Privacy policy

Last updated: 31 July 2026

This Privacy Policy explains how Gatitto Store collects, uses, stores, discloses and protects personal data when you visit, use or make a purchase through www.gatittostore.com, communicate with us or otherwise interact with our services.

Gatitto Store processes personal data in accordance with the General Data Protection Regulation — Regulation (EU) 2016/679, applicable national data protection laws and, where relevant, the United Kingdom GDPR and Data Protection Act 2018.

The GDPR governs how organisations process and transfer personal data relating to individuals in the European Union and European Economic Area.

Please read this Privacy Policy carefully. By using the website, you acknowledge that you have been informed about the processing activities described below.

1. Data controller

For personal data collected directly through the Gatitto Store website, the data controller is:

Gatitto Store
Website: www.gatittostore.com
Email: info@gatittostore.com

For privacy enquiries or requests to exercise your data protection rights, contact:

Email: info@gatittostore.com
Recommended subject: Privacy Request — GDPR

Where another company independently determines why and how your personal data is processed, that company may act as a separate controller. This may apply, for example, to certain payment providers, advertising platforms and Shopify services.

2. Scope of this policy

This Privacy Policy applies when you:

  • visit or browse our website;
  • create or use a customer account;
  • place or manage an order;
  • make a payment;
  • request a return, exchange or refund;
  • subscribe to marketing communications;
  • submit a product review;
  • contact Customer Support;
  • communicate with us by email, chat or forms;
  • interact with our advertising or social media content.

Where you follow a link to an independent website or complete a purchase through an external marketplace, that third party’s privacy policy will apply to its own processing activities.

3. What is personal data?

Personal data means information relating to an identified or identifiable individual.

This may include information that identifies you directly, such as your name or email address, as well as information that could identify you indirectly when combined with other data, such as an IP address, device identifier or order history.

Anonymous information that can no longer reasonably be connected to an identifiable individual is not personal data.

4. Personal data we collect

The information collected depends on how you interact with Gatitto Store.

4.1. Identity and contact information

We may collect:

  • full name;
  • billing address;
  • delivery address;
  • country and postcode;
  • email address;
  • telephone number;
  • account or customer identification details.

4.2. Account information

Where customer accounts are available, we may process:

  • login email;
  • protected password credentials;
  • saved addresses;
  • account settings;
  • communication preferences;
  • wish lists;
  • order history;
  • return and refund history.

Gatitto Store does not normally have access to your password in readable form.

4.3. Order and transaction information

We may collect:

  • products viewed;
  • products added to the basket;
  • products purchased;
  • product variants;
  • order number;
  • order value;
  • discounts;
  • shipping method;
  • transaction status;
  • returns;
  • exchanges;
  • cancellations;
  • refunds;
  • delivery and tracking information.

4.4. Payment information

Payments are normally processed by specialised third-party payment providers.

Depending on the payment method, information processed may include:

  • selected payment method;
  • transaction amount;
  • payment status;
  • transaction reference;
  • billing information;
  • partial card information, such as the last digits;
  • information required to process a refund;
  • fraud-prevention indicators.

Gatitto Store does not normally receive or store complete payment-card numbers, security codes or online-banking passwords.

Payment services may include, where enabled:

  • Shopify Payments;
  • Stripe;
  • PayPal;
  • Shop Pay;
  • Apple Pay;
  • Google Pay;
  • credit or debit card providers;
  • other payment services shown at checkout.

The inclusion of a provider in this policy does not necessarily mean that it is currently active in every country or transaction.

4.5. Customer Support communications

When you contact us, we may process:

  • your name;
  • email address;
  • telephone number;
  • order number;
  • the content of your message;
  • previous correspondence;
  • photographs or videos;
  • proof of purchase;
  • information required to resolve your enquiry.

Please do not send complete card details, account passwords or authentication codes by email, chat or social media.

4.6. Device and technical information

We may automatically collect:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • language;
  • time zone;
  • unique device or browser identifiers;
  • network information;
  • security and diagnostic data;
  • date and time of access.

4.7. Usage and browsing information

We may process information about:

  • pages visited;
  • products viewed;
  • searches;
  • links selected;
  • referring website;
  • time spent on pages;
  • basket activity;
  • checkout activity;
  • purchase events;
  • technical errors;
  • interaction with marketing messages.

This information may be collected through cookies, pixels, tags, local storage and similar technologies.

