Last updated: September 21, 2026
Think Tank S.R.L., with registered office at Via dei Lanaioli 60, Frazione Funo, 40050 Argelato (BO) Italy, VAT and Tax Code IT02712121207, REA BO-461105, owner of the website accessible at the URL weilizheng.com, as well as any other domains, subdomains, or addresses attributable to the same online store www.weilizheng.com (hereinafter, the “Site”), informs users and customers (hereinafter, the “Users” or “Data Subjects”) that personal data relating to browsing on the Site, account creation and management, purchases, payments, returns and refunds, assistance requests, and the use of other services will be processed in compliance with Regulation (EU) 2016/679 (“GDPR”), Legislative Decree 196/2003, as amended, and applicable personal data protection legislation. This notice is provided pursuant to Articles 13 and 14 of the GDPR and does not apply to third-party sites or services that may be accessible via links, integrations, or connections on the Site, for which their respective privacy policies apply.
1. DATA CONTROLLER
The Data Controller is Think Tank S.R.L., with registered office at Via dei Lanaioli 60, Frazione Funo, 40050 Argelato (BO) Italy, VAT and Tax Code IT02712121207, REA BO-461105, (hereinafter, the “Controller”). For matters relating to personal data protection and for the exercise of the rights provided for by the GDPR, the Controller can be contacted at the e-mail address support@weilizheng.com.
2. PURPOSES AND LEGAL BASES FOR DATA PROCESSING
a) To allow for proper browsing and operation of the Site. Technical and navigation data necessary for the operation of the Site, session management, cart, checkout, security, and strictly necessary preferences are processed for the performance of the services requested by the User pursuant to Art. 6, para. 1, letter b), of the GDPR and, where applicable, based on the legitimate interest of the Controller to ensure the security, integrity, and proper functioning of the Site pursuant to Art. 6, para. 1, letter f), of the GDPR.
b) To allow the use of customer account features. The Site may provide Users with customer account features provided and technically managed via the Shopify platform, which allow, among other things, to authenticate, view order history, manage profile information and addresses, check order status, and access any return features or other reserved services. Think Tank S.R.L. processes personal data related to the use of the customer account to make these features available and to manage the relationship with the User, pursuant to Art. 6, para. 1, letter b), of the GDPR. Technical management of the account and related authentication systems is carried out via Shopify, as specified in the section dedicated to recipients and platform providers. The provision of the necessary data is a requirement for the use of the relevant features.
c) To manage the purchase procedure and execute sales contracts. Identification, contact, billing, and shipping data, data relating to orders, products, returns, the right of withdrawal, refunds, legal guarantees, and related communications are processed to take pre-contractual measures at the request of the Data Subject and to conclude and perform the contract pursuant to Art. 6, para. 1, letter b), of the GDPR, as well as to comply with legal obligations related to sales pursuant to Art. 6, para. 1, letter c), of the GDPR.
d) To manage payments, collections, refunds, and related checks. Transaction data is processed to receive and reconcile payments, issue refunds, manage disputes, chargebacks, anti-fraud checks, and any other activity necessary for the execution of the purchase or return. The legal basis consists of Art. 6, para. 1, letter b), of the GDPR and, for regulatory and accounting compliance, Art. 6, para. 1, letter c), of the GDPR; anti-fraud and management activities may also be based on the legitimate interest of the Controller in the security of transactions pursuant to Art. 6, para. 1, letter f), of the GDPR. Full payment instrument data, such as the full card number and related security codes, are acquired and processed by payment service providers according to their respective systems and are not stored directly by the Controller.
e) To manage requests, assistance, and customer service. Data communicated via e-mail, telephone, contact forms, messaging, or other support channels are processed to respond to User requests and to manage pre-contractual, contractual, and post-sales activities. The legal basis is Art. 6, para. 1, letter b), of the GDPR when the request concerns a contractual or pre-contractual relationship and, in other cases, the legitimate interest of the Controller to respond to requests received pursuant to Art. 6, para. 1, letter f), of the GDPR.
