Covers login, profile, orders, wishlist, support, push tokens with prior consent, minimized technical logs and cancellation request.
Privacy Policy
How we process your personal data when you browse, purchase, ask for assistance or use the website's digital services.
These points summarize how the document applies to the experiences Next Solution Italia on the site and in the app.
The same information is linked by the website, Google Play, App Store and the App Document Centre.
You can change your preferences, ask for access to data or start the cancellation of the account from the mentioned paths.
Information on the processing of personal data
This statement clearly explains how Next Solution Italia processes the personal data of users who visit the site, buy products, create an account, request assistance or use the available digital functions.
1. What data can we process?
We only process the data needed to make the ecommerce work correctly, protect the site and offer assistance. Based on the actions you do, we can process:
- identification and contact data, such as first name, surname, email, telephone, billing address and shipping address;
- order data, such as purchased products, amounts, order status, tracking, returns, refunds and related communications;
- account data, such as technical credentials, preferences, saved addresses, order history and wishlist;
- payment data necessary for transaction management; complete card or payment instrument data are managed by authorised gateways and are not stored by Next Solution Italia;
- tax and administrative data necessary for billing, accounting and legal obligations;
- technical navigation data, such as IP address, security log, cookie identifiers, language preferences, device, browser and website interactions;
- messages, requests for assistance, questions about products and content sent by the user also through intelligent support or AI functions.
2. Why we process data
| Purpose | Legal basis | Concrete examples |
|---|---|---|
| Buying Management | Contract execution and pre-contractual measures | Trolley, checkout, order confirmation, shipping, tracking, after-sales assistance. |
| The customer account | Execution of the requested service | Access, saved addresses, recovery orders, favorites, historical purchases. |
| Payments and invoicing | Contract and legal obligations | Payment gateways, receipts, invoices, accounting and tax records. |
| Safety and prevention of abuse | Legal interest and security obligations | Firewall, account protection, technical logs, fraud prevention, checkout protection. |
| Customer Service | Contract, pre-contractual measures and legitimate interest | Responses to requests, complaints management, returns, guarantees, product information. |
| Statistics and site improvement | Consent when required or legitimate interest in aggregate technical measures | Performance analysis, UX improvement, understanding of the most visited pages. |
| Marketing and customization | User's consent when requested | Advertising cookies, campaigns, personalized content and marketing measurement. |
| AI functions and intelligent assistance | Pre-contractual measures, contract or legitimate interest | Product questions, information summary, support to purchase and improvement of answers. |
3. AI functions and intelligent support
The site may include artificial intelligence-based functions to help the customer better understand products, information content, compatibility and purchase information. The AI responses are designed as practical support and do not replace the official information in the product sheets, legal documents or assistance communications.
When you use these functions, avoid entering sensitive data or unnecessary information. If a request concerns an order, we will only use the information to manage the assistance.
4. To whom data can be communicated
The data can be communicated only when necessary and within the limits of the purposes indicated. Recipients may include:
- hosting, security, cache, firewall and technical infrastructure providers;
- platforms and services necessary for the operation of the ecommerce site;
- payment gateways, payment institutions and anti-fraud systems;
- logistic suppliers, couriers and dropshipping partners, including the subjects necessary to prepare and deliver the order;
- invoicing services, accounting, tax advisors and legal entities;
- transactional email providers and customer support;
- translation, analysis, marketing or measurement tools, only to the extent permitted and according to the cookie preferences of the user;
- public authorities, judicial authorities or legal entities, when required by law.
5. Transfers outside the European Economic Area
Some technology providers can also process data outside the European Economic Area. When this happens, we adopt instruments provided for by the GDPR, such as adequacy decisions, standard contractual clauses or additional measures, based on the service used and the level of risk.
