies and other tracking tools used by the Site, please refer to the Cookie Policy, available at the following link:
https://www.finamore.it/pages/cookie-policy

1. Data Controller

The Controller of the processing of personal data is:

SIAP S.r.l.
Registered office: Via Senato, 45 – 20121 Milan (MI), Italy
Operating office: Strada Consortile c/o Consorzio IMPRE.CO – 81032 Carinaro (CE), Italy
VAT no.: 04847611219
E-mail: info@finamore.it
Certified e-mail (PEC): siapsrlcisnola@legalmail.it

(hereinafter, the “Controller”).

For any request relating to the processing of personal data, or in order to exercise the rights granted by the applicable legislation, the data subject may contact the Controller using the contact details indicated above.

2. What personal data may be processed

“Personal data” means any information relating to an identified or identifiable natural person.

While the user browses and uses the Site, and in connection with purchases and services offered, the Controller may process various categories of personal data, depending on the specific functionalities used by the user.

2.1 Browsing data and technical data

The IT systems and software procedures used to operate the Site acquire, in the course of their normal operation, certain personal data whose transmission is inherent in the use of Internet communication protocols.

By way of example, the following may be processed: IP address, date and time of the request, technical identifiers of the connection or device, browser type and version, operating system, pages visited, referring and exit URLs, access logs, as well as information relating to any technical errors or malfunctions.

Such information is processed mainly in order to allow the proper functioning of the Site, ensure the security of the IT infrastructure, prevent unauthorised access or fraudulent activity, and manage any technical anomalies.

Where provided for and permitted by the applicable legislation, certain data may also be used to produce aggregate statistics on the use of the Site.

2.2 Data provided voluntarily by the user

The Controller may process the personal data that the user voluntarily decides to provide through the Site, for example by means of:

  • contact forms;
  • requests for information;
  • support requests;
  • communications sent by e-mail;
  • purchase procedures;
  • subscription to newsletters or commercial communications;
  • registration and management of an account, where available;
  • participation in promotional initiatives;
  • any other services made available through the Site.

Depending on the service used, such data may include, by way of example:

  • first name and surname;
  • e-mail address;
  • telephone number;
  • shipping address;
  • billing address;
  • tax code (codice fiscale);
  • VAT number;
  • company name;
  • data relating to orders and purchases;
  • information contained in requests sent to customer service;
  • information entered by the user in contact forms;
  • any further information voluntarily communicated by the user.

The Controller invites users not to communicate, through the forms on the Site or the support channels, personal data that are not necessary, or data belonging to the special categories referred to in Article 9 of the GDPR, unless this is strictly necessary and required in order to handle the specific request.

2.3 Purchase-related data

Where the user makes a purchase through the Site, the Controller may process the data necessary to manage the contractual relationship and the related obligations.

The data processed may include, among others, data relating to the products purchased, the amounts due or paid, orders placed, invoicing, delivery, shipments, returns, replacements, refunds, warranties and communications exchanged with customer service.

The Controller does not directly process full payment card details where payment is made through external providers that manage such information directly.

2.4 Account data

Where the Site allows the creation of a personal account, the data necessary for registration and management of the reserved area may be processed, as well as data relating to orders and preferences associated with the account.

The user is responsible for keeping their access credentials secure and must take all reasonable precautions to prevent their use by unauthorised third parties.

2.5 Data relating to commercial communications

Where the user gives their consent, the Controller may process contact data — in particular the e-mail address and, where applicable, other contact details — in order to send newsletters and commercial communications concerning the Controller’s products, services, promotions and initiatives.

Consent is optional and may be withdrawn at any time.

The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

The user may also object at any time to receiving commercial communications by using the unsubscribe link included in the communications received, or by contacting the Controller.

2.6 Data processed through cookies and tracking tools

The Site uses cookies and similar technologies for technical, analytical, statistical, advertising and marketing purposes.

In particular, on the basis of the configuration currently set out in the Cookie Policy, tools provided by the following parties may be used:

  • Shopify;
  • Shop.app;
  • Google Analytics 4;
  • Google Ads;
  • Google DoubleClick;
  • Meta;
  • Microsoft Clarity;
  • Microsoft/Bing.

Strictly necessary cookies may be used without the user’s prior consent, whereas tools requiring consent are activated, where required by the applicable legislation, only following the user’s choice through the preference management system.

For detailed information on the individual cookies, their purposes, duration and the ways in which consent can be managed, please refer to the Cookie Policy.

2.7 Data relating to chatbots, WhatsApp support and other messaging tools

Where the Site makes available support tools based on chatbots, WhatsApp or systems relying on artificial intelligence technologies, the Controller may process the personal data contained in the communications and requests made by the user.

