Privacy Policy
Last updated: January 2026 — James Forge SRL
James Forge SRL ("James Forge", "we", "us", "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store and protect your information when you visit our website (jamesforge.com) or use our services, in accordance with the EU General Data Protection Regulation (GDPR).
1. Data We Collect
We may collect the following categories of personal data:
- Identity data: first name, last name, username
- Contact data: email address, phone number, billing and shipping address
- Account data: login credentials, order history, wishlist and preferences
- Transaction data: payment details (processed by our payment providers), order amounts, purchase history
- Technical data: IP address, browser type, device information, operating system, referring URL
- Usage data: pages visited, time spent, click patterns, search queries
2. How We Use Your Data
We process your personal data for the following purposes:
- To process and fulfil your orders, including payment processing, shipping and customer support
- To create and manage your account on our platform
- To communicate with you about your orders, respond to inquiries and provide customer service
- To send marketing communications (only with your consent), including newsletters, promotions and product updates
- To improve our website, products and services through analytics and user research
- To prevent fraud, ensure security and comply with legal obligations
The legal bases for processing your data include: performance of a contract, your consent, our legitimate interests, and compliance with legal obligations (Article 6 GDPR).
4. Third Parties
We may share your personal data with trusted third-party service providers who assist us in operating our business:
- Payment processors: to securely process your transactions (e.g., Stripe, PayPal)
- Shipping partners: to deliver your orders (e.g., DHL, UPS, DPD)
- Analytics providers: to help us analyse website usage (e.g., Google Analytics)
- Email service providers: to send transactional and marketing emails
All third-party processors are contractually required to handle your data in accordance with GDPR and our instructions. We do not sell your personal data to third parties.
5. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing: Request that we limit the processing of your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests or direct marketing
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent
To exercise any of these rights, please contact us at info@jamesforge.com. We will respond within 30 days as required by law. You also have the right to lodge a complaint with your local data protection authority.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Order and transaction data: retained for the statutory retention period (typically 10 years for tax/accounting purposes under Italian law)
- Account data: retained for as long as your account is active, or as needed to provide services. You may request account deletion at any time
- Marketing data: retained until you withdraw consent or unsubscribe
- Technical/analytics data: typically retained for up to 26 months
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These include:
- SSL/TLS encryption for all data transmitted between your browser and our servers
- Secure storage of passwords using industry-standard hashing algorithms
- Regular security audits and vulnerability assessments
- Access controls to limit employee access to personal data on a need-to-know basis
While we strive to protect your data, no method of transmission over the Internet is 100% secure. We encourage you to use strong passwords and keep your account credentials confidential.
8. Contact
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:
See also our Terms & Conditions for information on orders, returns and general terms of use.
