Privacy policy

Last updated: November 2, 2025

North Star srl operates this store and website, including the information, content, features, tools, products, and services, in order to provide you, the customer, with an appropriate shopping experience (the “Services”). Pasta Dalla Costa is supported by Shopify, which enables us to provide you with the Services. This Privacy Policy describes how we collect, use, and disclose your personal data when you visit, use, make a purchase, or engage in any other transaction through the Services, or when you communicate with us. If there is any conflict between our Terms of Service and this Privacy Policy, the Privacy Policy prevails with respect to the collection, processing, and disclosure of your personal data.

Please read this Privacy Policy carefully. By using and accessing the Services, you confirm that you have read this Privacy Policy and understand what is described regarding the collection, use, and disclosure of your information.

The personal data we collect or process

When we use the term “personal data,” we mean information that identifies you or is reasonably linked to you or another person. Personal data does not include information collected in de-identified or anonymized form so that it cannot identify you or be linked to you. We may collect or process the following categories of personal data, including inferences drawn from such personal data, depending on your interaction with the Services, where you live, and as permitted or required by applicable laws:

  • Contact details including name, address, billing address, shipping address, phone number, and email address.

  • Financial data including credit card, debit card, and financial account numbers, card payment data, financial account data, transaction details, payment method, payment confirmation, and other payment details.

  • Account data including username, password, security questions, preferences, and settings.

  • Transaction data including items you view, add to cart, add to wish list, purchase, return, exchange, or remove, and past transactions.

  • Communications with us including information you include in communications with us, for example if you submit a dispute to customer support.

  • Device information including information about your device, browser or connection network, IP address, and other unique identifiers.

  • Usage information including information regarding your interaction with the Services, as well as how and when you interact with or browse the Services.

Sources of personal data

We may collect personal data from the following sources:

  • Directly from you including when you create an account, visit or use the Services, communicate with us, or provide us with your personal data;

  • Automatically through the Services including via your device when you use our products or services or visit our websites, and through the use of cookies and similar technologies;

  • From our service providers including when we engage them to implement a given technology and when they collect or process your personal data on your behalf;

  • From our partners or third parties.

How we use your personal data

Depending on how you interact with us or which Services you use, we may collect your personal data for the following purposes:

  • Provide, personalize, and improve the Services. We use your personal data to provide you with the Services, as well as to enforce our contract with you; process your payments; fulfill your orders; remember your preferences and items of interest; send you account-related notifications; process purchases, returns, exchanges, or other transactions; create, maintain, and manage your account; arrange shipping; facilitate returns and exchanges; allow you to post reviews; and create a personalized shopping experience, e.g., with product recommendations related to your purchases. This may include using your personal data to personalize and improve the Services.

  • Marketing and advertising. We use your personal data for marketing and advertising purposes, for example to send you marketing, advertising, and promotional communications by email, text message, or mail, and to show you online ads for products and services within our Services or on other websites, including based on items you previously purchased or added to your cart and other activity within the Services.

  • Security and fraud prevention. We use your personal data to authenticate your account; provide a secure payment and shopping experience; detect, investigate, or take action against fraudulent, illegal, unsafe, or harmful activities; protect public safety and our services. By choosing to use the Services and register an account, you are responsible for safeguarding your credentials. We recommend that you do not share your username, password, or other access data with anyone.

  • Communications with you. We use your personal data to provide customer support; respond to you; deliver effective services; and maintain our business relationships with you.

  • Legal reasons. We use your personal data in accordance with applicable laws or in response to valid legal processes, including requests from authorities or government agencies; to investigate or participate in testimony, potential or ongoing lawsuits, or other legal proceedings; to enforce or investigate potential violations of our terms or policies.

How we disclose personal data

In certain circumstances, we may disclose your personal data to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances may include:

  • With Shopify, vendors, and other third parties that perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, storage, fulfillment, and shipping).

  • With business and marketing partners to provide you with services and marketing ads. For example, we use Shopify to deliver personalized ads with third-party services based on your online activity with different merchants and websites. Our business and marketing partners will use your data in accordance with their privacy policies. Depending on where you reside, you may have the right to ask us not to share your data for personalized and marketing ads based on your online activity with different merchants and websites.

  • When you ask or authorize us to disclose certain information to third parties, for example to ship your products, or when you use social media widgets or login integrations.

  • With our affiliates or within our corporate group.

  • In connection with a business transaction such as a merger or bankruptcy; in compliance with any legal obligations (including responding to subpoenas, search warrants, and similar requests); to enforce terms of service or policies; and to protect or defend the Services, our rights, and those of our users or others.