Depending on the service used, the following may be processed:

  • identification and contact data;
  • the content of the requests;
  • information relating to orders;
  • data necessary to provide support;
  • any further information voluntarily entered by the user.

The Controller does not carry out any processing of personal data based on solely automated decision-making, including profiling, producing legal effects concerning the data subject or similarly significantly affecting them, within the meaning of Article 22 of the GDPR.

Users are invited not to enter, in conversations with chatbots or support systems, personal data that are not necessary for handling the request.

3. Purposes of the processing and legal bases

Personal data are processed exclusively for specified, explicit and legitimate purposes, and only to the extent necessary to pursue each individual purpose.

The legal basis of the processing varies according to the purpose pursued.

Purpose Description Legal basis
A. Browsing, operation and security of the Site Technical and browsing data are processed in order to allow the user to access the Site and use its functionalities, and to ensure its security, stability and proper functioning. Art. 6(1)(f) GDPR (legitimate interest of the Controller in the security and proper functioning of the site), and, where applicable, Art. 6(1)(c) GDPR.
B. Account registration and management Where available, account registration and management of the personal area involve the processing of the data necessary to create and administer the account, allow access to reserved functionalities, manage orders and keep the user’s information up to date. Art. 6(1)(b) GDPR (performance of pre-contractual measures and of the contract).
C. Order management Personal data are processed in order to allow the conclusion and performance of the sales contract, including order management, purchase confirmation, payment handling, preparation and delivery of the products, management of any returns, replacements and refunds, as well as after-sales support and management of the legal warranty. Art. 6(1)(b) GDPR.
D. Tax and accounting obligations Data are processed in order to comply with obligations laid down by tax, accounting and civil law legislation. Art. 6(1)(c) GDPR (compliance with a legal obligation to which the Controller is subject).
E. Handling of contact requests Data provided by the user through contact forms, e-mail or other support channels are processed in order to reply to the requests received, provide information on products and services, handle any issues relating to orders and provide pre- and post-sales support. Art. 6(1)(b) GDPR; in other cases, where applicable, Art. 6(1)(f) GDPR.
F. Sending commercial communications and newsletters Subject to the data subject’s consent, the Controller may send informational, promotional and commercial communications relating to its products and services. Consent is always optional and may be withdrawn at any time. Art. 6(1)(a) GDPR (the data subject has given consent to the processing of their personal data for one or more specific purposes).
G. Management of gift cards and discount vouchers Personal data are processed in order to allow the issue, top-up, management and use of gift cards for the purchase of products on https://www.finamore.it. Such data are also processed in order to check balances, manage refunds, prevent fraud and abuse, and comply with the accounting and tax obligations laid down by the legislation in force. Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR.
H. Establishment, exercise or defence of legal claims Data may be processed where necessary to protect a right of the Controller in judicial or out-of-court proceedings. Art. 6(1)(f) GDPR.

4. Nature of the provision of data

The provision of personal data must be assessed in relation to the specific purpose for which the data are requested.

The provision of the data necessary for the conclusion and performance of an order is essential to allow the Controller to manage the purchase, carry out delivery, comply with legal obligations and provide the support requested. Failure to provide the necessary data may therefore prevent the conclusion or performance of the contract.

The provision of the data requested in order to respond to contact or support requests is necessary to the extent that such data are essential in order to provide a reply or handle the request.

The provision of data for marketing and newsletter purposes is, by contrast, optional. A failure to give consent does not prevent the user from purchasing products or using the services of the Site that do not require such processing.

Any consent given may be withdrawn at any time, without prejudice to the lawfulness of the processing carried out before the withdrawal.

5. Methods of processing and security

Personal data are processed using paper-based, electronic and telematic means, in ways designed to ensure the security and confidentiality of the information and in compliance with the principles of personal data protection.

The Controller adopts technical and organisational measures appropriate to the risk, taking into account the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons.

Depending on the characteristics of the processing carried out, such measures may include authentication and access control systems, protection of IT infrastructure, secure communication protocols, backups, system updates, measures to protect against unauthorised access and procedures for managing security incidents.

Access to personal data is permitted exclusively to authorised persons or to suppliers processing the data on behalf of the Controller, within the limits of their respective duties and in accordance with the applicable legislation.

6. Recipients of personal data

Personal data may be disclosed, strictly to the extent necessary to pursue the purposes indicated in this notice, to parties that assist the Controller in managing the activities relating to the Site and the services offered.

By way of example, recipients may include:

  • authorised personnel and collaborators of the Controller;
  • providers of hosting, infrastructure and IT maintenance services;
  • providers of the technology platform and of the services necessary for the operation of the Site;
  • payment service providers;
  • couriers, shipping agents and logistics operators;
  • providers of IT and technology services;
  • providers of customer support services;
  • providers of newsletter and electronic communication services;
  • providers of chatbot and automated support services;
  • any providers of analytics, marketing and preference management services, within the limits and under the conditions laid down by the applicable legislation;
  • tax, accounting and legal advisers;
  • public authorities and parties to whom disclosure is required by a legal obligation.

