Privacy

Privacy

Last updated: 27 July 2026

This explains what Pacomaro S.R.L. does with personal data. It covers this website and the four shops we run: NobilZampa, Gold & Crown, Dream & Tale and Dream & Crown.

It is written to be read rather than to be survived. If something here is unclear, or you want us to act on one of the rights at the end, write to us and a person will answer.

01 Who is responsible

Pacomaro S.R.L. is the data controller. That means we decide what is collected and why, and we are the ones you can hold to this document.

Company
Pacomaro S.R.L.
Registered office
Via Bocchetto, 6, 20123 Milano, Italy
VAT / registration
IT 14757430963, REA MI-2805307
Contact
admin@pacomaro.com

We have not appointed a Data Protection Officer. We are not required to: we do not monitor people on a large scale and we do not process special-category data as a core activity. The address above reaches the two partners directly.

02 This website collects nothing

pacomaro.com is a set of static pages. There are no cookies, no analytics, no tracking pixels, no embedded video, no fonts loaded from anyone else's server, and no forms. Nothing on this page talks to a third party, and the content-security policy served with it forbids that from changing quietly.

The one thing that does happen is ordinary web-server logging: our content delivery network records the IP address, the page requested, the time and the browser string for each request, and discards it. We use it to keep the site up, not to build a picture of you. There is no consent banner because there is nothing to consent to.

Everything below is about the four shops, not about this page.

03 What the shops collect

Only what an order needs. Each shop states this again in its own terms at the point of purchase.

The photograph you upload
The image itself, and any faces in it. This is the whole point of the product, and it is the most sensitive thing we hold. See below for how long we keep it.
Order details
Name, delivery address, email address, and a phone number when the courier requires one.
Payment
The amount, the currency, the outcome, and the last four digits and card type. We never receive or store a full card number: the payment provider takes those directly.
Account, if you make one
Email address and order history. An account is optional. You can buy without one.
Device and usage
IP address, approximate country, browser, and the pages you visited. Used for fraud checks, tax and currency, and advertising measurement.

04 Why, and on what legal basis

Under the GDPR every use of personal data needs a lawful basis. Ours are these, and nothing is used for a purpose not listed here.

Making and delivering what you ordered
Performance of a contract. Without the photograph and the address there is no product.
Taking payment and preventing fraud
Performance of a contract, and our legitimate interest in not being defrauded.
Invoices, tax and accounting records
A legal obligation under Italian law.
Order emails: confirmation, dispatch, delivery
Performance of a contract. These are not marketing and you cannot unsubscribe from them while an order is open.
Marketing emails
Your consent, given when you ask for them. Every one carries a one-click unsubscribe, and unsubscribing takes effect immediately.
Advertising measurement on Meta, TikTok and Google
Your consent where the law requires it, otherwise our legitimate interest in knowing which advertising works. You can withdraw it at any time.
Answering you when you write to us
Our legitimate interest in running a business people can contact.

05 Who else handles it

We do not sell personal data and we never have. We do use other companies to do specific jobs, and each of them is bound by a written processing agreement that lets them use the data only for the job we gave them.

Hosting and storage
Amazon Web Services, in the Ireland region. Photographs, orders and the database all sit there.
Image generation
Several providers, used interchangeably so that one outage does not stop an order: Google, Segmind, Runware, KIE and fal. Your photograph is sent to whichever handles the job.
Printing and delivery
Gelato, which routes each order to a print partner near the delivery address. They receive the finished artwork and the address, not your original photograph.
Payments
Stripe, PayPal, Revolut, Mollie and Shopify Payments, depending on how you chose to pay.
Email
Resend, for order emails and magic-link sign-in.
Sign-in
Google, if you choose to sign in with a Google account.
Advertising measurement
Meta, TikTok and Google, which receive events about purchases. Where an identifier is sent it is hashed first.

We will also hand over data where the law compels us to: a court order, a tax inspection, or a criminal investigation.

06 Where it goes

Everything we control sits in the European Union, in Amazon's Ireland region. Some of the companies above are based in the United States. Where data reaches them it travels under the European Commission's adequacy decision for the EU-US Data Privacy Framework, or under Standard Contractual Clauses where that does not apply.

07 How long we keep it

The photograph you upload is deleted automatically 90 days after you upload it. This happens on a storage rule, not on someone remembering, and it applies whether or not you ordered anything. The finished artwork stays available in your account so you can download it again.

Order and invoice records are kept for 10 years, because Italian civil and tax law requires it. We cannot delete those earlier, even if you ask, until that period runs out.

An account lasts until you delete it. Marketing consent lasts until you withdraw it. Support correspondence is kept for two years, so that if you write again we know what happened last time.

08 Photographs of children

Two of our shops, Dream & Tale and Dream & Crown, exist to put a child in a picture. That deserves saying plainly rather than burying.

Those shops are sold to adults. Nobody under 18 may buy from us or open an account. When you upload a photograph of a child you are confirming that you are their parent or guardian, or that you have the permission of one.

A child's photograph is treated exactly like any other upload and deleted on the same schedule. We do not use it to train anything. We do not publish it. It appears in marketing only where a customer has specifically told us it may.

If a photograph of your child reached us and should not have, write to us and we will delete it and everything derived from it. That request goes to the front of the queue.

09 The generation, and what it does not do

The artwork is made by an image model, from your photograph and the style you picked. Three things are worth stating because people reasonably worry about them.

  • Your photographs are not used to train any model, ours or a provider's. The providers we use are contractually bound not to train on what we send them.
  • No decision that affects you legally or significantly is made by a machine on its own. Generation is a production step, not a judgement about you.
  • A person can look at an order when something has gone wrong with it, because otherwise we could not fix anything. Nobody browses uploads for entertainment, and access is logged.

10 What you can require of us

These are your rights under the GDPR. Exercising them is free and we will answer within one month.

  • Ask what we hold about you, and get a copy of it.
  • Have anything wrong corrected.
  • Have it deleted, except records the law obliges us to keep.
  • Have us stop or limit a particular use while a disagreement is resolved.
  • Receive what you gave us in a machine-readable file, or have us send it somewhere else.
  • Object to any use we base on legitimate interest, including advertising measurement.
  • Withdraw consent at any time, without that affecting anything done before you withdrew it.

Write to admin@pacomaro.com. We may ask you to confirm who you are, so that we do not hand your data to somebody else.

If we handle it badly you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or to the authority where you live. We would rather you told us first, but it is your right either way.

11 Keeping it safe

Data is encrypted in transit and at rest. Storage is private and reachable only through our own systems. Access to production is limited to the two partners and is logged. Payment card details never touch our servers.

No one can promise a breach will never happen. If one does and it puts you at risk, we will tell you and the Garante, within 72 hours of finding out.

12 Changes

When this changes we update the date at the top. If a change materially affects how we use data you have already given us, we will tell you directly rather than expecting you to re-read the page.

Back to Pacomaro