Privacy Policy and Cookies

Last updated: 12 August 2026

This Privacy and Cookie Policy explains how GLUECKLICH OHG DES CHRISTOPH STEINER & CO., operating the Alpe Piano brand, collects and processes personal data and uses cookies and similar technologies when you visit or interact with alpepiano.com, create an account, contact us, subscribe to marketing communications or place an order.

Alpe Piano is a brand owned and operated by GLUECKLICH OHG DES CHRISTOPH STEINER & CO. Alpe Piano is not a separate legal entity.

We process personal data in accordance with the EU General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”), applicable Italian data-protection and electronic-communications legislation and other data-protection laws that apply to our activities.

This Policy provides information about our processing activities. It does not constitute consent. Where consent is legally required, we request it separately.

1. Data Controller

The Data Controller responsible for processing personal data through this Website is:

GLUECKLICH OHG DES CHRISTOPH STEINER & CO.
Operating under the Alpe Piano brand
Piazza Municipio 11
39057 Appiano sulla Strada del Vino (BZ)
Italy
VAT number and tax code: IT02803430210
REA: BZ-206971
PEC: gluecklich@pec.bz.it
Email: we@alpepiano.com
Telephone: +39 0471 974989

GLUECKLICH OHG DES CHRISTOPH STEINER & CO. is an Italian general partnership corresponding to a società in nome collettivo (S.n.c./OHG).

2. Personal data we collect

Depending on how you interact with the Website and our services, we may collect the following categories of personal data.

2.1 Information you provide directly

This may include:

  • name and surname;

  • billing and shipping address;

  • email address;

  • telephone number;

  • order and purchase information;

  • payment-related information;

  • customer-account and login information;

  • newsletter preferences and marketing consent;

  • messages submitted through contact or withdrawal forms;

  • communications with customer service;

  • returns, exchanges, refunds and complaint information;

  • gift-card purchase and redemption information; and

  • other information you voluntarily provide.

Payment information is processed securely by the relevant payment provider. We generally do not receive or store complete payment-card numbers.

2.2 Information collected automatically

When you visit or use the Website, we may automatically collect:

  • IP address;

  • browser type and version;

  • operating system;

  • device type and device identifiers;

  • language and regional settings;

  • referring website, URL or campaign;

  • pages and products viewed;

  • date, time and duration of visits;

  • search, shopping-cart and checkout activity;

  • purchase and conversion events;

  • cookie and online identifiers;

  • consent preferences;

  • technical logs and security information; and

  • interactions with the Website, advertisements and marketing communications.

Some of this information is collected through cookies, pixels, local storage, server-side integrations and similar technologies.

2.3 Information received from third parties

We may receive personal data from third parties involved in providing our Website and services, including:

  • Shopify and related e-commerce services;

  • payment providers;

  • shipping and logistics providers;

  • Google analytics and advertising services;

  • Meta advertising and measurement services;

  • Mailchimp and Shopify Email;

  • fraud-prevention and security providers;

  • social-media and Instagram-feed services; and

  • customer-service and technical-support providers.

The information received depends on the service concerned and your interaction with that provider.

3. Purposes and legal bases for processing

3.1 Website operation and security

We process technical and usage information to provide the Website, maintain its functionality, protect accounts and transactions, prevent fraud and ensure system security.

Legal basis: our legitimate interests in providing a secure and functional online store under Article 6(1)(f) GDPR and, where applicable, compliance with legal obligations under Article 6(1)(c) GDPR.

Essential technical processing is necessary for the Website to function correctly.

3.2 Shopping cart, checkout and orders

We process identification, contact, order and transaction information to:

  • manage shopping carts;

  • process and confirm orders;

  • accept payments;

  • provide eGift Cards;

  • arrange delivery;

  • process returns, exchanges and refunds; and

  • perform our contractual obligations.

Legal basis: taking steps at your request before entering into a contract and performing the contract under Article 6(1)(b) GDPR.

Information marked as required during checkout is necessary to conclude and perform the purchase contract. Without it, we may be unable to process the order.

3.3 Payments

We process and transmit payment-related information to the payment provider selected during checkout to authorise and complete payments, prevent fraud and process refunds.

