Marketing Privacy Policy

Kanekalon Jumbo Hair Shop

Last updated: May 26, 2026

This Marketing Privacy Policy describes how TDS di Finardi Valeria, a sole proprietorship of Valeria Finardi, processes user personal data for marketing, newsletter, commercial communication, remarketing, retargeting, and campaign analysis purposes.

This Policy supplements the general Privacy Policy of the site and should be read together with the Cookie Policy, where applicable.


1. Data Controller

The Data Controller for personal data is:

TDS di Finardi Valeria
Sole proprietorship of Valeria Finardi
Via Giordano Alberghini, 16
44124 Ferrara (FE), Italy
VAT number: 02191020383
Email: thedreadmakersupplier@gmail.com

The Controller determines the purposes and methods of processing personal data collected for marketing activities, commercial communication, and promotion of products and services related to Kanekalon Jumbo Hair Shop, in compliance with Regulation (EU) 2016/679, known as GDPR, and applicable Italian law.


2. Purpose of Processing

The personal data collected may be used for the following purposes:

  • sending informative and promotional newsletters;

  • commercial communications related to products, services, offers, promotions, restocks, launches, and educational content;

  • sending communications related to similar or connected products to those purchased, within the limits permitted by applicable law;

  • remarketing and retargeting activities through digital tools, advertising platforms, social media, and tracking tools, with prior consent where required;

  • creation of custom or lookalike audiences on advertising platforms, within the limits permitted by law;

  • internal statistical analysis to evaluate campaign effectiveness, improve content, optimize user experience, and refine offered services;

  • management of promotions, contests, registration forms, waitlists, or commercial initiatives in which the user voluntarily decides to participate.

The data will not be used for purposes incompatible with those indicated in this Policy.


3. Legal Basis for Processing

The processing of personal data for marketing purposes is primarily based on the free, specific, informed, and unambiguous consent of the data subject, pursuant to Article 6, paragraph 1, letter a) GDPR.

Consent may be collected through:

  • newsletter subscription forms;

  • pop-ups on the website;

  • Shopify Forms or equivalent tools;

  • explicit selection at checkout;

  • account registration;

  • forms for promotions, quizzes, waitlists, contests, or voluntary initiatives;

  • cookie banners or consent management tools, for activities based on cookies, pixels, or similar technologies.

For sending commercial emails to existing customers related to similar products or services already purchased, the Controller may, where applicable, avail themselves of the exemption provided by Italian law regarding promotional communications via email. In any communication, the possibility to object or unsubscribe easily will always be guaranteed.

Consent can be revoked at any time, without affecting the lawfulness of processing carried out before the revocation.


4. Types of Data Collected

For marketing purposes, the following categories of personal data may be processed:

  • first and last name;

  • email address;

  • phone number, only if voluntarily provided and where necessary for specific communications;

  • country, city, or geographic area;

  • profession or activity declared by the user, for example, dreadmaker, braider, hairdresser, reseller, or creator;

  • purchase history on the website;

  • products viewed, added to cart, or purchased;

  • interactions with newsletters, promotional emails, ads, landing pages, or forms;

  • user expressed preferences;

  • technical data collected through cookies, pixels, or similar tools, such as IP address, online identifiers, device, browser, browsing events, and interactions with the website.

The Controller does not intentionally request special categories of personal data, such as data relating to health, political opinions, religious beliefs, sexual orientation, or other sensitive data according to applicable law.

Users are invited not to provide sensitive data through forms, emails, chats, or other contact channels.


5. Processing Methods

Personal data is processed primarily using electronic and digital tools, through platforms and services used for e-commerce management, commercial communications, advertising campaigns, and results analysis.

By way of example, processing may occur through:

  • e-commerce platform;

  • email marketing tools;

  • CRM systems or contact management tools;

  • advertising platforms;

  • social media;

  • analytics tools;

  • cookie consent management tools.

Access to data is limited to the Controller, any authorized individuals, and suppliers who support the activity, within the limits necessary for the performance of their respective functions.

Personal data is not sold to third parties.


6. Data Retention

Data processed for marketing purposes is retained until the user withdraws consent or requests deletion.