6. How long do we keep the data?
We apply verifiable periods or criteria according to the finality. Upon expiry the data is deleted, anonymized or isolated when a rule or a dispute still imposes its retention.
| Category | Period or criterion applied |
|---|---|
| Orders, payments, invoices and accounts | As a rule, 10 years from the accounting record or the closure of the report, except for investigations, disputes or additional terms provided for by law. The complete data of the payment instrument remain at the gateway. |
| Accounts, profile and addresses | For the duration of the account. After a valid request, data not subject to storage obligations are deleted or anonymized without undue delay; the parts still needed are limited to the residual finality only. |
| Social, media, messages and offers | As long as the content or account remains active or until the cancellation requested by the user. Evidence related to reports, fraud, complaints or disputes remains only for the time necessary to manage and protect rights. |
| Assistance, returns, guarantees and complaints | Until the termination of the practice and thereafter for the period necessary to document the service and to manage the warranties, disputes or applicable requirements. |
| Telemetry app in the WordPress log | Maximum 50 events and no later 30 days. The code automatically deletes older events; tokens, real IPs and persistent identifiers are excluded or removed. |
| Access and Security Web Log | Daily ordinary rotation with storage of 14 days on the server; an extract can only be isolated for longer when it is used to manage an accident, fraud or request of the author. |
| Cookies and preferences | According to the Cookie Policy: the native consent preference lasts 180 days; the other tools follow the duration indicated in the panel or by the supplier. |
| Marketing | Until the withdrawal of consent or opposition; minimum evidence of choice may remain to demonstrate compliance with the request. |
The security copies are not used for ordinary purposes: they remain protected until the technical rotation and, if restored, are again subject to the cancellation requests already accepted.
7. User rights and response times
You can request access, rectification, deletion, limitation, data portability, opposition to processing and withdrawal of consent when processing is based on consent. You can write to [email protected] or use the page Contact us.
We confirm the taking charge and respond as a rule within one month. If the request is complex or numerous, the deadline can be extended up to two further months; in such case we communicate within the first month the extension and the reason. We only ask for the information strictly necessary to verify the identity.
You also have the right to lodge a complaint with the Data Protection Supervisor via the official website garanteprivacy.it.
8. Security
We apply technical and organizational measures to protect accounts, checkouts, payments, logistics and communications. No system is immune to risks, but we work to reduce unnecessary exposure, keep protections up to date and limit data processed to what is really needed.
Controllo 18+, tutela dei minori e minimizzazione dei dati
Per le schede dei prodotti riservati agli adulti il sito usa un controllo di accesso prudenziale. Nel percorso dichiarativo attuale non chiediamo né conserviamo documento di identità, fotografia, data di nascita o identità dell'utente. Dopo la conferma viene creato il cookie strettamente necessario nsi_age_assurance, che contiene una prova firmata e temporanea del livello di accesso, della scadenza e dell'integrità tecnica. Non contiene account, prodotto consultato, indirizzo IP o dati anagrafici.
Il cookie age_verified può essere emesso soltanto come segnale tecnico di compatibilità e gestione cache: da solo non autorizza mai l'accesso. Un rifiuto può essere ricordato temporaneamente tramite nsi_age_denied per evitare la riapertura immediata del controllo. La durata effettiva della prova positiva è sempre mostrata nell'interfaccia; alla data di questo aggiornamento è configurata in 12 ore sul dispositivo. L'utente può azzerarla eliminando i cookie del sito.
I contatori di funzionamento sono aggregati per giorno e non conservano IP, account, prodotto o identificatore di sessione. Il trattamento è limitato alla tutela dei minori, alla sicurezza del servizio e all'applicazione delle regole di accesso; i cookie tecnici sono usati senza finalità pubblicitaria. Se diventasse necessario un accertamento forte tramite un soggetto terzo, il sito dovrà ricevere soltanto una prova di maggiore età separata dall'identità e dalla destinazione d'uso, secondo i principi di minimizzazione e doppio anonimato applicabili.
Dettagli operativi, perimetro editoriale e differenze tra web e app sono descritti nella pagina Controllo 18+ e prodotti per adulti.
9. Updates
This information may be updated when services, providers, functionalities or regulatory obligations change. The version published on this page is the one currently applicable.
Google AdSense and Advertising
The website can use Google AdSense to show advertisements and finance content and services from the marketplace. Google and other advertising providers may use cookies or similar technologies to post ads, limit their repetition, measure their performance and, when permitted, customize them according to previous interactions with this or other sites.
Users can manage or revoke marketing consent from the site privacy panel. Google's personalized advertising preferences can also be managed by the Google account ad settings.
