Privacy Policy
Privacy Policy
Last updated: April 2026 · genuinestrap.com
At GenuineStrap, your privacy is not an afterthought. We are a small family business and we handle your personal data with the same care we put into every leather piece we make. This policy explains clearly what we collect, why we collect it, and how we protect it. We will never sell, rent, or misuse your information.
Who we are
Our website address is genuinestrap.com. GenuineStrap is a family-owned leather goods business based in Italy, specialising in handcrafted camera straps and leather accessories made from full-grain Italian leather.
For any privacy-related questions, you can reach us at [email protected].
What personal data we collect and why
Orders and purchases
When you place an order on our website, we collect your name, email address, shipping address, and phone number. This information is necessary to process and deliver your order and to communicate with you about it. We do not store your payment card details. All payment transactions are processed securely through our payment provider.
Contact forms
If you contact us using a form on the website, the data you submit is sent directly to us via encrypted SMTP. No personal data is stored on the website itself. Your message will be read by our team and may be shared internally only where necessary to address your request.
To protect your information, we use SSL encryption across the entire website, which ensures that any data transmitted between you and our site is fully protected from interception.
Comments
When visitors leave comments on the site, we collect the data shown in the comments form along with the visitor's IP address and browser user agent string. This helps us detect and prevent spam. An anonymised string created from your email address may be sent to the Gravatar service to check whether you use it. You can review the Gravatar privacy policy for more details. Once a comment is approved, your profile picture may be visible publicly alongside your comment.
Media uploads
If you upload images to the website, please avoid uploading files that contain embedded location data (EXIF GPS). Visitors to the website may be able to download and extract location data from any images published on the site.
Cookies
Our website uses cookies in the following ways:
Comment cookies. If you leave a comment, you may opt in to saving your name, email address, and website in cookies for your convenience. These cookies last for one year.
Login cookies. If you have an account and log in, we set temporary cookies to manage your session and screen preferences. Login cookies last two days; screen preference cookies last one year. If you select Remember Me, your login persists for two weeks.
Editor cookies. If you edit or publish content, a short-lived cookie stores the ID of the post you edited. It expires after one day and contains no personal data.
Embedded content from other websites
Some pages on our site may include embedded content such as videos, images, or articles from other websites. Embedded content behaves in the same way as if you had visited the originating website directly. Those third-party websites may collect data about you, use cookies, and track your interactions with their embedded content.
Analytics and who we share data with
We may use analytics tools to understand how visitors use our website in aggregate. This data is anonymous and helps us improve the shopping experience.
We do not sell, rent, lease, or share your personal information with third parties in any way that would identify you as an individual. Contact messages received through the website are never used for marketing purposes or passed to external organisations.
Email newsletter
If you subscribe to our newsletter, we store your name and email address for the sole purpose of sending you our updates. We use a third-party email platform to manage this service. You can unsubscribe at any time using the link in any email we send, and we will remove your data from our mailing list promptly.
Order fulfilment
To deliver your order, we share your shipping address with our courier or postal service. This is the only third-party data sharing that occurs as part of the purchase process, and it is strictly necessary to complete your order.
How long we retain your data
Order and customer data is retained for as long as is necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting obligations. In most cases, we keep order records for up to 7 years in compliance with Italian and EU tax law.
If you leave a comment, the comment and its associated metadata are retained indefinitely so we can recognise and approve follow-up comments automatically.
For registered users, personal information stored in your profile can be viewed, edited, or deleted at any time by logging into your account or by contacting us directly.
What rights you have over your data
Under the General Data Protection Regulation (GDPR) and applicable Italian law, you have the following rights regarding your personal data:
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
How we protect your data
We take data security seriously and have implemented the following measures to protect your information:
SSL encryption is enabled across the entire website. All communications between your browser and our server are encrypted, ensuring that personal data cannot be intercepted by unauthorised parties.
Database hygiene. Any databases used for development or testing purposes are fully sanitised before use. Actual customer data is never used in non-production environments.
Access control. Access to customer data is restricted to authorised team members who need it to fulfil orders or respond to customer queries.
We do not sell, rent, or lease personal data. We will actively challenge any attempt by government agencies or third parties to gain access to information you have entrusted to us, unless legally compelled to do so.
Data breach procedures
In the unlikely event of a data breach, we will take immediate action to contain and assess the situation. Affected users will be notified as quickly as possible, and where required by GDPR we will report the breach to the relevant supervisory authority within 72 hours of becoming aware of it.
Where passwords may have been compromised, our system administrators will initiate a password reset process and notify affected users directly.
Third-party services we use
Payment processing
Payments on our website are handled by a certified third-party payment processor. We never store or have access to your full card details.
Shipping and logistics
Your delivery address is shared with our courier partner solely for the purpose of delivering your order.
Email marketing
We use a third-party email platform to send our newsletter. If you subscribe, your name and email address are stored with that provider. You can unsubscribe at any time.
Spam detection
Visitor comments may be checked through an automated spam detection service. This service processes IP addresses and user agent data only.
Analytics
We may use anonymised analytics tools to understand general usage patterns on our website. No personally identifiable information is shared with analytics providers.
Questions about your privacy?
We are happy to help. Send us an email and we will respond within 30 days.
Contact Us About Privacy
The GenuineStrap Team
Crafting since 2015 · genuinestrap.com