Privacy Policy

What data we collect and why

We do not store personal data on our own servers. We do not use cookies directly. The data we process is limited to what is necessary for the services described below.

  • If you subscribe to our newsletter, we collect your email address via Mailchimp. The legal basis is your consent, which you can withdraw at any time by using the unsubscribe link in any newsletter or by contacting us.
  • If you purchase a product, your name, email, billing address, and payment details are collected and processed by Paddle, our payment provider and merchant of record. The legal basis is the performance of a contract. Paddle's own privacy policy applies to data it processes: paddle.com/legal/privacy.

Third-party services

We rely on the following services, each of which may process data on our behalf:

  • Paddle — payment processing and order fulfilment for product purchases. Paddle acts as merchant of record and may set cookies strictly necessary to complete a transaction.
  • Mailchimp — newsletter distribution. Makes use of browser cookies and usage data. Only applies if you opt in.
  • Vimeo — video streaming. We have requested this service to not track our users.
  • Sanity CDN — image hosting and delivery.
  • Vercel Analytics — anonymous, cookieless traffic analytics.

Cookies

We do not set any cookies ourselves. Some third-party services listed above may set cookies when you interact with them. To manage or remove cookies, use your browser settings or follow the instructions on All About Cookies.

Data retention

  • Newsletter emails are retained in Mailchimp until you unsubscribe or request deletion.
  • Purchase records are retained by Paddle in accordance with their data retention policy and applicable tax and accounting obligations.
  • We do not maintain our own database of personal data.

Your rights

Under the EU General Data Protection Regulation (GDPR), you have the right to:

  • access the personal data we hold about you
  • request correction of inaccurate data
  • request deletion of your data
  • withdraw consent at any time, where processing is based on consent
  • object to processing based on legitimate interest
  • request restriction of processing
  • data portability
  • lodge a complaint with your local data protection authority

To exercise any of these rights, contact support@hidden-mountain.com. We will respond within 30 days.

Data transfers

Some of the third-party services listed above may process data outside the European Economic Area. Where this occurs, we rely on the safeguards provided by each service (such as Standard Contractual Clauses or adequacy decisions).

Changes to this policy

We may update this policy from time to time. The current version will always be available on this page.

Data controller

Hidden Mountain SRLS
VAT No. IT12202150962
Piazza Tripoli 1
20146 Milano
Italy

For any privacy-related questions, contact support@hidden-mountain.com.