Legal bases:

  • performance of a contract under Article 6(1)(b) GDPR;

  • compliance with legal obligations under Article 6(1)(c) GDPR; and

  • our legitimate interest in preventing fraudulent transactions under Article 6(1)(f) GDPR.

Payment providers may process information as independent data controllers under their own privacy policies.

3.4 Shipping and delivery

We provide the information necessary to deliver an order to the selected shipping or logistics provider. This normally includes the customer’s name, delivery address, contact details and relevant order information.

For international orders, information may also be shared with carriers, customs authorities and service providers involved in customs clearance.

Legal bases: performance of a contract under Article 6(1)(b) GDPR and compliance with legal obligations under Article 6(1)(c) GDPR.

3.5 Customer accounts

If you create a customer account, we process identification, contact, login and order information to manage the account, display order history and facilitate future purchases.

Legal basis: performance of a contract and taking steps at your request under Article 6(1)(b) GDPR.

Creating an account is voluntary unless otherwise indicated.

3.6 Customer service and enquiries

We process personal data to:

  • respond to enquiries;

  • provide customer support;

  • handle complaints;

  • manage withdrawal requests;

  • administer returns, exchanges and refunds; and

  • respond to product-safety or legal-guarantee matters.

Depending on the request, the legal basis is:

  • taking pre-contractual steps or performing a contract under Article 6(1)(b) GDPR;

  • compliance with a legal obligation under Article 6(1)(c) GDPR; or

  • our legitimate interest in responding to enquiries and providing customer service under Article 6(1)(f) GDPR.

3.7 Accounting, taxation and legal compliance

We process order, payment, invoice, customs and transaction information to comply with accounting, taxation, commercial, product-safety and other legal obligations.

Legal basis: compliance with legal obligations under Article 6(1)(c) GDPR.

3.8 Newsletters and promotional communications

If you subscribe to our newsletter or otherwise consent to receive promotional communications, we may process:

  • name;

  • email address;

  • marketing preferences;

  • subscription and consent records;

  • interactions with messages;

  • links selected;

  • associated purchase information; and

  • information used to measure and improve campaigns.

We use Mailchimp and Shopify Email to manage and send newsletters and promotional communications.

Legal basis: consent under Article 6(1)(a) GDPR.

Providing information for marketing is voluntary and is not required to make a purchase. You may withdraw consent at any time by selecting the unsubscribe link in a marketing email or contacting us at we@alpepiano.com.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Where permitted by applicable Italian law, we may send existing customers email marketing concerning products similar to those previously purchased. Customers may object at any time, free of charge.

3.9 Analytics and Website improvement

Subject to your cookie preferences, we process information about visits, product views, navigation, interactions, carts, checkouts and purchases to understand how visitors use the Website, measure performance and improve our services.

This includes the use of Google Analytics and Shopify analytics services.

Legal basis: consent under Article 6(1)(a) GDPR where non-essential analytics cookies or comparable technologies are used.

You can withdraw or change consent at any time through the Cookie Preferences tool.

3.10 Personalised advertising and campaign measurement

Subject to consent, we use cookies, pixels and similar technologies to:

  • measure advertising performance;

  • attribute purchases and other actions to campaigns;

  • create audiences;

  • retarget visitors;

  • improve campaign delivery;

  • control advertising frequency; and

  • display advertising that may be more relevant to your interests.

This may involve sharing online identifiers, cookie information, device information, Website interactions and purchase-related events with advertising partners, including Google and Meta.

Legal basis: consent under Article 6(1)(a) GDPR.

3.11 Fraud prevention and legal claims

We may process personal data to detect and prevent fraud, misuse, security incidents and violations of our terms, and to establish, exercise or defend legal claims.

Legal bases: our legitimate interests in protecting our business, customers, systems and legal rights under Article 6(1)(f) GDPR and, where applicable, compliance with legal obligations under Article 6(1)(c) GDPR.

4. Cookies and similar technologies

Cookies are small text files that websites store on or read from a user’s device.

Cookies may enable a Website to:

  • recognise a browser or device;

  • maintain a session;

  • remember settings;

  • retain products in a shopping cart;

  • manage checkout and payments;

  • understand how the Website is used; and

  • support advertising and campaign measurement.

