Privacy Policy
Last updated: 4 June 2026.
This Privacy Policy describes how Almagesto processes personal data through
www.almagesto.xyz, the Gatsby website used to present and sell customised
astronomy prints.
Almagesto is designed to run in two modes:
- Normal / privacy-first mode: no Google Tag Manager, Google Analytics, advertising pixels or marketing cookies are loaded by the site code.
- Campaign / marketing mode: optional marketing tags may be enabled through environment variables and loaded only after the visitor gives marketing consent.
Controller
The data controller is:
- RGBear di D'Ambrogio Massimo
- C.F. DMBMSM89M22A859X
- P.IVA 02663400022
- Registro delle Imprese n.000303126 BI
- Via Billotti 8, 13900 Biella, Italy
Contact: info@almagesto.xyz
TODO for maintainers: confirm whether info@almagesto.xyz is also the privacy
request inbox or publish a dedicated privacy contact address.
Data We Process
Site delivery and security
The website is hosted on Netlify. Netlify may process technical request data such as IP address, user agent, requested URL, timestamps, status codes and security-related logs to deliver the site, protect the infrastructure and run Netlify Functions.
Legal bases: legitimate interest in running and securing the site; legal obligations where applicable.
Product browsing and configurator
Visitors can browse products and use the configurator. Most configuration work
happens in the browser. When checkout starts, the selected product, quantity and
the minimum configuration needed to fulfil the order are sent to the
create-checkout-session Netlify Function.
Analytics events intentionally use aggregate properties only, such as product ID, quantity and whether a configuration exists. They must not include email addresses, names, shipping addresses, Stripe identifiers, full configuration metadata or preview URLs.
Legal basis: steps prior to entering into a contract and performance of a contract.
Checkout, payments and order fulfilment
Payments are handled by Stripe Checkout. The website creates a Stripe Checkout Session through a Netlify Function and redirects the visitor to Stripe. Stripe collects payment details on its hosted checkout page. Almagesto does not store card numbers.
When Stripe sends paid checkout webhook events, Netlify Functions retrieve and process the paid session and line items. The order pipeline may store order details in Baserow and send operational order notifications through Telegram. Processed order data may include Stripe session and event identifiers, product and line item details, customer email/name and shipping information returned by Stripe, as needed to fulfil and support the order.
Legal bases: performance of a contract, compliance with tax/accounting obligations and legitimate interest in preventing fraud and operating the order pipeline.
Newsletter
Newsletter signup forms submit to Mailchimp. When a visitor submits the form, Mailchimp receives the email address and the name fields submitted in the form. Mailchimp may process this data to manage mailing lists, send email campaigns and record subscription/unsubscription status.
Legal basis: consent. Visitors can unsubscribe using the link included in Mailchimp emails.
Analytics in normal mode
The codebase supports Plausible Analytics as the ordinary privacy-first
analytics provider when GATSBY_PLAUSIBLE_ENABLED=true and
GATSBY_PLAUSIBLE_DOMAIN is configured. Plausible is used for aggregate site
measurement and custom event goals. It is configured without marketing
identifiers and without sending personal data from the application.
Netlify Web Analytics may also be enabled in the Netlify dashboard outside this codebase. It is server-side analytics based on CDN logs and does not require client-side code from this repository.
Legal basis: legitimate interest in understanding aggregate site performance and product funnel health.
Campaign / marketing mode
When GATSBY_MARKETING_TAGS_ENABLED=true, the site displays a consent banner.
Google Tag Manager, direct GA4 tags or advertising pixels are not loaded before
marketing consent. Google Consent Mode v2 consent types default to denied:
ad_storage, analytics_storage, ad_user_data and ad_personalization.
If the visitor accepts marketing tags, the site may load configured providers such as Google Tag Manager, GA4 or advertising pixels configured through GTM. These tools may process usage data, campaign parameters, conversion events and technical identifiers according to their own policies and the tags configured by Almagesto.
Legal basis: consent.
TODO for maintainers: before enabling a campaign, document the exact providers and tag purposes in this page and in the Cookie Policy.
Cookies and Similar Technologies
See the Cookie Policy for the current storage inventory.
In normal mode, Almagesto does not need a marketing cookie banner because the site code does not load marketing tags. In campaign mode, consent choices are stored locally so the site can remember whether marketing tags may load.
Providers
Current or planned providers connected to the processing described above:
- Netlify: hosting, CDN, Functions and optional Web Analytics.
- Stripe: hosted checkout, payments and payment webhooks.
- Baserow: internal paid-order registry used by the order pipeline.
- Telegram: operational paid-order notifications.
- Mailchimp: newsletter list management.
- Plausible: optional privacy-first analytics.
- Google or social advertising providers: only in campaign mode after consent and only when configured.
Some providers may process data outside the European Economic Area. Where required, transfers should rely on the provider's data processing terms, standard contractual clauses or other valid transfer safeguards.
TODO for maintainers: confirm and archive current DPAs/SCCs for Netlify, Stripe, Baserow, Telegram, Mailchimp, Plausible and any campaign provider before production campaign use.
Retention
- Consent preferences: stored in the browser for 180 days.
- Newsletter popup state: stored locally for up to 1 day after closing or 1 year after signup so the popup is not repeatedly shown.
- Newsletter records: kept in Mailchimp until unsubscribe or list cleanup.
- Checkout and order records: kept for fulfilment, customer support, fraud prevention and legal/accounting obligations.
- Provider logs and analytics: retained according to the relevant provider settings and contracts.
TODO for maintainers: confirm exact internal order retention periods with the accountant/legal advisor and reflect them here.
User Rights
Depending on applicable law, users may have the right to access, rectify, erase, restrict or object to processing of their personal data, withdraw consent, receive a portable copy of their data and lodge a complaint with a competent data protection authority.
Requests can be sent to info@almagesto.xyz.
Changes
This policy may be updated when the website, providers, analytics setup or campaign tags change. If a change affects processing based on consent, Almagesto will request a new consent where required.