Privacy Policy
Last updated 24 August 2026. This policy covers the Infinity Milano mobile application (com.designanddevelopment.infinitycustomer) and https://infinitymilanoluxury.com.
In short
We collect only what the app needs to show you our jewellery, keep your account and handle your orders. We do not sell your personal data and we do not use it for third-party advertising. Face or fingerprint unlock happens on your own device — we never receive your biometric data.
1. Who is responsible
INFINITY SRL (trading as Infinity Milano) is the data controller.
- Via Paolo da Cannobio, 5 — 20122 Milano (MI), Italy
- VAT / P.IVA 12832170968
- Email [email protected]
- Telephone +39 328 4740006
Because we are established in Italy, we process personal data under the EU General Data Protection Regulation (GDPR).
2. What we collect, and why
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, telephone, delivery / billing address | To create and maintain your account, identify you when you sign in, and prepare quotations, proformas and orders. | Contract |
| Order, quotation and proforma records | To fulfil and document what you asked for, and to meet Italian bookkeeping and tax obligations. | Contract / legal obligation |
| Notification token | If you allow notifications, a device token lets us tell you about your order, an appointment or a document that is ready. Turning notifications off in your device settings stops this. | Consent |
| Camera images | Only when you open a feature that uses the camera — scanning a tag or barcode at our counter, or trying a piece on. Images are used to run that feature; try-on previews are processed for display and are not used to identify you. | Consent |
| Approximate or precise location | Only if you grant it — to show the nearest boutique or exhibition and relevant local information. The app works without it. | Consent |
| Messages you send to the in-app assistant | To answer your question about products, prices or your orders. | Consent / contract |
| Basic technical data (device model, app version, error reports) | To keep the app working and diagnose faults. | Legitimate interest |
We do not ask for, and the app does not collect, your contacts, calendar, SMS, call logs, microphone recordings or health data.
3. Face and fingerprint unlock
If you enable biometric sign-in, the check is performed by your own device — Android biometrics, Face ID / Touch ID, or Windows Hello — which simply tells the app whether the unlock succeeded. Your face or fingerprint data stays in your device's secure hardware.
We never receive, transmit or store face images, fingerprints or biometric templates.
You can remove a biometric enrolment at any time from the app's security settings, or by revoking it in your device settings.
4. Payments
Where the app or site lets you pay online, the payment is completed by a licensed payment provider. Card numbers are entered on the provider's own secure page and are never sent to, or stored on, our servers. We keep only the outcome of the payment and a reference, so we can match it to your order.
6. How long we keep it
- Account details — while your account is open, and then up to 12 months.
- Orders, proformas and invoices — 10 years, as Italian tax and accounting law requires.
- Notification tokens — until you disable notifications or uninstall the app.
- Camera images used for a feature — kept only as long as that feature needs them.
- Technical logs — normally 90 days.
7. Your rights
Under the GDPR you may ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong or incomplete;
- delete your data, where we are not required to keep it;
- restrict or object to a particular use;
- transfer your data to another provider;
- withdraw a consent you gave — for notifications, camera or location.
Write to [email protected] and we will reply within one month. You also have the right to complain to the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it).
8. Deleting your account
You can ask us to close your account and delete your data by emailing [email protected] from the address registered to the account, or from the account screen in the app where that option is available. We will confirm once it is done. Documents we must retain by law (invoices and related records) are kept for the period stated above and nothing more is done with them.
9. Security
Traffic between the app and our servers is encrypted with HTTPS. Access to the database and to the admin panel is restricted to named accounts, passwords are stored only as salted hashes, and sessions are signed. No system is perfectly secure, but if a breach ever affected your rights we will notify you and the supervisory authority as the GDPR requires.
10. Children
The app is intended for adults purchasing jewellery and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has given us personal data, contact us and we will remove it.
11. Changes to this policy
If we change how we use personal data we will update this page and move the “last updated” date. Where the change is significant we will also tell you in the app.
12. Contact
INFINITY SRL, Via Paolo da Cannobio, 5 — 20122 Milano (MI), Italy
[email protected] · +39 328 4740006
© 2026 INFINITY SRL. All rights reserved. · Home