Cookies may contain or generate information such as:

  • unique identifiers;

  • IP address;

  • browser and device information;

  • language and regional settings;

  • login and session information;

  • cart and checkout information;

  • referring website or campaign;

  • pages and products viewed;

  • purchase and conversion events; and

  • consent preferences.

Cookies placed directly by us or Shopify on our behalf are generally referred to as first-party cookies. Cookies placed or accessed by another provider are generally referred to as third-party cookies.

5. Similar tracking technologies

In addition to cookies, we may use:

  • pixels and tags;

  • local storage;

  • device and online identifiers;

  • software development tools;

  • server-side event transmission;

  • conversion APIs; and

  • other technologies that store information on or access information from a device.

These technologies are covered by this Policy where applicable.

Our Meta integration uses a browser-based Meta Pixel and server-side transmission through the Meta Conversions API. Server-side transmission does not necessarily place a cookie on the user’s device, but it may process online identifiers and information about interactions with the Website.

6. Legal framework for cookies

We use cookies and similar technologies in accordance with:

  • GDPR;

  • Article 122 of the Italian Personal Data Protection Code, Legislative Decree 30 June 2003, no. 196, as amended;

  • applicable Italian rules and guidance concerning cookies and tracking technologies; and

  • other applicable electronic-communications and data-protection laws.

Strictly necessary technologies may be used without consent where they are required to transmit a communication or provide a Website function or service expressly requested by the user.

Personalization, analytics, marketing, advertising and profiling technologies are used only after consent where required by law.

Consent is voluntary and may be withdrawn at any time.

7. Cookie categories

7.1 Required cookies

Required cookies are necessary for the Website and online store to operate.

They support:

  • Website navigation;

  • secure sessions;

  • shopping carts;

  • checkout and payment processing;

  • customer-account login;

  • gift-card redemption;

  • fraud prevention;

  • language, country and currency selection;

  • consent preferences; and

  • form protection.

Required cookies cannot be disabled through the Cookie Preferences tool because the Website or requested service may not function correctly without them.

Where required cookies process personal data, the legal basis may be:

  • Article 6(1)(b) GDPR for contractual or pre-contractual processing;

  • Article 6(1)(c) GDPR for legal obligations; or

  • Article 6(1)(f) GDPR for our legitimate interest in providing a secure and functional store.

7.2 Personalization cookies

Personalization cookies remember actions or choices to provide a more personalised experience.

They may remember:

  • language;

  • country or region;

  • currency;

  • display preferences;

  • previous interactions; and

  • selected features or content.

Non-essential personalization cookies are used only with consent under Article 6(1)(a) GDPR.

7.3 Analytics cookies

Analytics technologies help us understand how visitors use the Website.

They may measure:

  • visits and sessions;

  • pages and products viewed;

  • navigation paths;

  • referring websites and campaigns;

  • cart, checkout and purchase activity;

  • Website performance;

  • technical errors; and

  • aggregated usage trends.

Non-essential analytics technologies are used only with consent under Article 6(1)(a) GDPR.

7.4 Marketing cookies

Marketing technologies are used to:

  • attribute advertising;

  • measure conversions;

  • retarget visitors;

  • create audiences;

  • control advertising frequency;

  • personalise advertising; and

  • measure interactions with campaigns.

Marketing and profiling technologies are used only after consent under Article 6(1)(a) GDPR.

8. Cookie banner and consent choices

Where required by law, visitors are shown the Shopify Customer Privacy consent banner before non-essential cookies and similar technologies are activated.

The banner provides the following choices:

  • Accept

  • Decline

  • Manage preferences

Through “Manage preferences,” visitors may separately decide whether to allow:

  • personalization;

  • analytics; and

  • marketing.

Required cookies remain active because they are necessary for the operation and security of the Website or for a service requested by the user.

Optional categories are not selected by default.

Accepting optional categories authorises the corresponding technologies described in this Policy. Declining prevents their use, subject to strictly necessary processing.

Closing the preferences panel without saving optional selections does not constitute consent.

