privacy policy
General Information
This Privacy Policy explains how Rock & Ride der M.W. collects, uses, and protects your personal data when you visit our website, create an account, place an order, or otherwise interact with our Services. The terms “we”, “us” and “our” refer to Rock & Ride der M.W.
For the purposes of the General Data Protection Regulation (GDPR), we are the data controller responsible for the processing of your personal data.
Our online store is technically operated on the Shopify platform, which provides the infrastructure necessary to host the website and process orders.
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.
Personal Data We Collect
When you use our website or place an order, we collect personal data that is necessary to provide our Services. This includes, in particular, your name, billing and shipping address, email address, phone number, and order details.
If you place an order, we also process transaction-related information, such as the products purchased, returns, and refunds. Payment information is processed securely by our payment service providers and is not stored by us.
If you create a customer account, we process the account details you provide. When you contact us, we process the information contained in your communication.
In addition, technical data such as your IP address, browser type, device information, and website usage data may be collected automatically through cookies and similar technologies.
How and Why We Use Your Personal Data
We process your personal data primarily to fulfill our contractual obligations. This includes processing orders, arranging payment, shipping products, handling returns, and providing customer support.
We also use personal data to improve and optimize our website and Services, to ensure website security, to prevent fraud, and to comply with legal obligations such as accounting and tax requirements.
Where legally permitted, we may use your data to communicate with you about our products or services. Marketing communications are only sent where allowed by law and, where required, based on your consent. You may withdraw your consent at any time.
Legal Basis for Processing
Your personal data is processed in accordance with the GDPR and only where a lawful basis applies. This includes the performance of a contract, compliance with legal obligations, our legitimate interests in operating and securing our business, or your consent where required.
Sharing of Personal Data
We only share your personal data where this is necessary to operate our business and provide our Services. This includes sharing data with Shopify, payment service providers, shipping and logistics partners, and IT service providers.
All service providers act on our behalf and are required to process your data in compliance with applicable data protection laws.
We do not sell your personal data.
International Data Transfers
Some service providers may be located outside the European Union or European Economic Area. In such cases, personal data is transferred only where appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or equivalent legal mechanisms.
Cookies and Similar Technologies
We use cookies and similar technologies to ensure the proper functioning of our website, to analyze usage, and to improve user experience. Where required by law, cookies are used only with your consent.
You can manage your cookie preferences through our cookie banner and your browser settings. Further information is provided in our Cookie Policy.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal obligations, or to resolve disputes. Retention periods depend on the type of data and applicable legal requirements.
Your Rights Under GDPR
If you are located in the European Union or European Economic Area, you have the right to access your personal data, request correction or deletion, restrict or object to processing, and request data portability where applicable.
Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
To exercise your rights, please contact us using the details provided below. We may need to verify your identity before processing your request.
Right to Lodge a Complaint
If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with your local data protection authority. In Italy, this is the Garante per la Protezione dei Dati Personali.
Data Security
We take appropriate technical and organizational measures to protect your personal data. However, no online transmission or storage system can be guaranteed to be completely secure.
Children’s Privacy
Our Services are not intended for children, and we do not knowingly collect personal data from children under the age of legal consent.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or our Services. The most current version will always be available on this page.
Last updated: January 2026