f) To prevent abuse, fraud, and illicit use of the Site and transactions. The Controller may process data relating to navigation, the account, orders, and transactions to check for anomalies, attempted fraud, unauthorized use of payment instruments, abusive access, or violations of applicable conditions. Processing is based on the legitimate interest of the Controller in the security of the Site, transactions, and its assets pursuant to Art. 6, para. 1, letter f), of the GDPR, as well as, where applicable, on the fulfillment of legal obligations pursuant to Art. 6, para. 1, letter c), of the GDPR.
g) To send newsletters and commercial communications. The e-mail address and any additional data used for sending newsletters, promotional communications, and commercial initiatives are processed based on the consent of the Data Subject pursuant to Art. 6, para. 1, letter a), of the GDPR, except in cases where the law allows communications regarding similar products or services without further consent. Consent is optional and may be revoked at any time via the link provided in the communications or by contacting the Controller.
h) To perform statistical analysis, measurement, and marketing activities using cookies or similar technologies. Processing carried out through cookies and other non-strictly necessary technologies, including non-anonymized analytics tools, campaign measurement, personalization, and advertising, is carried out with the User's consent pursuant to Art. 6, para. 1, letter a), of the GDPR, in cases where such consent is required. Detailed information, durations, and methods for managing preferences are described in the Site's Cookie Policy.
i) To comply with legal, tax, accounting, and administrative obligations. Data is processed to comply with obligations provided for by applicable legislation, including provisions regarding tax, accounting, consumer protection, product safety, and cooperation with authorities. The legal basis is Art. 6, para. 1, letter c), of the GDPR.
j) To establish, exercise, or defend legal claims. Data may be processed to manage complaints, disputes, and litigation, debt collection, protect the Controller’s rights, or defend against third-party claims, based on the legitimate interest of the Controller pursuant to Art. 6, para. 1, letter f), of the GDPR.
3. TYPE AND SOURCES OF PROCESSED DATA
The Site is not intended for the conclusion of purchases by persons under 18 years of age. The Controller does not intend to knowingly collect personal data from minors to allow them to make purchases on the Site.
3.1. Navigation and technical data
During normal navigation, IP addresses, device and session identifiers, browser and operating system data, connection information, URLs and pages visited, date and time of requests, technical events, security logs, and other data generated by interaction with the Site may be processed. Such data may be processed by the Controller, by Shopify, and by other technical providers involved in order to provide the service, ensure security and functionality, prevent abuse, and produce usage statistics, where permitted.
3.2. Cookies and similar technologies
The Site uses cookies, pixels, tags, local storage, and similar technologies. Strictly necessary cookies are used for the operation of the Site and its features; preference, statistics, and marketing technologies are used within the limits and according to the choices expressed by the User via the consent management system. For detailed information on individual tools, providers, purposes, durations, and methods for revoking or modifying consent, please refer to the Cookie Policy available on the Site.
3.3. Account, order, and contractual relationship data
First and last name, e-mail address, phone number, credentials and information necessary for account management, shipping and billing addresses, tax code or other tax data, products purchased or returned, amounts, discounts, shipping and delivery methods, order status, and information relating to withdrawal, returns, exchanges, refunds, warranty, and post-sales assistance may be processed.
3.4. Payment and refund data
The Controller may receive information related to the transaction, such as the payment method used, amount, currency, authorization or payment status, transaction identifiers, partially masked payment instrument data, and information necessary for refunds, disputes, or reconciliations. Full card data and confidential payment credentials are processed by payment service providers according to their respective policies and conditions.
3.5. Data relating to third parties
The User may provide data of a third party, for example, when indicating a different recipient for delivery or purchasing a gift. Such data are processed exclusively to the extent necessary to execute the order and related activities. The User is invited to communicate third-party data only when authorized to do so. The Controller will provide the third party with the information required by Art. 14 of the GDPR in the cases and within the timeframes provided for by applicable law.
