Last modified 16th January 2026

1. Contents

    2. Introduction

    We protect your personal data in line with the requirements of the General Data Protection Regulation (GDPR). The GDPR requires data controllers such as ourselves to document our lawful basis for processing personal data. It also gives you rights over how your data is processed. This privacy policy documents the data we collect, why and how we process it, and how to exercise your rights.

    2.1 Data Controller

    The data controller responsible for this website is PIUAROMA LTD, who can be contacted at 24 Friary Rd, London, W3 6AF.

    This website contains links to third-party websites, which have their own data controllers and privacy policies. This privacy policy applies only to this website.

    2.2 Lawful basis for processing

    For each method by which we collect personal data, this privacy policy documents our lawful basis for processing the data. Where we rely on your consent to process your data, we explain how you can withdraw your consent and delete your data.

    2.3 Individual rights

    The GDPR gives you rights over how your personal data is processed. You can exercise your rights by contacting us. In some cases you can also exercise your rights through automated systems, as described at the relevant points in this privacy policy.

    2.4 Security

    The GDPR requires us to implement appropriate technical measures to protect data. We verify the identity of any individual who requests access to data before granting access. We use Transport Layer Security (TLS, also known as SSL) to encrypt any data you supply to us through our website. Additional technical measures are described at the relevant points in this privacy policy.

    2.5 Disclosures

    In addition to any sharing of data described elsewhere in this privacy policy, we may disclose data for legal reasons. If we suspect criminal activity we may disclose data relating to those involved or affected to the appropriate authorities. We may also be obliged to disclose data if we receive a request from an appropriate authority.

    2.6 Changes to this privacy policy

    We may occasionally make changes to this privacy policy. Following any changes, the date at the top of this privacy policy will be updated. If any change allows for wider access to data, such changes will only apply to data collected after the date of the updated privacy policy.

    3. Cookies

    Cookies are small pieces of text that are stored by your browser. Each cookie has a name and is associated with a particular site. When your browser sends a request to a site (for example, to download a page, image, or video), the computer that responds (known as a server) may tell your browser to set one or more cookies. When your browser makes further requests to the same site it sends the cookies back to the server. This allows the server to remember you as you browse the site, and provide features such as shopping baskets or password-protected areas. For more information on the cookies we use, see our cookie policy.

    4. Data collected by our shop

    4.1 Accounts

    When you place an order you can either create a guest account or register for a full account. A registered account allows you to log in to your account in future and view your order history, or place further orders without needing to enter your details again. You can also choose to create a registered account without placing an order. When you register for an account we collect your name, e-mail address, telephone number, and company.

    We send Mailchimp your name and e-mail address to allow us to send you e-mails concerning your order. You may also opt in to receive our newsletter. You may opt out at any time by clicking the unsubscribe link at the bottom of the newsletter. For more information on how Mailchimp handles the data it collects, see Mailchimp’s privacy policy.

    You can download the data we have collected about you by going to your account page and following the link to download your data.

    You can close your account by going to your account page and following the link to close your account. If you close your account we will retain records of any orders you have placed (as described below), but will delete any other data you have supplied.

    Lawful basis for processing: Consent given by data subject
    Why? You have supplied us with this data in order to create an account

    4.2 Orders

    When you place an order we collect your name, e-mail address, telephone number, company, delivery and billing addresses, and any comments you choose to leave.

    Lawful basis for processing: Performance of a contract
    Why? To enable us to enter into a contract with you and fulfil our obligations under it

    Lawful basis for processing: Compliance with a legal obligation
    Why? To maintain a record of financial transactions for taxation purposes

    4.3 Payment through Stripe

    When you make a payment through Stripe, we send Stripe your name, billing address, and e-mail address. After you enter your card details, Stripe attempts to take payment and tells us whether the payment was successful. For more information on how Stripe handles the data it collects, see Stripe’s privacy policy.

    Lawful basis for processing: Performance of a contract
    Why? To enable you to pay for your purchase

    4.4 Wishlists

    When you visit and interact with our website, we track:

    • Products you add to wishlists – this is done in order to present you and other visitors your favorite products, and to create targeted email campaigns.
    • Wishlists created by you – we’ll monitor wishlists you create and make them available to the store personnel.

    We also use cookies to follow wishlist contents while you browse our website.

    5. Data collected by third parties on our behalf

    5.1 Web-crafters.com

    Our site is hosted by WebCrafters (registered trade name 20201762376 in Colorado, USA). WebCrafters logs all requests in order to determine the causes of reported faults and to detect and block suspicious traffic. The log records the time of the request, your IP address, the requested resource, the referring site (if specified by your browser), and your browser’s user agent string (which will usually include the name and version of your browser and operating system). Log files are deleted after ninety days.

    Lawful basis for processing: Compliance with a legal obligation
    Why? To comply with the GDPR obligation to implement appropriate technical measures to protect data

    5.2 Meta Pixel

    We use Meta Pixel to track visitor interaction with our site in order to measure the success of our advertising and target it more effectively. Meta collects details of the adverts with which you interact, pages you view and the time you viewed them, the features of your browser, and your IP address. For more information on how Meta handles the data it collects, see Meta’s privacy policy.

    To opt out of Meta Pixel tracking on our site, see the Meta Pixel section of our cookie policy. To opt out of Meta Pixel tracking on all sites, see Meta’s Ad Preferences.

    5.3 Google Analytics

    We use Google Analytics to track visitor interaction with our site in order to produce statistical reports. Google collects details of the pages you view and the time you viewed them, the features of your browser, and your IP address. For more information on how Google handles the data it collects, see Google’s privacy policy.

    To opt out of Google Analytics tracking on our site, see the Google Analytics section of our cookie policy. To opt out of Google Analytics tracking on all sites, use the Google Analytics Opt-out Browser Add-on.

    5.4 WHATSAPP chat widget

    When you view a page containing the WhatsApp chat widget, your browser connects to WhatsApp. When you chat with us your messages are sent through WhatsApp and then shared with us, and our responses are sent through WhatsApp and then shared with you. For more information on how WhatsApp handles the data it collects, see WhatsApp’s privacy policy.

    Lawful basis for processing: Consent given by data subject
    Why? You have sent us a message in the expectation of receiving a reply

    6. Other data collected by third parties

    6.1 Google maps

    When you view a page containing Google maps, your browser connects to Google. For more information on how Google handles the data it collects, see Google’s privacy policy.

    6.2 YouTube video player

    When you view a page containing the YouTube video player, your browser connects to YouTube. For more information on how Google (the operator of YouTube) handles the data it collects, see Google’s privacy policy.

    6.3 Google Web Fonts

    For uniform representation of fonts, this page uses web fonts provided by Google. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly.

    For this purpose your browser has to establish a direct connection to Google servers. Google thus becomes aware that our web page was accessed via your IP address. The use of Google Web fonts is done in the interest of a uniform and attractive presentation of our plugin. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.

    If your browser does not support web fonts, a standard font is used by your computer.

    Further information about handling user data, can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy at https://www.google.com/policies/privacy/.

    6.4 Google reCAPTCH v3

    All of our forms are protected using Google’s reCAPTCHA version 3. For more information on how Google handles the data it collects, see Google’s privacy policy and terms of service.