Privacy Policy
Last updated: August 8, 2026
This Privacy Policy describes how Il mondo di Wit di Andreas Cattelan collects, uses, stores and protects the personal data of users who visit ilmondodiwit.com, make purchases, use a customer account, subscribe to the newsletter, publish reviews, contact us or otherwise interact with the services available on the website.
Personal data is processed in accordance with Regulation (EU) 2016/679 (“GDPR”), Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018, and other applicable provisions concerning personal data protection and electronic communications.
1. Data Controller
The Data Controller is:
Il mondo di Wit di Andreas Cattelan
Sole proprietorship
Via Zara 5
57033 Marciana Marina (LI)
Italy
VAT number: 01002090452
Email: info@ilmondodiwit.com
Email for privacy-related requests: admin@ilmondodiwit.com
Telephone: +39 334 944 2589
Users may also use the tools available in the Privacy section permanently accessible in the website footer to manage cookie preferences and, where available, submit requests concerning their personal data.
2. Personal data we process
Depending on how the user interacts with the website, we may process different categories of personal data.
Identification and contact data
We may process first name, last name, email address, telephone number, shipping address, billing address and any tax information required.
Order and purchase data
We may process information such as products purchased, quantities, amounts, order number and date, payment method, shipping information, returns, refunds and communications relating to the purchase.
Payment data
When an online payment is made, the data required to carry out the transaction is also processed by the payment service provider selected by the customer.
The Data Controller may receive information concerning the outcome of the transaction, the payment method used, the amount and any refunds.
Full payment card details are normally entered directly into the payment providers’ systems and are not made available to the Data Controller in their complete form.
Customer account data
Where customer account functions are used, we may process identification and contact data, saved addresses, order history, preferences and information required to manage the account.
Customer communications
When the user contacts us by email, telephone, WhatsApp, chat, website forms or other channels, we may process the contact details and the content of the communication.
Review data
When a user posts a review or a question relating to a product, we may process the displayed name, email address, rating, title, content of the review or question, and any photographs or videos voluntarily uploaded.
Newsletter and marketing data
We may process email address, where provided the user’s name, marketing preferences, date and method of subscription, information required to document consent, and information concerning interactions with commercial communications, within the limits permitted by law.
Technical and browsing data
When the website is used, data such as IP address, browser type, device, operating system, language, date and time of visit, pages viewed, referring URL, online identifiers, information concerning interactions with the website, cookies and similar technologies may be collected automatically.
3. Purposes and legal bases of processing
Order management and contractual relationship
Data is processed to receive and confirm orders, process payments, prepare products, arrange shipping, communicate with the customer, manage returns and refunds, and provide after-sales support.
Legal basis: performance of a contract or steps taken at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) GDPR.
Administrative, accounting, tax and legal obligations
Data is processed to comply with obligations arising from tax, accounting, commercial and other applicable laws.
Legal basis: compliance with a legal obligation pursuant to Article 6(1)(c) GDPR.
Customer support and information requests
Data is used to respond to questions, information requests, complaints and support requests.
The legal basis is performance of a contract or pre-contractual measures where the request concerns a purchase and, in other cases, the Data Controller’s legitimate interest in responding to requests and properly managing relations with users and customers.
Security, abuse prevention and fraud prevention
We may process technical data and order-related information to protect the website and prevent unauthorised access, fraud, spam, abusive automated activity and other unlawful use.
Legal basis: legitimate interest of the Data Controller pursuant to Article 6(1)(f) GDPR and any applicable legal obligations.
Newsletter and commercial communications
The sending of newsletters, offers, news, promotions and other electronic marketing communications is generally based on the user’s consent.
Legal basis: consent pursuant to Article 6(1)(a) GDPR and applicable electronic communications legislation.
Consent is optional and may be withdrawn at any time using the unsubscribe link contained in communications or by contacting the Data Controller.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Communications to existing customers – similar products
Where permitted by Article 130(4) of Italian Legislative Decree 196/2003, the email address provided by a customer in connection with a purchase may be used to offer our own products or services similar to those previously purchased.
The customer may object to such use free of charge at any time.
Analytics, statistics and website improvement
Analytics tools may be used to understand how the website is used, measure its performance, identify issues and improve products, content and services.
Where such tools involve access to information stored on the user’s device or non-essential tracking, they are used only with consent where required by law.
Advertising, measurement and profiling
Subject to user consent, cookies, pixels, tags and similar technologies may be used to measure advertising campaigns, attribute conversions, perform remarketing, create audience segments, analyse interactions with ads and content or display more relevant advertising.
Refusing consent does not prevent purchases or use of the website’s essential functions.
4. Cookies and similar technologies
The website uses cookies and other technologies that store or access information on the user’s device.
