Privacy Policy
Effective date: 24 September 2026 · Last updated: 24 September 2026
Finogadget is operated by BIZZER LLC, a company incorporated in the State of Delaware, United States of America, with its registered office at 16192 Coastal Hwy, Lewes, DE 19958-3608, United States ("Finogadget", "we", "us", "our"). You can contact us at info@finogadget.com. We are committed to processing personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the ePrivacy rules of the EU Member States, and, for our own compliance as a US-based company, the applicable United States federal and state laws, including Section 5 of the Federal Trade Commission Act and, where their thresholds are met, the consumer privacy laws of the individual States (such as the Delaware Personal Data Privacy Act and the California Consumer Privacy Act).
This document is organised in two parts. Part 1 sets out the terms that apply to our cash-on-delivery (COD) and other sales to customers located in the European Union / European Economic Area ("EU/EEA"), which is our primary market (currently Spain, Portugal, Italy, Slovakia, Slovenia, Bulgaria, Romania, Greece, Czech Republic, Poland, Hungary, Germany, Lithuania, Latvia). Part 2 sets out how we, as a company established in the United States of America (Delaware), comply with United States federal and state law, and the terms that apply to customers located outside the EU/EEA. Where both parts could apply to you, the more specific and more protective provisions of Part 1 prevail for EU/EEA consumers; nothing in Part 2 reduces the rights granted to you in Part 1.
Part 1 — European Union / EEA customers (GDPR)
1.1 Who we are (Data Controller)
The data controller responsible for your personal data when you are located in the EU/EEA is BIZZER LLC, registered address 16192 Coastal Hwy, Lewes, DE 19958-3608, United States.
Email: info@finogadget.com.
EU/EEA representative (Article 27 GDPR)
Because we offer goods to individuals located in the European Union / European Economic Area from outside the EU/EEA, we are required to designate a representative in the Union. Our appointed EU representative is: Polidori Luca srl, Via Oslo, 1, 00100 Roma, Italy — Phone: +39 328 382 9322. EU/EEA data subjects may contact our representative on all matters related to the processing of their personal data, in addition to contacting us directly.
1.2 Scope of this Part
This Part applies to personal data we process about customers, prospective customers, and visitors of our website who are located in the EU/EEA, whether you buy from us or simply browse. It does not apply to third-party websites we may link to, which have their own privacy policies.
1.3 The personal data we collect
- Identity and contact data — first and last name, delivery and billing address, email address, telephone number.
- Order and transaction data — products ordered, order value, payment method (including cash-on-delivery selection), delivery details, order history, and communications with our customer service.
- Payment data — where you pay online, payment is processed by our payment providers; we do not store full card numbers. For cash-on-delivery orders we process only the information needed to fulfil and collect the order.
- Technical and usage data — IP address, device and browser type, operating system, referring pages, pages viewed, and interactions on our site, collected through cookies and similar technologies (see our Cookie Policy).
- Marketing and communications data — your preferences in receiving marketing from us and your communication preferences.
We do not intentionally collect special categories of data (such as health or biometric data), and we ask that you do not provide such data to us.
1.4 How we collect your data
- Directly from you — when you place an order, fill in a form or landing page, subscribe to our newsletter, or contact us.
- Automatically — through cookies, pixels and similar technologies when you use our website (see our Cookie Policy).
- From third parties — such as advertising and analytics platforms (e.g. Google, Meta), payment providers, and delivery/logistics partners who help us fulfil and confirm your orders.
1.5 Why we use your data and our legal bases
We only process your personal data where we have a lawful basis to do so under Article 6 GDPR. The table below summarises our main processing activities:
| Purpose of processing | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Processing, fulfilling and delivering your order, including cash-on-delivery collection | Identity, contact, order, payment data | Performance of a contract (Art. 6(1)(b)) |
| Customer service, handling questions, returns, refunds and complaints | Identity, contact, order data | Performance of a contract; legitimate interests (Art. 6(1)(b)/(f)) |
| Preventing fraud, abuse and non-genuine orders | Order, technical data | Legitimate interests (Art. 6(1)(f)) |
| Accounting, tax and record-keeping obligations | Identity, order, transaction data | Legal obligation (Art. 6(1)(c)) |
| Sending marketing communications and personalising offers | Contact, usage, marketing data | Consent, or legitimate interests where permitted (Art. 6(1)(a)/(f)) |
| Website analytics, advertising and measuring campaign performance (including Google Ads, Google Analytics and Meta) | Technical, usage data | Consent for non-essential cookies (Art. 6(1)(a)) |
| Improving our website, products and services | Usage, order data | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing at any time (see Section 1.12).
1.6 Marketing communications
We may send you information about similar products and offers by email or other channels where permitted by law. You can withdraw your consent or opt out at any time by using the unsubscribe link in any marketing message, or by contacting us at info@finogadget.com. Opting out of marketing does not affect service messages relating to your orders.