4.8. Reviews and user-generated content

Where review functions are available, we may collect:

  • display name;
  • review rating;
  • written comments;
  • photographs or videos;
  • product reviewed;
  • date of submission.

Reviews may be visible publicly. Do not include unnecessary personal information about yourself or another person in a public review.

5. How we collect personal data

We may collect personal data:

Directly from you

For example, when you:

  • place an order;
  • create an account;
  • complete a form;
  • contact Customer Support;
  • request a return;
  • subscribe to marketing;
  • submit a review.

Automatically

Through:

  • the website;
  • your browser or device;
  • cookies;
  • analytics tools;
  • pixels;
  • server logs;
  • fraud-prevention technology.

From service providers

We may receive information from providers responsible for:

  • e-commerce technology;
  • payments;
  • fraud prevention;
  • shipping;
  • tracking;
  • customer support;
  • analytics;
  • marketing;
  • cloud storage.

From business partners and third parties

Where lawful, information may also be received from:

  • logistics partners;
  • social media platforms;
  • advertising providers;
  • payment institutions;
  • marketplaces;
  • suppliers;
  • fraud-prevention databases.

6. Why we use personal data

6.1. To process and fulfil orders

We use personal data to:

  • receive and validate orders;
  • process payments;
  • confirm purchases;
  • arrange fulfilment;
  • organise shipping;
  • provide tracking;
  • communicate delivery updates;
  • process cancellations;
  • manage returns and refunds.

The principal legal basis is normally the performance of a contract or taking steps at your request before entering into a contract.

6.2. To provide customer service

We use information to:

  • respond to questions;
  • locate orders;
  • investigate delivery issues;
  • handle complaints;
  • manage warranty and conformity claims;
  • process exchanges and refunds;
  • maintain a record of communications.

Depending on the circumstances, processing may be based on contractual necessity, legal obligations or our legitimate interests in providing effective customer service.

6.3. To operate and improve the website

We may use information to:

  • maintain website functionality;
  • remember preferences;
  • diagnose technical problems;
  • improve navigation;
  • develop new features;
  • measure website performance;
  • understand customer interests;
  • improve product presentation.

Processing may be based on our legitimate interests or consent, depending on the technology and purpose involved.

6.4. To protect the website and prevent fraud

We may process data to:

  • authenticate accounts;
  • protect the checkout;
  • detect suspicious transactions;
  • investigate fraud;
  • prevent unauthorised access;
  • protect customers and third parties;
  • maintain network and information security;
  • enforce our legal terms.

This processing may be based on legitimate interests, legal obligations and, where applicable, the establishment, exercise or defence of legal claims.

6.5. To comply with legal obligations

We may use and retain personal data to:

  • maintain financial and transactional records;
  • comply with accounting and tax obligations;
  • respond to lawful requests from public authorities;
  • comply with court orders;
  • manage product-safety obligations;
  • prevent money laundering or fraud where applicable;
  • establish, exercise or defend legal claims.

6.6. Marketing and advertising

Where legally permitted, we may use personal data to:

  • send promotional emails;
  • communicate new products and offers;
  • send basket reminders;
  • measure campaign performance;
  • create advertising audiences;
  • display personalised advertising;
  • understand engagement with marketing content.

Marketing may be based on your consent or, where permitted by applicable law, our legitimate interests.

You may unsubscribe from promotional emails at any time by using the unsubscribe link or contacting info@gatittostore.com.

Even after unsubscribing, you may continue to receive non-promotional messages concerning orders, payments, returns, security or Customer Support.

7. Legal grounds for processing

Depending on the purpose, we may rely on:

  • performance of a contract, including processing and delivering an order;
  • steps taken before entering into a contract, such as responding to a product enquiry;
  • compliance with a legal obligation, including tax and accounting duties;
  • legitimate interests, provided those interests are not overridden by your rights;
  • consent, particularly for certain marketing activities and non-essential cookies;
  • establishment, exercise or defence of legal claims;
  • other lawful grounds recognised under applicable data protection law.

Consent is not used as a blanket legal basis for all processing.

For example, we do not need marketing consent to use your delivery address for an order that you asked us to fulfil.

8. Legitimate interests

Where we rely on legitimate interests, those interests may include:

  • operating and improving our store;
  • preventing fraud;
  • securing accounts and transactions;
  • understanding website performance;
  • providing Customer Support;
  • maintaining business records;
  • protecting our legal rights;
  • preventing misuse of the website.

