Privacy Policy
This policy describes how Super-Bike processes the personal data of users and customers of the super-bike.ch online store. The store serves Switzerland and Liechtenstein. The text covers two levels. The Swiss level, based on the Federal Act on Data Protection (nFADP) and other applicable Swiss regulations, is always active. The European level, based on Regulation (EU) 2016/679 (GDPR), is provided for and applies to customers located in the European Union if sales to the European Union are opened. Where the two regimes differ, the difference is explicitly indicated.
1. Data controller and contact details
The data controller is Super-Bike, sole proprietorship of Raffaele Fico.
- The postal address is Corso San Gottardo 109, 6830 Chiasso, Switzerland.
- The contact email address is [email protected].
- The enterprise identification number (IDI/UID) is CHE-160.217.874. The VAT number is CHE-160.217.874 VAT.
For any request relating to personal data and for the exercise of the rights described in this policy, you can write to the email address [email protected].
A Data Protection Officer (DPO) has not been appointed because the processing carried out by Super-Bike does not fall within the cases in which such appointment is mandatory. The contact point for data-related matters remains the email address indicated above.
Representative in the European Union
Super-Bike is based in Switzerland and does not direct its activities towards the European Union, where sales and shipping are not active. For this reason, it is not required to designate a representative in the Union pursuant to Article 27 of the GDPR. If sales to the European Union are opened in the future, the controller will designate in writing a representative established in a Member State and will indicate their details here.
2. What data we process and for what purposes
We process the data that the user provides to us when browsing the website, creating an account, placing an order, contacting us or subscribing to the newsletter. In summary, this includes personal and contact details, delivery and billing addresses, order and payment data, browsing data and technical identifiers collected through cookies and similar technologies.
For each purpose, we also indicate below the legal basis provided for by the GDPR (Article 6), which applies to customers and visitors in the European Union. On the Swiss side, processing is lawful on the basis of the principles of the nFADP.
Where we rely on legitimate interest (Article 6(1)(f) GDPR), the interest pursued is to ensure the IT security of the store and prevent payment fraud. Any non-strictly necessary cookies set by reCAPTCHA remain subject to consent, as indicated in the Cookie Policy.
Providing contact, delivery and payment data is necessary to conclude and perform the purchase contract. Refusal to provide this data prevents the order from being completed. Providing data for the newsletter and profiling cookies is instead optional and is based on consent.
Should we process data in the future for a purpose different from those indicated here, we will first provide updated information.
3. Cookies and tracking technologies
The website uses technical cookies necessary for the operation of the store, which do not require consent, and statistical, profiling and marketing cookies, which are activated only after the user's consent. Details of the categories, individual tools and their respective durations, together with instructions for modifying or withdrawing choices, are set out in the Cookie Policy. Consent can be modified or withdrawn at any time through the cookie management link on the website.
4. Data recipients and providers
To manage the store and related services, we use third-party providers that process personal data on our behalf or as independent controllers for their respective purposes. The main recipients and providers are as follows.
Payments
- Wallee and PostFinance Checkout, which process credit card payments (Visa and Mastercard)
- PayPal
- PostFinance
- Twint
- HeyLight / HeidiPay
Statistics, advertising and tag management
- Google Tag Manager (GTM)
- Google Analytics 4 (GA4)
- Google Ads
- Meta pixel (Facebook)
- TikTok
- YouTube (videos embedded on the website)
Content delivery network, security and fraud prevention
- Cloudflare
- reCAPTCHA
Social access and login
- Social login via Facebook, Google and TikTok
Communications and marketing
- Newsletter managed internally through a PrestaShop module installed on the website, without an external email marketing provider
- Knowband (abandoned cart recovery)
- Website exit popup (PrestaShop module for the exit message)
We also disclose data, where necessary, to carriers and freight forwarders responsible for delivery, accounting and tax advisers, and competent authorities where required by law.
Data is not sold. It is disclosed only to the recipients indicated above and for the purposes described in this policy.
5. Transfers abroad and to the United States
Some of the providers indicated above, in particular Google, Meta, TikTok, Cloudflare and PayPal, may also process data outside Switzerland and the European Union, including in the United States.