In the EEA area, the UK and Switzerland, personalized ads are only activated with a valid consent and with the tools required by the applicable Google rules.
Mobile app Next Solution Italia
The mobile app Next Solution Italia is the official native client of the nextsolutionitalia.it marketplace. The app allows you to view catalogs and products, use search, shopping cart and wishlists, access the customer account, view orders, open support requests and request account cancellation.
Data processed via app
Depending on the functions used, the app can process contact and account data, such as first name, last name, email, phone and billing or shipping addresses; purchase data, such as historical orders and order details; usage data, such as searches, shopping cart, wishlists, products consulted and interactions with ecommerce functions; content sent voluntarily, such as support requests and privacy requests; technical identifiers, such as session tokens, trolley tokens, customer identifiers and, only after consent to notifications, device push tokens.
The app can also send technical and diagnostic data necessary for operation and security, such as app version, platform, model or general device information, screen path, error log and crash or malfunction data. These data are used to fix problems, prevent abuse, keep the service stable and improve the app experience.
Finality of treatment
The data collected via app are used for authentication, account management, shopping cart, wishlist, orders, secure checkout on the website nextsolutionitalia.it, customer support, account cancellation requests, operational notifications, security, fraud prevention, accounting or legal compliance and technical analysis of the app's operation. The app does not use data for cross-app or cross-site advertising tracking and does not integrate SDK advertising into the current build.
Push Notifications
Push notifications are optional. If the user activates them from the app, a technical device token is registered to send operational communications related to the service, such as account updates, orders or assistance. The user can disable notifications from the device settings or app when the function is available.
Delete app account
You can request the deletion of your account and associated data from the App Account area, in the Privacy section, or from the public page Account app cancellation request. Some data may be stored for the time required by tax obligations, accounting, guarantee, security, anti-fraud or rights protection.
Crash reporting, mobile suppliers and storage
The current build uses Sentry for crashes and malfunctions, with the sending of predefined personal data disabled, HTTP request excluded, IP replaced and network breadcrumb or touch removed. The project uses the European region of the supplier and the storage follows the period configured in the relative service. In the technical register WordPress remain to the maximum 50 events for no more 30 days
Expo/EAS is used for the technical preparation and distribution of builds; Apple and Google process the data necessary for the store distribution and, when the user enables notifications, push delivery according to their respective information. Next Solution Italia records only the necessary technical token and revokes it or replaces it when the device is disconnected or the function is disabled.
NSI Play: partite, progressi e classifiche
Quando usi NSI Play con un account, trattiamo l'identificativo utente e della sfida, la data, lo stato necessario a riprendere il gioco, tempo, errori, aiuti, completamento, punteggio e gli eventi aggregati che formano XP, livello, badge, missioni, stagioni e maestria dei singoli talenti. Le risposte e le soluzioni restano private e sono usate soltanto per eseguire e convalidare la partita. Per gli ospiti il progresso resta normalmente nel browser o nella sessione e non viene collegato a un profilo cliente.
Il trattamento serve a fornire e sincronizzare il servizio richiesto, mantenere un registro XP coerente e prevenire manipolazioni, frodi o abusi. Le basi giuridiche sono l'esecuzione del servizio richiesto e il legittimo interesse alla sicurezza e al fair play. La pubblicazione nelle classifiche è separata e facoltativa: si basa sulla scelta dell'utente, è inizialmente disattivata e mostra soltanto alias e dati aggregati previsti dalla modalità. La revoca impedisce nuove visualizzazioni pubbliche senza cancellare il profilo privato.
Il coach NSI Play calcola un suggerimento a basso impatto usando soltanto risultati aggregati, attività recente e talenti già provati o ancora da scoprire. Non usa acquisti, contenuti social o categorie sensibili e non prende decisioni con effetti legali o analogamente significativi. I dati operativi restano per la durata dell'account; alla cancellazione, partite, profilo, XP, badge, preferenze classifica e dati collegati vengono rimossi dalle tabelle operative, salvo copie di sicurezza protette fino alla normale rotazione e limitate agli obblighi descritti nella sezione 6.
Puoi consultare regole, soglie, bonus e criteri nella pagina Regole e Trasparenza NSI Play ed esercitare i diritti indicati nella sezione 8 di questa informativa.