3.6. Data obtained from sources other than the Data Subject
Some data may be received from Shopify, Sugo S.n.c., payment service providers, banks, wallets, payment circuits, couriers, carriers, anti-fraud services, applications integrated into the Site, or other providers involved in the execution of the order and requested services, limited to information necessary for the purposes described in this notice.
4. DATA PROCESSING METHODS
Processing is carried out using electronic, telematic, and, where necessary, paper-based tools, through operations of collection, recording, organization, structuring, storage, consultation, processing, use, communication, comparison, restriction, cancellation, and destruction, in accordance with principles of lawfulness, fairness, transparency, minimization, and security, and with the adoption of appropriate technical and organizational measures pursuant to Art. 32 of the GDPR.
The Controller may use automated security and anti-fraud systems to identify anomalous transactions or behaviors and to subject certain operations to further checks. As a rule, the Controller does not adopt decisions based solely on automated processing that produce legal effects or similarly significantly affect the Data Subject. However, payment providers and other third parties may independently carry out automated checks according to their own policies and conditions, for example, to authorize or reject a transaction.
5. DATA STORAGE
Personal data is stored for the time necessary to fulfill the purposes for which it is processed and, subsequently, for the periods required by applicable law or necessary to protect the Controller’s rights. In particular:
– data relating to orders, contracts, payments, refunds, and related administrative/accounting formalities are stored for the period necessary for the performance of the relationship and, where required by civil, tax, or accounting legislation, for up to ten years, without prejudice to further periods necessary in the event of disputes or litigation;
– account data is stored until the account is deleted, without prejudice to the separate storage of data that must be kept for legal obligations, execution of orders, prevention of abuse, or protection of rights;
– data relating to assistance requests is stored for the time necessary to manage the request and, if connected to an order or dispute, for the period applicable to the relevant relationship;
– data processed for newsletter and marketing purposes is stored until the Data Subject’s consent is revoked or objection is made, except for the minimum storage necessary to document the choices expressed;
– data collected via cookies and similar technologies is stored according to the times indicated in the Cookie Policy and in the consent settings;
– data processed to comply with legal obligations is stored for the period provided for by the relevant legislation;
– data processed to establish, exercise, or defend a right is stored for the time necessary to manage the relevant claim and, in any case, until the expiration of the applicable limitation periods or the resolution of any proceedings that may be initiated.
6. DATA COMMUNICATION AND SUBJECTS INVOLVED IN PROCESSING
Personal data may be communicated or made accessible, within the limits necessary for the purposes indicated above, to the subjects described below.
6.1. Sugo S.n.c. di Federico Sacchi e Cristian Antolini
The Controller uses Sugo S.n.c. di Federico Sacchi e Cristian Antolini, with registered office in Crevalcore (BO), via Giacomo Matteotti 154, Tax Code and VAT No. 03269341206, REA BO-505415 (hereinafter, also “Sugo”), for activities related to the operational management of the Site and e-commerce services, including, depending on the assignment, order management, customer support, returns, refunds, technical and administrative support, and management of payment flows. When operating on behalf of Think Tank S.R.L., according to the latter’s instructions and for purposes determined by the Controller, Sugo acts as a data processor pursuant to Art. 28 of the GDPR. Sugo is also appointed to receive and collect, in the name and on behalf of the Controller, sums related to purchases made on the Site and, where applicable, to manage related refund flows. Only where and to the extent that, in relation to specific further processing connected to bank relationships or payment accounts held by Sugo, the latter is required to process personal data to fulfill legal obligations directly incumbent upon it, manage its own relationships with banks or payment service providers, or protect its own rights, independently determining the purposes and essential means of the processing, does Sugo operate as an independent data controller for such activities. This potential status does not extend to activities carried out exclusively on behalf of the Controller.
6.2. Shopify
The Site is built and hosted using the Shopify platform. As part of the services rendered to the Controller, Shopify generally processes customer personal data as a data processor according to the applicable Data Processing Addendum. In relation to certain proprietary services aimed at consumers or advanced features, including services that may require the activation of Shopify Network Intelligence, Shopify may also process certain data as an independent controller, according to its own conditions and policies. More information on Shopify’s data processing and related privacy options is available at https://www.shopify.com/it/legal/privacy and, where applicable, at https://privacy.shopify.com.
