Privacy Policy – Treevaset

At Treevaset, accessible via www.treevaset.com, we are committed to protecting your privacy and ensuring that your personal data is handled securely and transparently, in accordance with the General Data Protection Regulation (GDPR – EU Regulation 2016/679).

1. Data Controller

The data controller responsible for the processing of your personal data is:

Treevaset
Email: luca@treevaset.com

(Additional company or address details may be provided upon request.)

2. Personal Data We Collect

Depending on how you interact with our website, we may collect the following personal data:

  • Identification data: name, billing and shipping address, email address, phone number

  • Order and transaction data: products purchased, order history, invoices

  • Payment information: payment status and method (payments are processed securely by third-party providers; Treevaset does not store or access full card details)

  • Technical and usage data: IP address, browser type, device information, pages visited, interaction data

  • Communication data: emails or messages you send to us

  • Geolocation data: We may process approximate location data (such as country or region derived from IP address) during the checkout process to automatically calculate shipping costs and applicable taxes. This data is used solely for order processing purposes and is not used for marketing or tracking.

3. Purpose of Data Processing

Your personal data is processed for the following purposes:

  • To process and fulfill orders placed through our website

  • To manage payments, shipping, and customer service

  • To communicate with you regarding purchases or inquiries

  • To improve website performance, usability, and security

  • To send marketing communications, only where you have provided explicit consent

4. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Performance of a contract: processing necessary to fulfill an order

  • Legal obligation: compliance with tax, accounting, and regulatory requirements

  • Legitimate interests: improving our services, ensuring website security, and preventing fraud

  • Consent: marketing communications and non-essential cookies or tracking technologies

5. Sharing of Personal Data

We may share personal data with trusted third parties only where necessary, including:

  • Payment service providers (e.g. PayPal, WooCommerce Payments / Stripe)

  • Shipping and logistics providers

  • Hosting and IT service providers

  • Analytics and user experience tools (such as Google Analytics and Microsoft Clarity) to understand how visitors interact with our website and to improve usability

All third parties process personal data under contractual obligations and in compliance with GDPR.

6. Analytics & User Experience Tools

We use analytics and user experience tools to better understand how visitors interact with our website and to improve its performance and usability.

In particular, we use Microsoft Clarity, a service provided by Microsoft Corporation, which allows us to analyze aggregated usage data through heatmaps and session recordings.

Microsoft Clarity may collect information such as:

  • IP address (anonymized where applicable)

  • Device and browser information

  • Interaction data (clicks, scrolling, navigation patterns)

This data is used exclusively for analytical and optimization purposes.

Microsoft may process data outside the European Economic Area (EEA). Where this occurs, appropriate safeguards are applied, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

Microsoft Clarity is activated only after the user has provided consent via the cookie banner.

7. International Data Transfers

Some service providers involved in data processing may be located outside the European Economic Area. In such cases, personal data is transferred only where appropriate legal safeguards are in place, in accordance with GDPR.

8. Data Retention

Personal data is retained only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by applicable legal and tax regulations.

Approximate geolocation data used for shipping calculations is not stored beyond the checkout session.

9. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, loss, or misuse.

10. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access

  • Right to rectification

  • Right to erasure (“right to be forgotten”)

  • Right to restriction of processing

  • Right to data portability

  • Right to object to processing

  • Right to withdraw consent at any time

To exercise your rights, please contact us at luca@treevaset.com.

You also have the right to lodge a complaint with your local data protection authority.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The most recent version will always be available on our website.

12. Contact

For any questions regarding this Privacy Policy or the processing of your personal data, please contact: luca@treevaset.com