Legal

Privacy
Policy

Welcome to the privacy policy of estyl.ai. This policy will help you understand what data we collect, why we collect it, and what your rights are in relation to it.

Last updated: November 24, 2025Effective immediately

Summary

Data We Collect Automatically

We automatically collect data from you when you visit estyl.ai.

Trackers
Usage Data
Device information
IP address
Email address
Phone number
+3 more
Data You Give To Us

We collect the data you provide, for example when signing up for our newsletter.

Phone number
Email address
First name
Contact info
Shipping address
Billing address
+2 more

Owner and Data Controller

Company:Estyl Startup Innovativa S.r.l.

Via Giovanni Boccaccio 20, 20123, Milano

a.monego@estyl.ai

Types of Data Collected

Among the types of Personal Data that this Application collects, by itself or through third parties, there are:

phone number
email address
Trackers
Usage Data
first name
contact info
shipping address
billing address
physical address
purchase history
device information
username
IP address
language
geographic position

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.

Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application. Unless specified otherwise, all Data requested by this Application is mandatory and failure to provide this Data may make it impossible for this Application to provide its services.

Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.

Any use of Cookies – or of other tracking tools — by this Application or by the owners of third-party services used by this Application serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document.

Mode and Place of Processing

Methods of Processing

The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.

The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner.

Place

The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located. Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own.

Retention Time

Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.

Data Transfer Outside the EU

The Owner is allowed to transfer Personal Data collected within the EU to third countries (i.e., any country not part of the EU) only pursuant to a specific legal basis. Any such Data transfer is based on one of the legal bases described below.

Transfers to Countries with Adequate Protection

Personal Data may be transferred to countries that provide adequate levels of data protection as determined by the European Commission. These transfers do not require additional safeguards beyond the standard contractual protections.

Standard Contractual Clauses

Where transfers occur to countries that have not been determined to provide an adequate level of protection, the Owner ensures that appropriate safeguards are in place, including the Standard Contractual Clauses (SCCs) adopted by the European Commission. These clauses provide contractual guarantees that the data will be protected according to EU standards.

User Consent

In the absence of any other legal basis, data transfer to third countries may take place when the User has explicitly consented to such transfer after being informed of the possible risks. Users can inquire with the Owner to learn which legal basis applies to which specific service.

Data Transfer to the United States

If Personal Data is transferred to the United States, this Application participates in and complies with applicable data protection frameworks, ensuring that the transfer is conducted in accordance with the requirements set forth in EU data protection laws.

Personal Data processed: various types of Data as specified in the privacy policy of the service

Purposes of Processing

The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following:

Contacting the User
Building and running this Application
Social features
Managing contacts and sending messages
Managing landing and invitation pages
Collection of privacy-related preferences
Location-based interactions
Device permissions for Personal Data access
Data transfer outside the EU

Detailed Information on Processing

Building and Running this Application

Key components of this Application are built and run directly by the Owner by making use of various software and services.

Ghost with User Subscriptions

This Application is built and run by the Owner via a CMS software (Content Management System) called Ghost.

Personal Data processed: billing address, contact info, device information, email address, first name, physical address, purchase history, shipping address, Usage Data

Collection of Privacy-related Preferences

This type of service allows this Application to collect and store Users' preferences related to the collection, use, and processing of their personal information, as requested by the applicable privacy legislation.

Contacting the User

Users that provided their phone number might be contacted for commercial or promotional purposes related to this Application, as well as for fulfilling support requests. By registering on the mailing list or for the newsletter, the User's email address will be added to the contact list of those who may receive email messages containing information of commercial or promotional nature concerning this Application.

Device Permissions for Personal Data Access

This Application requests certain permissions from Users that allow it to access the User's device Data including Contacts permission, Phone permission, and Call permission.

Location-based Interactions

This Application may collect, use, and share User location Data in order to provide location-based services. Most browsers and devices provide tools to opt out from this feature by default. If explicit authorization has been provided, the User's location data may be tracked by this Application.

