Privacy policy

Last updated: August 25, 2026

1. Controller and scope

Bagmira, at Via del Tritone 61, 00187 Roma RM, Italy, is the controller for personal data processed through https://www.bagmira.com, except where a provider acts as an independent controller. Privacy contact: hello@bagmira.com. Data-protection officer or representative, if required: No dedicated officer or representative is designated for this test site; confirm whether appointment is legally required before commercial use.

2. Data we collect

  • Identity and contact data, including name, email, telephone, billing and delivery address.
  • Account and order data, including products, variants, order history, returns, refunds, preferences, and account credentials.
  • Transaction data, including payment status and provider references; we do not ask customers to email full card details.
  • Support and complaint data, including messages and evidence needed to resolve an issue.
  • Technical and usage data, including IP address, browser, device, referral source, pages, cart events, security logs, and cookie choices.
  • Marketing data, including subscriptions, campaign interactions, preferences, and opt-out records.

Actual fields and systems: contact, account, order, payment-status, delivery, return, support, device, security, consent, and marketing-preference data processed through Shopify and any providers actually enabled for the store.

3. Sources

We obtain data from you, your device, Shopify, payment and fraud-prevention providers, carriers, fulfilment partners, support tools, analytics or advertising providers where enabled, and lawful public or professional sources.

4. Purposes and lawful bases

Activity Purpose Typical lawful basis
Account, checkout, order, delivery, return, and refund Provide the requested transaction and service Contract or steps requested before contract
Tax, accounting, product safety, consumer claims, and regulatory records Meet legal duties Legal obligation
Fraud prevention, security, support, and service improvement Protect customers and operate the store Legitimate interests, balanced against individual rights
Optional marketing and non-essential cookies Communications, measurement, or advertising Consent where required

Detailed purpose and basis record: contract for checkout and fulfilment; legal obligation for tax, accounting, safety, and claims; legitimate interests for proportionate security and support; consent where required for non-essential cookies and marketing.

5. Sharing and processors

We disclose only the data needed to Shopify, payment providers, carriers, warehouses, fulfilment partners, customer-service systems, security and fraud providers, analytics or advertising tools where enabled, professional advisers, acquirers, courts, and regulators. Current provider list, role, purpose, location, and notice: Shopify and the payment, hosting, security, analytics, customer-support, fulfilment, and carrier providers actually presented or enabled for the store; the final provider list and locations must be confirmed before commercial use.

6. Cookies and similar technologies

Strictly necessary technologies support security, cart, checkout, account, language, currency, and consent choices. Analytics, advertising, personalisation, or social technologies are used only under the applicable consent rule. Continued browsing is not treated as consent where prior consent is required. Cookie list, purposes, providers, durations, and consent controls: the Shopify storefront consent controls and cookie banner, where enabled, provide current categories and choices; non-essential technologies must not run before the consent required by law.

7. Marketing

We send electronic marketing only with a valid legal basis and the consent required by local ePrivacy rules. Each message provides an unsubscribe or preference route. Consent and opt-out evidence is retained to respect the choice. Marketing settings: Marketing is sent only where a valid legal basis and any required consent exist; each message must provide an unsubscribe or preference route.

8. International transfers

Providers may process personal data outside the European Economic Area. Where required, we use an adequacy decision, approved standard contractual clauses, another lawful transfer mechanism, and supplementary safeguards. Countries, providers, and mechanisms: Where a provider transfers personal data outside the EEA, it must rely on an adequacy decision, approved standard contractual clauses, or another lawful mechanism with appropriate safeguards.

9. Retention

We keep data only as long as needed for the purpose, contract, tax and accounting duties, product-safety records, fraud prevention, complaints, and legal claims, then delete or anonymise it. Retention schedule: Order, tax, safety, complaint, fraud, and consent records are retained only for the applicable legal or operational period, then deleted or anonymised; exact periods must be confirmed before commercial use.

10. Security

We use proportionate access controls, provider controls, encryption in transit, authentication, backups, monitoring, and incident procedures. No internet service is risk-free. Security contact: hello@bagmira.com.

11. Your GDPR rights

Subject to legal conditions, you may request access, correction, erasure, restriction, portability, object to processing, withdraw consent, and ask for human intervention where a solely automated decision has legal or similarly significant effects. Send requests to hello@bagmira.com or https://www.bagmira.com/pages/contact-us. We normally respond within one month, subject to lawful extension, verification, or exemption.

12. Complaints

Contact hello@bagmira.com first if you wish us to investigate. You may also complain to Garante per la protezione dei dati personali or another competent supervisory authority, and seek a judicial remedy where available.

13. Children

The store is not directed to children below 18 years. Age and parental-consent rules depend on the service and country. Contact us if you believe a child supplied data unlawfully.

14. Automated checks

Payment, fraud, delivery, analytics, or advertising providers may perform automated checks under their notices. Significant solely automated decisions, logic, consequences, and safeguards: No solely automated decision with legal or similarly significant effect is intentionally made by Bagmira; payment and fraud providers may perform checks under their own notices.

15. Changes

We update this policy when processing, providers, or law changes. The date above identifies the current version. Material changes will be communicated where required.