Privacy Policy

June 2026

1. Data Controller

The Data Controller for the processing of personal data is:

2. Scope

This privacy policy is provided pursuant to Article 13 of Regulation (EU) 2016/679 ("GDPR") and applies to all individuals who interact with the The Old Farm platform ("Service"), accessible through the domains app.theold.farm and www.theold.farm.

This policy covers three categories of data subjects:

  • Registered users: farm owners and operators who access the administrative dashboard.
  • Public visitors: people who view public content (e.g. product information) via QR tags, web links, or iframes.
  • Institutional website visitors: users who browse the www.theold.farm website.

3. Personal data collected

3.1 Registered users (owners and operators)

At the time of registration and during use of the Service, we collect:

DataRequiredPurpose
EmailYesAccess to the Service, service communications
First and last nameYesIdentification in the interface
Phone numberNoOptional contact
Profile photoNoInterface personalization
Preferred languageYesInterface personalization
TimezoneYesCorrect display of dates and times
Login credentials (password)YesAuthentication (managed by a dedicated system, not accessible to the application platform)
Last loginAutomaticAccount security
Navigation data in the admin areaAutomaticService analysis and improvement

3.2 Organization data (farms)

Users may enter data related to their farm: name, type, and description; logo and images; address, country, and region; website; VAT number / Tax code of the farm. Such data may constitute personal data in the case of sole proprietorships.

3.3 Public visitors (unregistered users)

When a visitor accesses a public page of the Service (e.g. a product page via QR tag), the following technical data is automatically collected: IP address, User Agent (browser type and operating system), browser language, referring URL (referer), date and time of access. Public visitors are not required to register and do not knowingly provide personal data.

3.4 Institutional website visitors

The website www.theold.farm does not collect personal data and does not use cookies. Anonymous and aggregated browsing data (pages visited, referrer, device type) is collected solely to improve the service. This data cannot be traced back to identifiable individuals and is not used for profiling.

3.5 Payment data

Payment data (credit card number, expiration date, CVV) is collected and managed exclusively by Stripe, Inc., our payment service provider. Such data is never transmitted to or stored on our systems. For information on how Stripe processes data, please refer to its privacy policy.

PurposeLegal basisData subjects
Service delivery (registration, account management, platform features)Performance of a contract (Art. 6.1.b GDPR)Registered users
Payment processing and billingPerformance of a contract (Art. 6.1.b GDPR) and legal obligation (Art. 6.1.c GDPR)Registered users
Service communications (technical notices, contract changes, deadlines)Performance of a contract (Art. 6.1.b GDPR)Registered users
Analysis of dashboard usage for Service improvementLegitimate interest of the Controller (Art. 6.1.f GDPR)Registered users
IT security, abuse prevention, and debuggingLegitimate interest of the Controller (Art. 6.1.f GDPR)Registered users, Public visitors
Logging of public page access for aggregate statistics and securityLegitimate interest of the Controller (Art. 6.1.f GDPR)Public visitors
Compliance with legal obligations, responses to authority requestsLegal obligation (Art. 6.1.c GDPR)All

With regard to processing based on legitimate interest, the data subject has the right to object at any time as described in section 9.

5. Processing methods

Personal data is processed using electronic tools and is protected by appropriate technical and organizational measures to ensure its security and confidentiality, in accordance with Article 32 of the GDPR. Data in transit and at rest is protected by encryption.

6. Recipients and sub-processors

To provide the Service, the Controller engages the following providers who process personal data as Data Processors (Art. 28 GDPR):

ProviderFunctionData processedLocation
Stripe, Inc.Payment processingPayment data, email, nameEuropean Union / United States (see Stripe DPA)
Google Cloud Platform (Google LLC)Storage of uploaded images and documentsImage files, documents (e.g. invoice PDFs)European Union
Amazon Web Services, Inc.Transactional email deliveryEmail, nameEuropean Union / United States (see AWS DPA)
Fatture in Cloud (TeamSystem S.p.A.)Electronic invoicingIdentity and billing dataItaly / European Union

Authentication is managed by a dedicated system hosted by the Controller (auth.theold.farm); passwords are not accessible to the application platform. All sub-processors are bound by Data Processing Agreements compliant with Article 28 of the GDPR. Personal data is not disclosed to third parties for purposes other than those indicated above, except where required by law.

7. Data transfers outside the EU

Personal data is stored on servers located within the European Union. Where any of the sub-processors indicated in section 6 processes data in countries outside the European Economic Area (EEA), such transfer is based on adequate safeguards pursuant to Articles 46-49 of the GDPR, such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs).

8. Data retention

The Controller retains personal data for the time strictly necessary to achieve the purposes for which it was collected, in compliance with the principle of data minimization. At the end of the identifiable retention period, data is anonymized and retained in aggregate form for statistical and Service improvement purposes.

Data categoryIdentifiable retentionAfterwards
Registered user profileFor the duration of the contract and up to 10 years after terminationAnonymization
Organization (farm) dataFor the duration of the contract and up to 10 years after terminationStatistical aggregation
Public page access data (IP, User Agent)90 daysAnonymization and aggregation
Operations log (audit log)24 monthsAnonymization
Uploaded images and documentsUntil deletion by the user or contract termination + 30 daysPermanent deletion
Login credentialsUntil account deletion + 30 daysPermanent deletion
Billing data10 years from accounting entry (Art. 2220 Italian Civil Code)Mandatory retention

Data may be retained for a longer period in the event of litigation or at the request of a competent authority.

9. Data subject rights

Pursuant to Articles 15-22 of the GDPR, the data subject has the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21) to processing based on the legitimate interest of the Controller, and withdrawal of consent where processing is based on consent (without affecting the lawfulness of processing carried out prior to withdrawal).

To exercise these rights, the data subject may contact the Controller at privacy@theold.farm. The Controller undertakes to respond within 30 days of receiving the request.

10. Right to lodge a complaint

The data subject has the right to lodge a complaint with the Italian Data Protection Authority:

11. Cookies and similar technologies

For details on the cookies and technologies used, please refer to the Cookie Policy. In summary: the dashboard (app.theold.farm) uses strictly necessary technical cookies (authentication, security) and usage analytics (PostHog) to improve the product, based on the legitimate interest of the Controller, with the right to object (by writing to privacy@theold.farm); the institutional website (www.theold.farm) collects by default only anonymous, aggregate statistics (PostHog cookieless) and enables full analytics with cookies only with the consent given via the banner. Public pages only save the language preference in localStorage.

12. Children's privacy

The Service is not intended for users under the age of 16. We do not knowingly collect data from minors.

13. Changes to this policy

The Controller reserves the right to modify this privacy policy at any time. Changes will be published on this page with an updated "last updated" date. In the event of material changes, registered users will be notified by email.