Draft pending legal review

This text is a draft and has not yet been reviewed by a lawyer. Parts in [square brackets] are details to fill in or points to verify.

Privacy policy

Version of October 1, 2026

This policy explains which personal data Amber Road processes, why, and your rights, under Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003.

1. Data controller

The controller is [RAGIONE SOCIALE], registered office at [INDIRIZZO], VAT number [P.IVA]. For any privacy request write to [EMAIL PRIVACY]. Data protection officer: [DPO, SE NOMINATO].

2. What data we process

  • Account: email, password (stored only in hashed form), Google identifier if you sign in with Google, username, display name, profile picture, country, site language.
  • Shipping address: name, address and optional phone number. The seller of each of your orders sees it in order to ship; when you sell, it is used as the sender and return address.
  • Billing details: private or business, name or company name, VAT number, tax code, SDI code or PEC, billing address. Only you and staff can see them.
  • Orders: cards bought or sold, amounts, shipping method, tracking numbers, refunds and payments to sellers.
  • Payments: payment card details are processed only by Stripe. For sellers, Stripe collects identity and bank account data; Amber Road only receives the Stripe account identifier and the verification and payout status.
  • Content: listings and their photos (public), collection and collection photos (public or private, your choice), wanted cards, chat messages and offers, reviews, reports with attached photos (visible only to the parties and staff), notifications.
  • Card verification: front and back photos (with the code sheet or taken with the camera), kept in private storage visible only to you and staff; result of the automatic check and a numeric fingerprint of the card image, used to recognise photos already used by other accounts.
  • Security and moderation: IP addresses recorded at sign-up and sign-in, account status, warnings and sanctions, username change requests.
  • Technical data: technical cookies (see the Cookie policy) and technical logs of the hosting provider.

3. Purposes and legal bases

  • Providing the service (account, listings, orders, shipping, Hub, chat, reports, card verification, notifications and service emails such as sign-up confirmation and password recovery): performance of a contract (art. 6.1.b GDPR).
  • Complying with legal obligations (accounting, tax, requests from authorities): legal obligation (art. 6.1.c).
  • Security and fraud prevention (IP logging, blocking banned IPs, recognising reused photos), moderation, sanctions and legal defence: legitimate interest (art. 6.1.f).

We do not use your data for advertising, marketing or profiling. [TO VERIFY whether promotional communications are planned.]

The automatic camera check can approve a verification on its own, but never rejects it: doubtful cases go to a staff member. Sanctions after lost reports are applied automatically based on staff decisions. [TO VERIFY: assessment under art. 22 GDPR.]

4. Who we share data with

We use these providers, appointed as processors where required:

  • Supabase: database, authentication and file storage (servers in [REGIONE DEI SERVER]);
  • Vercel: hosting and running the Site;
  • Cloudflare: storage and delivery of catalog images (no user data; as with any website, your browser sends its IP address when it downloads an image);
  • Stripe: payments, seller verification and transfers (for some processing Stripe acts as an independent controller);
  • [FORNITORE EMAIL]: sending account emails (confirmation, password recovery);
  • Google, only if you choose to sign in with Google (independent controller).

Some data is visible to other users: the public profile, listings, reviews and, for each order, the buyer's name, address and optional phone number to the seller (and the seller's return address to the buyer, in case of a return). Carriers receive the shipping data through the label bought by the seller.

Data may be disclosed to authorities where required by law.

5. Transfers outside the European Union

Some providers are based in the United States. Transfers take place on the basis of the EU-US Data Privacy Framework or the European Commission's standard contractual clauses. [TO VERIFY for each provider.]

6. How long we keep data

  • Account data and content: while the account is active, then [PERIODO] after closure.
  • Orders, payments and billing details: [10 ANNI — DA VERIFICARE] for tax and accounting obligations.
  • Verification photos: [PERIODO].
  • Chat messages: [PERIODO].
  • IP addresses: while the account is active; banned IPs for 12 months from the ban.

[TO VERIFY: the Site does not currently delete this data automatically; the periods must be defined and then enforced.]

7. Your rights

You can request access to your data, rectification, erasure, restriction of processing and portability, and object to processing based on legitimate interest. Much of your data can be changed directly in Settings; for the rest write to [EMAIL PRIVACY]. We reply within one month.

You can also lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with the authority of your country.

8. Security

Passwords are stored only in hashed form, access to data is restricted by database-level rules and private photos (verification and reports) open only through temporary links. Only authorised staff can see the data needed for moderation and verification.

9. Minors

The Site is reserved for people aged at least [ETÀ MINIMA]. [TO VERIFY: handling of underage users.]

10. Changes

We may update this policy; material changes are notified to registered users.