Strictly necessary cookies and technologies
These may be used without consent where necessary for website functionality, security, shopping cart, checkout, customer accounts, session management and storage of privacy preferences.
Analytics, marketing and other non-essential technologies
Non-essential technologies are used in accordance with the preferences expressed by the user and, where required by law, only after consent has been provided.
On the first visit, users may accept, reject or customise the use of non-essential categories.
Changing and withdrawing preferences
Choices made through the banner can be changed later.
At any time, users may use the “Cookies - preferences” or “Privacy Preferences” links in the website footer to reopen the consent management panel.
Through this panel, users may review processing categories, view information concerning detected cookies and tracking tools, modify their preferences or withdraw previously given consent.
Updated cookie list
To prevent a static list from becoming incomplete or outdated, the individual cookies and tracking tools used by the website, together with their categories, purposes and durations, are displayed directly in the privacy preferences panel.
This panel constitutes the updated detailed information concerning the cookies and tracking technologies actually used.
5. Consent management and third-party services
The website uses a third-party consent management platform specifically integrated with Shopify.
The preferences expressed by the user are communicated to compatible systems used by the website so that non-essential technologies are managed according to the user’s choices.
The integration includes the Shopify Customer Privacy API and, for compatible Google services, management of consent signals through Google Consent Mode.
Preferences may subsequently be changed or withdrawn using the tools available in the website footer.
6. Shopify
The online store is hosted and managed using the Shopify platform.
Shopify provides the technological infrastructure required to operate the ecommerce store and may process personal data when a user visits the website, uses checkout, creates or uses a customer account, makes a purchase or uses Shopify services connected to the store.
Depending on the specific activity, Shopify may act as a data processor on behalf of the Data Controller or process certain data as an independent data controller within the scope of its own services.
Information processed by Shopify may include identification and contact data, device and browsing information, order and transaction data, products viewed or purchased, privacy preferences and information concerning interactions with the store and Shopify services.
For more information:
Shopify Consumer Privacy Policy.
7. Shopify Network Intelligence and Advanced Services
Shopify Network Intelligence is enabled for this store.
When this feature is enabled, Shopify may securely use data from customers’ interactions with this store together with data from interactions with Shopify and other Shopify merchants to power features Shopify refers to as Advanced Services.
These services may be used, among other things, to:
- provide more personalised experiences;
- improve products, services and store performance;
- understand how users interact with the store and advertising campaigns;
- improve security and fraud prevention;
- make certain communications or advertisements more relevant where the user has provided the required consent.
Within the scope of these services, information concerning the user’s activity on our store may be disclosed to Shopify and other providers involved in providing the services, including in countries other than the user’s country.
For users subject to the laws of the EEA, United Kingdom or Switzerland, non-essential activities requiring consent, including certain forms of personalisation or advertising based on activity with this store, other merchants or Shopify, are subject to the preferences expressed through the consent management system.
The third-party banner used by the website is integrated with the Shopify Customer Privacy API.
Where a user does not consent to non-essential technologies, the relevant preferences are communicated to Shopify and device data originating from the website is handled by Shopify Network Intelligence in accordance with those choices for non-essential purposes.
Where a request for deletion of personal data relating to the store is accepted, Shopify also provides mechanisms to propagate deletion to affected data held within Shopify Network Intelligence, where applicable.
Shopify also provides its own Privacy Portal through which users may exercise applicable rights directly against Shopify.
Shopify Consumer Privacy Policy
Shopify Privacy Portal
8. Payments
During checkout, various payment methods may be made available through Shopify and/or external payment service providers.
The payment methods actually available may vary depending on the country, device, amount, currency and current store configuration.
These may include, among others, Shopify Payments and related managed payment methods, credit or debit cards, PayPal, Shop Pay, Amazon Pay, Apple Pay, Google Pay, Satispay and other methods displayed during checkout.
The selected payment provider receives the data necessary to authorise, execute and secure the transaction and to comply with its own legal obligations.
Certain payment providers act as independent data controllers for activities falling within their responsibilities. In such cases, their own privacy policies also apply.
The Data Controller does not normally store the full payment card number.
9. Shipping, couriers and logistics providers
To deliver orders, the personal data strictly necessary may be disclosed to couriers, postal operators, logistics companies and platforms used to organise shipments.
This data may include the recipient’s first and last name, delivery address, telephone number, email address and other information required for the proper management of the shipment.
Depending on the destination and service selected, providers may include Poste Italiane, SDA, BRT, UPS and other carriers used for specific shipments.
Packlink
For certain shipments, Packlink, operated by Auctane S.L.U., may be used as an intermediary platform to compare, purchase and manage shipping services.
