Privacy Policy
Last updated: 07/29/2026 · pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR")
1. Data Controller
The data controller is Fabio Ferrari, a natural person not carrying on a business activity, operating Stampista Scanner, Italian tax code FRRFBA96R18B774C, residing at Piazzale Cuoco 5, Milan, Italy, reachable at contact@stampista.com.
No Data Protection Officer has been appointed, as processing is not carried out on a large scale nor does it consist of regular and systematic monitoring of data subjects as a core activity, per Art. 37 GDPR. This assessment will be revisited as the service grows.
2. Categories of Data Processed
- Account data: name/nickname, email address, password (stored only in cryptographically secure form, never in plain text).
- Verification and login-security data: the email verification code sent at registration (stored only in hashed form, with limited validity) and, if you enable two-factor authentication (2FA), its secret key (stored encrypted) and backup codes (stored only in hashed form).
- Uploaded content and product metadata: STL files of products uploaded to run searches, plus any product name, description, and tags you provide. The platform accepts STL files only (synthetic 3D models): photos and videos cannot be uploaded, so no real-world image that might contain personal data is ever transmitted to third-party providers. STL files receive heightened confidentiality treatment: they are never made publicly accessible, are stored in a server area not reachable via the web, and are transmitted to the matching service only temporarily and encrypted to generate the search image, without being permanently stored there.
- Search results: for each search, we store the results returned by the reverse-image search engine, which may include the page URL, a thumbnail image of the product, the site's domain name, and a best-effort geographic market. We do not store or display the seller's name: results show only the product, the domain, and a link to the source page.
- Requests and reports: the subject, category, and text of requests or reports submitted through the in-app support channel, and our replies.
- Notifications: notifications generated within the platform (e.g. search completed, limit reached) and the related email-delivery preferences.
- Technical data: IP address, access logs, session identifiers, technical cookies (see Cookie Policy).
- Service usage data: number of searches run per month, automatic-check scheduling settings, notification preferences.
3. Purposes and Legal Basis
| Purpose | Legal basis |
|---|---|
| Account creation/management, provision of the requested service (search, history, automatic checks) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Transactional emails (email verification, password reset, result and service notifications) | Performance of a contract / legitimate interest in service operation (Art. 6(1)(b), 6(1)(f)) |
| Email address verification and, if enabled by the user, two-factor authentication (2FA) | Performance of a contract / legitimate interest in account security (Art. 6(1)(b), 6(1)(f)) |
| Security, abuse/fraud prevention, monthly usage limit enforcement | Legitimate interest (Art. 6(1)(f)) |
| Automated similarity analysis (visual and semantic) via third-party services and local processing | Performance of a contract, at the user's explicit request (Art. 6(1)(b)) |
| Handling and responding to requests and reports submitted by the user | Performance of a contract / legitimate interest (Art. 6(1)(b), 6(1)(f)) |
| Compliance with legal obligations (e.g. requests from supervisory authorities) | Legal obligation (Art. 6(1)(c)) |
4. Automated Processing and Similarity Score
Note: the semantic component of the score (local processing of the name, description, and tags) is currently disabled for technical reasons. Only the visual-similarity percentage is computed.
For each search result, the service automatically computes a similarity score, made up of a visual-similarity percentage (based on perceptual hashing) and, when you provide a description or tags, a semantic-coherence percentage between that text and the result (computed locally on our server, without sending your description to any third party). The two values are combined into an overall score, shown as a plain numeric value with no qualitative label or category assigned by the platform (we do not use terms like "copycat," "competitor," or similar): it is the user, not the service, who interprets the number and decides how to treat each result. This score is an automated similarity estimate and does not constitute a finding of intellectual property infringement, legal advice, or a judgment on any third party's conduct. It does not produce legal effects or similarly significantly affect any third party within the meaning of Art. 22 GDPR: it is informational support for the user, who remains solely responsible for any further verification or action.
5. Recipients and Transfers Outside the EU
The platform accepts STL files only, so the reverse-image search is always run from a synthetic render of the 3D model, meaning no content that might contain personal data (real-world photos or videos) is ever transmitted to third-party providers. The recipients of data are:
- Hosting provider (IONOS) - European Union, for the main site's infrastructure.
