EXTENDED COOKIE AND TRACKING TECHNOLOGIES POLICY

Pursuant to Directive 2002/58/EC (so-called “ePrivacy”), Regulation (EU) 2016/679 (“GDPR”), and the Guidelines on cookies and other tracking tools issued by the Italian Data Protection Authority (Provision no. 231 of June 10, 2021).

Last updated: 20th April 2026

1. Scope and Introduction

This Cookie Policy governs the use of tracking technologies on the domain luccafan.com and all related subdomains connected to the e-commerce infrastructure (hereinafter, jointly, the “Website” or “Site”). This document aims to transparently inform Users about the nature, purposes, and management methods of cookies and similar technologies installed directly by the Data Controller (Luccafan di Barbara Lerici) or by authorized third parties.

These regulations apply to all citizens and legal permanent residents of the European Economic Area (EEA) and Switzerland.

2. Definitions: What are Cookies and other Technologies?

To ensure proper functioning and an optimal user experience, our Website employs various tracking technologies:

  • Cookies: Small text files (typically consisting of letters and numbers) that websites visited by the User send and store on the User’s device (computer, tablet, smartphone), to be transmitted back to the same sites upon the next visit. Cookies allow the Website to remember the User’s actions and preferences (such as login data, preferred language, items in the shopping cart) so they do not have to be re-entered at each access.
  • Scripts: Fragments of computer code used to make our Website function correctly and interactively. Such codes are executed on our servers or directly on the User’s device to enable specific features (e.g., support chat, dynamic price updates).
  • Web Beacons (or Pixel Tags): Small graphic images or invisible code snippets integrated into the Website’s pages, used to monitor traffic, interactions, or conversions (e.g., completed purchases). Pixels often work in conjunction with cookies to record User behavior for statistical or advertising purposes.

3. Legal Classification of Cookies Used

Under current regulations, cookies are distinguished by their duration (session or persistent), their origin (first-party or third-party), and, most importantly, their purpose. On our Website, we use the following legal categories:

3.1 Technical and Functional Cookies (Strictly Necessary)

The technical storage of or access to these cookies is strictly necessary for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary for the Data Controller to provide a service explicitly requested by the User (e.g., the e-commerce infrastructure). The installation of such cookies does not require the User’s prior consent (Art. 122, paragraph 1, of the Italian Privacy Code).
Examples of use: Keeping products in the cart during checkout, maintaining authentication status (Single Sign-On), saving cookie consent preferences (e.g., Complianz plugin), preventing fraud and cyber-attacks via Google reCAPTCHA or Cloudflare.

3.2 Statistical and Analytical Cookies

The technical storage or access used exclusively for statistical purposes. These cookies allow the Data Controller to quantify visits, analyze traffic, and understand how Users interact with the Website (most visited pages, dwell times, conversion rates).
If the collected data are appropriately anonymized (e.g., IP address masking) and the third-party provider undertakes not to cross-reference the information with other data at its disposal, these cookies are treated equally to technical cookies. In the absence of such guarantees, the User’s explicit consent is required.
Examples of use: Google Analytics, Smartlook (recording UX interactions, clicks, and scrolls).

3.3 Profiling, Marketing, and Tracking Cookies

The technical storage or access is necessary to create user profiles to send advertising messages in line with the preferences expressed by the user while browsing the web, or to track the User on this or different websites for similar marketing purposes (Retargeting/Remarketing). Given the intrusiveness of such devices in the private sphere of Users, their installation always requires the prior, explicit, and unambiguous consent of the User.
Examples of use: Meta Pixel (Facebook/Instagram), TikTok Pixel, Pinterest Tag.

3.4 Third-Party Cookies and External Services

The Website integrates features developed by third parties within its pages, such as icons and preferences expressed on social networks, map management software (Google Maps), video platforms (Vimeo), or gateways for secure financial transactions (PayPal, Amazon Pay). These cookies are sent from third-party domains and partner sites. The Data Controller of the Website has no direct access to or control over such cookies, for which reference should be made to their respective and autonomous privacy policies (see Section 4).