Where Packlink is used, the data required for shipment may be transmitted to the platform and, through it, to the carrier responsible for delivery.
Packlink Privacy and Cookie Policy
SpedirePro by Alsendo
For certain shipments, SpedirePro by Alsendo may be used to organise and manage transport services.
Where this service is used, the data required for shipment may be transmitted to the platform and to the carrier actually responsible for delivery.
SpedirePro Privacy Policy
International shipments
For shipments to countries outside the European Union, certain data may also be disclosed where necessary to logistics providers, customs intermediaries, customs authorities or other public authorities.
Legal basis: performance of a contract and, where applicable, compliance with legal obligations.
10. Reviews – Judge.me
The website uses Judge.me to collect, manage, verify and publish reviews and questions relating to products and the shopping experience.
When a user submits a review, the following information may be processed depending on the information provided:
- name or displayed name;
- email address;
- rating;
- review title;
- review text;
- any photographs or videos uploaded;
- information necessary to verify that the review is linked to a purchase;
- technical data required for the functioning and security of the service.
The displayed name, rating, review text and any multimedia content may be published on the website.
The email address is not normally displayed publicly as part of the review.
Judge.me Privacy Policy
11. hCaptcha
Certain forms or functions on the website may be protected by hCaptcha, a service provided by Intuition Machines, Inc.
hCaptcha is used to verify that certain actions are performed by real people and to protect the website against spam, bots, fraud and other abusive activity.
For this purpose, technical data and information concerning interactions with the website may be analysed, including IP address, device, browser, duration of the visit, movements or other technical information required for security assessment.
Legal basis: the legitimate interest of the Data Controller in website security, fraud prevention and protection against abusive automated activity, pursuant to Article 6(1)(f) GDPR.
hCaptcha Privacy Policy
12. Newsletter
Users may voluntarily subscribe to the website newsletter.
The data is used to send information about products, news, promotions, initiatives and other commercial communications in accordance with the preferences expressed.
Subscription is optional and is not required in order to make purchases.
Each commercial email contains a mechanism that allows the user to unsubscribe.
Consent may also be withdrawn by contacting the Data Controller.
13. Analytics and advertising services
Subject to consent where required, the website may use analytics, measurement and advertising services provided by third parties.
The providers actually used and the associated tracking technologies are listed in the Cookies - preferences panel.
These tools may process device information, IP address, online identifiers, pages and products viewed, actions performed on the website, purchases and interactions with advertising campaigns.
The use of non-essential tools is subject to the preferences expressed by the user.
For compatible Google services, consent signals are also managed through Google Consent Mode.
14. WhatsApp, social networks and external services
When the user voluntarily chooses to contact us through WhatsApp, social networks or other messaging services, the information required for the communication is also processed by the relevant service provider in accordance with its own privacy policy.
The Data Controller uses the information received to respond to requests, provide assistance and, where necessary, manage the contractual relationship with the customer.
The website may also contain links to third-party websites or services.
When a user chooses to access such external services, the relevant provider’s privacy policy also applies.
15. Recipients of personal data
Personal data may be disclosed, within the limits necessary for their respective functions, to categories of recipients such as:
- Shopify and its providers;
- payment service providers and financial institutions;
- couriers and logistics operators;
- Packlink;
- SpedirePro by Alsendo;
- Judge.me;
- hCaptcha;
- IT, hosting and security service providers;
- email and newsletter service providers;
- analytics and advertising service providers, subject to consent where required;
- accountants, consultants and other professionals;
- tax, judicial, administrative or customs authorities where required by law.
Where a provider processes personal data on behalf of the Data Controller, the relationship is governed in accordance with Article 28 GDPR where applicable.
Certain providers may instead act as independent data controllers for specific processing activities.
Personal data is not publicly disclosed unless required by law or resulting from an explicit choice by the user, for example when publishing a review.
16. International transfers of data
Certain service providers used by the website may have their headquarters, affiliated companies or infrastructure outside the European Economic Area.
Where personal data is transferred to third countries, the transfer takes place in accordance with Articles 44 et seq. GDPR, using, depending on the circumstances, European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, the Data Privacy Framework where applicable, or other safeguards recognised by applicable law.
Shopify operates internationally and may process personal data in Canada, the United States and other countries in accordance with the safeguards described in its privacy policies and data processing agreements.
17. Retention periods
Personal data is retained only for as long as necessary for the purposes for which it was collected, without prejudice to legal obligations and the need to establish, exercise or defend legal claims.
Orders and administrative and tax documentation
Data subject to accounting and tax retention obligations is kept for the period required by applicable law, normally 10 years for documentation subject to such obligations.
Customer accounts
Data is retained for the period during which the account is used and subsequently for as long as necessary to comply with legal obligations and protect the Data Controller’s rights.