1.7 Cookies, advertising and similar technologies
We use cookies, pixels and similar technologies to operate our site, remember your preferences, analyse traffic and deliver relevant advertising. We use, among others, Google Ads, Google Analytics and the Meta Pixel. In line with Google's EU User Consent Policy, non-essential cookies (including analytics and advertising cookies) are only set after you give specific, informed, freely given consent through our consent-management (cookie banner) tool; you can withdraw that consent at any time. Where Google or another third party collects data as a result of your use of our site, that party acts as an independent controller of the data it collects; you can learn more about how Google uses this data at https://policies.google.com/technologies/partner-sites. Full details, including the categories and providers involved, are set out in our separate Cookie Policy.
1.8 Who we share your data with
We do not sell your personal data. We share it only with the following categories of recipients, and only to the extent necessary:
- Logistics and delivery partners — couriers and fulfilment providers who deliver your order and, for cash-on-delivery, collect payment.
- Payment service providers — to process online payments securely.
- Technology and hosting providers — website hosting, IT, customer-service and communication tools, some of which may be located in the United States or elsewhere outside the EU/EEA.
- Advertising and analytics providers — such as Google and Meta, to measure and improve our campaigns (subject to your cookie consent).
- Professional advisers and authorities — accountants, auditors, lawyers, and public authorities where required by law.
All processors act on our documented instructions under a written data-processing agreement that requires them to keep your data secure and to process it only for the agreed purposes.
1.9 International data transfers
We are established in the United States of America (Delaware), and our own processing of your data, as well as processing by some of our service providers, takes place outside the EU/EEA — including in the United States, for which the European Commission's adequacy decision (the EU-US Data Privacy Framework) covers only organisations certified under that framework; as we are not certified, it does not cover our own processing. This means your personal data may be transferred to, and processed in, countries that do not provide the same level of data protection as your home country.
Where we transfer personal data out of the EU/EEA, we rely on appropriate safeguards, in particular the Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical and organisational measures where necessary. Where a recipient (for example, a major advertising or analytics provider such as Google) is certified under the EU-US Data Privacy Framework for its own processing, transfers to that recipient for that processing may instead rely on that framework's adequacy decision. You may request a copy of the relevant safeguards by contacting us at info@finogadget.com.
1.10 How long we keep your data
- Order and transaction data — retained for the duration of our relationship and afterwards for the periods required by tax, accounting and consumer-protection law.
- Customer-service records — retained for as long as needed to handle your request and any related claim.
- Marketing data — retained until you withdraw consent or object, after which we suppress your details to honour your choice.
- Technical/cookie data — retained for the periods set out in our Cookie Policy.
When your data is no longer needed, we securely delete or anonymise it.
1.11 How we protect your data
We implement appropriate technical and organisational measures — including encryption in transit, access controls, and restricted staff access — designed to protect your personal data against unauthorised access, loss, misuse or alteration. While no method of transmission over the internet is completely secure, we work to protect your data and to notify you and the competent authority of any personal-data breach where required by law.
1.12 Your rights under the GDPR
If you are located in the EU/EEA, you have the right to:
- access the personal data we hold about you and obtain a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten") in certain circumstances;
- restrict or object to our processing, including objecting to direct marketing at any time;
- data portability — receive your data in a structured, commonly used, machine-readable format;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at info@finogadget.com. We will respond within one month, as required by the GDPR. You also have the right to lodge a complaint with your local data protection authority (a list of EU/EEA authorities is available on the European Data Protection Board website, edpb.europa.eu). We would, however, appreciate the chance to address your concerns before you approach the authority.
For the countries in which we currently sell, the competent data protection authorities are:
| Country | Data protection authority |
|---|---|
| Spain | Agencia Española de Protección de Datos (AEPD) |
| Portugal | Comissão Nacional de Protecção de Dados (CNPD) |
| Italy | Garante per la protezione dei dati personali |
| Slovakia | Úrad na ochranu osobných údajov Slovenskej republiky |
| Slovenia | Informacijski pooblaščenec Republike Slovenije |
| Bulgaria | Commission for Personal Data Protection (CPDP) |
| Romania | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) |
| Greece | Hellenic Data Protection Authority (HDPA) |
| Czech Republic | Úřad pro ochranu osobních údajů (ÚOOÚ) |
| Poland | Urząd Ochrony Danych Osobowych (UODO) |
| Hungary | Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) |
| Germany | the competent federal or state data protection authority (Bundesbeauftragte für den Datenschutz und die Informationsfreiheit / Landesdatenschutzbehörde) |
| Lithuania | Valstybinė duomenų apsaugos inspekcija (VDAI) |
| Latvia | Datu valsts inspekcija (DVI) |
1.13 Children's privacy
Our website and products are not directed at children, and we do not knowingly collect personal data from children under the age of 16 (or the applicable minimum age in your country). If you believe a child has provided us with personal data, please contact us and we will delete it.
1.14 Third-party links
Our website may contain links to third-party sites, plugins and applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy policy of every site you visit.
1.15 Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Where we use automated tools to detect fraud or non-genuine orders, meaningful human review is available on request.