9. Withdrawing or changing consent

You may withdraw or change consent at any time through the Cookie Preferences link in the Website footer.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

After changing a preference, it may be necessary to refresh the page. Cookies already stored on the device may remain until they expire or are deleted, but the corresponding optional technologies should no longer be used for new processing after withdrawal, subject to applicable technical and legal limitations.

Cookies may also be deleted through browser settings.

10. Shopify

The online store is hosted and operated through Shopify.

Shopify processes personal data to provide:

  • storefront functionality;

  • secure browsing;

  • shopping carts;

  • checkout and payment processing;

  • customer accounts;

  • Shop and Shop Pay functions;

  • fraud prevention;

  • consent management;

  • analytics and reporting; and

  • marketing services where consent has been provided.

For customers in the EEA, United Kingdom and Switzerland, personal data is generally initially processed by Shopify International Limited in Ireland. Shopify affiliates and subprocessors may process data in other countries.

Depending on the relevant activity, Shopify may act as our processor or as an independent controller.

Further information is available through:

11. Shopify Network Intelligence

Shopify Network Intelligence is enabled for the store.

Where the required consent has been provided, information about interactions with our store may be shared with Shopify and used together with information concerning interactions with Shopify and other Shopify merchants.

Shopify may use this information to provide enhanced services such as:

  • personalised Shop and Shop Pay experiences;

  • analytics and reporting;

  • fraud prevention;

  • product and service improvement;

  • marketing measurement; and

  • advertising personalisation and targeting.

Shopify states that other merchants cannot directly access our customer data.

For visitors in the EEA, United Kingdom and Switzerland, information from the store should not be used for non-essential Network Intelligence purposes where the visitor has not consented to the relevant categories through Shopify’s consent tools.

Users may withdraw consent through Cookie Preferences and may exercise certain choices through the Shopify Privacy Portal.

12. Shopify Payments, PayPal and payment providers

Where Shopify Payments is used, payment data may be processed by Shopify and its payment partners, including Stripe, to authorise payments, prevent fraud, process refunds and comply with financial obligations.

Where PayPal is selected, PayPal processes payment and transaction information under its own privacy rules.

Other payment methods displayed during checkout may involve additional payment providers. The provider selected by the customer may act as an independent controller for parts of its processing.

Payment providers may use required cookies or security technologies necessary to complete a requested payment. Any separate non-essential technologies remain subject to applicable consent requirements.

13. Mailchimp and Shopify Email

We use Mailchimp and Shopify Email to manage mailing lists and send newsletters and promotional communications.

These services may process:

  • name;

  • email address;

  • subscription status;

  • consent records;

  • marketing preferences;

  • campaign delivery information;

  • email opens and link selections;

  • device and browser information; and

  • purchase or interaction information used for campaign segmentation.

Marketing emails are sent only where we have an appropriate legal basis.

Tracking of email opens or interactions may be subject to consent or other requirements under applicable law. Where required, such tracking is enabled only in accordance with the user’s choices.

Users can unsubscribe at any time through the link provided in each marketing email.

Mailchimp is provided by Intuit and may process data outside the EEA using appropriate transfer mechanisms.

Further information is available in the Intuit Global Privacy Statement.

Information about Shopify’s processing is available through Shopify’s privacy documentation linked above.

14. Google Analytics and Google advertising services

Subject to analytics and marketing consent, we use Google services, including Google Analytics and Google advertising or campaign-measurement services.

Google technologies may process:

  • IP address;

  • cookie and online identifiers;

  • browser and device information;

  • approximate location derived from technical information;

  • referring URLs and campaign details;

  • pages and products viewed;

  • searches and Website interactions;

  • cart and checkout activity;

  • purchases and transaction values; and

  • interactions with advertisements.

We use these services to:

  • measure Website usage and performance;

  • understand navigation and product interest;

  • measure campaign effectiveness;

  • attribute purchases and other actions;

  • create advertising audiences; and

  • display or measure relevant advertising.

Google may combine information from our Website with information associated with other Google services, depending on the user’s settings and Google’s applicable terms.

Google may act as our processor for certain analytics activities and as an independent controller for other advertising or service-related processing.

Further information is available through:

15. Meta Pixel and Conversions API

Subject to analytics and marketing consent, we use the Facebook and Instagram integration provided by Meta Platforms.

