Privacy policy
Last updated: [DATE]
This policy explains which personal data the readymadeforai.com website and the ReadymadeForAI service collect, why we collect it and what rights you have.
Data controller
The data controller is [COMPANY NAME], registered office at [REGISTERED ADDRESS], VAT number [VAT NUMBER]. For any privacy request you can write to [PRIVACY EMAIL].
What data we collect
We only collect the data the website and the service need:
- Contact form: name, email, company, website and message, plus the page you wrote from, the referring site and any campaign parameters (UTM).
- Customer accounts: the email and sign-in data needed to access the console.
- Technical data: IP address and browser information logged by our hosting systems for security and operation.
Why we use it and on what legal basis
- Replying to requests sent through the contact form: pre-contractual steps you asked for (Art. 6(1)(b) GDPR).
- Providing the service to customers and managing their accounts: performance of a contract (Art. 6(1)(b) GDPR).
- Protecting the website from abuse and keeping it running: legitimate interest (Art. 6(1)(f) GDPR).
- Meeting legal obligations, such as tax requirements: legal obligation (Art. 6(1)(c) GDPR).
Cookies
The website only uses technical cookies needed for it to work, which do not require consent: the console sign-in session, the page to return to after signing in and your chosen language.
The public website does not use analytics, profiling or advertising cookies.
Data from customers' stores
When a customer connects their store (for example Shopify or WooCommerce) or their Google accounts (Analytics, Search Console, Merchant Center), ReadymadeForAI processes that data on the customer's behalf, as a data processor. The terms are set by the contract and the data processing agreement [DPA] signed with the customer.
Providers and transfers
To run the website and the service we rely on providers that process data on our behalf, including: Vercel (website hosting), Supabase (database and authentication), Fly.io (background processing) and artificial intelligence model providers through OpenRouter, used to analyze and improve customer catalogs.
Some providers may process data outside the European Economic Area. In those cases the transfer relies on the safeguards required by the GDPR, such as the European Commission standard contractual clauses. [UP-TO-DATE LIST OF PROVIDERS AND REGIONS]
How long we keep it
Contact form data is kept for [CONTACT DATA RETENTION PERIOD]. Account data is kept for the duration of the contract and, afterwards, for as long as the law requires. [TO BE CONFIRMED]
Your rights
You can ask at any time to access, correct or delete your data, restrict or object to its processing, or receive it in a readable format (Arts. 15-22 GDPR), by writing to [PRIVACY EMAIL].
If you believe the processing breaks the law you can lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or the authority of your country.
