Macelleria Mazzucchi
Privacy Policy
Last updated: 14 July 2026 · Versione italiana
This policy explains how personal data of users of the Macelleria Mazzucchi app (the "App") — used to place pickup orders at the shop — is processed under Regulation (EU) 2016/679 ("GDPR").
1. Data Controller
The data controller is Nari Information, which develops and operates the App (the "Controller"). Macelleria Mazzucchi is the shop where you collect your order; its authorised staff access order data in order to prepare it.
For any privacy matter you can contact the Controller at: hello@nariinfo.dev.
2. Personal Data We Process
| Category | Data | Source |
|---|---|---|
| Account data | Name, email address, identifier of the Apple or Google account used to sign in | Provided at registration via Sign in with Apple or Google |
| Order data | Products ordered, requested quantity, measured quantity after weighing, estimated and final price, chosen pickup time, order status, timestamps | Generated when you place an order |
| Notification tokens | Device push token (APNs on iOS, Firebase Cloud Messaging on Android) | Generated by the device if you allow notifications |
| Technical logs | IP address, request time and technical outcome, kept temporarily in server logs | Generated automatically for security and diagnostics |
| Preferences | Interface language (stored on your device only) | Set by you |
The App does not collect: payment data (payment happens exclusively at the shop on pickup), location data, advertising or profiling data, tracking cookies.
3. Purposes and Legal Bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Creating and managing your account, receiving and preparing orders, informing you of order status via push notifications | Performance of a contract (Art. 6(1)(b)) |
| Keeping order records for accounting and tax purposes | Legal obligation (Art. 6(1)(c)) |
| Service security, abuse prevention, technical logs | Legitimate interest (Art. 6(1)(f)) |
Push notifications are optional and can be disabled at any time in your device settings. We do not send promotional notifications.
4. Recipients and Processors
Data is accessed by the Controller's authorised staff and by authorised staff of Macelleria Mazzucchi, limited to the order data needed to prepare and hand over the order. The App relies on the following providers:
| Provider | Service | Location |
|---|---|---|
| Hetzner Online GmbH | Server and database hosting | Germany (EU) |
| Apple Inc. | Sign in with Apple, push notifications (APNs) | EU/US |
| Google LLC | Google Sign-In, push notifications (Firebase Cloud Messaging, Android only) | EU/US |
Account and order data is stored on servers located in the European Union. Any transfers to third countries by Apple and Google (e.g. for notification delivery) rely on the European Commission's Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework.
5. Retention
- Account data: kept while your account is active. When you delete your account, your name, email, sign-in identifiers and push tokens are removed or anonymised.
- Order records: kept, unlinked from the deleted profile, for the shop's operational, accounting and tax needs within the limits of Italian law (up to 10 years under Art. 2220 of the Italian Civil Code).
- Technical logs: kept for a limited period and rotated automatically.
6. Your Rights
Under Articles 15–22 GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interest.
Directly in the App you can:
- Export your data (profile and orders) in electronic format from your account settings;
- Delete your account yourself via Settings → Delete account.
For any other request, write to hello@nariinfo.dev. We reply within 30 days. You also have the right to lodge a complaint with your supervisory authority — in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it).
7. Children
The App is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will remove it.
8. Security
All communication between the App and our servers is encrypted (HTTPS/TLS). Access to data is limited to authorised staff and protected by authentication.
9. Changes to This Policy
Material changes will be published on this page with an updated date. Please review it periodically.