Depending on the provider, one of the following safeguards applies to these transfers.
- For certified US providers, the European Union adequacy decision relating to the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023). The certification of the individual provider can be verified in the official Data Privacy Framework register.
- In the absence of certification, the Standard Contractual Clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914), accompanied by a transfer assessment.
On the Swiss side, the disclosure of data to the United States is based on the Swiss-U.S. Data Privacy Framework for US providers that have joined it, in force since 15 September 2024, and, in the absence of certification, on the contractual safeguards provided for by Articles 16 and 17 nFADP. In all cases, the recipient countries are indicated and the required safeguards are applied.
The safeguard actually applicable must be verified for each provider, as it may vary from one tool to another.
6. Retention periods
We retain personal data for the time necessary to fulfil the purposes for which it was collected and to comply with legal obligations.
- Accounting and invoicing data is retained for 10 years, in accordance with the obligation to retain accounting records provided for by Article 958f of the Code of Obligations.
- Customer account data is retained until the account is deleted.
- Data processed for newsletters and marketing is retained until consent is withdrawn.
- Data collected through profiling cookies is retained for the duration of the cookies indicated in the Cookie Policy or until consent is withdrawn.
At the end of these periods, the data is deleted or anonymised.
7. User rights
The user's rights depend on the applicable regime. They are described below, separating Switzerland from the European Union.
7.1 Rights under Swiss law (nFADP)
Persons located in Switzerland may exercise the following rights against Super-Bike.
- Right of access to one's own data (Article 25 nFADP).
- Right to the delivery or transmission of data in a commonly used electronic format, in the cases provided for (Article 28 nFADP).
- Right to rectification of inaccurate data (Article 32 nFADP).
The nFADP does not provide for an autonomous "right to be forgotten" like that under the GDPR. In Switzerland, deletion or prohibition of processing is obtained through the protection of personality rights, by demonstrating an unjustified infringement of one's personality under the provisions of the nFADP and civil law.
7.2 Rights under European Union law (GDPR)
Persons located in the European Union may exercise, in addition to the above, the following rights provided for by the GDPR.
- Right of access (Article 15).
- Right to rectification (Article 16).
- Right to erasure, the so-called right to be forgotten (Article 17).
- Right to restriction of processing (Article 18).
- Right to data portability (Article 20).
- Right to object to processing, including direct marketing (Article 21).
- Right not to be subject to decisions based solely on automated processing (Article 22).
- Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7, paragraph 3). Withdrawal must be as easy as giving consent and takes place, for cookies, through the cookie management link, and for the newsletter through the unsubscribe link included in each message.
To exercise these rights, simply write to [email protected].
8. Supervisory authorities and complaints
Persons located in Switzerland may contact the Federal Data Protection and Information Commissioner (FDPIC).
Persons located in the European Union may lodge a complaint with the competent supervisory authority, normally that of the Member State of residence, place of work or place where the alleged infringement occurred (Article 77 GDPR). Since Super-Bike does not have a main establishment in the European Union, the one-stop-shop mechanism does not apply and each competent national authority may intervene.
9. Automated decision-making
Super-Bike does not make decisions based solely on automated processing, including decisions that produce legal effects or similarly and significantly affect individuals, pursuant to Article 22 GDPR. Profiling for marketing purposes, carried out through the cookies and pixels indicated in the Cookie Policy, is subject to the user's consent and right to object, and does not constitute automated decision-making of this kind.
10. Minors
The store and its services are not intended for minors. We do not knowingly collect data from minors without the consent of the person exercising parental responsibility. For customers and visitors located in the European Union, where processing is based on consent, such consent is valid from the age provided for by Article 8 of the GDPR and the applicable national rules. If we become aware that we have processed data relating to a minor without the required consent, we will delete it without delay.
11. Security and access control
We adopt appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse. Access to the store management panel (PrestaShop backend) is restricted to authorised persons, with personal credentials and appropriate authentication measures.
12. Updates to this policy
This policy may be updated to adapt it to changes in the store, the providers used or the applicable legislation. The version in force is always the one published on this page, with the date of the latest update indicated at the beginning.