Skip to content

Cart

Your cart is empty

Our privacy policy

Last update: 21 March 2025

This privacy policy describes how Weingut Eichenstein (the ‘Site’, ‘we’) collects and uses data. Your personal data will be shared when you visit weingut.eichenstein.it (the “Site”), use our services, make a purchase there, or otherwise communicate with us regarding the Site (collectively, the ‘Services’). For the purposes of this Privacy Policy, ‘you’ and ‘your’ refer to you as a user of the Services, whether you are a customer, website visitor, or other person whose information we have collected in accordance with this Privacy Policy.

Please read this Privacy Policy carefully.
Changes to this Privacy Policy

We may update this Privacy Policy from time to time, including to reflect changes in our practices or for other operational, legal or regulatory reasons. We will post the revised Privacy Policy on the Site, update the ‘Last Updated’ date, and take any other steps required by law.

How we collect and use your personal information

In order to provide the Services, we collect as set out below. The information we collect and use varies depending on how you interact with us.

In addition to the specific uses listed below, we may use the information we collect about you to communicate with you, provide or improve the Services, comply with any applicable legal obligations, enforce any applicable terms of service, and protect or defend our rights, the rights of our users, or others.

What personal data do we collect?

The type of personal data we receive about you depends on how you interact with our site and use our services. When we use the term ‘personal information,’ we are referring to information that identifies you, relates to you, describes you, or could be associated with you. The following sections describe the categories and specific types of personal data we collect.

Information we collect directly from you

The information you provide to us directly through our services may include:

Contact details – including your name, address, telephone number and email address.

Order information – including your name, billing address, delivery address, payment confirmation, email address and telephone number.

Account information – including your username, password, security questions, and other information used for account security.

Purchase information – including items you view, add to your shopping cart, store in your account (e.g., loyalty points, reviews, recommendations, or gift cards), or purchases.

Customer support information – including the information you include in your communications with us, for example when you send a message via the Services.

Some features of the Services may require you to provide us with certain information about yourself directly. You can choose not to provide this information, but this may prevent you from using or accessing those features.

Information we collect about your use

We may also automatically collect certain information about your interaction with the Services (‘Usage Data’). For this purpose, we may use cookies, pixels and similar technologies (‘Cookies’). Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information about your interaction with the Services.

Information received from third parties

Finally, we may receive information about you from third parties, including vendors and service providers who collect information on our behalf, such as:

Companies that support our Site and Services, such as Shopify.

Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment, fulfil your orders, and provide you with the products or services you requested in order to fulfil our contract with you.

When you visit our site, open or click on emails we send you, or interact with our services or advertisements, we or third parties we work with may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.

All information we receive from third parties is treated in accordance with this privacy policy. See also the section below, Third-party websites and links.

How we use your personal data

Provision of products and services. We use your personal data to provide you with the services and to fulfil our contract with you, including processing your payments, fulfilling your orders, sending you notifications regarding your account, purchases, returns, exchanges or other transactions, creating, maintaining and otherwise managing your account, organising shipping, facilitating returns and exchanges, and other functions and features related to your account. We may also improve your shopping experience by enabling Shopify to match your account with other Shopify services you may wish to use. In this case, Shopify will process your data in accordance with its privacy policy and consumer privacy policy.

Marketing and advertising. We may use your personal data for marketing and advertising purposes, such as sending marketing and promotional messages via email, SMS or post, and displaying advertisements for products or services to you. This may include using your personal data to better tailor the services and advertising on our site and other websites. If you are located in the EEA, the legal basis for these data processing activities is our legitimate interest in selling our products in accordance with Art. 6, para. 1 (f) GDPR.

Security and fraud prevention. We use your personal data to detect, investigate or take appropriate action against possible fraudulent, illegal or malicious activities. If you decide to use the services and register an account, you are responsible for the security of your account login information. We strongly recommend that you do not share your username, password or other access data with third parties. If you believe your account has been compromised, please contact us immediately. If you are located in the EEA, the legal basis for these data processing activities is our legitimate interest in ensuring the security of our website for you and other customers, in accordance with Art. 6, para. 1 (f) GDPR.

Communication with you and service improvement. We use your personal data to provide you with customer support and to improve our services. This is in our legitimate interest to be able to respond to you, provide you with effective services and maintain our business relationship with you, in accordance with Art. 6, para. 1 (f) GDPR.

Cookies

Like many websites, we use cookies on our site. Specific information about the cookies we use in connection with the provision of our shop via Shopify can be found at https://www.shopify.com/legal/cookies. We use cookies to operate and improve our site and services (including storing your actions and preferences), to perform analytics and to better understand user interaction with the services (in our legitimate interest to manage, improve and optimise the services). We may also allow third parties and service providers to use cookies on our site to better tailor the services, products and advertising on our site and other websites.

Most browsers automatically accept cookies by default. However, you can set your browser to remove or reject cookies via the browser controls. Please note that removing or blocking cookies may affect your user experience and may cause some of the Services, including certain features and general functionality, to not function properly or to become unavailable. In addition, blocking cookies does not completely prevent us from sharing information with third parties, such as our advertising partners.

How we share personal data

In certain circumstances, we may share your personal data with third parties for the purposes of contract fulfilment, legitimate purposes and other reasons subject to this privacy policy. These circumstances may include:

with providers or other third parties who provide services on our behalf (e.g. IT management, payment processing, data analysis, customer support, cloud storage, order fulfilment and shipping).

with business and marketing partners to provide you with services and advertise to you. Our business and marketing partners use your data in accordance with their own privacy policies.

When you instruct, request or otherwise give us your consent to share certain information with third parties, for example to send you products or through your use of social media widgets or login integrations, with your consent.

With our subsidiaries or otherwise within our group of companies, in our legitimate interest to run a successful business.