Our Meta Pixel is:

Alpe Piano Pixel ID: 1076718471444017

The integration operates through:

  • the browser-based Meta Pixel; and

  • server-side event transmission through the Meta Conversions API.

The Meta integration may process:

  • IP address;

  • browser and device information;

  • cookie and online identifiers;

  • referring URLs and campaign information;

  • pages and products viewed;

  • searches;

  • products added to or removed from the cart;

  • checkout activity;

  • purchases and transaction values;

  • advertising interactions; and

  • hashed contact or customer information where supported, appropriately configured and legally permitted.

We use the integration to:

  • measure advertising performance;

  • attribute purchases and actions to campaigns;

  • create audiences;

  • retarget visitors;

  • improve campaign delivery;

  • display more relevant advertisements; and

  • reduce unnecessary or repetitive advertising.

Meta may combine information received from the Website with information held through Facebook, Instagram and other Meta services.

Depending on the relevant processing, Meta may act as an independent controller or under applicable joint-controller or business-tool arrangements.

Further information is available through:

16. hCaptcha and form security

Shopify may use hCaptcha or comparable security technologies to protect login, contact, account, withdrawal and checkout forms against automated misuse, spam and fraud.

These services may process:

  • IP address;

  • device and browser information;

  • interaction and security signals;

  • time and page information; and

  • information used to determine whether an interaction originates from a person or an automated system.

Where the technology is strictly necessary to secure a form or prevent abuse, it is treated as required.

Further information is available through:

17. Instagram-feed integration

The Website uses a Shopify app or integration to display content from the Alpe Piano Instagram presence.

Loading or interacting with embedded social-media content may result in a connection to Meta or the relevant app provider. Depending on the configuration, technical information such as IP address, browser information, page visited and interaction information may be processed.

Where the integration uses non-essential cookies or tracking technologies, they are used only after applicable consent has been provided.

Following a link to Instagram takes the user to a service operated by Meta, and Meta’s own privacy and cookie terms apply.

Further information is available in the Instagram Privacy Policy.

18. Principal cookies and technologies

The cookies used may depend on the page visited, account status, checkout activity, selected country and currency, payment method, consent choices and provider updates.

Required Shopify cookies

Cookie Provider Purpose Typical duration
_shopify_essential Shopify Core storefront, session, checkout and anti-tampering functions Up to 1 year
_shopify_test Shopify Checks whether the browser supports cookies Approximately 1 minute
_tracking_consent Shopify Stores cookie and privacy preferences Up to 1 year
cart Shopify Stores shopping-cart information Up to 2 weeks
cart_currency Shopify Maintains the selected cart currency Up to 2 weeks
discount_code Shopify Stores an eligible discount code for checkout Session
localization Shopify Supports selected country, region or language Up to 1 year
login_with_shop_finalize Shopify Facilitates login through Shop Approximately 5 minutes
shopify_pay Shopify Supports Shop Pay login and checkout Up to 1 year
storefront_digest Shopify Supports access to a protected storefront where applicable Up to 1 year

Shopify analytics and marketing cookies

Cookie Provider Purpose Typical duration Category
_landing_page Shopify Records the visitor’s landing page Up to 2 weeks Analytics
_orig_referrer Shopify Records the referring source Up to 2 weeks Analytics
_shopify_analytics Shopify Supports storefront or checkout analytics Up to 1 year Analytics
_shopify_s Shopify Identifies a store-associated browser session Approximately 30 minutes, with rolling renewal Analytics
_shopify_y Shopify Supports storefront analytics Up to 1 year Analytics
shop_analytics Shopify Supports Shop-related analytics Up to 1 year Analytics
_shopify_marketing Shopify Stores marketing-related information Up to 1 year Marketing

Google cookies

Cookie Provider Purpose Typical duration Category
_ga Google Distinguishes visitors for analytics Up to 2 years Analytics
_ga_<container-id> Google Maintains session and analytics information Up to 2 years Analytics
_gid Google Distinguishes visitors for analytics where used Approximately 24 hours Analytics
_gcl_au Google Supports advertising conversion measurement Up to 3 months Marketing
Other Google advertising identifiers Google Attribution, audience and advertising measurement According to Google’s settings and policies Marketing