In any case, data may be retained for a maximum period of 24 months from the user's last significant interaction, unless a different term is required by law or necessary to protect the Controller's rights.

Significant interaction means, for example:

  • opening or clicking on a newsletter;

  • purchase on the website;

  • filling out a form;

  • participation in a promotion;

  • documentable interaction with commercial communications;

  • updating marketing preferences.

After this period, the data will be deleted, anonymized, or aggregated in such a way as to prevent user identification.

Data collected through cookies, pixels, or similar tools is retained according to the timelines indicated in the Cookie Policy or the consent management tool.


7. Disclosure of Data to Third Parties

Personal data will not be publicly disseminated or transferred to third parties for a fee.

Data may be communicated, to the necessary extent, to service providers related to marketing and e-commerce management activities, including:

  • e-commerce platforms;

  • newsletter and email marketing providers;

  • CRM service providers;

  • advertising platforms and social networks;

  • analytics and conversion measurement tools;

  • technical, tax, legal, or administrative consultants;

  • IT, hosting, security, and maintenance service providers.

These subjects may operate, depending on the case, as data processors, independent data controllers, or authorized processing subjects.

The Controller undertakes to use suppliers who offer adequate guarantees regarding the protection of personal data.


8. Transfer of Data Outside the European Union

Some providers of digital services, e-commerce platforms, email marketing tools, analytics, or advertising may process personal data also outside the European Union or the European Economic Area.

In such cases, the transfer will take place in compliance with Chapter V of the GDPR, through adequacy decisions, Standard Contractual Clauses, or other safeguards provided by applicable law.


9. Remarketing, Retargeting, and Personalized Advertising

With prior consent, where required, the Controller may use cookies, pixels, tags, or similar technologies to carry out remarketing, retargeting, and personalized advertising activities.

These activities may include:

  • displaying personalized ads on social media or advertising platforms;

  • conversion measurement;

  • audience segmentation;

  • excluding certain users from specific campaigns;

  • analysis of advertising performance;

  • optimization of marketing campaigns.

Users can manage or revoke consent through the cookie banner, website settings, or tools provided by individual platforms.


10. Newsletter and Unsubscription

Newsletter subscription is optional.

By subscribing to the newsletter, the user authorizes the Controller to send commercial, informative, and promotional communications related to products, offers, launches, restocks, educational content, and brand updates.

Users can unsubscribe at any time via:

Revocation of consent does not compromise the ability to make purchases on the website or receive communications necessary for order management.


11. Marketing Profiling

With prior consent, where required, user data may be used for segmentation and personalization of commercial communications.

For example, the Controller may send different content based on:

  • products purchased;

  • categories visited;

  • declared interests;

  • interactions with emails or ads;

  • abandoned carts;

  • user expressed preferences.

Such profiling has exclusively commercial and promotional purposes and does not produce legal effects on the user or similarly significantly affect them.


12. Data Subject Rights

Users can exercise their rights under Articles 15-22 GDPR at any time, including:

  • right of access to personal data;

  • right to rectification or update;

  • right to erasure;

  • right to restriction of processing;

  • right to object to processing for marketing purposes;

  • right to data portability;

  • right to withdraw consent at any time.

To exercise their rights, users can write to:

thedreadmakersupplier@gmail.com

The Controller will respond to requests within the timeframes provided by applicable law.

Users also have the right to lodge a complaint with the Italian Data Protection Authority if they believe that the processing of their data violates current regulations. The Authority indicates a complaint as the instrument through which the data subject can report a violation of personal data protection regulations. (Garante Privacy)


13. Data Security

The Controller adopts appropriate technical and organizational measures to protect personal data from unauthorized access, loss, alteration, disclosure, or unlawful use.

Measures adopted may include:

  • limited access to management platforms;

  • confidential credentials;

  • authentication systems;

  • security tools made available by used providers;

  • backups and technical protection measures, where available;

  • controlled management of data access.

Despite the adoption of adequate measures, no computer system can be considered completely risk-free.


14. Updates to this Policy

This Marketing Privacy Policy may be updated to comply with regulatory, technical, organizational, or service-related changes.

In case of substantial changes, users may be informed via email, notice on the website, or other suitable channel.

The updated version will always be published on this page with the date of the last update.