Parties processing personal data on behalf of the Controller are, where the relevant conditions are met, appointed as Data Processors pursuant to Article 28 of the GDPR and act on the basis of specific agreements or documented instructions.

Other parties may instead act as independent data controllers, where they autonomously determine the purposes and means of the processing falling within their remit. In such cases, the relevant processing is governed by the privacy notices of those parties.

7. Payment services

Any payments made through the Site may be handled by specialised payment service providers.

Depending on the payment methods actually available, services provided by PayPal, Stripe, Nexi or other operators may be used, by way of example.

The Controller neither stores nor directly processes full payment card details where such data are entered directly into the payment provider’s systems.

Payment-related data may be processed by the relevant provider in accordance with its own terms and privacy notices.

8. Personal account

Registration allows the user to access dedicated functionalities, such as viewing order history, managing shipping and billing addresses, tracking orders and updating their own data.

Registration may require data such as first name, surname, e-mail address, telephone number and information necessary for managing orders.

The user may request the deletion of their account by contacting the Controller, it being understood that certain data may be retained in accordance with criteria proportionate to the fulfilment of legal obligations or to the establishment, exercise or defence of a legal claim.

Deletion of the account does not necessarily entail the immediate deletion of all associated personal data, where retention obligations or other legal bases justifying such retention apply.

9. Chatbots, automated support, WhatsApp and other messaging tools

The Site may make available automated or conversational support tools intended to facilitate communication with the Controller and to provide answers to users’ requests.

Such tools may include, depending on the services actually available, chatbots integrated into the Site, systems connected to messaging services such as WhatsApp Business, or other tools.

The use of such tools is optional.

During interactions, data such as first name and surname, telephone number, e-mail address, the content of conversations, information relating to orders and other data voluntarily communicated by the user may be processed.

Data may be processed in order to provide support, respond to requests, provide information on products and services, manage orders and post-sales requests, and improve the quality of customer service.

Users are invited not to enter in conversations personal data that are not necessary and, in particular, data belonging to the special categories referred to in Article 9 of the GDPR, unless this is strictly necessary and required for the specific request.

Where such services are provided by third parties, the processing of data will be carried out according to the privacy role assumed by the individual provider and on the basis of the applicable agreements.

10. Cookies and other tracking tools

The Site uses cookies and, where applicable, other tracking tools in order to allow the pages and functionalities to work properly, store certain preferences and, where provided for, analyse the use of the Site or carry out marketing and profiling activities.

In relation to their function and the purposes pursued, the tools used may include:

  • technical tools, or tools strictly necessary for the operation of the Site;
  • tools used to store preferences and functionalities;
  • analytics tools;
  • marketing or profiling tools.

The use of technical tools and of other tools for which consent is not required takes place in compliance with the applicable legislation and the relevant conditions.

Tracking tools requiring consent are activated exclusively after the user has expressed a valid choice through the consent management system adopted by the Site.

The Site provides a dedicated Cookie Policy [LINK TO THE COOKIE POLICY], containing detailed information on the categories of cookies and tracking tools used, their purposes, the parties that may receive the data, their duration and the ways in which the user may manage or withdraw their preferences.

The preferences expressed by the user may be modified or withdrawn through the dedicated consent management tool available on the Site.

On first access to the Site, the user may manage their preferences relating to cookies and tracking tools through the consent management system used by the Site.

The user may:

  • accept all non-necessary tools;
  • reject non-necessary tools;
  • select their preferences by category;
  • modify or withdraw consent previously given.

Any consent given may be withdrawn at any time, without prejudice to the lawfulness of the processing carried out before the withdrawal.

11. Data retention period

Personal data are retained for no longer than is necessary for the purposes for which they were collected or subsequently processed.

The retention period varies according to the nature of the data and the purpose of the processing.

In particular:

  • data necessary for the management of orders and of the contractual relationship are retained for the period necessary to manage the relationship and any related obligations;
  • data subject to tax, accounting or civil law retention obligations are retained for the period laid down by the applicable legislation;
  • data relating to contact and support requests are retained for the time necessary to handle the request and, subsequently, for the period that may be necessary to protect the Controller’s rights;
  • data processed for marketing purposes are retained until consent is withdrawn or, in any case, in accordance with retention periods and criteria defined by the Controller in relation to the specific marketing activity;
  • account data are retained until the account is deleted, save where certain data must be retained to comply with legal obligations or to protect legal rights;
  • browsing data and technical logs are retained for the period necessary for security, operation and technical systems management purposes, in accordance with criteria proportionate to the purposes pursued;
  • data collected through cookies and tracking tools are retained for the periods indicated in the Cookie Policy and, where applicable, in accordance with the preferences expressed by the user.