- Image-matching microservice provider - [Render/Railway, specify region], for rendering the uploaded STL files.
- SerpAPI LLC (United States) - is the sole reverse-image search engine used and receives only the images generated by rendering uploaded STL files (synthetic renders that, depicting no real people or places, do not constitute personal data), to run the search via Google Lens. Because only synthetic, non-personal content passes through this channel, no transfer of personal data to a third country takes place.
- Email service provider - for transactional emails sent from contact@stampista.com.
- Public authorities, where required by law.
We do not sell or share data for third-party marketing purposes.
6. Third-Party (Seller) Data Found in Search Results
To minimize the personal data we process, search results do not include the seller's name: we show only the product image, the site's domain name, and a link to the source page, obtained via automated search of publicly accessible web sources. A site's URL or domain may still, in some cases, indirectly point to an identifiable individual (for example, a sole-trader online shop). To the extent this involves processing personal data of third parties who are not platform users, that processing is based on the legitimate interest of the controller and users in identifying potential intellectual-property infringement (Art. 6(1)(f) GDPR), balanced against the rights of the individuals concerned. Given the practical impossibility of individually notifying every person found via search, we rely on the exemption in Art. 14(5)(b) GDPR (disproportionate effort), and this policy serves as the substitute transparency measure.
If you are a third party whose personal data (or data you consider sensitive or confidential) appears in a search result generated by a platform user and you do not want it shown, or you wish to exercise your rights (access, rectification, erasure, objection), write to contact@stampista.com specifying the result URL and the data concerning you. We will respond within 30 days and, where the request is well-founded, remove the data from visible results.
If you operate a website or platform (for example a marketplace such as Etsy) and do not want links to your pages or their content to appear among the service's results, you can request their removal by writing to contact@stampista.com and indicating the domain or URLs concerned: we will manually exclude that domain from visible results within a reasonable time.
7. Retention Period
- Account data and uploaded content: for the lifetime of the account, until a deletion request is made.
- Search history and results: retained alongside the account to power "Past Searches"; deleted when the account is deleted.
- STL files: retained only on the main web application while the product/account exists; not permanently retained by the matching microservice.
- Requests and reports: retained for the lifetime of the account, to allow consultation and handling; deleted when the account is deleted.
- Technical security logs: up to 6 months, unless longer retention is required to investigate unlawful conduct.
- When you delete your account via the dedicated option in settings, the account, uploaded content, search history, notifications, requests, and 2FA data are deleted immediately and permanently from the database and file storage; any residual copies in backups or technical logs are removed or anonymized within 30 days, except where a legal obligation requires otherwise.
8. Data Security
We implement technical and organizational measures appropriate to the risk (Art. 32 GDPR), including:
- passwords stored with secure hashing algorithms, never in plain text;
- encrypted communication over HTTPS, with forced redirection and security headers (HSTS, Content-Security-Policy, clickjacking protection);
- email address verification at registration and availability of two-factor authentication (2FA), with its secret key stored encrypted (AES-256) and backup codes stored only in hashed form;
- rate limiting on login, registration, password recovery, and verification, to counter automated attacks;
- access control based on authentication and ownership checks for every uploaded file - particularly STL files, which are never exposed via direct public URLs;
- synchronous deletion of temporarily published search images immediately after use.
9. Your Rights
As a data subject, you may at any time request, by contacting contact@stampista.com:
- access to your personal data (Art. 15 GDPR);
- rectification of inaccurate or incomplete data (Art. 16 GDPR);
- erasure ("right to be forgotten," Art. 17 GDPR);
- restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- objection to processing based on legitimate interest (Art. 21 GDPR);
- lodging a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or your local supervisory authority.
10. Minors
The service is not intended for individuals under 18 years of age. We do not knowingly collect data from minors.
11. Changes to This Policy
We reserve the right to update this policy periodically. In case of material changes, we will notify you by email or via a notice on the site.