Managing Contacts and Sending Messages

This type of service makes it possible to manage a database of email contacts, phone contacts or any other contact information to communicate with the User. These services may also collect data concerning the date and time when the message was viewed by the User, as well as when the User interacted with it.

Social Features

This Application may use the Personal Data provided to allow Users to invite their friends and to suggest friends or connections inside it. Users may have public profiles that other Users can display.

Third-Party Services

This Application uses third-party services to provide certain functionality and enhance the user experience. Below is detailed information about each service and the data they process.

iubenda Consent Database

The iubenda Consent Database stores consent preferences and provides proof of consent for data processing activities. This service helps the Owner demonstrate compliance with privacy regulations by maintaining records of when and how Users provided their consent.

Personal Data processed: Trackers, Usage Data, consent records, timestamp of consent

GetSiteControl

GetSiteControl provides widgets for user engagement, including surveys, popups, and notification bars. This service is used to collect feedback and improve user experience on this Application.

Personal Data processed: Trackers, Usage Data, email address (if provided via widgets)

SumoMe

SumoMe (by Sumo Group) provides engagement tools including share buttons, list builders, and heat maps. These tools help understand user behavior and increase content reach.

Personal Data processed: Trackers, Usage Data, email address (if provided)

Mailchimp (The Rocket Science Group LLC, an Intuit company)

Mailchimp is an email marketing platform operated by The Rocket Science Group LLC, a subsidiary of Intuit Inc. This service is used to manage the mailing list and send newsletters and promotional communications to Users who have subscribed.

Personal Data processed: email address, first name, Usage Data (email opens, clicks)

Place of processing: United States - Privacy Policy

Firebase Dynamic Links (Google LLC)

Firebase Dynamic Links is a deep linking service provided by Google LLC. This service creates smart URLs that dynamically change behavior to provide the best experience across different platforms, directing users to the right content whether they have the app installed or not.

Personal Data processed: device information, Usage Data, IP address

Place of processing: United States - Privacy Policy

Newsletter Opt-in

By registering on the mailing list or for the newsletter, the User's email address will be added to the contact list of those who may receive email messages containing information of commercial or promotional nature concerning this Application. Your email address might also be added to this list as a result of signing up to this Application or after making a purchase.

Users can unsubscribe at any time by clicking the unsubscribe link in any email or by contacting the Owner directly. The Owner processes this data in compliance with applicable regulations and only for the purposes described in this privacy policy.

Personal Data processed: email address, first name, Usage Data

Privacy Controls

This Application provides Users with tools to manage their privacy preferences and control how their data is collected and processed.

iubenda Privacy Controls and Cookie Solution

This Application uses the iubenda Privacy Controls and Cookie Solution to collect and store Users' consent preferences related to the use of Cookies and other Trackers. This service allows Users to:

  • View and manage their consent preferences at any time
  • Accept or reject specific categories of Trackers
  • Withdraw previously given consent
  • Access detailed information about each Tracker used

Managing Your Preferences

You can access and modify your privacy preferences at any time by clicking on the privacy settings widget available on this Application. Your preferences are stored securely and will be respected across all sessions.

Personal Data processed: Trackers, consent preferences, timestamp of consent actions

Do Not Track Signals

This Application does not support "Do Not Track" requests. To determine whether any of the third-party services it uses honor the "Do Not Track" requests, please read their privacy policies.

Your Rights

For Users in the European Union

The Owner may process Personal Data relating to Users if one of the following applies:

  • Users have given their consent for one or more specific purposes
  • Provision of Data is necessary for the performance of an agreement with the User
  • Processing is necessary for compliance with a legal obligation
  • Processing is related to a task that is carried out in the public interest
  • Processing is necessary for the purposes of the legitimate interests pursued by the Owner

Rights Under GDPR

Users may exercise certain rights regarding their Data processed by the Owner:

Withdraw consent

Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.

Object to processing

Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.

Access their Data

Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data.

Verify and seek rectification

Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.

Restrict processing

Users have the right to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.

Have Data deleted

Users have the right to obtain the erasure of their Data from the Owner.

Data portability

Users have the right to receive their Data in a structured, commonly used and machine readable format and have it transmitted to another controller.