Part 2 — United States compliance (federal and state privacy laws)
BIZZER LLC is a limited liability company organised under the laws of the State of Delaware, United States of America. The United States does not have a single comprehensive federal privacy law; our processing is subject to Section 5 of the Federal Trade Commission Act (which prohibits unfair or deceptive practices, including in privacy notices), to sector-specific federal laws such as the CAN-SPAM Act, the Telephone Consumer Protection Act and the Children's Online Privacy Protection Act, and, where their applicability thresholds are met, to the consumer privacy laws of the individual States (for example the Delaware Personal Data Privacy Act and the California Consumer Privacy Act as amended by the California Privacy Rights Act). This Part complements, and does not replace, Part 1 above for EU/EEA data subjects, and sets out the position for customers and website visitors located in the United States and elsewhere outside the EU/EEA.
2.1 Categories of personal information we collect
In the preceding 12 months we have collected, and we continue to collect, the following categories of personal information, from the sources and for the purposes described in Part 1:
- Identifiers — name, delivery address, telephone number, email address, IP address and online identifiers.
- Commercial information — the products you ordered, order history and customer-service communications.
- Internet or other electronic network activity — browsing and interaction data collected through cookies and similar technologies, subject to your choices (see our Cookie Policy).
- Approximate geolocation — derived from your IP address.
We do not collect sensitive personal information (such as government identification numbers, precise geolocation, health data or financial-account credentials) for the purpose of inferring characteristics about you, and we do not use it for any purpose other than those permitted by law.
2.2 Sale, sharing and targeted advertising
We do not sell personal information for money. However, when you allow advertising cookies, providers such as Google and Meta may receive online identifiers and browsing activity in order to measure and personalise advertising; under some State laws this may be considered a "sale", "sharing" for cross-context behavioural advertising, or "targeted advertising". You can opt out at any time through the "Cookie settings" link in the footer of our website, and we treat a Global Privacy Control (GPC) signal sent by your browser as a valid request to opt out for that browser. We do not knowingly sell or share the personal information of consumers under 16 years of age.
2.3 Your State privacy rights
Depending on the State in which you reside, and subject to the conditions and exceptions of the applicable law, you may have the right to:
- know and access the personal information we have collected about you, and obtain a copy of it in a portable format;
- correct inaccurate personal information;
- delete personal information we have collected from you;
- opt out of the sale of personal information, of sharing for cross-context behavioural advertising, of targeted advertising and of profiling in furtherance of decisions that produce legal or similarly significant effects;
- not receive discriminatory treatment for exercising any of these rights.
To exercise these rights, email us at info@finogadget.com. We will verify your request by matching the information you provide with the information we hold, and we will respond within 45 days (extendable by a further 45 days where reasonably necessary, in which case we will inform you). You may use an authorised agent to submit a request on your behalf, subject to proof of authorisation. If we decline to take action on your request, you may appeal our decision by replying to our response with the subject line "Privacy appeal"; we will respond to your appeal within the timeframe required by the applicable law and, if the appeal is denied, you may contact the Attorney General of your State.
2.4 Children's privacy
Our website is not directed to children under 13, and we do not knowingly collect personal information from children under 13 in accordance with the Children's Online Privacy Protection Act (COPPA). If you believe that a child has provided us with personal information, please contact us and we will delete it.
2.5 Emails, calls and text messages
Any marketing emails we send comply with the CAN-SPAM Act: they identify us as the sender, include our postal address and contain a working unsubscribe link, and we honour opt-out requests promptly. For cash-on-delivery orders we may call or text the telephone number you provide solely to confirm, arrange and deliver the order you requested. We do not make marketing calls or send marketing text messages using an automatic telephone dialling system or an artificial or prerecorded voice without your prior express written consent, as required by the Telephone Consumer Protection Act, and you can opt out of text messages at any time by replying STOP.
2.6 Security and data breaches
We apply reasonable technical and organisational security measures appropriate to the nature of the personal information we hold. If a breach of security affecting your personal information occurs, we will notify you and, where required, the competent authorities in accordance with the applicable State breach-notification laws — including Delaware law (Title 6, Chapter 12B of the Delaware Code) — and, for EU/EEA data subjects, the GDPR.
2.7 Transfers and processing location
Personal information we collect is processed in the United States and may also be processed in other countries where we or our service providers operate, including the EU/EEA. For personal data of EU/EEA data subjects, the safeguards described in Section 1.9 apply.
2.8 Data controller identity
The business responsible for personal information handled under this Part 2 is BIZZER LLC, 16192 Coastal Hwy, Lewes, DE 19958-3608, United States.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in the law. The "Last updated" date at the top shows when it was last revised. Material changes will be notified through our website or by other appropriate means.
Contact us
If you have any questions about this document, or wish to exercise any of your rights, please contact us:
Finogadget (operated by BIZZER LLC)
Registered address: 16192 Coastal Hwy, Lewes, DE 19958-3608, United States
Email: info@finogadget.com
Website: finogadget.com