Meta cookies and technologies

Cookie or technology Provider Purpose Typical duration Category
_fbp Meta Advertising measurement, attribution, audiences and retargeting Generally up to 90 days Marketing
_fbc Meta Stores Meta advertising-click information Generally up to 90 days Marketing
Meta Pixel events Meta Records Website and commerce interactions According to Meta’s policies and settings Analytics and marketing
Meta Conversions API events Meta Transmits selected conversion events server-side According to Meta’s policies and settings Analytics and marketing

Email-marketing technologies

Mailchimp and Shopify Email may use tracking pixels or encoded links to measure delivery, opens, link interactions and campaign performance. These technologies are used only in accordance with applicable legal requirements and the user’s marketing and tracking choices.

The precise list may change when Shopify or another provider updates its services, security mechanisms or cookie names. The categories selected through Cookie Preferences continue to govern whether optional technologies may be used.

19. Cookie duration and browser controls

Cookies may be:

  • session cookies, which generally expire when the browser is closed; or

  • persistent cookies, which remain until their expiry, deletion or replacement.

The durations in this Policy are expected or typical maximum periods provided by the relevant service. A cookie’s duration may be renewed when the user revisits or interacts with the Website.

Server-side event data may be retained separately under the relevant provider’s retention policy.

Most browsers allow users to view, delete or block cookies. Blocking required cookies may prevent the shopping cart, login, checkout or other Website functions from working properly.

Browser settings do not necessarily prevent server-side processing or remove information already transmitted. Cookie Preferences should therefore also be used to withdraw consent.

20. Recipients of personal data

Where necessary, personal data may be disclosed to or processed by:

  • Shopify International Limited and Shopify affiliates and subprocessors;

  • Shopify Payments, Stripe and other payment providers;

  • PayPal where selected;

  • shipping, logistics and customs providers;

  • Mailchimp and Shopify Email;

  • Google entities and service providers;

  • Meta Platforms Ireland Limited and other Meta entities;

  • hCaptcha and its service providers;

  • Instagram-feed and social-media integration providers;

  • hosting, IT, cybersecurity and technical-support providers;

  • customer-service and communication providers;

  • accountants, tax advisers, legal advisers and consultants;

  • banks, insurers and fraud-prevention providers;

  • public authorities, courts, regulators and law-enforcement bodies where legally required; and

  • potential purchasers and advisers in connection with a merger, restructuring or business transfer, subject to appropriate safeguards.

Depending on the relevant activity, these recipients may act as processors, independent controllers or joint controllers.

We do not sell personal data for monetary consideration.

21. International data transfers

Some providers, affiliates or subprocessors may process personal data outside the EU or EEA, including in the United States and other countries.

Where required by GDPR, an appropriate transfer mechanism is used, such as:

  • an adequacy decision adopted by the European Commission;

  • the EU–US Data Privacy Framework where applicable;

  • Standard Contractual Clauses approved by the European Commission;

  • supplementary technical, contractual or organisational safeguards; or

  • another mechanism permitted under GDPR.

You may contact us at we@alpepiano.com for further information about applicable transfers and safeguards.

22. Data retention

We retain personal data only for as long as necessary for the relevant purpose and to comply with legal, accounting, taxation and documentation obligations.

Applicable periods include:

  • Order, invoice, payment and accounting data: generally 10 years, or longer where legally required or necessary for proceedings.

  • Customer-account data: while the account remains active and thereafter where retention is required for orders, legal obligations or claims.

  • Customer-service communications: for the period necessary to handle the request and thereafter for applicable limitation periods.

  • Return, warranty and complaint information: for the period necessary to handle the matter and document compliance with consumer-law obligations.

  • Marketing data: until consent is withdrawn, an objection is made or the data is no longer required for the relevant marketing purpose.

  • Consent and objection records: for as long as necessary to demonstrate compliance and defend potential claims.

  • Technical and security logs: for the period reasonably necessary to maintain security, investigate incidents and prevent fraud.

  • Cookie and analytics data: for the periods indicated in this Policy, the Cookie Preferences tool or the provider’s settings.