Lodge a complaint

Users have the right to bring a claim before their competent data protection authority.

For Users in the United States

This section applies to Users who are residents in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Montana.

Users may exercise certain rights regarding their Personal Information including:

  • The right to access Personal Information: the right to know
  • The right to correct inaccurate Personal Information
  • The right to request the deletion of your Personal Information
  • The right to obtain a copy of your Personal Information
  • The right to opt out from the Sale of your Personal Information
  • The right to non-discrimination

How to Exercise These Rights

Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month.

Information for Users in Switzerland

This section applies to Users in Switzerland, and, for such Users, supersedes any other possibly divergent or conflicting provisions contained in the privacy policy.

The processing of Personal Data is governed by the Swiss Federal Act on Data Protection (DPA) and, as of September 1, 2023, the revised Federal Act on Data Protection (nDSG/revDSG).

Legal Basis for Processing

The Owner may process Personal Data relating to Users in Switzerland if one of the following applies:

  • Users have given their consent for one or more specific purposes
  • Processing is necessary for the performance of a contract with the User or for pre-contractual measures
  • Processing is necessary for compliance with a legal obligation to which the Owner is subject
  • Processing is necessary to protect the vital interests of the User or of another natural person
  • Processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party

Rights of Swiss Users

Users in Switzerland have the following rights regarding their Personal Data:

Right to access

Users have the right to obtain information about the processing of their Personal Data and a copy of such data.

Right to rectification

Users have the right to request the correction of inaccurate Personal Data and the completion of incomplete data.

Right to data portability

Users have the right to receive their Personal Data in a structured, commonly used and machine-readable format.

Right to deletion

Users have the right to request the deletion of their Personal Data under certain circumstances.

Right to object

Users have the right to object to the processing of their Personal Data for reasons relating to their particular situation.

Right to withdraw consent

Users have the right to withdraw their consent at any time where processing is based on consent.

Supervisory Authority

Users in Switzerland may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC):

Federal Data Protection and Information Commissioner (FDPIC)

Feldeggweg 1, CH-3003 Bern, Switzerland

Website: www.edoeb.admin.ch

US Notice at Collection

This section provides additional information required under various US state privacy laws, including the categories of Personal Information collected and the purposes of collection.

Categories of Personal Information Collected

The following categories of Personal Information may be collected about you:

Identifiers

Information that identifies, relates to, describes, or is capable of being associated with you.

Name
Email address
Phone number
IP address
Username
Account name

Commercial Information

Records of personal property, products or services purchased, obtained, or considered.

Purchase history
Products viewed
Shopping preferences
Transaction details

Geolocation Data

Information about your physical location.

GPS coordinates
City/Region
Country
Approximate location from IP

Internet or Network Activity

Information regarding your interaction with this Application and other websites or applications.

Browsing history
Search history
Pages viewed
Interactions with content
Device information

Inferences

Inferences drawn from the above categories to create a profile about you.

Preferences
Characteristics
Behavior patterns
Interests
Predispositions

Purposes of Collection

The Personal Information described above is collected and used for the business or commercial purposes disclosed in the relevant sections of this privacy policy, including but not limited to: providing the Service, analytics, personalization, marketing communications, and compliance with legal obligations.

State-Specific Privacy Rights

In addition to the rights described above, residents of certain US states have additional rights under their respective state privacy laws.

California (CCPA/CPRA)

California residents have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:

  • Right to Know: Request disclosure of the categories and specific pieces of Personal Information collected
  • Right to Delete: Request deletion of Personal Information, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate Personal Information
  • Right to Opt-Out of Sale/Sharing: Direct businesses not to sell or share your Personal Information for targeted advertising
  • Right to Limit Use of Sensitive Personal Information: Limit the use and disclosure of Sensitive Personal Information to what is necessary
  • Right to Non-Discrimination: Not be discriminated against for exercising privacy rights

To exercise these rights, California residents may contact us using the details provided in this document or use our opt-out mechanisms.

