Free Worldwide Shipping on all orders

Privacy Policy

A – Types of Data Processed

I. Identification Data

When you browse or shop on this website, we may collect personal data that can directly or indirectly identify you, including:

  • Name
  • Residential or shipping address
  • Email address
  • Phone number
  • IP address
  • Any other identification data voluntarily provided

This website does not collect sensitive data under Article 9 of the GDPR (racial or ethnic origin, political opinions, religious beliefs, genetic data, biometric data, etc.) unless explicitly consented to and required for specific information in exceptional circumstances.

II. Banking Details

During the purchase process, data related to the payment instrument used (e.g., credit card number or PayPal account details) is processed through secure payment gateways, limited to information necessary to manage the transaction.

This website does not directly store any sensitive payment data.

III. Browsing Data

The computer systems and software programs used to operate this website acquire some personal data during their normal operation, the transmission of which is inherent in the use of Internet communication protocols.

These data include:

  • IP address
  • Type of browser used
  • URI of requested resources
  • Time and method of request
  • Server response status
  • Parameters related to the user's IT environment

This data is processed in aggregated and anonymous form solely to obtain statistical information on website usage and ensure its proper functioning. However, in the event of computer crimes, this data may be used to determine liability.

IV. Data Voluntarily Provided by Users

If users voluntarily send information via contact forms or make purchases, the website collects the data provided to:

  • Manage requests and orders
  • Provide assistance
  • Comply with legal and tax obligations

This data is provided entirely autonomously by the user, who assumes responsibility for any third-party data or copyrighted content inserted.

V. Data Collected via Cookies

This website uses technical and analytical cookies to improve the navigation experience and collect statistical data. For specific details, please refer to the Cookie Policy on this website, which also explains how to manage or disable cookies through browser settings.

B – Purpose of Processing

Personal data collected by this website is processed by the Data Controller for the following purposes:

  • Order management and shipment of purchased products, including related logistics and administrative activities;
  • Processing anonymous statistical data on website usage to improve structure, content, and services;
  • Verifying the proper technical functioning of the website and its services;
  • Sending informational, promotional communications, and newsletters via email or other digital channels, subject to explicit user consent;
  • Determining liability for computer crimes or illegal activities against this website;
  • Fulfilling legal obligations, regulations, or community legislation.

Disclosure of collected data can only occur upon request by judicial authorities, within the limits and in the manner prescribed by law.

C – Legal Basis for Processing

The Data Controller processes personal data in accordance with the principles of lawfulness, fairness, transparency, relevance, and necessity as set out in Article 5(1) of the GDPR.

I. Performance of Contract

The primary legal basis for processing is the execution of product purchase contracts on the website and related pre-contractual activities. This also includes fulfilling obligations arising from subscription terms and conditions, and pursuing the Data Controller's legitimate interest in ensuring service efficiency.

II. Consent of Interested Parties

Certain data processing is based on the user's free, explicit, informed, and unambiguous consent. Examples include:

  • Voluntarily sending information via email or contact forms;
  • Subscribing to newsletters;
  • Using data for promotional purposes.

In these cases, consent can be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.

III. Compliance with Legal Obligations

Processing may occur without consent when necessary to fulfill legal obligations (e.g., tax or accounting) or respond to judicial authority requests.

IV. Optionality of Data Provision

Except for:

  • Data required for contract performance;
  • Legal obligations;
  • Technical and navigation cookies;

Providing personal data is optional. However, refusal to provide such data may result in the inability to provide requested services, such as processing orders or responding to requests.

D – Processing Methods and Duration

Personal data is processed using IT and telematic tools in full compliance with Regulation (EU) 2016/679 and Decree 196/2003 (as amended by Decree 101/2018). Processing follows principles of lawfulness, fairness, transparency, and minimization, limited to the time necessary to achieve the purposes stated in this policy.

Retention Period

Data will be stored:

  • For the time necessary to provide requested services and perform administrative management of orders;
  • Or until explicitly requested for cancellation by the relevant party;
  • Subject to legal limits and fiscal/civil obligations.

Security and Authorization

The Data Controller adopts appropriate technical and organizational measures to safeguard data against:

  • Accidental loss;
  • Unauthorized access;
  • Misuse or alteration of personal information.

