Legal & compliance
Privacy Notice
Last updated: 28 July 2026
This notice explains, plainly, what personal data Meet Me Gently collects when you browse, buy, or download from this site, why we collect it, how long we keep it, who we share it with, and the rights you have over it — under the EU General Data Protection Regulation (GDPR), the UK GDPR, and the equivalent laws of several other countries.
1. Who we are
The data controller responsible for your personal data is:
Ardit Tashi, trading as Meet Me Gently, registered at Via Antonio Fogazzaro 1, 20135 Milano (MI), Italy (company registration number Not applicable — this is a professional activity (libero professionista), not a commercial enterprise, and is therefore not registered with the Registro delle Imprese. No REA number exists., VAT ID IT11291420963). Our data-protection contact point is No Data Protection Officer has been appointed. One is not required under Article 37 GDPR: this site does not carry out large-scale regular and systematic monitoring of data subjects, and does not process special categories of data on a large scale., reachable at privacy@meetmegently.com.
If you are in the European Union, our Article 27 representative is [EU REPRESENTATIVE — ART. 27]. If you are in the United Kingdom, our UK GDPR representative is not required — we do not offer goods or services to individuals in the United Kingdom, and UK shipping destinations are not available at checkout.
↑ Back to top2. What personal data we collect, and why
We keep collection to what is genuinely needed to sell and deliver the product, run the shop securely, and support you if something goes wrong. We do not run a data-broking business and we do not sell personal data.
| Data category | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Email address | Order confirmation, delivering digital downloads, customer support | Art. 6(1)(b) — performance of the contract | [RETENTION PERIOD — TAX/INVOICE LAW] for invoicing records; support threads deleted or anonymised after resolution plus a short grace window |
| Name, shipping address, phone number | Fulfilling physical print-on-demand orders (the phone number is a carrier requirement for customs/delivery, not used for marketing) | Art. 6(1)(b) — performance of the contract | As long as required by tax/commercial-record retention law (typically 6–10 years depending on country; see [RETENTION PERIOD — TAX/INVOICE LAW]) |
| Payment data | Processing payment for orders | Art. 6(1)(b) — performance of the contract | Held by Stripe under its own retention rules; we retain only a payment token, last four digits, and status |
| Server / edge logs (IP address, user agent, timestamps, requested URL) | Security, abuse and fraud prevention, keeping the site and downloads working | Art. 6(1)(f) — legitimate interests (balancing test on file) | Short rolling window, typically 30 days, per Cloudflare's logging configuration |
| Support email correspondence | Answering questions, resolving order problems | Art. 6(1)(b) contract / Art. 6(1)(f) legitimate interests | Deleted or anonymised a reasonable time after the matter is closed |
| Marketing email address (optional) | Sending news about new editions, if you opted in | Art. 6(1)(a) — consent | Until you unsubscribe or withdraw consent |
| 18+ age attestation | Recording that the buyer confirmed they are of legal age, attached to the order | Art. 6(1)(c) legal obligation / Art. 6(1)(f) legitimate interests | Same retention as the order record |
Saved cards, favourites and progress stay on your device
Anything you "save" while browsing — favourited prompts, sampler or deck progress, and interface preferences — is stored using your browser's localStorage, on your own device. It is never transmitted to us, we cannot see it, and it is not part of any data category above. Clearing your browser's site data removes it. See Cookies & similar technologies for the full list of keys we use this way.
What "lawful basis" means, in plain terms
Under GDPR we can only process personal data where one of a fixed set of legal grounds applies. We rely on: contract (Art. 6(1)(b)) to take your order and deliver it; legal obligation (Art. 6(1)(c)) to keep tax and invoicing records for the period your country requires; legitimate interests (Art. 6(1)(f)) for security, fraud prevention and improving the service, always balanced against your rights and never used to override them; and consent (Art. 6(1)(a)) for anything optional, like marketing email or non-essential cookies, which you can withdraw at any time.
↑ Back to top3. Sensitive data — what we don't ask for
We do not request or knowingly collect special-category data under Article 9 GDPR (health, sex life or sexual orientation, religion, political opinion, and similar). Purchasing an adults-only product, including the After Dark edition, is treated by us with extra discretion — for example in discreet packaging and neutral billing descriptors, see shipping — but the fact of a purchase is not, by itself, special-category data.
Please do not send us sensitive personal details (health information, details of a relationship crisis, or similar) in support emails. If you do, we will handle it with care and delete it once your query is resolved, but we do not ask for it and have no use for it.
↑ Back to top4. Who we share data with — processors & sub-processors
We use a small number of specialist providers to run the shop. Each is contractually bound to use your data only to provide their service to us, not for their own purposes.
| Provider | Role | Location |
|---|---|---|
| Stripe | Payment processing — we never see or store full card numbers | Ireland / United States |
| Cloudflare | Hosting, content delivery, security and edge logs | Global edge network, United States |
| Selected print-on-demand provider | Manufacture and shipping of physical decks — receives name and address for physical orders only | Provider and production country shown before payment |
| Brevo (Sendinblue SAS, France — EU-based), used for transactional email only: sign-in links, contact-form replies, order confirmations and receipts | Transactional email (order confirmations, download links) and, where consented, marketing email | Brevo (Sendinblue SAS, France — EU-based), used for transactional email only: sign-in links, contact-form replies, order confirmations and receipts region |
| [ANALYTICS PROVIDER — IF ANY] | Website analytics, if and when deployed — see cookies | [ANALYTICS PROVIDER — IF ANY] region |
5. International transfers
Because we use global providers, personal data from the EU, UK or Switzerland may be transferred to and processed in the United States and other countries. Where that happens, we rely on recognised safeguards: the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK's International Data Transfer Addendum to those clauses, and, where a given processor is certified, the EU–US Data Privacy Framework. We (or our processors) carry out transfer impact assessments to confirm the safeguard actually works in practice for the destination country.