Requests and customer support
Communications are retained for the time necessary to handle the request and subsequently, where necessary, to document the relationship with the customer or protect legal rights.
Newsletter and marketing
Data is processed until consent is withdrawn, the data subject objects, or the retention of such data is no longer necessary or appropriate for the relevant purpose, without prejudice to the minimum information necessary to document consent, withdrawal or objection.
Reviews
Reviews and related data are retained for the period necessary to manage and publish the review, subject to deletion requests where applicable and without prejudice to any legal obligations or legitimate interests requiring retention.
Cookies and tracking technologies
The duration of individual tools is indicated in the Cookies - preferences panel.
18. Mandatory or optional provision of data
The provision of data required for order management, payment, invoicing and shipping is necessary to enter into and perform the contract.
Without such data, it may not be possible to complete a purchase.
The provision of data for newsletters, marketing, personalised advertising, non-essential analytics and profiling is optional.
Refusal or withdrawal of consent for such purposes does not prevent purchases or use of essential website functions.
19. Rights of the data subject
In the cases provided for by Articles 15-22 GDPR, the data subject may exercise their rights and, in particular, may request:
- confirmation as to whether personal data concerning them is being processed;
- access to their personal data;
- rectification of inaccurate data;
- completion of incomplete data;
- erasure of personal data where applicable;
- restriction of processing;
- data portability where applicable;
- objection to processing;
- withdrawal of consent at any time;
- information regarding automated decision-making where provided by law.
The data subject always has the right to object to the processing of personal data for direct marketing purposes.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Requests may be sent to:
admin@ilmondodiwit.com
or through the GDPR Privacy Requests tools available in the Privacy section of the website footer.
20. Rights and preferences relating to Shopify
For processing activities for which Shopify acts directly as a data controller, users may have additional rights against Shopify.
Through the Shopify Privacy Portal, users can review available options relating to access, deletion, objection and, where applicable, opting out of certain uses or disclosures of data for advertising based on activity across different merchants.
Access the Shopify Privacy Portal
These rights are in addition to the rights users may exercise directly against Il mondo di Wit.
21. Rights relating to cookies and tracking
To change cookie preferences only, users do not need to send an email request.
Users may use Cookies - preferences or Privacy Preferences in the footer at any time.
Updated preferences replace previously expressed choices for the relevant browser or device according to the technical operation of the consent management system.
22. Rights for users in other countries
Depending on the country or state of residence, users may have additional privacy rights.
Users subject to applicable United States privacy laws may, for example, have rights relating to the sale or sharing of personal information and targeted advertising.
For such requests, US Privacy Requests tools are available in the Privacy section of the footer.
Users subject to Canadian privacy law may have additional rights available through the Canadian Privacy Rights section.
The existence and scope of such rights depends on the law applicable to the individual user.
23. Right to lodge a complaint
A data subject who believes that the processing of personal data infringes the GDPR may lodge a complaint with the competent supervisory authority.
For Italy, the competent authority is:
Garante per la protezione dei dati personali
www.garanteprivacy.it
This is without prejudice to the data subject’s right to seek judicial remedies.
24. Automated decision-making
The Data Controller does not directly make decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect them, except where permitted by law.
Certain technology, payment, security or fraud prevention providers may use automated systems to assess risk, identify fraud or protect transactions in accordance with their own responsibilities and privacy policies.
Personalisation and advertising activities carried out with consent do not, in themselves, constitute decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR.
25. Data security
The Data Controller implements technical and organisational measures appropriate to the risk in order to protect personal data against unauthorised access, loss, alteration, destruction or unlawful disclosure.
Communications between the user’s browser and the website are protected through encrypted HTTPS/TLS connections.
No computer system or method of transmission over the Internet can guarantee absolute security.
26. Minors
The website and the products offered are not specifically intended for the collection of personal data from minors.
If the Data Controller becomes aware that personal data relating to a minor has been collected in violation of applicable law, the necessary measures will be taken to delete or properly manage such data.
27. Changes to this Privacy Policy
This Privacy Policy may be updated to reflect changes in law, processing activities, new services, new providers or changes to the website configuration.
The updated version is published on this page together with the date of the latest update.
Where a change involves new processing for which consent is required by law, such consent will be requested before the relevant processing takes place.
28. Contact details
Il mondo di Wit di Andreas Cattelan
Via Zara 5
57033 Marciana Marina (LI)
Italy
VAT number: 01002090452
Email: info@ilmondodiwit.com
Privacy: admin@ilmondodiwit.com
Telephone: +39 334 944 2589
Users may also use the functions available in the Privacy section in the footer of ilmondodiwit.com.