Before relying on legitimate interests, we consider:

  • the purpose of the processing;
  • whether the processing is necessary;
  • the reasonable expectations of the individual;
  • the possible impact on privacy;
  • appropriate safeguards;
  • whether the individual’s rights override our interests.

You may object to processing based on legitimate interests in the circumstances described in Section 23.

9. Marketing communications

We may send marketing communications where:

  • you have provided consent;
  • you requested such communications;
  • another lawful basis permits the communication under applicable law.

Marketing messages may contain information about:

  • promotions;
  • product launches;
  • discounts;
  • recommendations;
  • abandoned baskets;
  • special campaigns.

You can withdraw marketing consent or unsubscribe at any time.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

10. Cookies and similar technologies

We use cookies and similar technologies to:

  • operate the website;
  • maintain the basket;
  • authenticate users;
  • remember preferences;
  • secure the checkout;
  • prevent fraud;
  • analyse website use;
  • measure advertising;
  • personalise content and marketing.

Strictly necessary cookies may operate without consent where they are required to provide a service requested by the user.

Analytics, personalisation and advertising cookies will be used in accordance with the choices presented through our cookie banner or preference panel.

For further information, consult the Gatitto Store Cookie Policy.

Shopify provides privacy tools that allow merchants to configure privacy policies, cookie banners and data-sharing controls, but using Shopify does not, by itself, guarantee compliance with the GDPR.

11. Data collected through chat and contact forms

The website may provide chat, email forms or other communication tools.

Information submitted through these tools will be used to:

  • respond to the enquiry;
  • provide requested support;
  • identify the relevant order;
  • resolve a complaint;
  • maintain appropriate support records;
  • protect against fraud or misuse.

Information submitted for Customer Support will not automatically be used for unrelated marketing purposes without an appropriate legal basis.

Chat and form providers may process technical and communication information on our behalf or for their own independently stated purposes.

12. How we share personal data

We do not disclose personal data indiscriminately.

We may share information with service providers and other recipients where necessary and lawful.

12.1. Shopify

Our website is hosted and operated using Shopify technology.

Shopify may process information to:

  • host the store;
  • provide checkout functions;
  • maintain infrastructure;
  • secure accounts;
  • prevent fraud;
  • provide technical support;
  • improve Shopify services;
  • support certain analytics and personalisation features.

Depending on the activity, Shopify may act as:

  • a processor acting on our instructions; or
  • an independent controller for its own specified purposes.

Shopify explains that, where it processes data on behalf of a merchant, customers may be directed to submit privacy requests to that merchant.

12.2. Payment providers

We may share information with:

  • banks;
  • card networks;
  • payment gateways;
  • payment processors;
  • digital-wallet providers;
  • fraud-prevention services.

This may be necessary to:

  • authorise payment;
  • authenticate a transaction;
  • prevent fraud;
  • process refunds;
  • manage payment disputes.

12.3. Suppliers and logistics providers

Where necessary to fulfil an order, we may share information with:

  • product suppliers;
  • manufacturers;
  • fulfilment centres;
  • warehouses;
  • postal operators;
  • couriers;
  • customs agents;
  • tracking providers.

Information may include:

  • customer name;
  • delivery address;
  • telephone number;
  • email address where required;
  • product and order details;
  • delivery instructions;
  • customs information where legally necessary.

12.4. Technology and professional providers

We may use providers responsible for:

  • website hosting;
  • cloud storage;
  • email delivery;
  • customer service;
  • security;
  • fraud prevention;
  • analytics;
  • accounting;
  • legal advice;
  • technical support;
  • consent management.

12.5. Advertising and analytics partners

Where the appropriate legal basis exists, identifiers and activity information may be processed by:

  • Google;
  • Meta, including Facebook and Instagram;
  • TikTok;
  • Pinterest;
  • email-marketing services;
  • advertising measurement providers;
  • other marketing platforms.

The providers actually used depend on the applications and integrations enabled on the website.

12.6. Public authorities and legal recipients

We may disclose information where necessary to:

  • comply with law;
  • respond to a valid court order;
  • respond to a competent authority;
  • investigate fraud;
  • protect legal rights;
  • prevent serious harm;
  • establish, exercise or defend legal claims.

12.7. Business transactions

Personal data may be disclosed in connection with:

  • a merger;
  • acquisition;
  • reorganisation;
  • financing;
  • insolvency;
  • sale of assets or business operations.

