Privacy Policy
We collect only what we need to run your course, and we never sell or share your data for advertising.
Who we are
Pizzamandolin is operated by Angelo Tassi, Italy, who is the data controller for the personal data described here. For any privacy question or request, write to [email protected] or use the contact form.
What we collect and why
- Account: your email address and a securely hashed password (we never store the password itself), plus the optional two-factor authentication secret if you turn 2FA on. Used to create and protect your account (contract).
- Learning progress: your level, streaks, review schedule and quiz answers. Used to run the spaced-repetition course (contract).
- Subscription status: your plan, its status and renewal date, and the Stripe customer and subscription identifiers. Used to give you access to paid content (contract, legal obligations).
- Contact messages: your name, email address and message when you use the contact form. Used to answer you (legitimate interest).
- Technical data: IP address, browser and request details processed by our hosting and security providers to deliver the site and block abuse (legitimate interest).
We do not use advertising, tracking pixels or third-party analytics cookies.
Payments
Payments are handled by Stripe, which acts as the merchant of record for your purchase. Your card details go directly to Stripe: we never see or store them. Stripe processes payment data under its own privacy policy.
Cookies
We use a single, strictly necessary session cookie that keeps you signed in. It is not used for tracking and does not require consent.
Who processes your data
- Oracle Cloud Infrastructure (United States): hosting of the application and database.
- Cloudflare: content delivery, TLS and protection against attacks.
- Stripe: payments and subscriptions.
- Resend (United States): delivery of account and notification emails.
- Zoho Mail (European Union): our contact inbox.
- Google Fonts and unpkg: delivery of the site's fonts and one JavaScript library, which means your browser contacts their servers.
Where data is transferred outside the European Economic Area, it is protected by the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
How long we keep it
Account and progress data are kept while your account exists. Billing records are kept as long as tax law requires. Contact messages are kept for up to 24 months. When your account is deleted, your data is removed from the live database immediately and disappears from our backups within 30 days.
Your rights
Under the GDPR you can ask to access, correct, delete or export your data, and to restrict or object to its processing. To delete your account or make any other request, write to [email protected] from the email address of your account: we reply within 30 days. You can also lodge a complaint with a data protection authority, such as the Italian Garante per la protezione dei dati personali.
Children and changes
Pizzamandolin is not intended for children under 16. If we change this policy, we will update the date at the top and, for significant changes, notify registered users by email.