6.3. Payment service providers, banks, and other recipients
Data may also be communicated or made accessible to:
– payment service providers, digital wallets, card circuits, issuers, banks, and payment institutions, including PayPal, Shopify Payments, Klarna, or other subjects available from time to time at checkout, which may process data as independent controllers for the purposes determined in their respective policies;
– couriers, carriers, shippers, logistics operators, and pickup points, to the extent necessary for delivery, collection, and management of any returns;
– IT, hosting, security, technical support, customer care, communications, e-mail, analytics, marketing, returns management, and other application service providers integrated into the Site, which operate as data processors or, where the conditions are met, as independent controllers;
– accountants, consultants, lawyers, auditors, and other professionals, within the limits necessary for the performance of their respective assignments;
– judicial, administrative, tax, public security authorities, or other public subjects, when communication is provided for or required by law;
– personnel, collaborators and subjects authorized by the Controller, within the limits of their respective duties and instructions.
The updated list of data processors can be requested from the Controller at the contact details indicated in this policy.
7. DATA TRANSFER TO THIRD COUNTRIES
The use of Shopify and other technology, payment, analytics, marketing, or support providers may involve the processing or transfer of personal data outside the European Economic Area. Shopify International Limited, as the reference contractual entity for EMEA merchants, may rely on group companies and sub-processors established in different countries; Shopify also declares that it currently stores some data of European merchants and customers “at rest” in Europe, while continuing to carry out international transfers necessary for the provision of its services.
When data is transferred to countries that do not benefit from an adequacy decision by the European Commission, the transfer is carried out using appropriate safeguards pursuant to Articles 44 et seq. of the GDPR, such as, depending on the case, Binding Corporate Rules, standard contractual clauses approved by the European Commission, and further measures required by applicable law. For transfers carried out by Shopify, please also refer to the relevant Data Processing Addendum and the information on international transfers published by Shopify. Other providers possibly involved apply the transfer mechanisms indicated in their respective policies and conditions.
8. DATA SUBJECT RIGHTS
In the cases and within the limits provided by the GDPR, the Data Subject may exercise the following rights against the Controller:
– obtain confirmation of the existence of processing and access their personal data and the information provided for by Art. 15 of the GDPR;
– obtain the rectification of inaccurate data and the completion of incomplete data pursuant to Art. 16 of the GDPR;
– obtain the erasure of personal data in the cases provided for by Art. 17 of the GDPR;
– obtain the restriction of processing in the cases provided for by Art. 18 of the GDPR;
– receive, in the cases provided for by Art. 20 of the GDPR, the data provided to the Controller in a structured, commonly used and machine-readable format and transmit them to another controller;
– object, for reasons connected to their particular situation, to processing based on legitimate interest pursuant to Art. 21 of the GDPR and object at any time to processing for direct marketing purposes;
– withdraw consent given at any time, without prejudice to the lawfulness of the processing carried out before the withdrawal;
– not to be subject, in the cases provided for by Art. 22 of the GDPR, to decisions based solely on automated processing which produce legal effects or similarly significantly affect the person;
– lodge a complaint with the competent supervisory authority. In Italy, the Data Protection Authority (Garante per la protezione dei dati personali) can be reached via the website www.garanteprivacy.it.
Requests relating to processing carried out by Think Tank S.R.L. can be sent to the Controller at the address support@weilizheng.com. For processing carried out by third parties as independent controllers, including Shopify in cases where it acts in such capacity, payment service providers, and, limited to any specific activities indicated in point 6.1, Sugo, the Data Subject may exercise their rights directly against the relevant controller according to their respective policies.
9. CHANGES TO THE PRIVACY POLICY
The Controller reserves the right to modify or update this Privacy Policy to adapt it to regulatory, organizational, technical, or service-related changes. The updated version will be published on the Site with an indication of the date of the last update. In the event of substantial changes that require specific communication to Data Subjects, the Controller will adopt the information measures required by applicable law.