Any recipient will be required to process the data in accordance with applicable law.

13. Shopify Network Intelligence and enhanced services

Shopify may offer services that use information from interactions across Shopify merchants to provide enhanced functions, fraud prevention, analytics or personalised services.

Where such features are enabled, Shopify may process certain personal data for its own specified purposes.

Relevant privacy choices and information may be available through Shopify’s privacy portal. Shopify also requires merchants using certain enhanced services to provide appropriate disclosures and links to available privacy controls.

Shopify privacy information and controls are available through its official privacy portal.

14. International transfers

Gatitto Store uses Shopify and other providers that may process personal data outside the country in which you live.

This may include transfers outside:

  • the European Economic Area;
  • the European Union;
  • the United Kingdom;
  • Switzerland.

Where personal data is transferred internationally, we will rely on an appropriate transfer mechanism, such as:

  • a European Commission adequacy decision;
  • Standard Contractual Clauses;
  • the UK International Data Transfer Agreement or UK Addendum;
  • binding corporate rules;
  • another legally recognised safeguard;
  • a permitted GDPR derogation in limited circumstances.

The GDPR requires international transfers to comply with its conditions, and the European Commission’s Standard Contractual Clauses may be used to provide appropriate safeguards for transfers to third countries.

Where required, supplementary technical, organisational or contractual measures may also be applied.

You may contact us for further information about the transfer safeguards relevant to your personal data.

15. Data retention

We retain personal data only for as long as reasonably necessary for the purposes described in this policy.

Retention periods depend on:

  • the type of information;
  • the purpose of processing;
  • the duration of the customer relationship;
  • tax and accounting obligations;
  • product guarantee periods;
  • fraud-prevention needs;
  • limitation periods for legal claims;
  • pending complaints or disputes;
  • legal retention requirements.

For example, order and transaction records may need to be retained after an account is closed in order to comply with tax, accounting and consumer-protection obligations.

When information is no longer required, it will be:

  • deleted;
  • anonymised;
  • securely isolated until deletion is possible; or
  • retained only where legally permitted or required.

16. Data security

We seek to use appropriate technical and organisational measures to protect personal data, including, where applicable:

  • encrypted connections;
  • access controls;
  • authentication;
  • restricted permissions;
  • fraud-prevention tools;
  • system monitoring;
  • secure payment processing;
  • backups;
  • supplier due diligence;
  • incident-response procedures.

No system or method of transmission is completely secure. Therefore, we cannot guarantee absolute security.

You are responsible for:

  • protecting your password;
  • not sharing authentication codes;
  • using secure devices and networks;
  • informing us promptly of suspected unauthorised account use.

17. Personal data breaches

If a personal data breach occurs, we will assess:

  • the nature of the incident;
  • the categories of data involved;
  • the number of individuals affected;
  • the likely consequences;
  • the risk to individuals;
  • available containment and mitigation measures.

Where required by applicable law, we will notify:

  • the competent supervisory authority; and
  • affected individuals where the breach is likely to result in a high risk to their rights and freedoms.

18. Children’s privacy

The Gatitto Store website is not specifically directed at children.

We do not knowingly collect personal data directly from children for marketing or account purposes without an appropriate legal basis and, where required, valid parental or guardian authorisation.

If you believe that a child has provided personal data improperly, contact info@gatittostore.com so that we can investigate and take appropriate action.

Age thresholds and parental-consent requirements may vary according to the law of the country in which the child lives.

19. Third-party websites

Our website may contain links to independent websites, social networks or applications.

Where you access an external service, that third party may collect information according to its own:

  • privacy policy;
  • cookie policy;
  • terms of use;
  • security practices.

Gatitto Store is not responsible for the independent privacy practices of third-party websites that it does not control.

We recommend reviewing the applicable privacy information before submitting personal data to an external service.

20. Embedded content

Pages may contain embedded content such as:

  • videos;
  • images;
  • maps;
  • reviews;
  • social-media posts;
  • payment widgets;
  • external tools.

Embedded content may operate as though you had visited the external provider directly.

The provider may:

  • receive your IP address;
  • place cookies;
  • collect device information;
  • measure interaction with the embedded content;
  • associate activity with an existing user account.

Non-essential embedded content should be managed in accordance with the consent choices available on the website.

21. Automated decision-making

Some payment and fraud-prevention providers may use automated systems to assess transactions.

