Skip to content

Privacy Notice

Version 3 — in force since Sep 13, 2026

Courtesy translation: in case of divergence the Italian text prevails. Read the Italian version

(EU Regulation 2016/679 — GDPR, Articles 13 and 14)

2.1 Data controller

NEXXST di Falconati Barbara, Via Alessandro Volta 12, 21020 Varano Borghi (VA), Italy. VAT no. 04132920127 — REA VA-404194. Certified email (PEC) BARBARA.FALCONATI@PEC.IT. Privacy contact: privacy@registrotcg.com.

No DPO has been appointed: the activity does not fall within the cases in which Article 37 GDPR makes one mandatory.

2.2 Please note: this notice covers two different things

For the data of restorers and of visitors to the site, we are the controller, and that is what this document is about.

For the data of end clients that a studio uploads into Registro, the controller is the studio, and we are the processor. That relationship is governed by the agreement in chapter 4, not by this notice. If you are a collector and want to know how your data is processed, the party to contact is the studio to which you entrusted your cards, and its privacy notice is the one it gave you.

2.3 What data we process, and why

DataWhyLegal basisFor how long
Name, email, password (in encrypted form), studio detailsproviding the serviceperformance of the contract — Art. 6(1)(b)duration of the contract + 30 days
Billing data, VAT number, payment historytax obligationslegal obligation — Art. 6(1)(c)10 years
Technical logs, IP address, access datasecurity, fault diagnosislegitimate interest — Art. 6(1)(f)12 months
Emails to privacy@ or to supportreplying to youlegitimate interest — Art. 6(1)(f)24 months
Commercial emails about the productinforming you of newsconsent — Art. 6(1)(a)until withdrawn
Browsing data on the public pages (pages viewed, where you came from, cookie identifiers)measuring visits and learning which ads bring studios to sign upconsent — Art. 6(1)(a)see the cookie policy; withdrawable at any time

We do not process special categories of data (Art. 9) and we do not take automated decisions concerning you. Only if you accept marketing cookies may the advertising platforms listed in section 2.4 use browsing data from the public pages to show Registro ads.

2.4 Who we share data with

Only with providers we need to run the service, all appointed as processors under Article 28:

ProviderWhat it doesWhere the data is
Supabasedatabase and authenticationIreland (EU)
Cloudflare R2storage of photographsEuropean Union (WEUR)
Netlifydelivery of the application and running its server functions, such as composing PDFsUnited States
Resendsending emailsIreland (EU) — region eu-west-1
StripepaymentsIreland (EU) and United States
Klaviyosending the newsletter, only to subscribersUnited States

On transfers outside Europe. Netlify, Stripe and Klaviyo involve a transfer to the United States. Resend sends from the eu-west-1 region (Ireland), but the provider is headquartered in the United States and may access the data for support purposes: the transfer must therefore be declared all the same. It takes place on the basis of the Standard Contractual Clauses approved by the European Commission and, where the provider is certified, the Data Privacy Framework. You can ask us for a copy of the safeguards in place by writing to privacy@registrotcg.com.

We do not sell data.

Measurement and advertising, only if you accept them

On the public pages of the site — never in the app, the client area or the studios' pages — and only with your consent in the cookie banner, we use these tools:

ProviderToolWhere
Google Ireland LtdGoogle Analytics, Google AdsEU, with transfer to the United States
Microsoft Ireland Operations LtdMicrosoft ClarityEU, with transfer to the United States
Meta Platforms Ireland LtdMeta pixelEU, with transfer to the United States
TikTok Technology LtdTikTok pixelIreland, with access from third countries
OpenAIOpenAI Ads pixelUnited States

Google Analytics and Microsoft Clarity measure visits on our behalf. For advertising, Google, Meta, TikTok and OpenAI also use the data as independent controllers, under their own privacy policies; with Meta we are joint controllers, limited to the collection and transmission of data through the pixel. Transfers rely on the Data Privacy Framework for certified providers and, for the others — TikTok included — on the Standard Contractual Clauses. Cookies, durations and how to withdraw consent are in the cookie policy. After you sign up, if you accepted marketing, Meta, TikTok and OpenAI receive only the hashed form (SHA-256) of your email, never the address.

If you write to us on WhatsApp, the message goes through WhatsApp Ireland Ltd under its terms.

2.5 Your rights

You have the right of access, rectification, erasure, restriction, portability and objection (Articles 15-22 GDPR), and the right to withdraw a consent already given at any time, without affecting the lawfulness of what was done before.

You exercise them by writing to privacy@registrotcg.com. We reply within 30 days.

If you believe the processing breaches the law you may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (garanteprivacy.it) or with the authority of your country of residence.

2.6 Security

Data encrypted in transit and at rest, access limited to those who need it, isolation between studios enforced by the database and not by application code, passwords stored only in non-reversible encrypted form. Photographs have no public addresses: they can only be reached through signed links that expire.

No measure makes a system impregnable. In the event of a breach that poses a risk to your rights, we notify you and the Authority within the legal deadlines.

Back to the home page