Relationship with Shopify

The Services are supported by Shopify, which collects and processes personal data related to your access to and use of the Services to deliver and improve the Services for you. To provide and improve the Services for you, data you submit to the Services will be transmitted and shared with Shopify and third parties that may be located in countries other than your own. In addition, to help you protect, grow, and improve your business, we use certain advanced Shopify features that incorporate data and information received from you through your interactions with our store, as well as with other merchants and with Shopify. To provide such advanced features, Shopify may use personal data collected from your interactions with our store, with other merchants, and with Shopify itself. In such circumstances, Shopify is responsible for processing your personal data, including responding to your requests to exercise your rights related to the use of your personal data for those purposes. For more information on how Shopify uses your personal data and the rights you may have, you can consult Shopify’s Consumer Privacy Policy. Depending on where you reside, you may exercise certain rights related to your personal data here: Shopify Privacy Portal link.

Third-party websites and links

The Services may feature links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated with or controlled by us, you may need to accept their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy and security of such sites, nor for the accuracy, truthfulness, or reliability of the information contained therein. Information you provide in public or semi-public contexts, including what you share on third-party social platforms, may also be viewed by other users of the Services and/or users of those third-party platforms, without restrictions on its use by us or third parties. Our inclusion of such links does not imply any endorsement by us of the content of those platforms or of their owners or operators, except as disclosed within the Services.

Children’s data

The Services are not suitable for use by minors, and we do not knowingly collect personal data from children below the age of majority in your jurisdiction. If you are a parent or guardian of a minor who has provided us with their personal data, you may contact us using the details below to request deletion. As of the effective date of this Privacy Policy, we are not aware of the “sharing” or “sale” (as those terms are defined under applicable laws) of personal data of individuals under 16 years of age.

Data security and retention

Please note that no security measure is perfect or impenetrable, and we cannot guarantee “absolute security.” In addition, data you submit to us may not be secure during transmission. We recommend using only secure channels to communicate confidential or sensitive information to us.

The retention period for personal data depends on several factors, such as whether we need the data to maintain your account, to provide the Services to you, to meet legal obligations, to resolve disputes, or to enforce other contracts and policies.

Your rights and choices

Depending on where you reside, you may have one or more of the rights regarding personal data listed below. However, these rights are not absolute and may apply only in certain circumstances, and we may deny your request to the extent permitted by law.

  • Right of access/knowledge. You may have the right to request access to your personal data in our possession.

  • Right to deletion. You may have the right to request the deletion of your personal data in our possession.

  • Right to correction. You may have the right to request correction of your personal data in our possession.

  • Right to portability. You may have the right to receive a copy of your personal data in our possession and to ask us to transfer it to a third party, in certain circumstances and with certain exceptions.

  • Communication preference management. We may send you promotional emails and you can opt out at any time using the unsubscribe option in our emails. If you opt out, we may still send you non-promotional emails, such as those related to your account or your orders.

If you reside in the United Kingdom or the European Economic Area, and subject to the restrictions and limits imposed by local laws, you may exercise the following rights in addition to those mentioned above:

  • Objection to processing and restriction of processing. You may have the right to ask us to stop or restrict the processing of personal data for certain purposes.

  • Withdrawal of consent. Where your consent is required to process your personal data, you have the right to withdraw it. If you withdraw consent, this will not affect the lawfulness of processing based on your consent before its withdrawal.

You may exercise any of these rights where indicated in the Services or by contacting us using the details below. For more information about how Shopify uses your personal data and your possible rights, including those related to data processed by Shopify itself, you can visit https://privacy.shopify.com/en.

You will not be discriminated against for exercising these rights. Before processing your requests, we may need to verify your identity, within the limits permitted by applicable laws. In accordance with applicable laws, you may appoint an authorized agent to make requests on your behalf in order to exercise your rights. Before accepting a request from an agent, we will ask them to provide proof that they have been authorized by you, and we may ask you to verify your identity directly. We will respond to your request within the timeframes reasonably required by applicable laws.

Complaints

If you have complaints about how we process your personal data, contact us using the details below. Depending on where you reside, you may have the right to appeal our decision by contacting us using the details below, or to report your complaint to your local data protection authority. For the EEA, you can find a list of competent data protection supervisory authorities here.

International transfers

Please note that we may transfer, store, and process your personal data outside the country in which you reside.

If we transfer your personal data outside the European Economic Area or the United Kingdom, we will rely on reliable transfer mechanisms, such as the European Commission’s Standard Contractual Clauses, or equivalent contracts issued by the competent UK authorities, unless the data is transferred to a country considered to provide an adequate level of protection.

Changes to this Privacy Policy

We will update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will publish the updated Privacy Policy on the website, change the “Last updated” date, and issue a notice as required by applicable law.

Contact

If you have questions about our privacy practices or this Privacy Policy, or if you intend to exercise any rights available to you, call +39 0522173710, email privacy@northstaritaly.com, or contact us at north star srl, Via Brigata Reggio 27, Reggio Emilia, RE, 42124, IT. For the purposes of applicable data protection laws, we are the controller of your personal data.