These systems may consider:

  • order value;
  • payment information;
  • device information;
  • account history;
  • address consistency;
  • transaction patterns;
  • fraud indicators.

A transaction may be:

  • approved;
  • refused;
  • held for review;
  • subjected to additional verification.

Where a decision is based solely on automated processing and produces legal or similarly significant effects, you may have the right to:

  • request human intervention;
  • express your point of view;
  • contest the decision;
  • request meaningful information about the logic involved, subject to applicable limitations.

22. Your data protection rights

Depending on the circumstances, you may have the following rights:

Right to be informed

You have the right to receive clear information about how your personal data is processed.

Right of access

You may request confirmation that we process your personal data and obtain a copy of that information.

Right to rectification

You may request correction of inaccurate or incomplete data.

Right to erasure

You may request deletion of personal data in circumstances recognised by law.

This right is not absolute. Information may need to be retained to comply with legal obligations, fulfil existing contracts or establish, exercise or defend legal claims.

Right to restriction

You may request that processing be restricted in certain circumstances.

Right to data portability

Where processing is based on consent or contract and carried out by automated means, you may request your data in a structured, commonly used and machine-readable format.

Right to object

You may object to processing based on legitimate interests.

We will stop the processing unless we demonstrate compelling legitimate grounds that override your rights or the processing is required for legal claims.

Right to object to direct marketing

You may object to direct marketing at any time.

Where you object, your personal data will no longer be processed for that marketing purpose.

Right to withdraw consent

Where processing is based on consent, you may withdraw it at any time.

Withdrawal does not affect the lawfulness of processing completed before withdrawal.

Rights concerning automated decisions

Where applicable, you may request human review of a decision based solely on automated processing that produces legal or similarly significant effects.

The European Commission and European Data Protection Board recognise rights including information, access, correction, erasure, restriction, objection and portability under the GDPR.

23. Exercising your rights

To exercise a privacy right, contact:

Email: info@gatittostore.com
Recommended subject: Privacy Request — GDPR

Please provide:

  • your full name;
  • the email address used with Gatitto Store;
  • the right you wish to exercise;
  • a clear description of your request;
  • the order number, where relevant.

We may request information necessary to verify your identity and protect your data from unauthorised access.

We will not request more information than is reasonably necessary for verification.

24. Response time

We will respond to valid requests without undue delay and normally within one month of receipt.

Where a request is complex or involves multiple requests, the response period may be extended where permitted by law. If an extension is required, we will inform you of the reason and expected response time.

Requests are normally handled free of charge.

A reasonable fee may be charged, or a request may be refused, where it is manifestly unfounded or excessive, particularly because of repeated requests, as permitted by applicable law.

25. Authorised representatives

You may appoint an authorised person to submit a request on your behalf.

We may require:

  • proof of your identity;
  • proof of the representative’s identity;
  • written authorisation;
  • confirmation directly from you.

These measures are used to protect personal data from unauthorised disclosure.

26. Complaints to a supervisory authority

You have the right to lodge a complaint with a competent data protection supervisory authority, particularly in:

  • the EU or EEA Member State where you normally live;
  • the country where you work;
  • the country where you believe a data protection infringement occurred.

You may contact us first so that we have an opportunity to investigate, but you are not required to do so before approaching a supervisory authority.

27. United Kingdom customers

Where the UK GDPR applies, individuals may exercise equivalent rights concerning:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability;
  • automated decision-making;
  • withdrawal of consent.

UK customers may also lodge a complaint with the UK Information Commissioner’s Office.

International transfers from the United Kingdom will be handled using a legally recognised UK transfer mechanism where required.

28. European representatives and data protection officers

Where the GDPR requires Gatitto Store to appoint an EU representative or a Data Protection Officer, the relevant contact details will be made available in this policy or through the website.

The absence of a formally appointed Data Protection Officer does not prevent you from exercising your rights through:

info@gatittostore.com

29. Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

  • changes in law;
  • regulatory guidance;
  • new services or website features;
  • changes to payment methods;
  • new suppliers or processors;
  • changes to Shopify services;
  • changes to marketing or analytics tools;
  • operational or security changes.

The revised version will be published on this page with an updated date.

Where required, we will provide an additional notice or request renewed consent.

30. Contact us

For questions concerning this Privacy Policy, our processing activities or your data protection rights, contact:

Gatitto Store
Website: www.gatittostore.com
Email: info@gatittostore.com

Recommended subject: Privacy Request — GDPR