Virginia (VCDPA)

Virginia residents have rights under the Virginia Consumer Data Protection Act (VCDPA), including:

  • Right to Access: Confirm whether a controller is processing your Personal Data and access such data
  • Right to Correct: Correct inaccuracies in your Personal Data
  • Right to Delete: Delete Personal Data provided by or obtained about you
  • Right to Data Portability: Obtain a copy of your Personal Data in a portable format
  • Right to Opt-Out: Opt out of targeted advertising, sale of Personal Data, and profiling

Virginia residents may appeal a decision regarding their request by contacting us through the contact details provided.

Colorado (CPA)

Colorado residents have rights under the Colorado Privacy Act (CPA), including:

  • Right to Access: Confirm whether a controller is processing your Personal Data
  • Right to Correct: Correct inaccuracies in your Personal Data
  • Right to Delete: Delete Personal Data you have provided or that has been collected about you
  • Right to Data Portability: Obtain your Personal Data in a portable, readily usable format
  • Right to Opt-Out: Opt out of targeted advertising, sale of Personal Data, and certain profiling

Colorado residents may designate an authorized agent to make requests on their behalf.

Connecticut (CTDPA)

Connecticut residents have rights under the Connecticut Data Privacy Act (CTDPA), including:

  • Right to Access: Confirm whether a controller is processing your Personal Data and access such data
  • Right to Correct: Correct inaccuracies in your Personal Data
  • Right to Delete: Delete Personal Data provided by or obtained about you
  • Right to Data Portability: Obtain a copy of your Personal Data in a portable format
  • Right to Opt-Out: Opt out of targeted advertising, sale of Personal Data, and profiling

Utah (UCPA)

Utah residents have rights under the Utah Consumer Privacy Act (UCPA), including:

  • Right to Access: Confirm whether a controller is processing your Personal Data and access such data
  • Right to Delete: Delete Personal Data you have provided
  • Right to Data Portability: Obtain a copy of your Personal Data in a portable format
  • Right to Opt-Out: Opt out of targeted advertising and sale of Personal Data

Utah residents should note that the UCPA does not provide a right to correct inaccurate Personal Data or a right to appeal.

Definitions and Legal References

Personal Data
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Usage Data
Information collected automatically through this Application, which can include: the IP addresses or domain names of the computers utilized by the Users, the URI addresses, the time of the request, the method utilized to submit the request to the server, the size of the file received in response, and other parameters about the device operating system and/or the User's IT environment.
User
The individual using this Application who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
Data Controller (Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application.
This Application
The means by which the Personal Data of the User is collected and processed.
Service
The service provided by this Application as described in the relative terms and on this site/application.
Cookie
Cookies are Trackers consisting of small sets of data stored in the User's browser.
Tracker
Tracker indicates any technology - e.g Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting - that enables the tracking of Users.
Sale of Personal Information
Sale of Personal Information means any exchange of Personal Information by the Owner to a third party, for monetary or other valuable consideration, as defined by applicable US state legislation. Please note that the exchange of Personal Information with a service provider pursuant to a written contract that meets the requirements set by applicable law does not constitute a Sale of Personal Information.
Sharing of Personal Information (for Targeted Advertising)
Sharing means any sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's Personal Information to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions between a business and a third party for cross-context behavioral advertising for the benefit of a business in which no money is exchanged.
Sensitive Personal Information
Sensitive Personal Information includes: (a) Personal Information revealing racial or ethnic origin, religious or philosophical beliefs, or union membership; (b) genetic data or biometric data processed for the purpose of uniquely identifying a natural person; (c) Personal Information concerning a person's sex life or sexual orientation; (d) Social Security, driver's license, state identification card, or passport numbers; (e) account log-in information with required security codes; (f) precise geolocation; (g) contents of mail, email, or text messages (unless the business is the intended recipient); and (h) genetic data.

Additional Information

Legal Action

The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services. The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.

System Logs and Maintenance

For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) or use other Personal Data (such as the IP Address) for this purpose.

Changes to This Privacy Policy

The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.

Should the changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User, where required.

This privacy policy relates solely to this Application, if not stated otherwise within this document.

For questions, contact us at a.monego@estyl.ai

Estyl. Like Magic