Privacy Policy
Last updated: 14 September 2026
This is a courtesy translation; the Italian version (/privacy) prevails. This notice describes how personal data is processed through the i-Connect platform under Regulation (EU) 2016/679 (“GDPR”).
1. Controller
i-creativi s.r.l.s., Via Villapizzone 26, 20156 Milano (MI), Italia — VAT IT08673460963 — email: support@i-creativi.com.
2. Data we process
- Account data: email address, password (stored encrypted only), company name, role.
- Billing data: company name, address, VAT number, payment outcomes. Card data is processed exclusively by Stripe and never reaches our systems.
- Technical data: synchronisation logs, IP addresses, session identifiers, integration configuration.
- Connected shop data: to provide the service, the Platform processes on the customer’s behalf the data present in their e-commerce and ERP (e.g. orders and related end-customer details). For such data the customer is the controller and i-creativi acts as processor under Art. 28 GDPR, based on the DPA signed with the customer.
3. Purposes and legal bases
- Service delivery and account management — performance of a contract (Art. 6(1)(b)).
- Invoicing and tax obligations — legal obligation (Art. 6(1)(c)).
- Platform security, abuse prevention, technical logs — legitimate interest (Art. 6(1)(f)).
- Service communications — performance of a contract.
- Commercial communications about similar products — legitimate interest, with the right to object at any time.
4. Recipients
- Vercel Inc. — application hosting (EU data centres; any non-EU transfers covered by Standard Contractual Clauses).
- Supabase Inc. — database and authentication (eu-west-1, Ireland).
- Stripe Payments Europe Ltd. — payments and VAT calculation.
- Resend (Plus Five Five Inc.) — service emails (e.g. refund-to-process notices, links to choose between refund and voucher).
- Google Ireland Ltd. — Google Analytics for website usage statistics, in Consent Mode: without consent no analytics cookies are set and Google only receives aggregate signals without identifiers (see Cookie Policy); it is not active in the private area, and Google Maps Platform for address autocompletion at sign-up and in billing details.
- The Controller’s administrative and tax advisors, for legal compliance.
When the customer connects their own services (for example Microsoft Dynamics 365 Business Central, Sendcloud, Klaviyo), the Platform sends them the necessary data on the customer’s instruction, through the customer’s own accounts and credentials: those providers operate under the contracts the customer has entered into with them.
Data is never sold or shared with third parties for marketing purposes.
5. Transfers outside the EU
Data is primarily stored in the European Union. Any transfers to third countries by the providers above rely on adequacy decisions or Standard Contractual Clauses (Art. 46 GDPR).
6. Retention
- Account data: for the duration of the contract and up to 12 months after account closure.
- Billing data: 10 years, as required by Italian law.
- Technical and synchronisation logs: up to 12 months.
- Data of the end customers of connected stores: personal details are removed from orders after 12 months, or earlier on the instruction of the customer acting as controller (available in the dashboard). When an account is closed, all store data is deleted within 12 months.
7. Your rights
Under Arts. 15–22 GDPR you may exercise your rights of access, rectification, erasure, restriction, portability and objection by writing to support@i-creativi.com. You may also lodge a complaint with your supervisory authority (in Italy: Garante per la protezione dei dati personali).
8. Changes
Changes to this notice will be published on this page and, where relevant, notified by email.