In connection with a business transaction such as a merger or bankruptcy, to comply with all applicable legal obligations (including responding to subpoenas, search warrants and similar requests), to enforce all applicable terms of service, and to protect or defend the services, our rights and the rights of our users or others.

We disclose We disclose the following categories of personal data and sensitive personal data about users for the purposes described above in ‘How we collect and use your personal data’ and ‘How we disclose personal data’.

Categories of recipients

Identifiers such as basic contact details and certain order and account information

Commercial information such as order information, purchase information and customer support information

Internet or other similar network activity, such as usage data

Geolocation data, such as locations determined via an IP address or other technical means

Providers and third parties who provide services on our behalf (such as internet service providers, payment processors, fulfilment partners, customer support partners and data analysis providers)

Business and marketing partners

Affiliates

We do not use or disclose your personal data without your consent or for the purpose of inferring your personal data.

With your consent, we share personal data for the purpose of conducting advertising and marketing activities as follows.

User-generated content

The Services may allow you to post product reviews and other user-generated content. If you choose to submit user-generated content in a public area of the Services, that content is public and accessible to everyone.

We have no control over who has access to the information you make available to others and cannot guarantee that parties who have access to this information will respect your privacy or keep it secure. We are not responsible for the privacy or security of information you make publicly available, or for the accuracy, use or misuse of information you disclose or receive from third parties.

Third-party websites and links.

Our Site may contain links to websites or other online platforms operated by third parties. If you follow links to websites that are not affiliated with or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee or assume responsibility for the privacy or security of such websites, including the accuracy, completeness or reliability of the information found on those websites. Information you provide in public or semi-public places, including information you share on third-party social networking platforms, may also be viewed by other users of the Services and/or users of such third-party platforms without restriction as to its use by us or third parties. Our inclusion of such links does not automatically constitute an endorsement of the content of such platforms or their owners or operators, except as disclosed in the Services.

Children's Data

The Services are not intended for use by children, and we do not knowingly collect personal data from children. If you are a parent or guardian of a child who has provided us with their personal data, you can contact us using the contact details below and request that this data be deleted.

At the time this Privacy Policy comes into effect, we have no actual knowledge that we are ‘disclosing’ or ‘selling’ (as those terms are defined in applicable law) personal data from individuals under the age of 16.

Security and retention of your data

Please note that no security measures are perfect or impenetrable, and we cannot guarantee ‘perfect security.’ In addition, the information you send us may not be secure during transmission. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.

How long we retain your personal data depends on various factors, such as whether we need the data to manage your account, provide the services, comply with legal obligations, resolve disputes, or enforce other applicable contracts and policies.

Your rights

Depending on where you live, you may have some or all of the rights listed below in relation to your personal data. However, these rights are not absolute and only apply in certain circumstances. In certain cases, we may refuse your request to the extent permitted by law.

Right of access/information: You may have the right to request access to the personal data we hold about you, including details of how we use and share your data.

Right to erasure: You may have the right to request the erasure of the personal data we hold about you.

Right to rectification: You may have the right to request the correction of inaccurate personal data we hold about you.

Right to portability: You may have the right to obtain a copy of the personal data we hold about you and, in certain circumstances and with certain exceptions, to request that this data be transferred to a third party.

Right to object to sale, sharing or targeted advertising: You may have the right to instruct us not to ‘sell’ or “share” your personal data, or to object to the processing of your personal data for purposes that qualify as ‘targeted advertising’ under applicable data protection laws. Please note: If you visit our site with the ‘Global Privacy Control’ opt-out preference signal enabled, we will automatically treat this as a request to object to the “sale” or ‘sharing’ of information for the device and browser you are using to visit the site, depending on your location.

Restriction of processing: You may have the right to request that we stop or restrict the processing of your personal data.

Withdrawal of consent: If we rely on your consent to process your personal data, you may have the right to withdraw that consent.

Right to object: If we refuse to process your request, you may have the right to appeal our decision. You can do this by responding directly to our refusal.

Manage communication settings: We may send you promotional emails, and you can opt out of receiving these emails at any time by using the unsubscribe option displayed in our emails to you. If you unsubscribe, we may still send you non-promotional emails, such as those related to your account or orders.

You can exercise these rights as indicated on our site or by contacting us using the contact details provided below.

We will not discriminate against you for exercising any of these rights. We may need to collect information from you, such as your email address or account information, to verify your identity before we can respond to your request. In accordance with applicable law, you may appoint an authorised representative to make requests on your behalf to exercise your rights. Before we accept such a request from a representative, we must obtain proof from them that you have authorised them to act on your behalf. We may also need to confirm your identity directly with us. We will respond to your request in a timely manner, as required by applicable law.

Complaints

If you have any complaints about the way we process your personal data, please contact us using the contact details provided below. If you are not satisfied with our response to your complaint, depending on where you live, you may have the right to appeal our decision by contacting us using the contact details provided below or by submitting your complaint to your local data protection authority. For the EEA, you can find a list of the relevant data protection supervisory authorities here.

International users

Please note that we may transfer, store and process your personal data outside the country in which you live. Your personal data will also be processed by employees and external service providers and partners in these countries.

When we transfer your personal data to countries outside Europe, we rely on recognised transfer mechanisms such as the European Commission's standard contractual clauses or equivalent contracts from the relevant UK authority, unless the data transfer is to a country that has been determined to provide an adequate level of protection.

Contact

If you have any questions about our data protection practices or this privacy policy, or if you wish to exercise any of your rights, please call us or send us an email at info@eichenstein.it or contact us at Anselm-Pattis-Straße 24/1, Marling, BZ, 39020, IT.

In accordance with applicable data protection laws and unless expressly stated otherwise, we are the controller of your personal data.