  • Legal-claim data: until the matter is concluded and applicable limitation periods have expired.

After the relevant period, personal data is deleted, anonymised or securely restricted unless further retention is required by law.

23. Your data-protection rights

Subject to GDPR conditions and limitations, you may have the right to:

  • obtain confirmation as to whether we process your personal data;

  • access your personal data and receive a copy;

  • request correction of inaccurate or incomplete data;

  • request erasure;

  • request restriction of processing;

  • receive certain data in a structured, commonly used and machine-readable format;

  • request transmission of eligible data to another controller;

  • object to processing based on legitimate interests;

  • object at any time to direct marketing and related profiling;

  • withdraw consent at any time;

  • obtain information about international-transfer safeguards;

  • not be subject to certain decisions based solely on automated processing; and

  • lodge a complaint with a competent supervisory authority.

To exercise these rights, contact:

Email: we@alpepiano.com

We may request information reasonably necessary to verify your identity and protect personal data against unauthorised disclosure.

We will respond without undue delay and generally within one month. This period may be extended by two months where permitted by GDPR, taking into account the complexity and number of requests.

Exercising these rights is generally free. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act as permitted by law.

24. Global Privacy Control and regional opt-outs

Where required by applicable regional law and supported by our Shopify configuration, Global Privacy Control signals and requests made through Shopify’s data-sharing opt-out tools may be treated as requests to opt out of processing that qualifies as a sale, sharing or targeted advertising.

These concepts arise primarily under certain non-European privacy laws and do not replace the consent requirements applicable in the EEA.

Available privacy and data-sharing choices may be accessed through the relevant link in our Website policies, Cookie Preferences or privacy interface.

25. Automated decision-making

We do not use personal data to make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.

Service providers may use automated systems to identify potentially fraudulent or unauthorised transactions. An order or payment may be reviewed, delayed or rejected where a risk is identified. Where applicable, you may contact us to request information or human review.

Advertising and analytics providers may use data, subject to consent, to create audiences, measure campaigns or personalise advertising. This does not generally produce legal or similarly significant effects concerning you.

26. Data security

We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Measures are selected by considering the nature, scope and risks of processing, available technology and implementation costs.

No electronic transmission or storage system can be guaranteed to be completely secure. Customers are responsible for keeping account credentials confidential and notifying us if they suspect unauthorised account access.

27. Children’s privacy

Our services are not directed at children, and we do not knowingly collect personal data from children in circumstances requiring parental or guardian authorisation.

If you believe that a child has improperly provided personal data, contact us at we@alpepiano.com so that we can investigate and, where appropriate, delete it.

28. Third-party websites and services

The Website may contain links to third-party websites, social-media platforms or services.

We are not responsible for the privacy practices of third parties acting as independent controllers. We recommend reviewing the relevant third party’s privacy policy before providing personal data or using its services.

29. Right to lodge a complaint

You have the right to lodge a complaint with the Italian Data Protection Authority:

Garante per la protezione dei dati personali
Piazza Venezia 11
00187 Rome
Italy
Website: www.garanteprivacy.it

You may also contact the competent data-protection authority in the EU or EEA country where you reside, work or believe an infringement occurred.

We encourage you to contact us first at we@alpepiano.com so that we can attempt to address your concern directly.

30. Changes to this Policy

We may update this Policy to reflect changes to:

  • our services and processing activities;

  • cookies and tracking technologies;

  • Shopify configuration;

  • payment, analytics, advertising or marketing providers;

  • consent-management tools;

  • applicable legal requirements; or

  • guidance issued by supervisory authorities.

The current version will be published on this page with the latest-update date.

Where required, we will provide additional notice or request renewed consent before using a new non-essential technology or processing personal data for a materially different purpose.

31. Contact information

For questions about this Policy, our processing of personal data, our use of cookies or the exercise of data-protection rights, contact:

GLUECKLICH OHG DES CHRISTOPH STEINER & CO.
Operating under the Alpe Piano brand
Piazza Municipio 11
39057 Appiano sulla Strada del Vino (BZ)
Italy
VAT number and tax code: IT02803430210
PEC: gluecklich@pec.bz.it
Email: we@alpepiano.com
Telephone: +39 0471 974989