Data can only be processed by authorized parties, including:

  • Internal collaborators, employees, or consultants of the Data Controller (e.g., commercial, logistics, legal departments);
  • External service providers (e.g., hosting providers, IT companies, payment and shipping service providers);
  • Public entities within legal limits for regulatory compliance.

Data will not be disclosed or transferred to unspecified recipients.

Breaches and Notification

While advanced security measures are in place, no system is immune to cyber attacks. In the event of a data breach, users and competent authorities will be notified in accordance with Articles 33 and 34 of the GDPR.

E – Place of Processing

Processing operations related to services on this website are carried out at the Data Controller's operating offices by formally authorized and trained personnel.

External parties may also be utilized, including collaborators, consultants, technology/logistics providers, and selected business partners. Upon appointment as Data Processors, they operate under GDPR regulatory obligations and security measures.

Data is not disclosed to third parties without explicit consent, unless necessary for legal compliance or essential for protecting rights and website operation.

Servers and Storage

Personal data is stored on servers managed by qualified providers with high security standards. These servers may be located in third countries outside the EU deemed to have an adequate level of data protection by the European Commission.

Any data transfer outside the EU will comply with personal data protection regulations, ensuring adequate security, confidentiality, and integrity.

F – Rights of Interested Parties

Under Regulation (EU) 2016/679, interested parties have the right to exercise the following at any time:

  • Access (Art. 15 GDPR): Confirm if personal data is being processed and receive a copy.
  • Rectification (Art. 16 GDPR): Correct inaccurate or incomplete data.
  • Restriction (Art. 18 GDPR): Limit processing under legal conditions.
  • Erasure (Art. 17 GDPR): Request deletion of illegally processed or no longer necessary data.
  • Objection (Art. 21 GDPR): Object to processing for legitimate reasons, including direct marketing.
  • Withdrawal of Consent (Art. 7 GDPR): Withdraw consent at any time without affecting prior lawfulness.
  • Data Portability (Art. 20 GDPR): Receive data in a structured, machine-readable format.

Exercising Rights

The Data Controller commits to responding within 30 days of receiving a request.

If rights are not adequately protected, complaints can be lodged with the Italian Data Protection Authority (www.garanteprivacy.it) or legal action taken under Art. 77 GDPR.

G – Updates

This policy may change due to regulatory updates or service changes. The latest version is always available at www.auroraveilbags.com. Significant changes will be notified via the website.

Cookie Policy

What are cookies?

Cookies are small text files stored on your device by your browser when you visit a website. They allow the collection of anonymous information for technical, analytical, or marketing purposes.

Cookies are categorized by:

  • Origin: First-party (installed by the site) or Third-party (installed by external parties like analytics or social networks).
  • Purpose: Technical, Analytical, Profiling.

Types of Cookies Used

I. Technical Cookies

Essential for website operation and navigation. Includes session cookies (deleted on browser close) and persistent cookies (store preferences). Consent is not required, but disabling them may limit functionality.

II. Analytical Cookies

Used to collect anonymous statistical data. Third-party cookies include Google Analytics, BugSnag, Akamai. Can be disabled via browser settings.

III. Social Plugin & Profiling Cookies

May use social network cookies (Facebook, Instagram, etc.) and third-party profiling cookies (Google Ads, Meta Ads) for personalized advertising.

Privacy Policies of Third Parties:

Facebook Pixel

We use Facebook Pixel for statistical analysis and remarketing without personally identifying users. You can revoke consent for Pixel usage here: Facebook Ads Settings.

Klarna

To offer Klarna payment methods, we may pass personal data (contact/order details) to Klarna at checkout for eligibility assessment. Processed per Klarna Privacy Policy.

Mobile Terms of Service

The Aurora Veil mobile message service (the "Service") is operated by Aurora Veil. Your use of the Service constitutes your agreement to these terms and conditions.

Subscription

By subscribing, you agree to receive recurring automated promotional and personalized marketing text messages (e.g., cart reminders) from Aurora Veil at the cell number used when signing up. Consent is not a condition of any purchase.

Cost and Frequency

Message and data rates may apply. Message frequency varies. Check with your mobile provider for details.

Cancellation

Text the single keyword command STOP to cancel at any time. You'll receive a one-time opt-out confirmation text.

Privacy Protection

Aurora Veil is committed to protecting your privacy. For full details on how we process your personal data, please refer to our Privacy Policy above.

If you don't find the style you like, please contact us and we will prepare it for you.