Legal and Transparency

Privacy Policy


Last updated: April 2026  ·  genuinestrap.com

At GenuineStrap, your privacy is not an afterthought. We are a small family business and we handle your personal data with the same care we put into every leather piece we make. This policy explains clearly what we collect, why we collect it, and how we protect it. We will never sell, rent, or misuse your information.

Who we are

Our website address is genuinestrap.com. GenuineStrap is a family-owned leather goods business based in Italy, specialising in handcrafted camera straps and leather accessories made from full-grain Italian leather.

For any privacy-related questions, you can reach us at [email protected].

What personal data we collect and why

Orders and purchases

When you place an order on our website, we collect your name, email address, shipping address, and phone number. This information is necessary to process and deliver your order and to communicate with you about it. We do not store your payment card details. All payment transactions are processed securely through our payment provider.

Contact forms

If you contact us using a form on the website, the data you submit is sent directly to us via encrypted SMTP. No personal data is stored on the website itself. Your message will be read by our team and may be shared internally only where necessary to address your request.

To protect your information, we use SSL encryption across the entire website, which ensures that any data transmitted between you and our site is fully protected from interception.

Comments

When visitors leave comments on the site, we collect the data shown in the comments form along with the visitor's IP address and browser user agent string. This helps us detect and prevent spam. An anonymised string created from your email address may be sent to the Gravatar service to check whether you use it. You can review the Gravatar privacy policy for more details. Once a comment is approved, your profile picture may be visible publicly alongside your comment.

Media uploads

If you upload images to the website, please avoid uploading files that contain embedded location data (EXIF GPS). Visitors to the website may be able to download and extract location data from any images published on the site.

Cookies

Our website uses cookies in the following ways:

Comment cookies. If you leave a comment, you may opt in to saving your name, email address, and website in cookies for your convenience. These cookies last for one year.

Login cookies. If you have an account and log in, we set temporary cookies to manage your session and screen preferences. Login cookies last two days; screen preference cookies last one year. If you select Remember Me, your login persists for two weeks.

Editor cookies. If you edit or publish content, a short-lived cookie stores the ID of the post you edited. It expires after one day and contains no personal data.

Embedded content from other websites

Some pages on our site may include embedded content such as videos, images, or articles from other websites. Embedded content behaves in the same way as if you had visited the originating website directly. Those third-party websites may collect data about you, use cookies, and track your interactions with their embedded content.

Analytics and who we share data with

We may use analytics tools to understand how visitors use our website in aggregate. This data is anonymous and helps us improve the shopping experience.

We do not sell, rent, lease, or share your personal information with third parties in any way that would identify you as an individual. Contact messages received through the website are never used for marketing purposes or passed to external organisations.

Email newsletter

If you subscribe to our newsletter, we store your name and email address for the sole purpose of sending you our updates. We use a third-party email platform to manage this service. You can unsubscribe at any time using the link in any email we send, and we will remove your data from our mailing list promptly.

Order fulfilment

To deliver your order, we share your shipping address with our courier or postal service. This is the only third-party data sharing that occurs as part of the purchase process, and it is strictly necessary to complete your order.

How long we retain your data

Order and customer data is retained for as long as is necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting obligations. In most cases, we keep order records for up to 7 years in compliance with Italian and EU tax law.

If you leave a comment, the comment and its associated metadata are retained indefinitely so we can recognise and approve follow-up comments automatically.

For registered users, personal information stored in your profile can be viewed, edited, or deleted at any time by logging into your account or by contacting us directly.

What rights you have over your data

Under the General Data Protection Regulation (GDPR) and applicable Italian law, you have the following rights regarding your personal data:

👁
Right to AccessRequest a copy of all personal data we hold about you.
✏️
Right to RectificationAsk us to correct any inaccurate or incomplete data.
🗑
Right to ErasureRequest deletion of your data, subject to legal obligations.
🚫
Right to ObjectObject to processing of your data for marketing purposes.
📦
Right to PortabilityReceive your data in a structured, machine-readable format.
Right to RestrictionAsk us to restrict processing in certain circumstances.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.

How we protect your data

We take data security seriously and have implemented the following measures to protect your information:

SSL encryption is enabled across the entire website. All communications between your browser and our server are encrypted, ensuring that personal data cannot be intercepted by unauthorised parties.

Database hygiene. Any databases used for development or testing purposes are fully sanitised before use. Actual customer data is never used in non-production environments.

Access control. Access to customer data is restricted to authorised team members who need it to fulfil orders or respond to customer queries.

We do not sell, rent, or lease personal data. We will actively challenge any attempt by government agencies or third parties to gain access to information you have entrusted to us, unless legally compelled to do so.

Data breach procedures

In the unlikely event of a data breach, we will take immediate action to contain and assess the situation. Affected users will be notified as quickly as possible, and where required by GDPR we will report the breach to the relevant supervisory authority within 72 hours of becoming aware of it.

Where passwords may have been compromised, our system administrators will initiate a password reset process and notify affected users directly.

Third-party services we use

Payment processing

Payments on our website are handled by a certified third-party payment processor. We never store or have access to your full card details.

Shipping and logistics

Your delivery address is shared with our courier partner solely for the purpose of delivering your order.

Email marketing

We use a third-party email platform to send our newsletter. If you subscribe, your name and email address are stored with that provider. You can unsubscribe at any time.

Spam detection

Visitor comments may be checked through an automated spam detection service. This service processes IP addresses and user agent data only.

Analytics

We may use anonymised analytics tools to understand general usage patterns on our website. No personally identifiable information is shared with analytics providers.

Questions about your privacy?

We are happy to help. Send us an email and we will respond within 30 days.

Contact Us About Privacy
The GenuineStrap Team Crafting since 2015 · genuinestrap.com