↑ Back to top6. Your rights
Under GDPR and UK GDPR, you have the following rights over your personal data:
- AccessA copy of the personal data we hold about you.
- RectificationCorrection of inaccurate or incomplete data.
- ErasureDeletion of your data, subject to what we must legally keep.
- RestrictionLimiting how we use your data in certain circumstances.
- PortabilityReceiving your data in a portable, machine-readable format.
- ObjectionObjecting to processing based on legitimate interests, and an absolute right to object to direct marketing at any time.
- Withdraw consentAt any time, without affecting the lawfulness of processing carried out before withdrawal.
- No automated decisionsThe right not to be subject to solely automated decision-making or profiling with legal or similarly significant effects. We do not carry out any such automated decision-making.
7. How to exercise your rights
Email privacy@meetmegently.com. We respond within one month of a valid request, extendable by a further two months for complex or numerous requests (we will tell you if that applies). Exercising your rights is free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline. We may need to verify your identity before acting on a request.
↑ Back to top8. Complaints & supervisory authorities
If you are unhappy with how we've handled your data, please contact us first at privacy@meetmegently.com so we can try to put it right. You also have the right to complain directly to a supervisory authority: your EU member state's data protection authority, the UK Information Commissioner's Office (ico.org.uk) if you are in the UK, the Swiss Federal Data Protection and Information Commissioner (FDPIC) if you are in Switzerland, or Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, Italy — tel. +39 06 696771 — protocollo@gpdp.it — PEC protocollo@pec.gpdp.it — www.garanteprivacy.it.
↑ Back to top9. Children
This site and its products are strictly 18+ and are not directed at, marketed to, or intended for children. See our full age-verification policy. We do not knowingly collect personal data from anyone under the age of majority in their jurisdiction.
↑ Back to top10. Security & breach notification
We use technical and organisational measures proportionate to the data we hold, including encryption in transit (TLS), access controls limiting who can see order and support data, and data minimisation — we simply don't collect what we don't need. In the unlikely event of a personal-data breach that poses a risk to you, we are committed to notifying the relevant supervisory authority within 72 hours of becoming aware of it where required by law, and to notifying affected individuals without undue delay where the risk is high.
↑ Back to top11. Changes to this notice
We may update this notice as our processors, products or legal obligations change. The "Last updated" date at the top will always reflect the most recent revision. Material changes will be highlighted here.
↑ Back to top12. California (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you additional rights. In the statute's own category language, we collect: identifiers (name, email, IP address), commercial information (order and purchase history), internet or network activity (site interaction, edge logs), and, inferred from IP address, approximate geolocation. Because a purchase of adults-only material could be considered sensitive-adjacent, we apply heightened care to this category voluntarily, beyond what the statute strictly requires.
We do not sell personal information and do not share it for cross-context behavioural advertising, so no "Do Not Sell or Share My Personal Information" opt-out is legally required of us — but if you would like to exercise that preference anyway, contact privacy@meetmegently.com and we will honour it. We honour the Global Privacy Control (GPC) signal where it is technically detectable from your browser.
You have the right to know what personal information we collect, to delete it, to correct it, to opt out of sale/sharing (moot, since we do neither), to limit use of sensitive personal information, and to be free from retaliation or discrimination for exercising any of these rights. You may use an authorised agent to submit a request on your behalf.
↑ Back to top13. Brazil (LGPD)
If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) gives you equivalent rights to those described above — access, correction, deletion, portability, information about sharing, and revocation of consent — enforced by the Autoridade Nacional de Proteção de Dados (ANPD). Use the same contact route, privacy@meetmegently.com, to exercise them.
↑ Back to top14. Canada (PIPEDA / Quebec Law 25)
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA), and in Quebec, Law 25, give you equivalent rights of access, correction and, in Quebec, deletion and data portability, overseen by the Office of the Privacy Commissioner of Canada and, in Quebec, the Commission d'accès à l'information. Use the same contact route, privacy@meetmegently.com.
↑ Back to top15. Australia (Privacy Act 1988)
If you are in Australia, the Privacy Act 1988 and the Australian Privacy Principles (APPs) give you equivalent rights to access and correct your personal information and to complain about mishandling, overseen by the Office of the Australian Information Commissioner (OAIC). Use the same contact route, privacy@meetmegently.com.
↑ Back to top16. Switzerland (revFADP/nFADP)
If you are in Switzerland, the revised Federal Act on Data Protection (revFADP/nFADP) gives you equivalent rights of access, correction, deletion and information about processing, overseen by the Federal Data Protection and Information Commissioner (FDPIC). Use the same contact route, privacy@meetmegently.com.
↑ Back to top