Google customer reviews
After a purchase, the confirmation page can show the optional Google Customer Reviews form. To present the choice and, only in case of accession, schedule the invitation to the review after the estimated delivery, the form receives the Merchant Center ID of Next Solution Italia, a unique reference of the order, the email address used for the confirmation, the country of delivery, the estimated delivery date and, when available, the GTIN of the purchased products.
Participation in the review is voluntary and does not affect order, payment, delivery, assistance, warranty or withdrawal. Next Solution Italia does not use this data to add the customer to promotional lists and records for the technical health of the module only aggregated counters and operating dates, without email, order number or other customer data. Google processes the data received according to its own Privacy Policy and the conditions of the Google Customer Reviews program.
Google and Sign in with Apple access
Access with Google and Sign in with Apple is optional. You can continue to use the site credentials. During the connection we do not receive the provider's password: we verify a signed identity token and treat the provider's stable identifier, the verified email address, the date of the link and, when available, the name and surname. Google may communicate first and last names; Apple normally only communicates them to the first authorization and may provide a private forwarding email address.
This data is used to create or connect the customer account, authenticate access, prevent abuse and maintain consistent orders and assistance. The legal basis is the execution of the requested service and, for security and fraud prevention, the legitimate interest of the owner. We do not keep the Google access token beyond the authentication flow. For Apple, we keep in the encrypted vault of the site the only refresh token needed to revoke the link when the account is deleted; it is not used for profiling or marketing.
The link remains as long as the account is active or as long as you ask for its removal.States and security nonce are disposable and expire in a few minutes; the Google technical cookie used to compare the status expires after about 12 minutes. For processing of your own competence consult the information of Google e Apple.
Google Pay and Apple Pay via Nexi XPay
When Google Pay or Apple Pay are available in the checkout hosted by Nexi XPay, card data, wallet token and payment authentication are handled by Nexi and the selected wallet. Next Solution Italia receives only the information necessary to connect the outcome to the relevant order, as transaction identifier, amount, status, circuit or anti-fraud reference and method: the complete card data do not pass through the site.
The processing is necessary to perform the contract, manage refunds and disputes, prevent fraud and fulfil accounting obligations. We keep the references of the transaction together with the order according to the periods indicated in the 6 section; Nexi, Google and Apple apply their information to the processing of their respective expertise.
Social Marketplace, moderation and messages
Social marketplace functions may process data related to public profile, ads, articles, messages, favorites, reports, moderation, seller status, reputation, support requests and marketplace security. Operating rules are available on the page Social Marketplace and App. The data is used to provide the service, protect users and sellers, prevent abuse, handle complaints and comply with legal obligations.
Payments Nexi XPay, credit sellers and technical logs
In the current checkout customer receipts are managed via Nexi XPay connected to the Intesa Sanpaolo banking report of Next Solution Italia. Nexi manages the complete data of the card or payment instrument. Next Solution Italia retains only the information necessary to link order, outcome of transaction, accounting, reimbursement, assistance and reconciliation, according to applicable contractual, tax, anti-fraud and security obligations.
Automatic credits to third-party sellers are not active. The site, WordPress and app do not ask for IBAN or identity documents for payouts. Before a future activation will be indicated the regulated provider, the required data, the finality, the retention time and the onboarding path; bank details and documents must remain with the responsible provider unless specifically required by law.
The gateway's technical logs are limited to the events necessary for security and diagnosis. Bodies of payment responses, registry, contact details and unnecessary identifiers are removed before registration; access and preservation are limited to the time strictly necessary for technical control, accidents, anti-fraud or legal obligations.
Klarna: payments, access and additional order data
To offer Klarna payment methods, quick checkout, information messages and optional function Klarna Bank AB (publ). The access function is not mandatory: you can always register or log in with the usual methods of the site.
When you choose "Log in with Klarna" we ask after the confirmation shown by Klarna full name, email address, phone number and billing address, necessary to create or link the WooCommerce account of Next Solution Italia correctly. We do not request through this function date of birth, shipping address, country or language preference.
During the purchase we can also send Klarna the additional data necessary for anti-fraud assessment, risk management and order management and after-sales assistance: the recipient's name, e-mail, telephone and shipping address, together with the order details. The complete payment data is collected in the protected forms of Klarna and is not stored by Next Solution Italia.
