Via Matteotti 60B, 20883 Mezzago (MB), Italia
VAT number: IT14290760967
info@cardunity.io1. Controller and scope
Spells Technologies S.r.l. is the controller of Cardunity users' data for accounts, subscriptions, support and service management. You can contact us at info@cardunity.io or using the contact details on this page.
For buyer data imported by a seller from their channels, the seller determines the purposes of order management and Cardunity processes the data to provide the service on their behalf. The seller must inform their customers and have a legal basis for processing. This policy does not replace the data processing agreements required under Article 28 of the GDPR.
2. Data collected and its sources
We receive account and shop details, email, login credentials, billing information, uploaded content and support requests from you. From channels you authorise, we receive identifiers, integration credentials, stock, listings, prices and orders; orders may include the buyer's name, contact details and shipping address, depending on the channel's permissions and features.
The service also processes technical connection data, operational logs and account activity information. Payment providers handle payment method details: Cardunity receives customer, payment and subscription identifiers and status, not the full card number.
3. Purposes and legal bases
Operational emails concern your account, the service and orders. Promotional communications require consent where required by law, except for permitted exceptions for existing customers and similar services. You can disable them in the workspace email preferences or by writing to us, separately from cookie consent.
We use the data needed to create your account, authenticate you, connect channels, manage stock and orders, provide support and administer your subscription on the basis of contract performance or pre-contractual steps. Data required for these features is necessary: without it we may be unable to provide the service.
Tax compliance and binding requests from authorities are based on legal obligations. Security, abuse prevention, defence of rights and internal analysis of service use are based on the legitimate interest in protecting and improving Cardunity, respecting data subjects' rights. Optional analytics and advertising tools are activated with your consent, which you can refuse or withdraw without losing access to core features.
4. Visits and service use
For authenticated users, we internally record the first and last visit, the number of visits and sections visited, linking them to the account and workspace. This helps us understand usage and returning users. These identifiers are not sent to browser analytics or advertising tools.
Daily activity detail is limited to the last 90 days when the record is next updated; this is not automatic deletion of all data after 90 days. Overall totals and dates remain associated with the account according to the retention criteria below.
6. Recipients and transfers
Data is accessible to authorised staff and providers necessary for the service: infrastructure and hosting, payments (Stripe), email delivery (Resend), support and, if authorised, the analytics and advertising tools described above. Data needed for operations is exchanged with the marketplaces you connect. These may act as independent controllers under their own policies. Authorities and advisers may receive data where needed for legal obligations or the protection of rights.
Using international providers may involve processing outside the European Economic Area. Transfers require the safeguards provided by the GDPR, such as an adequacy decision or standard contractual clauses, depending on the recipient and service. You can request information about recipients and applicable safeguards by writing to info@cardunity.io.
7. Retention and security
We retain account and workspace data for as long as necessary to provide the service and manage the relationship. After closure, retention is limited to legal requirements, accounting and tax obligations and the management of any disputes. Logs and support requests are retained in relation to their purpose; you can request information on retention of your data and deletion where the conditions are met.
Passwords are stored as hashes and integration credentials are encrypted. Access to data is restricted according to service permissions. Disconnecting a marketplace prevents new operations through that connection but does not delete orders or data already imported.
8. Your rights
Where provided by the GDPR, you can request access, rectification, erasure, restriction and portability, object to processing based on legitimate interest and withdraw consent without affecting the lawfulness of prior processing. Write to info@cardunity.io; we may request information needed to verify your identity. We respond within statutory deadlines, normally within one month, subject to permitted extensions.
You can lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali) or the competent supervisory authority in your country. If your request concerns a purchase from a seller using Cardunity, the seller is the first contact for order data; we can assist them in handling the request.
9. Automations and updates
Stock and Price Bot automations apply the seller's product settings; they are not automated decisions about individuals with legal or similarly significant effects. This policy may be updated to reflect changes to the service or legislation. The date above shows the latest revision; any new purposes requiring consent will be subject to a separate choice.