At the end of the applicable retention period, personal data are deleted, anonymised or otherwise rendered no longer directly attributable to the data subject, unless their further retention is necessary to comply with a legal obligation or to establish, exercise or defend a legal claim.

12. Transfers of personal data to third countries

Personal data are, as a rule, processed within the European Economic Area.

Where, in order to use certain services or providers, it becomes necessary to transfer personal data to countries outside the European Economic Area or otherwise to international organisations, the Controller will carry out such transfers in compliance with the provisions of Articles 44 et seq. of the GDPR.

Depending on the case, the transfer may take place:

  • to countries covered by an adequacy decision of the European Commission;
  • through the adoption of Standard Contractual Clauses (SCCs).

Where necessary, the Controller will adopt the further measures required by the applicable legislation in relation to international transfers.

13. Rights of data subjects

In relation to the personal data processed, the data subject may exercise, in the cases and under the conditions provided for by the GDPR, the rights granted by Articles 12 to 22 of the Regulation.

In particular, the data subject may:

  • obtain confirmation as to whether or not personal data concerning them are being processed and, in that case, obtain access to the data and the information referred to in Article 15 of the GDPR;
  • request the rectification of inaccurate personal data or the completion of incomplete data;
  • request, in the cases provided for by law, the erasure of personal data;
  • request, in the cases referred to in Article 18 of the GDPR, the restriction of processing;
  • object to the processing of personal data in the cases referred to in Article 21 of the GDPR;
  • receive, in the cases referred to in Article 20 of the GDPR, the personal data provided to the Controller in a structured, commonly used and machine-readable format and, where technically feasible and provided for by law, transmit them to another controller;
  • withdraw at any time consent previously given, where the processing is based on consent, without prejudice to the lawfulness of the processing carried out before the withdrawal;
  • lodge a complaint with the competent supervisory authority, pursuant to Article 77 of the GDPR.

The right to object may be exercised, in particular, in relation to processing based on the Controller’s legitimate interest, in the cases and under the conditions referred to in Article 21 of the GDPR.

Where personal data are processed for direct marketing purposes, the data subject may object to such processing at any time, including in respect of specific communication channels only.

The exercise of these rights is subject to the conditions and limits laid down by the applicable legislation. In particular, certain rights may be restricted where the retention or processing of the data is necessary to comply with a legal obligation or to establish, exercise or defend a legal claim.

To exercise their rights, the data subject may send a request to the Controller using the following contact details:

SIAP S.r.l. — E-mail: info@finamore.it

The Controller will respond to the request within the time limits laid down by the applicable legislation.

Where the data subject considers that the processing of their personal data is carried out in breach of the applicable legislation, they also have the right to lodge a complaint with the competent supervisory authority, in particular with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with the procedures indicated on its official website.

14. Data relating to minors

The Site is addressed to a general audience and is not specifically intended for minors.

The Controller does not intend to knowingly collect the personal data of minors in breach of the applicable legislation.

Should the Controller become aware that it has collected the personal data of a minor in circumstances in which such processing is not permitted by law, it will take reasonable and appropriate measures in relation to the specific case, including, where necessary, deletion of the data.

Parents or those exercising parental responsibility who believe that a minor has provided personal data to the Controller may contact the Controller using the details indicated in this notice.

15. Links to third-party sites and services

The Site may contain links to websites, platforms or services operated by third parties.

The presence of such links does not entail any liability on the part of the Controller in relation to the ways in which those parties process personal data.

Users are invited to consult the privacy notices of third-party services before providing them with personal data or using their functionalities.

16. Updates to this Privacy Policy

This Privacy Policy may be amended or updated over time, for example as a result of regulatory changes, the introduction of new services or functionalities, or changes in the ways in which personal data are processed.

The updated version of the Privacy Policy will be published on the Site and will bear the date of the last update.

Where the changes involve substantial modifications to the ways in which personal data are processed, or require, under the applicable legislation, a specific notification to data subjects, the Controller will take the necessary measures to inform data subjects by appropriate means.

Users are therefore invited to consult this page periodically in order to check for any updates.

17. Contacts

For any information relating to this Privacy Policy, to the processing of personal data, or in order to exercise the rights granted by the GDPR, you may contact:

SIAP S.r.l.
Registered office: Via Senato, 45 – 20121 Milan (MI), Italy
Operating office: Strada Consortile c/o Consorzio IMPRE.CO – 81032 Carinaro (CE), Italy
VAT no.: 04847611219
E-mail: info@finamore.it

Last updated: 31/08/2026