4. Details of Services and Installed Cookies

Below is a detailed mapping of the main service providers and the types of cookies that may be placed on the User’s device while browsing our Website:

  • WordPress and E-commerce Platform (First Party – Technical): Cookies necessary for the functioning of the CMS. They preserve session status (wordpress_logged_in_*, PHPSESSID), language settings (wp_lang), and security tokens (_abck, csrf_session_id). Expiration: Session or up to 1 year. Data is not shared.
  • Consent Management / Complianz (First Party – Technical): They record the User’s choice regarding the acceptance or rejection of cookies (cmplz_consenttype, cmplz_preferences, cmplz_marketing, etc.). Expiration: 365 days. No consent required for installation.
  • Google Analytics (Third Party – Statistical): Cookies (_ga, _gid, _gat_gtag_*) used to generate reports on User interactions. Expiration: From 1 minute to 2 years. Data transfer to USA (subject to Data Privacy Framework).
  • Google reCAPTCHA and Fonts (Third Party – Security/Technical): Anti-spam filter for form validation and typography loading (rc::a, rc::b, rc::c). They collect the IP address and hardware/software data to distinguish a human from an automated bot.
  • Meta / Facebook / Instagram (Third Party – Profiling/Marketing): The Meta Pixel (e.g., _fbp, actppresence cookies) enables measuring, optimizing, and building audiences for ad campaigns. It tracks events such as conversions and cart abandonments. Requires prior consent.
  • TikTok Pixel (Third Party – Profiling/Marketing): Tracks views and actions (tt_webid, tt_webid_v2, ttwid) to process customized advertising metrics on the TikTok platform. Requires prior consent.
  • WhatsApp (Third Party – Functional): Cookies to enable the chat widget and customer support (wa_lang_pref, wa_ul).
  • Payment Gateways e.g., PayPal (Third Party – Security/Technical): Cookies and Local Storage (__paypal_storage__) required during checkout to ensure transaction security and prevent financial fraud. They operate as Independent Data Controllers.

5. Consent Management and Withdrawal

In compliance with legal requirements, upon first access to any page of the Website, a banner (Consent Management Platform) containing a brief notice is presented. Through this banner, the User has the option to:

  • Accept all cookies, including profiling and marketing ones.
  • Reject all non-necessary cookies (keeping only technical ones active).
  • Customize choices in a granular manner, consenting only to specific categories (e.g., only Statistics, but not Marketing).

Right of withdrawal: The User may change their preferences or withdraw previously given consent at any time. To do so, simply click on the floating icon or the link named “Manage Cookie Consent”, always available in the footer of the Website.

6. Disabling Cookies via Browser Settings

In addition to the management panel on the Website, the User can configure their web browser to automatically accept or reject all cookies, or to receive an on-screen warning whenever a cookie is proposed. Below are the links to the official instructions for the main browsers:

Warning: The total or partial disabling of technical cookies can severely compromise the use of the Website’s functionalities reserved for registered users or the ability to complete a purchase procedure via the electronic cart. The disabling of profiling or third-party cookies, conversely, does not in any way prejudice the normal navigability and usability of the Website.

7. Exercise of the Data Subject’s Rights

Pursuant to the GDPR, the User (Data Subject) enjoys the right of access to their data, the right to obtain its rectification, erasure (the so-called right to be forgotten), restriction of processing, and portability. They also have the right to object to processing for marketing or profiling purposes. To learn about these rights in detail and the methods of exercising them, please refer to the full reading of our Privacy Policy.



DEFINITIONS AND LEGAL REFERENCES

Cookies

Cookies are Tracking Technologies consisting of small portions of data stored within the User’s browser.

Tracking Technology

Tracking Technology refers to any technology – e.g., Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting – that enables the tracking of Users, for example by collecting or storing information on the User’s device.

Personal Data (or Data)

Any information that, directly or indirectly, also in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data

Information collected automatically through this Website (also from third-party applications integrated into this Website), including: the IP addresses or domain names of the computers utilized by the User who connects with this Website, the URI (Uniform Resource Identifier) addresses, the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s response (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the visitor, the various time details per visit (e.g., the time spent on each page) and the details about the path followed within the Website with special reference to the sequence of pages visited, the parameters about the device operating system and the User’s IT environment.

User

The individual using this Website who, unless otherwise specified, coincides with the Data Subject.

Data Subject

The natural person to whom the Personal Data refers.

Data Processor (or Processor)

The natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Controller, as described in this privacy and cookie policy.

Data Controller (or Controller)

The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and the instruments adopted, including the security measures concerning the operation and use of this Website. The Data Controller, unless otherwise specified, is the owner of this Website.

This Website (or Site)

The hardware or software tool by which the Personal Data of the User is collected and processed.

Service

The Service provided by this Website as defined in the relative terms (if available) on this Site.

European Union (or EU)

Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.

Legal References

Unless otherwise specified, this policy relates exclusively to this Website.

Document summary