The processing is linked to the execution of the requested service, the prevention of fraud and the applicable legal obligations. Klarna processes the data according to its own Information about privacy. You can exercise the rights described in this information by contacting Next Solution Italia or Klarna for the treatments of its competence.
Facebook, Instagram and Meta services
Next Solution Italia can use the official Meta Platforms Ireland Limited APIs to update the catalog, publish on Page Facebook and on the account Instagram professional content related to products, articles, ebooks and website initiatives. The automatic publication uses only public information in the catalogue or editorials.
Instagram Business Login is used to manage the professional account of Next Solution Italia and, optionally, to allow the marketplace profiles of type Company or Creator to connect their account Instagram professional. It is not a consumer access system for personal Instagram accounts. For marketplace profiles we only require the basic professional identity and keep separately for each user, with AES-256-GCM encryption, tokens, technical identifiers, usernames, account type and expiration. We do not receive or retain the password Instagram.
The Instagram link of the marketplace profile can be revoked at any time from the account area. At the disconnect we delete tokens and local technical data and try to revoke the authorization at Instagram. The simple link does not authorize publications, automatic messages or advertising campaigns on behalf of the profile.
Permissions Instagram may allow organic publication, statistics, comment management, Direct mentions and messages. The webhook checks Meta's signature and records only minimum technical data on the reception of events; The content of messages and comments shall be treated only when necessary for assistance, moderation or response requested by the user.
Only after optional consent to the category Marketing, the Meta Pixel and the API Conversions can communicate to Meta, from the browser and the server, page and product views, catalog identifiers, added to the shopping cart, start the checkout and purchases with amount and currency. Technical data of the browser and device, IP address, normalized contact data and subjected to hashing and Meta cookies can be processed as _fbp e _fbc, for measurement, attribution and correspondence between site and catalog Facebook/Instagram. In the absence or withdrawal of consent scripts are blocked, server events are not sent and the cookies are deleted by the preferences manager.
Optional function “Continua con Facebook” Instead, it allows buyers to create, connect or access the Next Solution Italia account. After consent we receive ID Facebook, name and email, but not password, list of friends, private posts or messages.
You can revoke Meta links or request deletion from the page Deleting account. For more information, please consult theMeta's Privacy PolicyThe legal basis is consent, execution of the requested service and legitimate interest in security and moderation.
Misurazione pseudonima degli account
Se accedi al tuo account e hai espresso il consenso Analytics, associamo agli eventi di Google Analytics 4 un identificatore opaco generato sul server con hash crittografico a chiave. Non contiene email, telefono, nome o ID WordPress e non viene registrato come dimensione personalizzata.
Con lo stesso consenso registriamo gli eventi consigliati login e sign_up e il solo metodo generale usato (password, Google, Apple, Facebook o passkey). Nell’ambito dello User-ID e degli eventi di accesso non trasmettiamo credenziali, indirizzi email, nomi, telefoni, identificativi del provider o ID WordPress.
Lo User-ID viene inviato solo dopo il consenso Analytics, può essere revocato dalle Preferenze privacy e viene escluso quando navighi senza account. Google Analytics e l’export eventi BigQuery lo trattano per statistiche aggregate, continuità tra dispositivi e qualità della misurazione; la conservazione degli eventi della proprietà è impostata a 14 mesi, fatti salvi periodi inferiori o obblighi di legge.
Conversioni avanzate e dati forniti dagli utenti. Solo quando completi un ordine e hai espresso il consenso marketing, possiamo trasmettere a Google dati di contatto normalizzati e sottoposti ad hash SHA-256 (email, telefono, nome e cognome), insieme a paese e codice postale, per misurare e deduplicare la conversione e migliorare la corrispondenza con i servizi Google collegati. Il rilevamento automatico dei dati nei moduli è disattivato: il sito prepara unicamente il payload esplicito relativo all’ordine. I segnali vengono bloccati quando ad_storage, ad_user_data o ad_personalization non sono concessi; puoi revocare il consenso per gli invii futuri dalle Preferenze privacy.
For questions about personal data, orders, returns or accessibility you can write to [email protected] or use the help page.
