Privacy notice
Last updated: July 13, 2026
This notice explains, in plain language, what data we process, why, and what rights you have. The principle we follow is to collect only what is essential.
Data controller
The data controller is the natural person who runs the Nico & The Shoppers project, a non-profit project. The official contact channel for any request about your data is [email protected]; the controller's full identifying details are provided on written request to that address.
What data we process
- Registration data: first name, last name, email and username (email and username normalized to lowercase), phone number, and the password hash. We never store the password in plain text.
- Content you publish: profile, listings, private messages, public chat messages, reviews, and feedback.
- If you buy an item: the shipping address you enter for the order (see the dedicated section below).
- Minimal technical data for security: IP address in hashed form, browser information (user-agent), anti-abuse logs, and timestamps.
- Technical cookies needed for the site to work.
Why we process data
- To provide the service (registration, account, publishing listings and content, messaging): performance of the contract with you and of the pre-contractual measures you request, under Article 6(1)(b) GDPR.
- To ensure security and prevent abuse, fraud, and spam (anti-abuse logs, IP address hashing, anti-bot protection): our legitimate interest, under Article 6(1)(f) GDPR.
- To comply with legal obligations, under Article 6(1)(c) GDPR.
Shipping address
If you buy an item through the platform, we collect and store the shipping address you enter (name, address, city, postal code, province, country and, if you provide it, a phone number). We use it to generate a PDF shipping label and send it, together with the address, by email to the seller of that specific sale, solely so they can ship you the item you purchased. The legal basis is performance of the sales contract between you and the seller, under Article 6(1)(b) GDPR.
The payment provider you use to pay the seller does not receive the shipping address from us and is not a data processor for this data: you reach it yourself, through a redirect to its website, independently of the platform.
We keep the shipping address for 12 months from completion of the order, after which it is removed or anonymized, unless a different legal obligation applies.
Cookies
We use only first-party technical and essential cookies: session cookies, the anti-CSRF token, and your language and theme preferences. We do not use profiling or advertising cookies, and we do not profile our users or track them for advertising.
User profiles can embed third-party content (YouTube, SoundCloud), loaded only when you visit a profile that uses it. In that case those providers receive your IP address and may set their own cookies under their privacy policies.
How long we keep data
We keep data for as long as needed for the purposes described. When an account is deleted, personal data is removed or anonymized, except for security logs, which are kept only for as long as strictly necessary.
Messages in the global public chat are ephemeral: they are automatically removed after a short, rolling period.
No sale of data
We do not sell or transfer your data to third parties for marketing purposes.
Your rights
Under the GDPR (Articles 15-22) you have the right to access, rectification, erasure, restriction, objection, and portability of your data. To exercise them you can write to [email protected]. You also have the right to lodge a complaint with the competent supervisory authority: in Italy, the Garante per la protezione dei dati personali.
Providers
Some providers may process data as data processors, only to the extent needed to run the service: for example for hosting and image storage, and Cloudflare for content delivery (CDN/proxy) and anti-bot protection (Turnstile). For these security purposes, technical data including the IP address is processed. Some providers may be located outside the European Union, for example in the United States: in that case the transfer takes place on the basis of the adequate safeguards required by the GDPR (Chapter V), such as the Standard Contractual Clauses (SCC) approved by the European Commission and, for transfers to the United States, the provider's participation in the EU-US Data Privacy Framework.
Minimum age
The service is not intended for children under 14.