Privacy and Legal
Welcome to midsummer-milano.com (“Website”). This Privacy Policy explains how Midsummer Milano (“we”, “us”) collects, uses, shares, and protects your personal data when you browse our Website or purchase our products—regardless of whether you complete a transaction. We comply with the EU General Data Protection Regulation (GDPR) and applicable Italian laws.
1) Data Controller
Controller: Midsummer Milano
Email: info@midsummer-milano.com
Postal address (optional): Via Andegari, 4, 20121 Milano (MI) Italy
2) Personal Data We Collect
Device Information collected automatically when you visit the Website: IP address, browser, time zone, pages viewed, referring URLs, and interaction data.
Order Information when you purchase or attempt to purchase: name, billing and shipping address, email, phone, and payment details (processed securely by our payment providers).
3) Cookies & Tracking
We use cookies, log files, and similar technologies (web beacons/tags/pixels) to operate the site, remember choices, analyze performance, and support marketing. You can disable cookies in your browser. For general information see allaboutcookies.org. See also our Cookie Policy (if available).
4) How We Use Personal Data
- To process and fulfill orders (payments, shipping, confirmations, invoices).
- To communicate with you about orders, support, or service updates.
- To prevent fraud and ensure site security (including IP checks).
- To improve the Website and measure the effectiveness of campaigns (analytics).
- With your consent or where permitted, to send product news and tailored offers.
5) Legal Bases (GDPR)
We process personal data under one or more of these legal bases:
- Contract (Art. 6(1)(b)): to fulfill purchases and provide requested services.
- Legitimate interests (Art. 6(1)(f)): site security, fraud prevention, analytics, service improvement, and limited marketing to existing customers.
- Consent (Art. 6(1)(a)): optional email marketing and certain cookies. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): tax/accounting, regulatory or court requests.
6) Sharing & Processors
We share data with trusted service providers (“processors”) strictly to deliver our services:
- Shopify (store platform). Privacy: shopify.com/legal/privacy.
- Payment providers (e.g., Shopify Payments, PayPal, American Express) for secure transactions.
- Analytics: Google Analytics. Privacy: google.com/policies/privacy | Opt-out: GA Opt-out.
We may also disclose information if required by law, regulation, or a valid legal request, or to protect our rights.
7) International Transfers
Some providers may process data outside the EEA (e.g., Canada/USA). When we transfer data internationally, we rely on lawful safeguards such as adequacy decisions or Standard Contractual Clauses.
8) Data Retention
We retain Order Information as long as necessary for contract performance and legal obligations (e.g., tax), then securely delete or anonymize it. You can request deletion earlier where legally permitted.
9) Your Rights
If you are in the EEA/UK (and, where applicable, elsewhere), you may request:
- access, rectification, or erasure of your personal data;
- restriction or objection to processing;
- data portability;
- withdrawal of consent (where processing is based on consent);
- to lodge a complaint with a supervisory authority (in Italy: the Garante per la Protezione dei Dati Personali).
To exercise your rights, contact info@midsummer-milano.com.
10) Security
We implement appropriate technical and organizational measures to protect personal data. No online transmission is 100% secure, but we strive to safeguard your information.
11) Children’s Data
Our Website is not intended for children under 16. We do not knowingly collect data from children. If you believe a child provided data, please contact us to delete it.
12) Do Not Track
Our Website currently does not respond to Do Not Track browser signals. You can control cookies via your browser settings and the tools linked above.
13) Changes to this Policy
We may update this Policy to reflect operational, legal, or regulatory changes. The latest version applies from the “Last updated” date below.
14) Contact
Questions or requests about privacy: info@midsummer-milano.com.
15) Applicable Law
This Policy is governed by EU GDPR and Italian law, including the Italian Data Protection Code (Legislative Decree 196/2003, as amended).
Last updated: 29 January 2026