Legal
Privacy policy
Last updated: 26 August 2026
This policy explains how Booklane processes personal data of bookstores, contacts and website visitors, in accordance with EU Regulation 2016/679 (GDPR) and applicable Italian law.
Data controller
The data controller for personal data collected through the Booklane website and platform is the entity operating the Booklane service.
To exercise your rights or for any privacy request, email [email protected] or use the form on the Contact page.
Scope
This policy applies to the Booklane marketing website, registration and contact forms, and use of the SaaS platform by customers.
It does not cover third-party websites or services reachable via external links — please read their respective privacy policies.
Data we process
Depending on how you interact with Booklane, we may process the following categories of data:
- Identity and contact data: bookstore name, contact name, email, phone, city and country provided at signup or via the contact form.
- Contract and billing data: selected plan, upgrade requests, communications relating to the commercial relationship.
- Platform usage data: access logs, actions in the Booklane environment, store configuration and data entered in the application (catalog, customers, sales, etc.) processed on behalf of the customer.
- Technical data: IP address, browser type, operating system, timestamps and logs required for security and service operation.
- Marketing data: only if you explicitly consent to receive Booklane updates and news.
Purposes and legal basis
We process personal data for the purposes below, on the corresponding legal bases under the GDPR:
- Account creation and management, service delivery and support — contract performance or pre-contractual measures.
- Email verification and free trial activation — contract performance.
- Handling contact and upgrade requests for Pro or Enterprise plans — contract performance or legitimate interest.
- Tax, accounting and legal obligations — legal obligation.
- Service security, abuse prevention and legal protection — legitimate interest.
- Marketing communications — consent, withdrawable at any time.
Retention
We keep personal data only for as long as necessary for the purposes for which it was collected.
Customer account data is retained for the duration of the contractual relationship and, thereafter, for the period required by law or to protect the controller's rights.
Data collected via contact forms without establishing a contractual relationship is kept for the time needed to handle the request and, unless otherwise required, no longer than 24 months.
Technical logs are retained for limited periods proportionate to security and diagnostic needs.
Recipients and processors
Data may be processed by authorised staff and by providers acting as data processors under Article 28 GDPR, appointed by appropriate agreement.
Such providers include, for example, hosting providers, cloud infrastructure, transactional email services and technical support tools strictly necessary to deliver the service.
We do not sell or transfer personal data to third parties for their own marketing purposes.
Security
We implement appropriate technical and organisational measures to protect personal data from unauthorised access, loss, destruction or alteration.
Measures include access control, encryption in transit where applicable, backups and internal incident management procedures.
No system is completely risk-free: please protect your account credentials and report suspicious access promptly.
Your rights
As a data subject you have the rights under Articles 15–22 GDPR, including:
- Access to your personal data and obtaining a copy.
- Rectification of inaccurate data or completion of incomplete data.
- Erasure of data, where provided by law.
- Restriction of processing in the cases provided by the GDPR.
- Data portability, where applicable.
- Objection to processing based on legitimate interest, where provided.
- Withdrawal of consent for marketing, without affecting the lawfulness of prior processing.
Complaint to the supervisory authority
You have the right to lodge a complaint with your data protection authority if you believe processing of your data violates applicable law.
In Italy, the authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it). We encourage you to contact us first so we can address your concerns promptly.
Changes to this policy
We may update this policy to reflect regulatory changes, service evolution or new features.
The last update date is shown at the top of this page. For material changes we may inform you via the website, email or in-platform notice.
Privacy contact
For privacy requests, exercising your rights or questions about this policy, email [email protected] or use the Contact page form, stating the subject of your request.