Stampista Scanner logo Stampista Scanner

Privacy Policy

Last updated: 07/29/2026 · pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR")

1. Data Controller

The data controller is Fabio Ferrari, a natural person not carrying on a business activity, operating Stampista Scanner, Italian tax code FRRFBA96R18B774C, residing at Piazzale Cuoco 5, Milan, Italy, reachable at contact@stampista.com.

No Data Protection Officer has been appointed, as processing is not carried out on a large scale nor does it consist of regular and systematic monitoring of data subjects as a core activity, per Art. 37 GDPR. This assessment will be revisited as the service grows.

2. Categories of Data Processed

3. Purposes and Legal Basis

Purpose Legal basis
Account creation/management, provision of the requested service (search, history, automatic checks)Performance of a contract (Art. 6(1)(b) GDPR)
Transactional emails (email verification, password reset, result and service notifications)Performance of a contract / legitimate interest in service operation (Art. 6(1)(b), 6(1)(f))
Email address verification and, if enabled by the user, two-factor authentication (2FA)Performance of a contract / legitimate interest in account security (Art. 6(1)(b), 6(1)(f))
Security, abuse/fraud prevention, monthly usage limit enforcementLegitimate interest (Art. 6(1)(f))
Automated similarity analysis (visual and semantic) via third-party services and local processingPerformance of a contract, at the user's explicit request (Art. 6(1)(b))
Handling and responding to requests and reports submitted by the userPerformance of a contract / legitimate interest (Art. 6(1)(b), 6(1)(f))
Compliance with legal obligations (e.g. requests from supervisory authorities)Legal obligation (Art. 6(1)(c))

4. Automated Processing and Similarity Score

Note: the semantic component of the score (local processing of the name, description, and tags) is currently disabled for technical reasons. Only the visual-similarity percentage is computed.

For each search result, the service automatically computes a similarity score, made up of a visual-similarity percentage (based on perceptual hashing) and, when you provide a description or tags, a semantic-coherence percentage between that text and the result (computed locally on our server, without sending your description to any third party). The two values are combined into an overall score, shown as a plain numeric value with no qualitative label or category assigned by the platform (we do not use terms like "copycat," "competitor," or similar): it is the user, not the service, who interprets the number and decides how to treat each result. This score is an automated similarity estimate and does not constitute a finding of intellectual property infringement, legal advice, or a judgment on any third party's conduct. It does not produce legal effects or similarly significantly affect any third party within the meaning of Art. 22 GDPR: it is informational support for the user, who remains solely responsible for any further verification or action.

5. Recipients and Transfers Outside the EU

The platform accepts STL files only, so the reverse-image search is always run from a synthetic render of the 3D model, meaning no content that might contain personal data (real-world photos or videos) is ever transmitted to third-party providers. The recipients of data are:

We do not sell or share data for third-party marketing purposes.

6. Third-Party (Seller) Data Found in Search Results

To minimize the personal data we process, search results do not include the seller's name: we show only the product image, the site's domain name, and a link to the source page, obtained via automated search of publicly accessible web sources. A site's URL or domain may still, in some cases, indirectly point to an identifiable individual (for example, a sole-trader online shop). To the extent this involves processing personal data of third parties who are not platform users, that processing is based on the legitimate interest of the controller and users in identifying potential intellectual-property infringement (Art. 6(1)(f) GDPR), balanced against the rights of the individuals concerned. Given the practical impossibility of individually notifying every person found via search, we rely on the exemption in Art. 14(5)(b) GDPR (disproportionate effort), and this policy serves as the substitute transparency measure.

If you are a third party whose personal data (or data you consider sensitive or confidential) appears in a search result generated by a platform user and you do not want it shown, or you wish to exercise your rights (access, rectification, erasure, objection), write to contact@stampista.com specifying the result URL and the data concerning you. We will respond within 30 days and, where the request is well-founded, remove the data from visible results.

If you operate a website or platform (for example a marketplace such as Etsy) and do not want links to your pages or their content to appear among the service's results, you can request their removal by writing to contact@stampista.com and indicating the domain or URLs concerned: we will manually exclude that domain from visible results within a reasonable time.

7. Retention Period

8. Data Security

We implement technical and organizational measures appropriate to the risk (Art. 32 GDPR), including:

9. Your Rights

As a data subject, you may at any time request, by contacting contact@stampista.com:

10. Minors

The service is not intended for individuals under 18 years of age. We do not knowingly collect data from minors.

11. Changes to This Policy

We reserve the right to update this policy periodically. In case of material changes, we will notify you by email or via a notice on the site.